Chat on WhatsApp

Privacy Centre

Data Processing Agreement

This DPA applies where ConsentGuru processes Personal Data on behalf of a Customer and is intended to support DPDP, GDPR, UK GDPR, CCPA/CPRA and other applicable privacy laws.

Last updated 21 September 2026 · Effective 21 September 2026

32.Introduction

This Data Processing Agreement ("DPA") forms part of the agreement between ConsentGuru and the organisation subscribing to or using ConsentGuru's services ("Customer"). This DPA applies where ConsentGuru processes Personal Data on behalf of the Customer. It establishes the responsibilities and safeguards applicable to such processing. Where applicable, this DPA is intended to support compliance with applicable data protection laws, including India's Digital Personal Data Protection Act, 2023 and applicable rules, GDPR, UK GDPR, CCPA/CPRA and other applicable privacy legislation.

33.Definitions

Applicable Data Protection Law
any applicable data protection, privacy, cybersecurity or electronic communications law governing processing of Personal Data.
Customer Data
Personal Data processed by ConsentGuru on behalf of the Customer.
Data Fiduciary
as defined under applicable Indian data protection law.
Data Controller
entity determining purposes and means of processing Personal Data.
Data Processor
entity processing Personal Data on behalf of a Data Fiduciary or Data Controller.
Data Principal
individual to whom Personal Data relates.
Personal Data
information relating to an identified or identifiable individual or equivalent protected information.
Processing
collecting, recording, organising, storing, retrieving, using, transmitting, modifying, disclosing, restricting or deleting Personal Data.
Security Incident
confirmed breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Personal Data.
Sub-processor
third party appointed by ConsentGuru to process Customer Data on behalf of the Customer.

34.Roles of the Parties

For Customer Data processed through ConsentGuru, the Customer generally acts as the Data Fiduciary, Data Controller or equivalent entity, while ConsentGuru generally acts as the Data Processor, service provider or equivalent entity. The Customer determines the purposes of processing. ConsentGuru processes Customer Data only for the purposes described in the Agreement, this DPA and documented instructions. Nothing in this DPA transfers the Customer's responsibility for determining the purpose or lawful basis of processing.

35.Subject Matter and Nature of Processing

ConsentGuru may process Customer Data to provide consent management, cookie management, privacy preference management, consent records, audit trails, reporting, APIs and integrations, technical support, security and service maintenance, and related privacy technology services. Processing may include receiving, recording, organising, storing, retrieving, transmitting, synchronising, reporting and deleting information.

36.Categories of Personal Data

Depending on the Customer's configuration, Customer Data may include name, email address, telephone number, account identifiers, user identifiers, IP addresses, device information, cookie identifiers, online identifiers, consent records, privacy preferences, marketing preferences, communication preferences, date and time of consent, withdrawal records, technical logs and other Personal Data submitted by the Customer.

37.Categories of Data Principals

Customer Data may relate to customers, website visitors, application users, employees, contractors, students, patients, members, subscribers, prospective customers and other individuals whose Personal Data is processed by the Customer.

38.Customer Responsibilities

The Customer shall ensure an appropriate legal basis for processing; provide appropriate privacy notices; obtain valid consent where required; ensure consent requests are clear; provide withdrawal mechanisms; respond to Data Principal requests where responsible; configure ConsentGuru appropriately; avoid unnecessary Personal Data; comply with Applicable Data Protection Law; and provide lawful and documented instructions to ConsentGuru. The Customer remains responsible for its privacy notices, consent notices, processing purposes and configuration.

39.ConsentGuru Responsibilities

ConsentGuru shall process Customer Data in accordance with the Agreement and documented instructions; maintain appropriate security measures; restrict access to authorised personnel; maintain confidentiality; assist the Customer where reasonably necessary; maintain appropriate processing records where required; notify the Customer of applicable Security Incidents; manage Sub-processors in accordance with this DPA; and delete or return Customer Data as required.

40.Confidentiality

ConsentGuru shall ensure that personnel authorised to process Customer Data access it only where necessary, receive appropriate privacy and security instructions, and are subject to confidentiality obligations. These obligations continue after termination of employment or access.

41.Security Measures

ConsentGuru shall maintain reasonable technical and organisational security measures appropriate to the risks associated with processing Customer Data. These may include encryption in transit, encryption or equivalent protection at rest, access controls, authentication, role-based access, logging, monitoring, vulnerability management, backup and recovery, security testing, incident response, access reviews, personnel security and business continuity measures.

42.Security Incidents

ConsentGuru shall notify the Customer without undue delay after becoming aware of a confirmed Security Incident affecting Customer Data where notification is required by Applicable Data Protection Law or the Agreement. Where reasonably available, notification may describe the nature of the incident, categories of Personal Data affected, categories or approximate number of affected individuals, likely consequences, measures taken and relevant contact information. ConsentGuru shall take reasonable steps to contain, investigate and mitigate the incident.

43.Sub-processors

The Customer authorises ConsentGuru to use appropriate third-party service providers necessary to provide the Services, including cloud infrastructure, storage, security, analytics, customer support, communication, payment and other technology providers. ConsentGuru shall impose appropriate data protection obligations on Sub-processors and remain responsible for its Sub-processors to the extent required by Applicable Data Protection Law.

44.International Transfers

Where Customer Data is transferred outside the jurisdiction in which it was collected, ConsentGuru shall implement safeguards required by Applicable Data Protection Law. These may include adequacy mechanisms, standard contractual clauses, contractual safeguards, approved transfer mechanisms or other legally recognised safeguards.

45.Assistance with Data Principal Rights

Taking into account the nature of processing, ConsentGuru shall provide reasonable assistance to the Customer in responding to Data Principal requests where technically feasible and legally required. Such requests may include access, correction, deletion, withdrawal of consent, restriction, objection, portability and other applicable rights.

46.Data Protection Assessments

Where reasonably required, ConsentGuru shall provide information reasonably necessary for the Customer to assess privacy and security risks associated with the Services. The Customer remains responsible for determining whether it is required to conduct a Data Protection Impact Assessment or equivalent assessment.

47.Regulatory Cooperation

Where legally required, ConsentGuru shall provide reasonable cooperation and information necessary for the Customer to demonstrate compliance with Applicable Data Protection Law. Nothing requires ConsentGuru to disclose confidential information belonging to another customer or information protected by law.

48.Audits

The Customer may request reasonable information concerning ConsentGuru's data protection and security practices. Where required by law, the parties may agree to an appropriate audit mechanism. Audits shall be conducted with reasonable advance notice, during reasonable business hours, with minimal disruption and subject to confidentiality and security requirements.

49.Return and Deletion of Customer Data

Upon termination or expiry of the Services, ConsentGuru shall, subject to the Agreement and Applicable Data Protection Law, return Customer Data where technically feasible and contractually required or delete Customer Data. ConsentGuru may retain limited information where required by law or reasonably necessary to establish or defend legal claims.

50.Government Requests

If ConsentGuru receives a legally binding request from a government authority for Customer Data, ConsentGuru may disclose the information where legally required. Where legally permitted, ConsentGuru will provide reasonable notice to the Customer and seek to limit disclosure to the information legally required.

51.No Sale of Customer Data

ConsentGuru will not sell Customer Data or use Customer Data for unrelated advertising or marketing purposes. ConsentGuru may use aggregated or anonymised information that no longer identifies an individual for service improvement, security analysis, statistical analysis, product development and business reporting, subject to Applicable Data Protection Law.

52.Sensitive or Special-Category Data

Customers should not provide sensitive or special-category Personal Data to ConsentGuru unless such processing is necessary, supported by the Services and permitted by Applicable Data Protection Law. Where such processing is required, appropriate additional safeguards shall be implemented where reasonably necessary.

53.Children and Minors

Where Customer Data relates to children or minors, the Customer is responsible for ensuring that applicable age-related safeguards, parental or guardian consent and other legal requirements are satisfied. ConsentGuru shall process such information only in accordance with the Customer's documented instructions and the Agreement.

54.Data Protection Officer

ConsentGuru's Data Protection Officer is Shijas Mohidheen, shijas@consentguru.com. The DPO may be contacted regarding privacy and data protection matters relating to ConsentGuru's processing activities.

55.Precedence

If there is a conflict between this DPA and another agreement concerning the processing of Personal Data, this DPA shall apply to the extent of the conflict concerning data protection obligations, unless the parties expressly agree otherwise in writing.

56.Changes to the DPA

ConsentGuru may update this DPA where reasonably necessary to reflect changes in Applicable Data Protection Law, the ConsentGuru Services, security practices, Sub-processors or processing activities. Where a material change materially affects the Customer's data protection obligations, ConsentGuru shall provide reasonable notice where required.

57.Term and Survival

This DPA shall remain effective for as long as ConsentGuru processes Customer Data on behalf of the Customer. Confidentiality, security, deletion, regulatory cooperation and other provisions that by their nature should survive termination shall continue to apply to the extent required by Applicable Data Protection Law.

58.Contact

ConsentGuru, #10, Second Floor, Manasa Towers, MG Road, Mangalore - 575003, Karnataka, India. General Privacy Contact: support@consentguru.com. Data Protection Officer: Shijas Mohidheen, shijas@consentguru.com. Website: www.consentguru.com.

Appendix A — Processing Details

Subject Matter
Consent management, cookie management, privacy preference management, consent records, audit trails and related privacy technology services.
Duration
For the duration of the Customer's subscription or contractual relationship with ConsentGuru, together with any applicable retention or deletion period.
Nature of Processing
Collection, recording, organisation, storage, retrieval, use, transmission, synchronisation, reporting, deletion and other processing necessary to provide the Services.
Purpose
To provide ConsentGuru services in accordance with the Customer's instructions and the Agreement.
Categories of Data Principals
Customers, users, website visitors, employees, contractors, members, subscribers, prospective customers, students, patients and other individuals whose information is submitted by the Customer.
Categories of Personal Data
Identity information, contact information, online identifiers, device information, IP addresses, cookie identifiers, consent records, privacy preferences, marketing preferences, communication preferences, timestamps, technical logs and other information configured or submitted by the Customer.
Special Categories
ConsentGuru should not be used to process sensitive or special-category Personal Data unless expressly agreed or supported by the applicable Services and appropriate safeguards are in place.
Processing Locations
Customer Data may be processed in India and/or other jurisdictions in which ConsentGuru or its authorised service providers operate, subject to Applicable Data Protection Law and appropriate safeguards.
Data Protection Contact
Shijas Mohidheen, Data Protection Officer, shijas@consentguru.com