Operational draft — not legal advice. This is a working template. It must be reviewed and approved by a qualified lawyer, and (for many customers) signed, before it is relied on. Last updated 5 July 2026.

Data Processing Addendum (DPA)

This addendum forms part of the agreement between UnionFold ("Processor") and the customer ("Controller") and applies where UnionFold processes personal data on the Controller's behalf.

1. Roles

The Controller determines the purposes and means of processing. UnionFold acts as Processor and processes personal data only on documented instructions from the Controller, including as configured in the product.

2. Scope of processing

  • Subject matter: provision of the FoldCMP consent, declaration, scanning, and monitoring services.
  • Nature & purpose: storing and processing consent-related records and site configuration to operate the service.
  • Personal data: primarily consent-log records relating to the Controller's site visitors (a record that a consent choice was made, with associated metadata) and account data of the Controller's users.
  • Data subjects: the Controller's website visitors and authorised users.

UnionFold acknowledges it may process the Controller's visitor consent-log data as a processor.

3. Obligations of UnionFold (Processor)

  • Process personal data only on the Controller's instructions.
  • Ensure persons authorised to process data are bound by confidentiality.
  • Implement appropriate technical and organisational security measures.
  • Engage sub-processors only under written terms and maintain a current sub-processor list; notify of intended changes.
  • Assist the Controller, taking into account the nature of processing, with data-subject requests and with security, breach-notification, and (where applicable) impact-assessment obligations.
  • On termination, delete or return personal data as instructed, subject to legal retention.
  • Make available information reasonably necessary to demonstrate compliance with this addendum.

4. Security measures (summary)

Access controls and least-privilege; encryption in transit; hashed credentials; audit logging of administrative actions; EU-based primary hosting; retention controls. (Specific measures to be confirmed and expanded during legal/security review.)

5. Data location and transfers

Primary hosting is in the EU. Where a sub-processor processes data outside the EU/EEA, appropriate safeguards — such as the European Commission's Standard Contractual Clauses — will be applied where required by law.

6. Sub-processors

Current sub-processors are listed at /legal/subprocessors.

7. Liability & precedence

This addendum is subject to the liability provisions of the main Terms of Service. Where this addendum conflicts with the Terms on data protection, this addendum prevails for that subject matter.

← Back to unionfold.com