Data Processing Agreement
Effective on the date you accept the ConsentHub Terms of Service or begin using the service. This DPA is a click-through agreement between you ("Customer", the Data Controller / Data Fiduciary) and ConsentHub ("Processor", the Data Processor / Data Processor under the DPDP Act).
1. Roles
Customer is the Controller / Data Fiduciary of personal data submitted to the service. ConsentHub is the Processor and acts only on Customer's documented instructions, including as set out in the Terms and product configuration.
2. Scope and nature of processing
- Subject matter: providing the ConsentHub CMP and DSAR dashboard.
- Duration: for the term of the Terms plus any retention window.
- Categories of data subjects: Customer's website visitors and end users.
- Categories of personal data: hashed IP addresses, consent choices, user-agent, timestamps, DSAR request contact (email) and message text.
- Special categories: none processed by design; Customer must not submit special category data.
3. Processor obligations (GDPR Art. 28 / DPDP)
- Process personal data only on documented Customer instructions.
- Ensure persons authorised to process are under confidentiality obligations.
- Implement appropriate technical and organisational security measures (see Annex A).
- Assist Customer with data subject requests and security incident notification.
- Delete or return personal data at the end of the service, subject to legal retention.
- Make available information necessary to demonstrate compliance and support audits.
4. Sub-processors
Customer authorises ConsentHub to use the following sub-processors: managed Postgres (database and storage), email delivery, and hosting/edge CDN. A current list is available on request. ConsentHub will give prior notice of new sub-processors and Customer may object on reasonable data-protection grounds.
5. International transfers
Where personal data is transferred outside its country of origin, the parties rely on the Standard Contractual Clauses and equivalent DPDP-permitted transfer mechanisms, incorporated here by reference.
6. Security incidents
ConsentHub will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer data, with the information required for Customer to meet its notification obligations.
7. Data subject requests
ConsentHub provides in-product tooling (the DSAR queue, export, and delete actions) to help Customer respond to access, correction, deletion, and opt-out requests within regulatory timelines.
8. Return and deletion
On termination, Customer may export data via the dashboard. ConsentHub will delete Customer personal data within a reasonable period thereafter, unless retention is required by law.
9. Liability
Liability under this DPA is subject to the limitations in the Terms of Service.
Annex A — Security measures
- Encryption in transit (TLS) and at rest for the database.
- IP addresses are one-way hashed with a server-side salt; raw IPs are not stored.
- Row-level security on all customer-scoped tables.
- Least-privilege access for administrators and audit logging of admin actions.
- Regular backups and tested restore procedures.
Contact
For DPA questions, email support@consentsol.com.