Skip to content
Legal

Data Processing Agreement

Effective: October 6, 2026
STENVARD s.r.o.

GDPR Article 28

Contract under Article 28 GDPR

EU Data Residency

Primary data stored in Frankfurt, DE

Transfers Outside the EEA

Adequacy decision or SCCs, see Section 9

This DPA is automatically incorporated into your Terms of Service when you use Conseto.

This Data Processing Agreement ("DPA") forms part of and supplements the Terms of Service ("Agreement") between STENVARD s.r.o., IČO 57 713 880, registered at Solivarská 14E, 080 05 Prešov, Slovak Republic ("Processor" or "Conseto") and the entity or person accepting the Agreement ("Controller" or "Customer").

This DPA reflects the parties' agreement with regard to the processing of Personal Data in accordance with the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Slovak Data Protection Act (Zákon č. 18/2018 Z. z.).

By using the Conseto Services, the Controller accepts this DPA. Where the Controller acts on behalf of an organization, they warrant that they have authority to bind that organization.

This version takes effect on October 6, 2026 for contracts concluded from that day. For Controllers who accepted the previous version, it takes effect on November 5, 2026; until then their contract is governed by the previous version.

1. Definitions

In this DPA, the following terms have the meanings set out below. Capitalized terms not defined here have the meanings given in the Agreement or the GDPR.

  • "Personal Data" means any information relating to an identified or identifiable natural person ("Data Subject") as defined in Article 4(1) GDPR
  • "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, restriction, erasure, or destruction, as defined in Article 4(2) GDPR
  • "Controller" means the Customer who determines the purposes and means of the Processing of Personal Data by using the Services
  • "Processor" means STENVARD s.r.o. (Conseto), which processes Personal Data on behalf of the Controller
  • "Data Subject" means the identified or identifiable natural person to whom the Personal Data relates
  • "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data
  • "Services" means the Conseto Site Growth Platform, including analytics, compliance, security, marketing, and AI features as described in the Agreement
  • "Standard Contractual Clauses" ("SCCs") means the standard contractual clauses adopted by the European Commission under Commission Implementing Decision (EU) 2021/914

2. Scope and Duration

2.1 Scope

This DPA applies to all Processing of Personal Data by the Processor on behalf of the Controller in connection with the provision of the Services. This DPA does not apply to data that Conseto processes as a data controller in its own right (covered by the Privacy Policy).

2.2 Duration

This DPA shall remain in effect for the duration of the Agreement between the parties. The obligations of the Processor regarding data return and deletion (Section 13) shall survive termination of this DPA.

2.3 Precedence

In the event of a conflict between this DPA and the Agreement, this DPA shall prevail with respect to data protection matters.

3. Nature and Purpose of Processing

The Processor processes Personal Data on behalf of the Controller for the following purposes:

  • Web Analytics: Collecting, storing, and analyzing website visitor data including page views, events, sessions, e-commerce interactions, scroll depth, form interactions, file downloads, and outbound link clicks
  • Consent Management: Recording, storing, and providing audit trails of cookie consent preferences and consent banner interactions for GDPR compliance
  • Security Scanning: Analyzing website security posture, third-party scripts, and potential vulnerabilities using automated scanning tools
  • Marketing Attribution: Tracking campaign performance, UTM parameters, conversion paths, and customer journey data
  • Ask (AI): Answering the Controller's questions about its website's data, in the app and through the MCP server, with the Anthropic Claude model on Amazon Bedrock in EU regions. Query results sent to the model may list individual visits or events; email addresses in them are masked and they never contain IP addresses. Answers saved in the app keep the query results they stand on for no longer than the Controller's plan keeps analytics data, and an erasure of a Data Subject deletes the saved answers that mention them
  • Event Forwarding: Where the Controller turns it on, sending visitor events server-side to Google Analytics 4, Meta, TikTok or LinkedIn under Section 9.2
  • Reporting: Generating dashboards, scheduled email reports, and data exports for the Controller

4. Types of Personal Data Processed

The following categories of Personal Data may be processed under this DPA:

CategoryData Elements
Network DataThe visitor's IP address: we do not store it in the database. We store only a one-way fingerprint of it with a component that changes every calendar month, and the country, region, city, approximate coordinates, time zone and network provider derived from it. The location is determined on the Processor's servers from an open IP location database, without sending the IP address to a third party. The IP address itself is processed only transiently when an event is received (location and bot detection) and when events are forwarded to services the Controller connects (Section 9.2)
Device DataBrowser type and version, operating system, device type, screen resolution, user agent string
Behavioral DataPage views, custom events, click events, scroll depth, time on page, navigation paths, referral source, landing pages, exit pages
E-commerce DataProduct views, add to cart, purchases, order values, conversion events (as configured by Controller)
Consent DataConsent choices, timestamp, banner interaction, consent withdrawal records
IdentifiersPseudonymous session tokens, visitor tokens, ad click identifiers (for example fbp and fbc), optional user IDs and hashed (SHA-256) email addresses and phone numbers that the Controller provides via the SDK
Campaign DataUTM parameters, campaign identifiers, referral URLs, tracked link clicks
Performance DataCore Web Vitals (LCP, INP, CLS), TTFB, page load times

The Processor does not intentionally collect special categories of data (Article 9 GDPR) such as health data, biometric data, or data revealing racial or ethnic origin. The Controller must not configure the Services to collect such data without explicit prior written agreement.

5. Categories of Data Subjects

The Data Subjects whose Personal Data is processed under this DPA include:

  • Website Visitors: Individuals who visit the Controller's websites where the Conseto SDK is installed
  • E-commerce Customers: Individuals who make purchases or interact with e-commerce features on the Controller's website
  • App Users: Users of the Controller's web applications where Conseto tracking is implemented

6. Obligations of the Processor

The Processor (Conseto) shall:

  • Process Personal Data only on documented instructions from the Controller, unless required to do so by EU or Slovak law (in which case the Processor shall inform the Controller of that legal requirement before processing, unless the law prohibits such information)
  • Ensure that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality
  • Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk (as detailed in Section 10)
  • Not engage another processor (sub-processor) without prior specific or general written authorization of the Controller (see Section 8)
  • Taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures, insofar as possible, for the fulfillment of the Controller's obligation to respond to Data Subject requests
  • Assist the Controller in ensuring compliance with obligations under Articles 32 to 36 GDPR (security, breach notification, DPIA, prior consultation)
  • At the choice of the Controller, delete or return all Personal Data to the Controller after the end of the provision of Services, and delete existing copies unless EU or Slovak law requires storage (see Section 13)
  • Make available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits, including inspections (see Section 12)
  • Immediately inform the Controller if, in the Processor's opinion, an instruction from the Controller infringes GDPR or other EU or Slovak data protection provisions

7. Obligations of the Controller

The Controller (Customer) shall:

  • Ensure there is a lawful basis for the processing of Personal Data through the Services (e.g., consent, legitimate interest) and maintain records of processing activities
  • Provide a clear and compliant privacy notice to Data Subjects that discloses the use of Conseto and the categories of data collected
  • Configure the Conseto consent banner and SDK appropriately for the jurisdictions in which their website operates
  • Obtain and manage necessary consents from Data Subjects where required by applicable law
  • Respond to Data Subject requests (access, deletion, portability) relating to their website visitors, using the tools provided by Conseto
  • Not instruct the Processor to process Personal Data in violation of GDPR or other applicable data protection laws
  • Not configure the Services to collect special categories of Personal Data without prior written agreement
  • Provide documented processing instructions to the Processor (the Agreement and SDK configuration constitute documented instructions)

8. Sub-processors

8.1 General Authorization

The Controller grants the Processor general written authorization to engage sub-processors to process Personal Data on behalf of the Controller. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors, providing the Controller an opportunity to object within 30 days.

8.2 Current Sub-processors

The following sub-processors are authorized as of the effective date of this DPA:

Sub-processorPurposeLocationSafeguards
Vercel Inc.Website and dashboard hostingEU (Frankfurt, fra1)EU region, DPA, DPF and SCCs
Fly.ioAPI gateway and audit engine hostingEU (Frankfurt, DE)EU region, DPA, DPF and SCCs
SupabasePostgreSQL databaseAWS eu-central-1 (Frankfurt, DE)EU region, DPA, DPF and SCCs
Cloudflare Inc.Encrypted database backups (R2 storage) and Turnstile bot protection on formsBackups: EU (R2, EU jurisdiction); Turnstile: global networkDPF, SCCs, DPA
Amazon Web Services (SES)Transactional email deliveryEU regionEU region, DPA, DPF and SCCs
Amazon Web Services (Bedrock)AI models (Anthropic Claude) for Ask (in the app and through the MCP server): questions, project details and query results, with email addresses masked and without IP addresses. Data is sent to AWS, not directly to Anthropic, and is not used to train modelsEU regions (requests from Paris, eu-west-3)EU regions, DPA, DPF and SCCs, email masking, no IP addresses
Revolut BusinessPayment processing, only for card payments, which we do not offer yet (billing data only, not visitor data)EU (Lithuania)EU region, regulated entity
Google LLCSearch Console and GA4 API access, only for properties the Controller connects itselfGlobal (customer-controlled)Customer-authorized OAuth scope, Google DPA

8.3 Sub-processor Obligations

The Processor shall impose on each sub-processor, by way of a written contract, the same data protection obligations as set out in this DPA. The Processor remains fully liable to the Controller for the performance of the sub-processor's obligations.

8.4 Right to Object

If the Controller has reasonable grounds to object to a new sub-processor, the Controller may notify the Processor in writing within 30 days of being informed. The parties shall discuss the objection in good faith. If no resolution is reached, the Controller may terminate the Agreement with respect to the Services that cannot be provided without the objected-to sub-processor.

9. International Data Transfers

9.1 Primary Processing Location

Data is stored and primarily processed within the European Economic Area (EEA): website and dashboard hosting (Vercel) and the API gateway and audit engine (Fly.io) run in Frankfurt, Germany, and the PostgreSQL database (Supabase, on AWS eu-central-1) is also located in Frankfurt.

9.2 Transfers Outside the EEA

The sub-processors listed in Section 8.2 store data in data centers in the European Union. Some of them (Vercel Inc., Fly.io, Supabase, Cloudflare, Inc. and Amazon Web Services) are companies based in the USA or with a parent company there and may access data from the USA as well, for example for support or operations; Cloudflare Turnstile processes the IP address and browser data in its global network. These transfers rely on Commission Decision (EU) 2023/1795 for companies certified under the EU-U.S. Data Privacy Framework and otherwise on the standard contractual clauses under Commission Implementing Decision (EU) 2021/914.

Visitors' Personal Data may also leave the EEA on the Controller's instruction: (a) where it connects its own Google Search Console or GA4 property; (b) where it turns on server-side event forwarding to Google Analytics 4, Meta (Conversions API), TikTok or LinkedIn. In case (b) the Processor sends the event from its infrastructure together with the visitor identifier, for Meta and TikTok also with the IP address and user agent string, with ad click identifiers, and with the user ID and a hashed email address or phone number where the Controller provided them, and only for a visitor who gave the matching consent (analytics for Google Analytics 4, advertising for Meta, TikTok and LinkedIn). In these cases the recipient is the Controller's contractual partner, not the Processor's sub-processor, and the transfer is governed by the contract between the Controller and that recipient.

For transfers outside the EEA for which the Processor is responsible, the following safeguards apply:

  • Standard Contractual Clauses (SCCs) as adopted by the European Commission under Implementing Decision (EU) 2021/914, Module Two (Controller to Processor) or Module Three (Processor to Processor) as applicable
  • Transfer Impact Assessments where required
  • Supplementary technical measures including data minimization, pseudonymization, and encryption in transit (TLS)
  • For AI processing specifically: the data stays in EU regions, email addresses in query results and in earlier questions and answers are masked before they reach the model, and query results never contain IP addresses

9.3 Adequacy Decisions

Where the European Commission has issued an adequacy decision for the recipient country, transfers may rely on such decision. The Processor shall monitor the validity of any relied-upon adequacy decisions.

10. Technical and Organizational Security Measures

The Processor implements the following security measures in accordance with Article 32 GDPR, taking into account the state of the art, costs of implementation, nature, scope, context, and purposes of processing, as well as the risk to the rights and freedoms of Data Subjects:

10.1 Encryption

  • Data in transit: TLS encryption for all connections to the API, SDK and app (HTTPS)
  • Data at rest: the Supabase database is encrypted (AES-256); we encrypt backups in Cloudflare R2 before storing them (AES-256)
  • Passwords: bcrypt hashing (never stored in plaintext)
  • MCP keys (cmk_): we store only their SHA-256 hash. Project keys (csk_) are stored in the database as issued, so that a project admin can view them

10.2 Access Control

  • Role-based access control in each project (admin, editor, viewer)
  • JWT-based authentication with 7-day token expiration
  • Only authorized persons of STENVARD s.r.o. have access to the production infrastructure and database

10.3 Network Security

  • Network-level DDoS protection via the Vercel and Fly.io edge networks
  • Cloudflare Turnstile bot protection on public forms
  • Rate limiting: 1000 req/15min (general), 200 req/15min (auth), 30 req/min (audit), 10 req/hr (AI generation), and an hourly limit on Ask questions by plan
  • Bot filtering with 50+ detection patterns
  • HTTP security headers via Helmet.js (HSTS, CSP, X-Frame-Options)

10.4 Data Integrity and Availability

  • Daily encrypted database backups outside the primary provider (Cloudflare R2, EU jurisdiction)
  • Input validation and sanitization on all API endpoints (Zod schema validation)
  • Parameterized database queries to prevent SQL injection
  • Request logs contain no IP addresses and no visitor data; user email addresses appear in the logs for some events

10.5 Organizational Measures

  • Confidentiality obligations for everyone with access to Personal Data
  • Personal Data Breach procedure under Section 11
  • Regular dependency vulnerability scanning (npm audit in CI)
  • Automated tests before changes are merged (CI)

11. Personal Data Breach Notification

11.1 Notification to Controller

The Processor shall notify the Controller without undue delay, and at the latest within 48 hours of becoming aware of a Personal Data Breach affecting the Controller's data. The notification shall be sent via email to the Controller's registered account email address and shall include:

  • A description of the nature of the breach, including categories and approximate number of Data Subjects and records affected
  • The name and contact details of the Processor's data protection contact
  • A description of the likely consequences of the breach
  • A description of the measures taken or proposed to address the breach, including measures to mitigate its adverse effects

11.2 Cooperation

The Processor shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach. The Processor shall also assist the Controller in fulfilling its obligations to notify the supervisory authority (Article 33 GDPR) and Data Subjects (Article 34 GDPR) where applicable.

11.3 Record Keeping

The Processor shall maintain a record of all Personal Data Breaches, including the facts relating to the breach, its effects, and the remedial action taken.

12. Audit Rights

12.1 Information and Documentation

The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA. This includes providing documentation of security measures, sub-processor agreements, and breach records upon reasonable request.

12.2 Audits and Inspections

The Controller may conduct audits or appoint a qualified third-party auditor (subject to reasonable confidentiality obligations) to verify the Processor's compliance with this DPA. Audits shall be conducted:

  • With at least 30 days' written notice to the Processor
  • During normal business hours (CET/CEST)
  • No more than once per calendar year (unless a Personal Data Breach has occurred)
  • In a manner that does not unreasonably disrupt the Processor's operations
  • At the Controller's expense, unless the audit reveals a material breach by the Processor

12.3 Certifications

The Processor may satisfy audit requests by providing relevant certifications, audit reports, or summaries of independent security assessments, where available.

13. Return and Deletion of Data

13.1 Data Export

Where the Controller deletes its account or a project itself, that is its instruction to delete at once; the Processor deletes the data immediately, in a single step, and the export period under this Section does not apply. Otherwise, during the term of the Agreement and for 30 days following termination, the Controller may export their data using the export functionality available in the Conseto dashboard (CSV and JSON formats) or via the API.

13.2 Deletion

Upon termination of the Agreement and after the 30-day export period, the Processor shall:

  • Delete all Personal Data from active production systems within 90 days
  • Delete Personal Data from backup systems as they are regularly rotated
  • Provide written confirmation of deletion upon the Controller's request

13.3 Exceptions

The Processor may retain Personal Data beyond the deletion schedule where required by EU or Slovak law (e.g., tax records must be retained for 10 years under Slovak law). The Processor shall inform the Controller of any such legal retention requirement and ensure the data is only processed for the legally required purpose.

During the term of the Agreement these default retention periods apply and are the Controller's documented instruction: analytics data according to the Controller's plan (see pricing); records where a visitor saw the consent banner or made a choice, 3 years. All are deleted immediately when the Controller deletes the project or the account.

14. Liability

14.1 GDPR Liability

Each party shall be liable for damages caused by processing that infringes the GDPR in accordance with Article 82 GDPR. The Processor shall be liable for damage caused by processing only where it has not complied with obligations specifically directed to processors under the GDPR, or where it has acted outside or contrary to the lawful instructions of the Controller.

14.2 Limitation

The limitation of liability under Section 9 of the Terms of Service also applies to this DPA, except for (a) liability towards Data Subjects under Article 82 GDPR and (b) damage caused intentionally or by gross negligence.

14.3 Indemnification

Each party shall indemnify the other against all costs, claims, damages, and expenses incurred as a result of the indemnifying party's material breach of this DPA or applicable data protection law, subject to the limitations set out in the Agreement.

15. Governing Law and Jurisdiction

This DPA shall be governed by and construed in accordance with the laws of the Slovak Republic, without regard to its conflict of law provisions. Any disputes arising from or relating to this DPA shall be decided by the court with subject-matter jurisdiction for the registered office of STENVARD s.r.o.

For matters related to GDPR enforcement, the competent supervisory authority shall be the Úrad na ochranu osobných údajov SR, Slovak Republic, without prejudice to the Controller's right to lodge a complaint with their local supervisory authority.

Contact

For questions about this DPA or to exercise rights under it:

STENVARD s.r.o.

Solivarská 14E, 080 05 Prešov, Slovak Republic
IČO: 57 713 880
privacy@conseto.io