Data Processing Agreement (DPA)
Last Updated: September 7, 2026
1. Definitions
- Controller: The customer who uses WebPage Cookie Consent services
- Processor: Xinc Aktiebolag (WebPage Cookie Consent)
- Personal Data: Any information relating to an identified or identifiable natural person
- Processing: Any operation performed on Personal Data
2. Scope and Purpose
This Data Processing Agreement ("DPA") governs the processing of Personal Data by WebPage Cookie Consent on behalf of the Controller in connection with the provision of cookie consent management services.
The Processor agrees to process Personal Data only for the purpose of providing the Service and in accordance with the Controller's instructions and applicable data protection laws.
3. Processing Activities
3.1 Types of Personal Data
The Processor may process the following categories of Personal Data:
- Consent preferences and choices
- IP addresses and location data
- Browser and device information
- Website usage data
- Cookie identifiers
3.2 Categories of Data Subjects
Personal Data relates to visitors of the Controller's websites who interact with the cookie consent banner.
4. Processor Obligations
The Processor agrees to:
- Process Personal Data only in accordance with documented instructions from the Controller
- Ensure that persons authorized to process Personal Data are bound by confidentiality obligations
- Implement appropriate technical and organizational measures to ensure security
- Assist the Controller in responding to data subject requests
- Notify the Controller of any data breaches without undue delay
- Delete or return Personal Data upon termination of services
5. Security Measures
The Processor implements the following security measures:
- Encryption of data in transit and at rest
- Access controls and authentication mechanisms
- Regular security assessments and updates
- Incident response procedures
- Data backup and recovery systems
6. Sub-Processors
The Processor may engage sub-processors to assist in providing the Service. The Processor will:
- Inform the Controller of any intended changes to sub-processors
- Ensure sub-processors are bound by equivalent data protection obligations
- Remain fully liable for sub-processor compliance
7. Data Subject Rights
The Processor will assist the Controller in fulfilling data subject rights requests, including:
- Right of access
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right to data portability
- Right to object
8. Data Retention
Personal Data will be retained only for as long as necessary to provide the Service or as required by law. Upon termination, data will be deleted or returned as requested by the Controller.
9. International Transfers
If Personal Data is transferred outside the European Economic Area, appropriate safeguards will be implemented, such as Standard Contractual Clauses approved by the European Commission.
10. Audit Rights
The Controller has the right to audit the Processor's compliance with this DPA, subject to reasonable notice and confidentiality obligations.
11. Liability
The Processor shall be liable for any damages caused by processing that violates this DPA or applicable data protection laws.
12. Contact
For questions about this DPA, please contact:
Xinc Aktiebolag
Email: dpo@webpage.nu
Website: Contact Us