Skip to content
How it works Plans and pricing FAQs
Join the beta
How it works Plans and pricing FAQs Contact us Join the beta
  1. Home
  2. Legal
  3. Data processing agreement
On this page
  • About this agreement
  • Roles and scope
  • Details of processing
  • Our obligations
  • Sub-processors
  • International transfers
  • Personal data breaches
  • When the service ends
  • Information and audits
  • General
  • Annex: security measures
  • Annex: sub-processors

Data processing agreement

Last updated 6 October 2026

About this agreement

This data processing agreement (“DPA”) forms part of the agreement under which Webwax Ltd, a company registered in England and Wales (company number 08125321), which runs the FortuneCookies service at fortunecookies.cloud (“we”, “us”), provides that service to a client (“you”), as described in our service terms. It applies whenever we process personal data on your behalf, and meets the requirements of Article 28 of the UK GDPR and, where it applies, Article 28 of the EU GDPR. For clients in Canada, it is also the written contract that PIPEDA and Quebec’s Law 25 expect when personal information is entrusted to a service provider.

If this DPA and the rest of our agreement conflict on data protection, this DPA wins. Words such as “controller”, “processor”, “personal data”, “processing” and “personal data breach” have the meaning given in the UK GDPR or EU GDPR, as applicable.

Roles and scope

You are the controller of the personal data processed through the service, and we are your processor (for Canadian clients, your service provider). You’re responsible for having a lawful basis for the processing, for the cookie categories and banner wording you approve, and for telling visitors to your websites about it in your own privacy information.

We process personal data only on your documented instructions. Our agreement, this DPA and the settings and sign-offs you give us are your instructions. We’ll tell you straight away if we think an instruction breaks data protection law.

Details of processing

Subject matterShowing a cookie consent banner on your websites, holding back trackers until visitors agree, recording visitors’ choices, and scanning your websites.
DurationFor as long as we provide the service, plus the deletion period in “When the service ends”.
Nature and purposeDelivering the banner script to visitors’ browsers; storing a record of each choice as proof of consent; letting you look up a visitor’s record when they ask; loading your public web pages to find the cookies and trackers they use; limiting abuse.
Categories of data subjectsVisitors to your websites.
Types of personal dataConsent records: a random consent ID (also stored in the visitor’s fc_consent cookie), the time, the choices made, the banner version, the page path (without query string) and the visitor’s country. Technical data: IP address and browser details, used briefly to deliver the banner and limit abuse, and not stored with consent records.
Special category dataNone.
RetentionConsent records are deleted automatically two years after they were made, or sooner on your instruction.
Storage locationConsent records are stored in Cloudflare’s EU region (D1, EU jurisdiction).

Our scans load your public pages as a new visitor would. They aren’t designed to collect personal data; if a page shows any, we don’t keep it beyond the scan’s list of cookies and trackers.

Our obligations

  • Confidentiality. Everyone we authorise to process the personal data is bound by confidentiality.
  • Security. We take appropriate technical and organisational measures under Article 32, including those in the security annex, and keep them under review.
  • Individuals’ rights. Taking into account the nature of the processing, we help you respond to requests from individuals, including by looking up a visitor’s consent records by their consent ID. If we receive a request directly, we pass it to you without undue delay and don’t respond ourselves unless you ask us to.
  • Other help. We give you reasonable help with security, breach notifications, data protection impact assessments (including Law 25 privacy impact assessments), and consultations with a supervisory authority, taking into account the information available to us.
  • Records. We keep a record of the processing we carry out for you, as Article 30(2) requires.

Sub-processors

You give us general authorisation to use the sub-processors listed in the sub-processor annex. We’ll give you at least 30 days’ notice by email before adding or replacing one, so you can object on reasonable data protection grounds. If we can’t address your objection, you may end the affected service without penalty.

We put a written contract in place with each sub-processor that gives the same level of protection as this DPA, and we remain responsible to you for their performance.

International transfers

We are based in the UK. For clients in the EU or EEA, transfers to us are covered by the European Commission’s adequacy decision for the UK; for clients in Canada, by our commitments in this DPA. Consent records are stored in the EU. Cloudflare may process technical data in transit outside the UK, EEA and Canada, including in the United States; those transfers rely on Cloudflare’s certification under the EU–US Data Privacy Framework and its UK Extension, backed by the EU Standard Contractual Clauses and the UK International Data Transfer Addendum in Cloudflare’s data processing terms. We won’t make any other restricted transfer without a lawful transfer mechanism in place.

Personal data breaches

We’ll tell you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach (for Canadian clients, a confidentiality incident) affecting your data. We’ll give you the information you need to meet your own notification duties as it becomes available, and take reasonable steps to contain and fix the breach.

When the service ends

When the service ends, we’ll send you a copy of your consent records and sign-off history on request. Within 30 days we’ll delete the personal data we process for you, unless the law requires us to keep it. Backups held by our sub-processors are deleted in line with their normal cycles.

Information and audits

We’ll make available the information you reasonably need to show compliance with Article 28, and allow for and contribute to audits, including inspections, by you or an auditor you appoint. Audits need reasonable notice, take place during business hours, no more than once a year unless a breach or a regulator requires it, and are subject to confidentiality. We may first answer by giving you relevant documents, such as our sub-processors’ security certifications.

General

This DPA lasts as long as we process personal data for you. The liability terms in our service terms apply to it, except where the law doesn’t allow them to. It is governed by the law of England and Wales, unless the law requires otherwise.

Annex: security measures

  • All connections use HTTPS, with HSTS.
  • No IP addresses or browser details are stored with consent records; the consent ID is random and doesn’t identify a person by itself.
  • Consent records are stored in an EU-jurisdiction database and deleted automatically after two years.
  • Admin access is limited to named staff, protected by a strong password (stored only as a salted hash), rate-limited sign-in and secure, HTTP-only session cookies.
  • Abuse limits on the consent-logging endpoint.
  • Code changes are tested automatically and kept in version control before they go live.

Annex: sub-processors

Sub-processorWhat it doesLocation
Cloudflare, Inc.Hosting of the banner script, admin and database; storage of consent records; headless browser for scans; email delivery.Consent records: EU. Network: global.

Cookie consent, done for you. Set up, checked and looked after for small and medium websites in the UK, the EU and Canada.

Service

  • How it works
  • What a scan finds
  • Plans and pricing
  • FAQs

Legal

  • Privacy notice
  • Cookie notice
  • Legal notice
  • Service terms
  • Data processing agreement

Contact

  • Join the beta
  • Contact us
  • hello@fortunecookies.cloud
  • privacy@fortunecookies.cloud
© 2026 FortuneCookies No cookie banner here, on purpose.