Last updated: 2026-09-06 Version: 1
This Data Processing Agreement ("DPA") forms part of the agreement between Filova Ltd, a company registered in England and Wales, company number 17263134, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom, email privacy@filova.io, phone +44 20 3967 8386 ("Processor", "Filova", trading as "Consentivo"), and the customer identified in the applicable order or account ("Controller"), governing the Processor's processing of personal data on the Controller's behalf in the course of providing the Consentivo service.
This DPA is incorporated into the Terms of Service (consentivo.com/en/legal/terms-of-service) and forms part of the parties' agreement wherever the Processor processes Personal Data on the Controller's behalf. The Controller's acceptance of the Terms of Service — through the Service's legal-acceptance flow or an order form referencing them — is acceptance of this DPA. No separate signature is required, and this DPA is fully effective without one.
Governing law: England and Wales.
"GDPR" means Regulation (EU) 2016/679 and, as applicable, the UK GDPR as defined in the Data Protection Act 2018. "Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Sub-processor" have the meanings given in the GDPR. "KVKK" means the Turkish Personal Data Protection Law No. 6698 and its implementing regulations, where applicable to the Controller's own data subjects. Where KVKK applies, the Controller is the "veri sorumlusu" (data controller) and the Processor is the "veri işleyen" (data processor) with respect to the same categories of Personal Data described in this DPA — the GDPR/KVKK terminology differs, but the controller/processor role split described throughout this DPA is the same under both regimes.
The Processor processes Personal Data on the Controller's behalf solely to provide the Consentivo consent-management service: recording consent choices made by visitors to the Controller's website(s), and (where the Controller has enabled it) scanning the Controller's website(s) for cookies and scripts to help the Controller categorize them. This DPA continues for as long as the Processor processes Personal Data on the Controller's behalf under the parties' agreement.
anon_id); the consent choice and categories accepted/
rejected; timestamp; detected region/legal regime; a country code derived
from IP address (the raw IP address is not stored in Personal Data records
processed under this DPA — infrastructure providers listed in Annex 1 may
still transiently process IP addresses in their own server/request logs
under their own retention policies); a Global Privacy Control signal if
present. The browser's user-agent string is not stored in these records
in any form, neither raw nor hashed. The Processor does not process the
data subject's name, email address, or other directly identifying
information as part of this service, nor any special category / sensitive
Personal Data.The Processor shall:
Process Personal Data only on the Controller's documented instructions — including with regard to international transfers — unless required to do otherwise by law applicable to the Processor, in which case the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such notice.
Ensure confidentiality — personnel authorized to process the Personal Data are subject to a duty of confidentiality.
Implement appropriate technical and organizational security measures under GDPR Article 32, as set out in Annex 2.
Engage Sub-processors only with the Controller's general authorization as set out in Annex 1, and inform the Controller of any intended addition or replacement of a Sub-processor, giving the Controller the opportunity to object on reasonable data-protection grounds.
Assist the Controller, insofar as reasonably possible, in responding to requests from data subjects to exercise their rights, and in the Controller's compliance with its obligations regarding security, breach notification, data protection impact assessments, and consultation with supervisory authorities, taking into account the nature of processing and the information available to the Processor.
Notify the Controller without undue delay after becoming aware of a Personal Data breach affecting the Controller's Personal Data, and provide the information reasonably available to the Processor so that the Controller can meet its own notification obligations, including under GDPR Article 33.
At the Controller's choice, delete or return all Personal Data to the Controller after the end of the provision of services, and delete existing copies, except to the extent applicable law requires the Processor to continue storing it.
This applies to consent records as it does to all other Personal Data. During the term, consent records are held on an append-only basis so that they remain reliable evidence of the consent decisions actually collected: they are not altered, and no ordinary application path, API key or service credential can delete one. That integrity protection does not override this Section 7. On the Controller's documented instruction at the end of the provision of services — or where erasure is otherwise required by applicable law or a competent authority — the Controller's consent records are erased through a restricted internal process available only to authorized personnel, targeted at the Controller's own organization or at a specific visitor identifier, and recorded without retaining the identifier erased.
This process is manual, not automatic. Nothing is deleted on a fixed schedule or by an automated job, and Consentivo does not provide self-service export or deletion tooling. Return or deletion is carried out on a verified request, subject to verification of identity and authority and to the Processor's security requirements.
Make available to the Controller all information necessary to demonstrate compliance with this Article and allow for, and contribute to, audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, subject to: at least 30 days' prior written notice; no more than once per 12-month period (except where required following a Personal Data breach or by a supervisory authority); confidentiality; and the audit not unreasonably interfering with the Processor's normal business operations.
The Controller warrants that it has a lawful basis under applicable law (GDPR, KVKK, CCPA, or other) for the collection and processing of Personal Data via the Consentivo service, and that its instructions to the Processor comply with applicable law. In particular, the Controller is responsible for: providing lawful notice to its own website visitors (e.g. its own cookie/privacy notice); obtaining any consent required beyond what the Consentivo banner itself records; correctly configuring the banner and cookie/script categorization for its own site; responding to data-subject access requests concerning its own visitors as the controller of that relationship (with the Processor's assistance per Section 4.5); and determining the appropriate retention period for its own account and configuration data, subject to Section 4.7.
See Annex 1. The Controller authorizes the engagement of the listed Sub-processors generally, subject to the notice-of-change right in Section 4.4.
Personal Data may be transferred outside the UK/EEA in the course of providing the Service. The Processor contracts with each Sub-processor on that Sub-processor's own published data processing terms, and relies on the transfer safeguards those terms provide:
eu-central-1): Supabase's own
disclosed Sub-processors (its cloud infrastructure and support providers)
are located in the United States and Singapore. Supabase's published Data
Processing Agreement attaches the EU Standard Contractual Clauses, the UK
International Data Transfer Addendum and a Swiss Addendum, and provides that
entering into that agreement constitutes signature of them. Remote access to
Supabase's EU-hosted data by the Processor's own UK-based personnel is itself
treated as a transfer under EDPB Recommendations 01/2020.No payment provider is currently engaged, so no payment-related transfer takes place. If one is engaged, Annex 1 and this Section will be updated and Controllers notified under Section 4.4 before processing begins.
The Processor states the terms it contracts on rather than asserting that a particular mechanism applies to a particular route, because that depends on the contracting entity and the destination in each case. Where the Processor has not verified which mechanism applies, it does not assert one.
Where the Controller's own data subjects are protected under KVKK, the KVKK-specific position is set out separately at consentivo.com/tr/yasal/kvkk-aydinlatma-metni.
Each party's total liability arising out of or in connection with this DPA, whether in contract, tort (including negligence), or otherwise, shall not exceed the greater of (a) the total fees paid by the Controller to the Processor under the parties' agreement in the 12 months preceding the event giving rise to the claim and (b) GBP 100, except where such limitation is not permitted by applicable law (including for death, personal injury, fraud, or breaches of confidentiality or data protection obligations that cannot be limited by law).
The GBP 100 floor matters while the Service is provided free of charge: fees paid may be nil, and this cap is aligned with Section 8 of the Terms of Service into which this DPA is incorporated.
This DPA and any dispute arising out of or in connection with it is governed by the laws of England and Wales, and the courts of England and Wales shall have exclusive jurisdiction, without prejudice to any mandatory local data protection law obligations the Controller may separately owe to its own data subjects (e.g. under KVKK, where the Controller is itself subject to Turkish law).
| Sub-processor | Purpose | Location | Status |
|---|---|---|---|
| Supabase | Database (Postgres) and authentication hosting | EU (eu-central-1); Supabase's own Sub-processors (infrastructure, support) in the United States and Singapore |
Live |
| Vercel | Application hosting | United States (default function region; an EU region is not currently configured) | Live |
| Google Cloud Platform (Cloud Run) | Execution environment for the cookie-scanning worker | Region set at deployment; not currently fixed | Feature disabled across the Service — no Personal Data processed at present |
No payment provider is engaged. Billing is not enabled, so no Personal Data is processed for payment purposes by anyone on the Processor's behalf.
The measures below are those currently implemented.
proof_hash) computed over the record's contents, so alteration
by a party without the signing key can be detected.Section 7 (International transfers) and Annex 1 (Sub-processors) were prepared based on official regulatory sources (European Commission, EDPB, UK ICO, KVKK Kurumu) and the relevant vendors' own published data processing terms, current as of the "Last updated" date above. This is not a substitute for legal advice.
Optional signature blocks
This DPA is incorporated into the Terms of Service and is effective without signature for the standard online relationship (see the introduction above). The blocks below exist only for Controllers who require a separately executed copy — for example alongside an order form or a procurement process. Leaving them blank does not affect the validity or effect of this DPA.
For and on behalf of Filova Ltd: ___________________________ Date: _______
For and on behalf of the Controller: ___________________________ Date: _______