Data processing agreement
Last updated 6 October 2026
About this agreement
This data processing agreement (“DPA”) forms part of the agreement under which Webwax Ltd, a company registered in England and Wales (company number 08125321), which runs the FortuneCookies service at fortunecookies.cloud (“we”, “us”), provides that service to a client (“you”), as described in our service terms. It applies whenever we process personal data on your behalf, and meets the requirements of Article 28 of the UK GDPR and, where it applies, Article 28 of the EU GDPR. For clients in Canada, it is also the written contract that PIPEDA and Quebec’s Law 25 expect when personal information is entrusted to a service provider.
If this DPA and the rest of our agreement conflict on data protection, this DPA wins. Words such as “controller”, “processor”, “personal data”, “processing” and “personal data breach” have the meaning given in the UK GDPR or EU GDPR, as applicable.
Roles and scope
You are the controller of the personal data processed through the service, and we are your processor (for Canadian clients, your service provider). You’re responsible for having a lawful basis for the processing, for the cookie categories and banner wording you approve, and for telling visitors to your websites about it in your own privacy information.
We process personal data only on your documented instructions. Our agreement, this DPA and the settings and sign-offs you give us are your instructions. We’ll tell you straight away if we think an instruction breaks data protection law.
Details of processing
| Subject matter | Showing a cookie consent banner on your websites, holding back trackers until visitors agree, recording visitors’ choices, and scanning your websites. |
|---|---|
| Duration | For as long as we provide the service, plus the deletion period in “When the service ends”. |
| Nature and purpose | Delivering the banner script to visitors’ browsers; storing a record of each choice as proof of consent; letting you look up a visitor’s record when they ask; loading your public web pages to find the cookies and trackers they use; limiting abuse. |
| Categories of data subjects | Visitors to your websites. |
| Types of personal data | Consent records: a random consent ID (also stored in the visitor’s fc_consent cookie), the time, the choices made, the banner version, the page path (without query string) and the visitor’s country. Technical data: IP address and browser details, used briefly to deliver the banner and limit abuse, and not stored with consent records. |
| Special category data | None. |
| Retention | Consent records are deleted automatically two years after they were made, or sooner on your instruction. |
| Storage location | Consent records are stored in Cloudflare’s EU region (D1, EU jurisdiction). |
Our scans load your public pages as a new visitor would. They aren’t designed to collect personal data; if a page shows any, we don’t keep it beyond the scan’s list of cookies and trackers.
Our obligations
- Confidentiality. Everyone we authorise to process the personal data is bound by confidentiality.
- Security. We take appropriate technical and organisational measures under Article 32, including those in the security annex, and keep them under review.
- Individuals’ rights. Taking into account the nature of the processing, we help you respond to requests from individuals, including by looking up a visitor’s consent records by their consent ID. If we receive a request directly, we pass it to you without undue delay and don’t respond ourselves unless you ask us to.
- Other help. We give you reasonable help with security, breach notifications, data protection impact assessments (including Law 25 privacy impact assessments), and consultations with a supervisory authority, taking into account the information available to us.
- Records. We keep a record of the processing we carry out for you, as Article 30(2) requires.
Sub-processors
You give us general authorisation to use the sub-processors listed in the sub-processor annex. We’ll give you at least 30 days’ notice by email before adding or replacing one, so you can object on reasonable data protection grounds. If we can’t address your objection, you may end the affected service without penalty.
We put a written contract in place with each sub-processor that gives the same level of protection as this DPA, and we remain responsible to you for their performance.
International transfers
We are based in the UK. For clients in the EU or EEA, transfers to us are covered by the European Commission’s adequacy decision for the UK; for clients in Canada, by our commitments in this DPA. Consent records are stored in the EU. Cloudflare may process technical data in transit outside the UK, EEA and Canada, including in the United States; those transfers rely on Cloudflare’s certification under the EU–US Data Privacy Framework and its UK Extension, backed by the EU Standard Contractual Clauses and the UK International Data Transfer Addendum in Cloudflare’s data processing terms. We won’t make any other restricted transfer without a lawful transfer mechanism in place.
Personal data breaches
We’ll tell you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach (for Canadian clients, a confidentiality incident) affecting your data. We’ll give you the information you need to meet your own notification duties as it becomes available, and take reasonable steps to contain and fix the breach.
When the service ends
When the service ends, we’ll send you a copy of your consent records and sign-off history on request. Within 30 days we’ll delete the personal data we process for you, unless the law requires us to keep it. Backups held by our sub-processors are deleted in line with their normal cycles.
Information and audits
We’ll make available the information you reasonably need to show compliance with Article 28, and allow for and contribute to audits, including inspections, by you or an auditor you appoint. Audits need reasonable notice, take place during business hours, no more than once a year unless a breach or a regulator requires it, and are subject to confidentiality. We may first answer by giving you relevant documents, such as our sub-processors’ security certifications.
General
This DPA lasts as long as we process personal data for you. The liability terms in our service terms apply to it, except where the law doesn’t allow them to. It is governed by the law of England and Wales, unless the law requires otherwise.
Annex: security measures
- All connections use HTTPS, with HSTS.
- No IP addresses or browser details are stored with consent records; the consent ID is random and doesn’t identify a person by itself.
- Consent records are stored in an EU-jurisdiction database and deleted automatically after two years.
- Admin access is limited to named staff, protected by a strong password (stored only as a salted hash), rate-limited sign-in and secure, HTTP-only session cookies.
- Abuse limits on the consent-logging endpoint.
- Code changes are tested automatically and kept in version control before they go live.
Annex: sub-processors
| Sub-processor | What it does | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting of the banner script, admin and database; storage of consent records; headless browser for scans; email delivery. | Consent records: EU. Network: global. |