Data Processing Agreement

Version of 10 October 2026. To sign a copy for your company, write to hello@flatconsent.com.

This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Customer", the controller) and Matt Lingner, trading as Flat Consent, San Francisco, California, United States ("Flat Consent", the processor; full postal address in the signed copy) for the Flat Consent service (the "Service").

1. Subject matter, duration, nature and purpose

1.1 Flat Consent processes personal data on behalf of Customer to provide the Service: showing a consent banner on Customer's websites, holding trackers until visitors choose, recording visitors' choices as proof of consent, checking Customer's websites for cookies and trackers, and the dashboard and API through which Customer manages this.

1.2 This DPA lasts as long as Flat Consent processes personal data for Customer under the agreement, and until that data is deleted under section 10.

1.3 The categories of data subjects, types of personal data and processing operations are set out in Annex I.

2. Instructions

2.1 Flat Consent processes personal data only on Customer's documented instructions, including for transfers to third countries, unless required to do so by Union or Member State law; in that case Flat Consent informs Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest (GDPR art. 28(3)(a)).

2.2 The agreement, this DPA, and Customer's settings in the Service (for example, how long records are kept, and deletions Customer makes) are Customer's instructions.

2.3 Flat Consent tells Customer at once if, in its opinion, an instruction infringes the GDPR or other data protection law (art. 28(3)(h), last subparagraph).

3. Confidentiality

Flat Consent ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (art. 28(3)(b)).

4. Security

Flat Consent takes the technical and organisational measures in Annex II, as required by GDPR art. 32 (art. 28(3)(c)). Flat Consent may update them, provided the overall level of security is not reduced.

5. Subprocessors

5.1 Customer gives general written authorisation for Flat Consent to engage the subprocessors listed at https://flatconsent.com/subprocessors/ (art. 28(2)).

5.2 Flat Consent gives notice of any intended addition or replacement of a subprocessor at least 30 days before it takes effect, by email to Customer's workspace owners and admins and to anyone subscribed at that page. Customer may object on reasonable data protection grounds within that period. If the parties can't resolve the objection, Customer may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for it.

5.3 Flat Consent imposes on each subprocessor, by contract, data protection obligations that provide sufficient guarantees, as in this DPA, and remains fully liable to Customer for each subprocessor's performance (art. 28(4)).

6. Data subject rights

Taking into account the nature of the processing, Flat Consent assists Customer by appropriate technical and organisational measures in responding to requests from data subjects (art. 28(3)(e)). In the Service, Customer can find a visitor's consent records by their consent ID, export them, and delete them. Flat Consent forwards to Customer any request it receives directly from a data subject about Customer's data, without responding to it itself unless Customer instructs it to.

7. Assistance with security, breaches and impact assessments

7.1 Flat Consent assists Customer in ensuring compliance with GDPR arts. 32 to 36, taking into account the nature of the processing and the information available to Flat Consent (art. 28(3)(f)).

7.2 Flat Consent notifies Customer of a personal data breach affecting Customer's data without undue delay after becoming aware of it, and in any case within 48 hours, with the information art. 33(3) requires as it becomes available.

8. Audits and information

Flat Consent makes available to Customer all information necessary to demonstrate compliance with art. 28 and allows for and contributes to audits, including inspections, conducted by Customer or an auditor Customer mandates (art. 28(3)(h)). Audits are on at least 30 days' notice, no more than once a year unless required by a supervisory authority or after a breach, at Customer's cost, and are satisfied first by Flat Consent's written answers and available third-party reports (for example, its hosting provider's SOC 2 and ISO 27001 reports).

9. International transfers

9.1 Consent records and account data are stored in a database restricted to the European Union. Some processing takes place outside the EEA, as the subprocessor list states.

9.2 Where personal data is transferred outside the EEA to a country without an adequacy decision, the transfer is covered by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor) between Customer and Flat Consent and Module Three (processor to processor) between Flat Consent and its subprocessors, or by the subprocessor's certification under the EU-U.S. Data Privacy Framework. Flat Consent is established in the United States, so the Module Two clauses are incorporated into this DPA by reference between Customer (data exporter) and Flat Consent (data importer), with: clause 7 (docking) included; clause 9 option 2 (general authorisation, 30 days' notice); clause 11 optional language excluded; clause 17 option 1, the law of Ireland; clause 18, the courts of Ireland. Annex I below is Annex I of the clauses and Annex II is Annex II. For transfers from the United Kingdom, the UK International Data Transfer Addendum applies; from Switzerland, the clauses apply as adapted for the Swiss Federal Act on Data Protection.

10. Deletion or return at the end

At the end of the Service, Flat Consent deletes or returns all personal data to Customer, at Customer's choice, and deletes existing copies unless Union or Member State law requires storage (art. 28(3)(g)). Customer can export all consent records at any time from the dashboard. Unless Customer asks otherwise, Flat Consent deletes Customer's data 30 days after the end of the Service. Consent records deleted before the end are kept only as the one-way fingerprints in sealed daily chains, which contain no personal data.

11. General

11.1 This DPA prevails over the rest of the agreement where they conflict on data protection.

11.2 Liability under this DPA is subject to the limits in the agreement, except where the law does not allow such a limit.

11.3 This DPA is governed by the law of Ireland, and the courts of Ireland have jurisdiction, as for the clauses in section 9.


Annex I: Details of processing

Controller and data exporter: Customer, as identified in its account and the signed copy. Processor and data importer: Matt Lingner, trading as Flat Consent, San Francisco, California, United States; contact hello@flatconsent.com.

Visitors to Customer's websites Customer's team
Personal data A random consent ID; the choice made (by category) and when; the banner version and settings shown; the country, and the state or province in the US and Canada; the language; the browser family; whether a Global Privacy Control signal was sent. No IP address is stored in any form: it is used only to work out the location, then discarded. Email address; role and site access; sign-in records; two-factor secret (encrypted) and recovery codes (hashed) if used; settings changes and access to records they make. Billing details are processed by Stripe.
Operations Serving the banner, holding trackers, recording and storing choices, sealing them into tamper-evident daily chains, exports, deletion. Sign-in, access control, audit logs, notices.
Sensitive data None intended. None.
Retention As Customer sets per site (1 to 5 years), then deleted automatically. For the life of the account; then per section 10.
Frequency Continuous. Continuous.

The site check also opens Customer's public web pages in a browser and records the cookies and services they set; it does not sign in or process visitors' data.

On about one page view in ten, the banner also reports the host names of the outside services the page contacted and the names (never the values) of the cookies the page can read, with no consent ID or other visitor identifier. These are counted per site and per day, kept for 30 days, and used only to show Customer services and cookies the site check can't reach, such as on signed-in pages.

Annex II: Technical and organisational measures

Matching https://flatconsent.com/security/ as of 25 September 2026.