ConsentLedger

DATA, WITH RESPONSIBILITY

Data Processing Agreement

This agreement accompanies the merchant terms. Authorized merchants can review and accept both documents in the app’s Agreements page.

Version 2026-09-19

Provider: ConsentLedger
290 Myrtle Street, Manchester, NH 03104, United States
[email protected]

1. Parties, roles and instructions

This DPA is between ConsentLedger (Provider), identified below, and the merchant identified in the agreement confirmation (Merchant). Merchant determines the purposes and means of processing buyer personal data and acts as controller; Provider processes that data on Merchant’s behalf as processor. If Merchant acts for another controller, Merchant must have authority to give these instructions. For account administration, billing contacts, security and legal obligations that Provider determines independently, Provider is responsible for its own processing as explained in the privacy policy.

Provider will process Merchant personal data only on documented instructions in this agreement, Merchant’s app configuration and lawful written requests, including instructions concerning disclosure and international transfers. If law requires other processing, Provider will inform Merchant beforehand unless prohibited. Provider will promptly flag instructions it believes breach applicable data protection law and pause the affected instruction pending clarification. Merchant is responsible for lawful collection, required notices and a valid legal basis; a buyer checkbox is not a substitute for those duties.

2. Processing schedule

Subject and purpose: operate Merchant’s buyer acknowledgement and order evidence workflow. Activities: receive and match rule conditions, display questions, validate required responses, record and organize evidence, search and retrieve it, send Merchant-directed exports or order references, handle privacy requests and delete expired data. Processing lasts for the service period and the limited return or deletion period described below.

Data subjects: Merchant’s buyers and customers, and authorized store users where present in operational records. Data categories: store and order identifiers, order references, customer identifiers when available, submitted checkbox or text answers, published rule wording and version, confirmation and retention timestamps, and relevant product and checkout attributes used for rule matching. Authentication, access and export audit events support operation and security. Buyer-entered text may itself identify a person. No sensitive personal data is required or intended. Merchant must not configure questions to collect it.

Merchant may determine lawful questions and targeting, choose a plan and its retention period, configure optional order summaries and export destinations, issue access or erasure requests and end the service. Provider will not sell or share buyer records for cross-context behavioral advertising, use them for its own advertising, or combine them with unrelated datasets for an independent commercial purpose.

3. Confidentiality and safeguards

Provider will restrict access to persons who need it to provide or secure the service and who are bound by confidentiality duties. Provider will maintain measures appropriate to the nature and risk of processing, review their effectiveness and address identified weaknesses. Current measures include HTTPS, certificate-verified encrypted database connections, authenticated Shopify store access, store-scoped queries, guarded export credentials, validated privacy webhooks, access/export audit events and scheduled retention deletion. Secrets are kept out of source control and ordinary logs.

Provider will maintain incident handling and reasonable measures for service resilience and recovery appropriate to the service. The current hosting configuration is a single web service with a development database; this DPA does not represent that dedicated backups, point-in-time recovery, high availability or independent security certification are included. Merchant should assess suitability for its risk and securely retain any necessary independent exports. Provider will not materially reduce the agreed safeguards during processing.

4. Subprocessors

Merchant gives general written authorization to use DigitalOcean, LLC for application hosting and database storage, currently in New York, United States. This is the current subprocessor list. Shopify supplies Merchant’s commerce platform and billing under Merchant’s own relationship with Shopify; Merchant-configured recipients of exports are Merchant’s responsibility and are not selected as Provider’s subprocessors by that configuration.

Provider will impose appropriate written data protection and confidentiality obligations on its subprocessors and remains responsible to Merchant for their performance of delegated processing obligations. Provider will give at least 30 days’ advance notice of an intended subprocessor addition or replacement through the app or Merchant’s designated contact, identifying the service and location. Merchant may object on reasonable data protection grounds during that period. The parties will seek an alternative; if unresolved, Merchant may end the affected service before that subprocessor processes its data and request return or deletion.

5. International processing

The service stores app and database records in the United States. Merchant must consider this location before sending personal data. Where applicable law restricts an international transfer, the parties must establish the required lawful transfer mechanism and any supplementary safeguards before that restricted transfer begins. Contact Provider to arrange the necessary transfer documentation. This DPA alone is not an executed set of EU standard contractual clauses, a UK transfer addendum, or a claim of certification under a transfer framework. Do not send data requiring an additional transfer mechanism until it is in place.

6. Rights requests and assistance

Provider will promptly refer buyer requests concerning Merchant’s records to Merchant, unless legally required to respond directly. Taking account of the processing and information available, Provider will reasonably assist Merchant with access, correction, deletion, restriction, portability and objection requests. The app supports Shopify customer data requests and erasure webhooks and a merchant privacy workflow. Contact support for assistance beyond those controls; do not send passwords or unnecessary buyer information.

Provider will also provide reasonable information and assistance with Merchant’s security obligations, breach assessment, data protection impact assessments and prior consultation with supervisory authorities where applicable. Merchant remains responsible for its decisions and notices to buyers and regulators.

7. Personal data incidents

Provider will notify Merchant without undue delay after becoming aware of a personal data breach affecting Merchant’s data. Notification will use Merchant’s designated contact or an available authenticated store contact and describe known facts, affected data and people where available, likely consequences, response measures and a contact for follow-up. Information may be supplied in stages as it becomes available. Provider will take reasonable containment and remediation steps and cooperate with Merchant. Notification is not an admission of liability. Merchant should designate a monitored contact and promptly report suspected incidents to Provider.

8. Retention, return and deletion

Each evidence record receives a deletion deadline when created: 90 days for Starter, 365 days for Growth or 730 days for Pro. Existing deadlines do not extend with a plan change. Scheduled maintenance deletes expired evidence. Customer erasure removes associated retained records; limited opaque suppression markers prevent delayed events from recreating erased data. Merchant-directed copies in Shopify or export destinations are governed by Merchant’s handling and those systems’ deletion processes.

At the end of the service, Merchant may request return of remaining personal data in a commonly usable format and subsequent deletion, or deletion without return. Contact support before uninstalling or automated erasure, because already deleted or expired records cannot be returned. Provider will assist with return regardless of plan export eligibility and complete a verified termination deletion request within 30 days, unless a shorter legal deadline applies. Shopify’s shop erasure notification removes store app data and sessions, including agreement records. Only data that law requires to be retained may remain, isolated from ordinary use and deleted when that requirement ends; Provider will explain that exception unless prohibited.

9. Verification and applicable privacy duties

Provider will make information reasonably necessary to demonstrate its compliance with this DPA available to Merchant and allow and contribute to proportionate audits or inspections by Merchant or a qualified independent auditor under confidentiality safeguards. Arrange scope, timing and secure access in advance where possible; protect other merchants’ data and avoid unnecessary disruption. These arrangements do not prevent urgent checks, regulator access or rights required by law.

Where applicable US state privacy law treats Provider as a service provider or contractor, Provider will retain, use and disclose personal information only for the specified services and permitted purposes, will not sell or share it as prohibited by that law, and will provide the level of protection required by that law. Provider will notify Merchant if it can no longer meet those duties. Merchant may take reasonable steps to verify compliance and stop and remediate unauthorized use. Nothing in this DPA reduces data subjects’ mandatory rights or either party’s obligations under applicable law.

10. Acceptance and notices

Provider offers this DPA as part of the merchant terms. It takes effect between the parties when Merchant’s authorized representative explicitly accepts it in the app, or when both parties separately execute it in writing. The app records the store, merchant and representative names, designated contact, version, exact agreement text, its integrity hash and acceptance time. A store-authenticated submission does not independently verify the representative’s legal identity. Keep a copy of the confirmation for your records. Send instructions, objections, audit requests and privacy notices to Provider at the contact below.