Data Processing Agreement
Last updated: 25 September 2026
This Data Processing Agreement (“DPA”) sets out the terms on which Pixadoro Ltd., Blvd. Cherni Vrah 47, 1407, Sofia, Bulgaria, company number 206777328, VAT: BG206777328, the operator of Kukie.io (“Kukie”, “we”, “us”), processes personal data on behalf of its customers (“Customer”, “you”). It contains the terms required by Article 28(3) of the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
This DPA forms part of our Terms of Service (the “Terms”). It applies automatically to every Customer who accepts the Terms, from the moment the account is created, and needs no separate signature. If your organisation needs a copy countersigned by us for its records, email support@kukie.io.
This DPA covers the personal data of visitors to your websites that the Services process for you. It does not cover the data we collect about you as our customer (your account, team members and billing details). For that data we are the controller, and our Privacy Policy applies.
1. Definitions
Terms defined in the Terms of Service have the same meaning in this DPA. In addition:
- “Applicable Data Protection Law” means the GDPR, the Bulgarian Personal Data Protection Act, the UK GDPR and the Data Protection Act 2018, the Swiss Federal Act on Data Protection, and United States state privacy laws such as the California Consumer Privacy Act, in each case to the extent they apply to the processing of Customer Personal Data.
- “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing” and “Supervisory Authority” have the meanings given in the GDPR.
- “Customer Personal Data” means the Personal Data of End Users that we process on your behalf when providing the Services, as described in Annex I.
- “Dashboard” means the customer area of the Services at app.kukie.io.
- “End User” means a visitor to a website on which you have installed the Banner Script.
- “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
- “Standard Contractual Clauses” means the clauses adopted by Commission Implementing Decision (EU) 2021/914.
- “Sub-processor” means a third party we engage that processes Customer Personal Data.
2. Roles and Scope
2.1. Controller and Processor
You are the Controller of Customer Personal Data and we are your Processor. You decide whether the Banner Script runs on a website, how it is configured, whether consent records are kept and for how long.
2.2. Agencies and Customers Acting for Others
If you use the Services on behalf of your own clients (for example as an agency managing their websites), you may act as a Processor yourself. In that case we act as your Sub-processor, you confirm that your client has authorised you to engage us on the terms of this DPA, and you pass on your client's instructions to us. We deal with you, not with your client, unless the law requires otherwise.
2.3. Details of the Processing
The subject matter, nature, purpose and duration of the processing, the types of Personal Data and the categories of Data Subjects are described in Annex I.
3. Your Instructions
3.1. Documented Instructions
We process Customer Personal Data only on your documented instructions. Your instructions are the Terms, this DPA, and the settings you choose in the Dashboard, such as banner and region rules, script and iFrame blocking, whether consent logging is enabled, the consent record retention period, and the deletion of records or sites. You may give further written instructions (email is enough) as long as they are consistent with the Terms and the functionality of the Services. Instructions that go beyond that functionality need our agreement.
3.2. Processing Required by Law
If European Union or Member State law requires us to process Customer Personal Data other than on your instructions, we will tell you about that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
3.3. Unlawful Instructions
We will tell you promptly if, in our opinion, an instruction infringes Applicable Data Protection Law. We may suspend that instruction until you confirm or change it.
3.4. No Other Use
We do not use Customer Personal Data for our own purposes. In particular we do not sell it, share it for advertising, use it to profile or track End Users, or combine it with data from other customers or other sources. We may produce aggregated statistics (such as consent counts) that identify neither you nor any End User, as described in clause 6.6 of the Terms.
4. Your Obligations
You are responsible for:
- having a lawful basis for the processing you instruct, and giving End Users the information required by Articles 13 and 14 GDPR, including in your own privacy or cookie notice;
- the configuration of the Banner Script on your websites, including the consent categories, the scripts, cookies and services assigned to them, and the texts shown to End Users. Cookie categories suggested by our scanner are suggestions, and you decide whether to accept them;
- not configuring the Services to collect special categories of Personal Data (Article 9 GDPR) or data relating to criminal convictions;
- keeping your account secure, including managing team members and their roles and using two-factor authentication, which is available to every account;
- assessing whether the security measures in Annex II are appropriate for your processing.
5. Confidentiality
We ensure that every person we authorise to process Customer Personal Data is bound by a duty of confidentiality, by contract or by law. Access is limited to what is needed to provide, support and secure the Services and to comply with the law. The duty of confidentiality continues after the person's engagement with us ends.
6. Security
We implement the technical and organisational measures described in Annex II to protect Customer Personal Data, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing, as required by Article 32 GDPR. We may change these measures as technology develops, provided that the overall level of protection is not reduced.
7. Sub-processors
7.1. General Authorisation
You give us a general authorisation to engage Sub-processors. The Sub-processors we use today are listed in Annex III. The full list of our service providers, including those that process only our own customer and billing data, is in section 6.1 of our Privacy Policy.
7.2. Sub-processor Contracts
We engage each Sub-processor under a written contract that imposes data protection obligations no less protective than those in this DPA, to the extent they apply to the service the Sub-processor provides. We remain responsible to you for the performance of each Sub-processor's obligations.
7.3. New Sub-processors
We will tell you by email, sent to the owner of your account, at least 30 days before a new or replacement Sub-processor begins processing Customer Personal Data, and we will update Annex III.
7.4. Objections
You may object to a new Sub-processor on reasonable data protection grounds by writing to us within 14 days of our notice. We will discuss your objection in good faith and, where possible, offer a way to use the Services without that Sub-processor processing your Customer Personal Data. If we cannot resolve the objection before the change takes effect, you may terminate the Agreement by written notice with effect before the new Sub-processor begins processing Customer Personal Data. Unpaid Fees for the remainder of the billing period do not become due on a termination under this clause.
7.5. Urgent Replacement
If we must replace a Sub-processor at short notice to protect the security or availability of the Services, we will tell you as soon as reasonably possible, and clause 7.4 applies from the date of that notice.
8. International Transfers
Customer Personal Data is stored in the European Union. Some Sub-processors process Customer Personal Data outside the European Economic Area in the course of their service, as shown in Annex III. We transfer Customer Personal Data outside the European Economic Area only where Chapter V of the GDPR is complied with, through an adequacy decision of the European Commission (including the EU-U.S. Data Privacy Framework for certified recipients) or through the Standard Contractual Clauses (Module Three, processor to processor) concluded with the Sub-processor, together with any supplementary measures that are needed.
If you are established in the United Kingdom or Switzerland, your transfer of Customer Personal Data to us in the European Union is covered by the adequacy regulations those countries have adopted for the European Union.
9. Data Subject Requests
9.1. Built-in Functions
The Services are designed so that you can answer most requests yourself. End Users can change or withdraw their consent at any time through the banner's preferences. In the Dashboard, you can export consent records and delete individual records or all records for a site, and you can shorten the retention period.
9.2. Our Assistance
Where the Dashboard does not offer a function you need to answer a request under Chapter III GDPR (for example, locating the records that belong to a particular visitor identifier), we will carry out the request on your written instruction within a reasonable time. We provide this assistance free of charge unless requests are manifestly unfounded or excessive.
9.3. Requests Sent to Us
If an End User contacts us directly about Customer Personal Data, we will forward the request to you without undue delay and will not answer it ourselves, except to tell the End User to contact you, unless the law requires us to.
10. Personal Data Breaches
10.1. Notification
We will notify you of a Personal Data Breach without undue delay, and in any event within 72 hours after we become aware of it, by email to the owner of your account.
10.2. Content
Our notification will describe, as far as the information is available, the nature of the breach, the categories and approximate number of End Users and records concerned, the likely consequences, and the measures taken or proposed to address the breach and reduce its effects. Where not all the information is available at once, we will provide it in stages without further undue delay.
10.3. Response
We will take reasonable steps to contain and investigate the breach, reduce its effects, and keep you informed. We will not notify a Supervisory Authority or End Users about a breach of Customer Personal Data on your behalf unless you instruct us to or the law requires it. A notification under this clause is not an admission of fault or liability.
11. Impact Assessments and Consultation
Taking into account the nature of the processing and the information available to us, we will give you reasonable assistance with data protection impact assessments and prior consultations with a Supervisory Authority (Articles 35 and 36 GDPR) that relate to the Services, mainly by providing the information in this DPA and in our product documentation.
12. Audits and Information
12.1. Information
On request, we will make available the information necessary to demonstrate our compliance with this DPA and Article 28 GDPR, including a description of our security measures and written answers to a reasonable security questionnaire, once in any 12-month period (and additionally after a Personal Data Breach or at the request of a Supervisory Authority).
12.2. Certifications
We do not currently hold a third-party certification of our own, such as ISO/IEC 27001 or SOC 2. The data centres of our hosting provider are operated under an ISO/IEC 27001-certified information security management system.
12.3. Audits
If the information under clause 12.1 is not sufficient to demonstrate compliance, or a Supervisory Authority requires it, you may audit our compliance with this DPA, yourself or through an independent auditor who is bound by confidentiality and is not our competitor. Audits require at least 30 days' written notice, take place during Business Days, are limited to once in any 12-month period (except after a Personal Data Breach or at the request of a Supervisory Authority), and must not give access to other customers' data or put the security of the Services at risk. You bear your own costs of an audit.
12.4. Authority Requests
We will tell you without undue delay if a Supervisory Authority or other public authority contacts us about Customer Personal Data, unless the law prohibits it.
13. Deletion and Return
13.1. During the Agreement
You control the deletion of Customer Personal Data throughout the Agreement. Consent records are deleted automatically once they are older than the retention period set for the site (within the maximum of your Plan), by a job that runs every day. You can delete consent records in the Dashboard at any time. Deleting a site deletes its consent records, scan results and banner configuration immediately, and deleting your account does the same for every site in the organisations you own.
13.2. At the End of the Agreement
You can export your consent records from the Dashboard at any time before your account is closed and, under clause 8.4 of the Terms, you may request an export within 30 days after termination. After that period, we delete the remaining Customer Personal Data within a further 30 days, unless European Union or Member State law requires us to keep it. We will confirm the deletion in writing on request.
13.3. Backups and Technical Copies
Deleted Customer Personal Data leaves our backups within 30 days, as the backup cycle expires. Backups are used only for disaster recovery. Copies in server logs and processing queues are deleted automatically within the periods set out in Annex I.
14. United States Privacy Laws
To the extent the California Consumer Privacy Act or a similar United States state privacy law applies, we act as your “service provider” or “processor”. We will not sell or share Customer Personal Data, will not retain, use or disclose it outside our direct business relationship with you or for any purpose other than providing the Services, and will not combine it with personal information we receive from others except as those laws permit. We will tell you if we can no longer meet these obligations, and you may take reasonable steps to stop and remedy any unauthorised use.
15. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in section 10 of the Terms. Nothing in this DPA limits either party's liability to Data Subjects under Article 82 GDPR, or any liability that cannot be limited by law.
16. Term, Precedence and Changes
16.1. Term
This DPA applies for as long as we process Customer Personal Data, including after the Agreement ends until the deletion under clause 13 is complete.
16.2. Precedence
For the processing of Customer Personal Data, this DPA prevails over the Terms and the Privacy Policy. Where Standard Contractual Clauses apply, they prevail over this DPA.
16.3. Changes
We may update this DPA to reflect changes in the law, in the Services or in our Sub-processors (for which clause 7 applies). We will tell you by email at least 30 days before a change that reduces the protection of Customer Personal Data takes effect, as described in section 15 of the Terms. The date at the top of this page shows when it was last updated.
16.4. Governing Law
This DPA is governed by the laws of Bulgaria, and the courts of Bulgaria have exclusive jurisdiction, as set out in section 17 of the Terms.
16.5. Severability
If any provision of this DPA is found invalid or unenforceable, the remaining provisions remain in full force.
16.6. Contact
Questions about this DPA, instructions, objections and audit requests can be sent to support@kukie.io.
Annex I: Description of the Processing
A. Parties
- Controller: the Customer, as identified in its Kukie.io account. Contact: the owner of the account.
- Processor: Pixadoro Ltd., Blvd. Cherni Vrah 47, 1407, Sofia, Bulgaria, company number 206777328. Contact: support@kukie.io.
B. Data Subjects
Visitors to the Customer's websites on which the Banner Script is installed (End Users).
C. Nature and Purpose
Showing a consent banner to End Users, holding back scripts and embedded content until the End User consents, storing the End User's choice, and keeping a record of consent so that the Customer can demonstrate it (Article 7(1) GDPR). The processing consists of collection, recording, storage, hashing, retrieval, transmission and erasure. It is continuous for as long as the Banner Script runs on the Customer's websites.
D. Processing Activities and Personal Data
1. Delivering the banner and detecting the region. Each time a page with the Banner Script loads, the End User's browser requests the script and region information from our servers through our content delivery network. The request contains the End User's IP address, browser user agent and the requested URL. The IP address is used to determine the End User's country (and, for the United States and Canada, the state or province) so that the right banner rules apply. The country is taken from the header added by our content delivery network or, failing that, looked up on our own servers in a locally stored geolocation database. No IP address is sent to a separate geolocation provider. Our application does not store the IP address. Technical server logs are kept for no longer than 90 days.
2. Recording consent (only while consent logging is enabled for the site, which is the default). Each consent record contains:
- a random consent identifier and a random visitor identifier, both generated in the End User's browser. The consent identifier is the one stored in the End User's consent cookie, so the End User holds the reference to their own record (where an older version of the Banner Script does not send it, our server generates the consent identifier instead);
- the action taken (for example accept all, reject all or a custom choice) and the consent categories accepted;
- the date and time, and the banner version shown;
- the End User's country code;
- the address of the page on which consent was given, without its query string or fragment;
- keyed cryptographic hashes (HMAC-SHA256) of the End User's IP address and browser user agent. The IP address and user agent themselves are not stored;
- where supplied, the resulting Google Consent Mode state.
Consent records are kept for the retention period chosen for the site, which cannot exceed the maximum of the Customer's Plan (between 12 and 36 months), and are deleted within one month after that period ends. Short-lived technical copies exist while a record is being written: rate-limiting entries keyed on a hash of the IP address expire within 10 minutes, and a record that fails to be written is kept in the processing queue for up to 30 days for diagnosis.
3. Storing the choice on the End User's device. The Banner Script stores the End User's choice in the End User's own browser, where it is not accessible to us:
- the
_cc_consentcookie holds the consent choices, the consent identifier of the matching consent record, the date, the banner version and the region, for the period the Customer configures (1 to 730 days, 365 by default); - local storage holds the random visitor identifier used in consent records, until the End User clears it;
- if the Customer enables consent cookies on its own subdomain, a
kk_consentcookie holds the same choices for 365 days. To set it, our server receives the choices over that subdomain and returns them as a cookie without storing them; - if the Customer enables the accessibility widget, the End User's display preferences are kept in local storage and are never sent to us.
4. Verifying a consent record. A consent record can be looked up by its consent identifier (the one in the End User's consent cookie) together with the site key. The response contains the choices, the date, the country code and the banner version, and does not contain the visitor identifier, the hashes or the page address.
5. Scanning, compliance checks and uptime monitoring. These features visit the Customer's public pages from our servers with a fresh automated browser. They do not process data about real End Users. The cookie scanner records the cookies and storage entries created during its own visit (including a sample of each value), and the scripts and embedded content it finds; scan results are kept for 30 days, and the 5 most recent scans of each site are always kept. Uptime checks record only the response status, response time and type of error.
E. Special Categories
None. The Services are not designed to process special categories of Personal Data.
F. Duration
For the term of the Agreement and until deletion under clause 13.
G. Supervisory Authority
For Kukie: the Commission for Personal Data Protection of Bulgaria. For the Customer: the Supervisory Authority competent for the Customer.
Annex II: Technical and Organisational Measures
1. Confidentiality
- Hosting and physical security. All servers run in data centres of Hetzner Online GmbH in the European Union, operated under an ISO/IEC 27001-certified information security management system. We keep no servers or Customer Personal Data in our offices.
- Server access. Administrative access to the production servers is limited to authorised personnel and uses SSH key authentication. The database is protected by credentials and accepts connections from the application.
- Account security. Passwords are stored as bcrypt hashes and are checked against known breached passwords when set. Two-factor authentication (TOTP) is available to every account. Sign-in, two-factor and password reset attempts are rate-limited. Session cookies are Secure, HttpOnly and SameSite, and sessions expire after 120 minutes of inactivity.
- Roles and tenant separation. Every customer's data is logically separated by organisation and checked on each request. Access within an organisation follows the owner, admin and editor roles and per-site access, and exporting or deleting consent records requires the owner or admin role. The separation is covered by automated tests.
- Our staff's access. Our staff access a customer account only to provide support, investigate a security issue or meet a legal obligation. The start of every support session in a customer account is recorded in an audit log. The administration area is not visible to customer accounts.
- Secrets. Credentials for third-party services, two-factor secrets and mail server passwords are stored encrypted (AES-256). API keys are stored only as hashes.
2. Pseudonymisation and Data Minimisation
- IP addresses and browser user agents are never stored in consent records, only keyed HMAC-SHA256 hashes of them. The key is held outside the database.
- Page addresses are stored without query strings or fragments. Location is stored only as a country code.
- The Banner Script does not send the End User's other cookies, storage or page content to us.
- The Customer can switch consent logging off per site and shorten the retention period.
- Error reports are stripped of cookies, request bodies, headers and user details before they are sent to our error monitoring service.
3. Integrity
- Encryption in transit. All traffic to the Services uses HTTPS, with HTTP Strict Transport Security. Consent subdomains set up by customers require TLS 1.2 or higher. Backups are transferred over an encrypted SSH connection.
- Input handling. All input is validated on the server. Public endpoints are rate-limited per site, per visitor and per IP address. Server-side requests to customer-supplied addresses are restricted to public destinations. HTML and CSS supplied by customers are sanitised, and the Dashboard enforces a Content Security Policy and CSRF protection.
- Consent records. Consent records are written only by the server and cannot be edited in the Dashboard, only exported or deleted.
- Audit log. Sign-ins, failed sign-ins, password resets, account registrations, administrative actions and deletions of consent records are recorded in an audit log.
4. Availability and Resilience
- Traffic passes through Cloudflare's network, which provides DDoS protection and caches each site's Banner Script at the edge.
- Consent records are written through a queue that retries failed writes automatically. Queue workers are supervised and restarted automatically, and a scheduled job empties the queue if a worker stops.
- Errors are reported to an error monitoring service. System health, the task scheduler and the age of the latest backup are checked automatically, and failures raise an alert.
5. Recoverability
- A full database backup is taken every six hours and stored with a separate backup provider in the European Union for 30 days. A failed backup raises an alert.
- Each deployment is installed as a separate release, so a faulty release can be rolled back.
6. Regular Testing and Review
- An automated test suite, including tests for tenant separation, access control, rate limits and security headers, must pass before each deployment and runs again on every push to our code repository.
- We regularly review the code for security issues and record each finding in a defect register until it is fixed.
- Dependencies are updated regularly and checked against published security advisories when they are updated.
- Sub-processors are selected with a review of their data protection terms and are engaged under contracts that meet Article 28 GDPR.
- We review this Annex at least once a year and whenever the processing changes materially.
Annex III: Sub-processors
These Sub-processors process Customer Personal Data. Providers that process only our own customer and billing data (such as payment and newsletter providers) are listed in section 6.1 of our Privacy Policy.
| Sub-processor | Service | Customer Personal Data | Location and safeguard |
|---|---|---|---|
| Hetzner Online GmbH (Gunzenhausen, Germany) |
Hosting of the application, the database and the Banner Script files | All Customer Personal Data | European Union |
| Cloudflare, Inc. (San Francisco, USA) |
Content delivery, DDoS protection, TLS termination (including customers' consent subdomains) and country detection | IP address, user agent and request contents, in transit | Global network, including outside the EEA. EU-U.S. Data Privacy Framework and Standard Contractual Clauses |
| Functional Software, Inc. (Sentry) (San Francisco, USA) |
Error monitoring | Only incidental, such as a page address in an error report. Cookies, request bodies, headers and user details are removed before sending | EU data region (Germany). Standard Contractual Clauses |
| NS1.bg (Bulgaria) |
Offsite backup storage | Database backups, including consent records, kept for 30 days | European Union |
