Data Processing Agreement
Last updated: 2026-06-14
Introduction
This Data Processing Agreement ("DPA") forms part of the agreement between the Customer and GDPRChecker, operated by QIN ZHANYA (51, Mais 1, Triq il-Molletta, Is-Swieqi, Malta) ("Processor", "we", "us") when the Customer uses GDPRChecker to process personal data relating to the Customer's website visitors, consent records, or other end users on the Customer's behalf.
This DPA applies whenever we act as a processor and the Customer acts as controller under applicable data protection law (including GDPR and UK GDPR).
Version 2026-06-14.
Definitions
"Customer", "you", or "Controller" means the entity that determines the purposes and means of processing end-user personal data through the Service.
"Processor" means GDPRChecker as described above.
"Personal Data", "Processing", "Data Subject", "Sub-processor", and "Supervisory Authority" have the meanings in applicable data protection law.
"Service" means the GDPRChecker platform, runtime scripts, consent tools, dashboards, APIs, and related services subscribed to by the Customer.
"Customer Data" means personal data processed by Processor on behalf of Customer through the Service.
Annex 1 — Processing Details
This Annex describes the processing performed under this DPA:
- Subject matter: GDPRChecker platform services, runtime scripts, consent management, compliance scanning, and runtime telemetry configured by the Customer.
- Duration: for the term of the Customer's use of the Service, plus deletion, backup, and legal retention periods described in this DPA and the Terms.
- Nature and purpose: hosting, storing, analyzing, and displaying customer site configuration, consent logs, scan results, runtime telemetry, and related support data solely to provide and secure the Service.
- Categories of data subjects: Customer users (administrators and team members), Customer website visitors, and end users interacting with consent banners or runtime controls.
- Categories of personal data: account identifiers, email addresses, authentication metadata, site domains, IP-derived technical data if collected, consent choices, timestamps, browser or runtime telemetry, scan evidence, and related technical logs.
- Special category data: the Service is not intended for special category data (Article 9 GDPR) or criminal offence data (Article 10 GDPR). Customer must not submit such data through the Service unless separately agreed in writing.
Processor Obligations
Processor shall:
- Process Customer Data only on documented instructions from Customer, including through Service configuration, the Terms, this DPA, and applicable order or checkout flows.
- Ensure persons authorized to process Customer Data are bound by confidentiality.
- Implement appropriate technical and organizational measures under Article 32 GDPR as described in Annex 2.
- Not engage another processor without Customer authorization subject to the Sub-processors section below.
- Assist Customer, taking into account the nature of processing, with data subject requests where technically feasible.
- Assist Customer with security, breach notification, and impact assessment obligations where applicable and where Processor has relevant information.
- At Customer's choice, delete or return Customer Data when the Service ends, subject to legal retention requirements.
- Make available information reasonably necessary to demonstrate compliance and allow audits described below.
Customer Obligations
Customer shall:
- Ensure a valid legal basis and appropriate notices exist for processing end-user data through the Service.
- Configure the Service lawfully, including consent categories, policy links, and blocking rules.
- Not instruct Processor to process data unlawfully.
- Not submit special category data unless separately agreed in writing.
- Respond to data subject and supervisory authority requests relating to Customer's role as controller.
Sub-processors
Customer authorizes Processor to use Sub-processors to deliver the Service, depending on the features Customer uses.
GDPRChecker may use the following subprocessors to provide the Service, depending on the features you use. Processor remains responsible for Sub-processors to the extent required by applicable data protection law.
The current Sub-processor list is published at https://www.gdprchecker.online/dpa/subprocessors and forms part of this DPA.
Processor will provide at least 30 days' prior notice of material Sub-processor changes where required by applicable law, by email to the Customer's account address and by updating the published list.
Customer may object to a new Sub-processor on reasonable data protection grounds where legally required by notifying legal@gdprchecker.online within 14 days of notice. If the parties cannot resolve the objection with a commercially reasonable alternative, Customer may terminate the affected paid Service before the new Sub-processor begins processing.
Processor will impose data protection obligations on Sub-processors by contract or equivalent legal mechanism.
Annex 2 — Technical and Organizational Measures
Processor maintains measures appropriate to the risk, including the following categories. Specific implementations may evolve with the Service and infrastructure providers.
- Access control — role-based access, authentication for administrative systems, and revocation of access when no longer required.
- Least privilege — personnel and systems receive only the access needed for their function.
- Encryption in transit — TLS for data transmitted over public networks.
- Encryption at rest — where provided by infrastructure providers for stored Customer Data.
- Logging and monitoring — security and operational logging to detect abuse, errors, and unauthorized access.
- Backup and recovery — periodic backups and recovery procedures consistent with service continuity needs.
- Incident response — internal procedures to assess, contain, and remediate security incidents.
- Sub-processor due diligence — contractual safeguards and review of Sub-processors that process Customer Data.
- Secure development practices — change control, dependency management, and testing appropriate to the Service.
Personal Data Breach
Processor will notify Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Data.
Notification will include information reasonably available to Processor to help Customer meet its breach notification obligations. Processor will cooperate in good faith with Customer's investigation and remediation efforts.
International Transfers
Customer Data may be processed in or transferred to countries outside the European Economic Area or United Kingdom where Sub-processors or infrastructure providers operate.
Where required by applicable law, Processor implements appropriate safeguards, including EU Standard Contractual Clauses and equivalent mechanisms.
Where UK GDPR applies, Processor uses the UK International Data Transfer Addendum or another lawful UK transfer mechanism where required.
Audit
Upon reasonable written request, Processor will first provide documentation and written responses reasonably necessary to demonstrate compliance with this DPA.
If documentation is insufficient and mandatory law or a confirmed material breach requires further verification, Customer may request an audit no more than once per calendar year unless required by a Supervisory Authority, following a confirmed material breach, or otherwise required by mandatory law.
Audits require reasonable advance notice, must protect confidentiality and security, and must not unreasonably disrupt Processor operations.
Deletion and Return
Upon termination of the Service or written request, Processor will delete or return Customer Data within a reasonable period, except where retention is required by law or legitimate backup cycles. Backups are purged according to Processor retention schedules.
Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms, except where prohibited by applicable law.
Governing Law and Order of Precedence
This DPA is governed by the laws of Malta.
If there is a conflict between this DPA and the Terms regarding processing of Customer Data, this DPA prevails. Mandatory data protection law always prevails over conflicting contract terms.
Contact
For privacy, data protection, or legal requests, please contact us at legal@gdprchecker.online.
Legal name: QIN ZHANYA
Title: Founder & Product Builder
Postal address: 51, Mais 1, Triq il-Molletta, Is-Swieqi, Malta
Country: Malta
Email: legal@gdprchecker.online
Contact page: https://www.gdprchecker.online/contact
Sub-processor list: https://www.gdprchecker.online/dpa/subprocessors
Terms: https://www.gdprchecker.online/terms