Data Processing Agreement
Last updated: August 29, 2026
This DPA forms part of the agreement between you (“Customer”) and CMPStack, operator of CMPStack (“Processor”), when you use the service to process personal data. Processor notices: Bangladesh. It supplements our Terms of Service and Privacy Policy.
1. Roles
Customer is the controller (or a processor acting for a controller) of end-user consent data and related visitor signals collected via the embedded banner. CMPStack acts as a processor and processes that data only to provide the service.
2. Subject matter
Processing includes storing account profile data, domain configuration, cookie inventory metadata, consent preferences, and optional webhook delivery of consent events that Customer configures.
3. Duration
Processing continues for the life of Customer’s account and for retention periods applicable to consent logs under the Customer’s plan, unless earlier deletion is requested or required by law.
4. Nature and purpose
Purpose is limited to operating the CMP: authentication, banner delivery, compliance configuration, scanning, consent logging, notifications, and billing. We do not sell Customer personal data or use consent logs for advertising.
5. Types of data
- Account email, name, and authentication credentials (hashed passwords)
- Domain names, DNS verification tokens, and banner settings
- Consent actions, category preferences, language, region, user agent, and IP address associated with visitor interactions
- Support correspondence Customer sends to us
6. Customer instructions
Customer instructs CMPStack to process personal data as necessary to provide the documented features of the service. Customer is responsible for lawful collection notices, privacy policy links, and regulatory choices configured in the dashboard.
7. Security measures
Processor implements appropriate technical and organizational measures described on our Security page, including TLS in transit, hashed passwords, access controls, domain verification, and rate limiting.
8. Subprocessors
Customer authorizes use of the following subprocessors. We will update the list on the Security page when providers change.
- Railway — Application hosting and managed PostgreSQL
- Paddle — Merchant of record for paid subscriptions
- Resend — Transactional email (invites, password reset, support)
9. International transfers
Infrastructure may process data in regions where our hosting and subprocessors operate. Where required, we rely on appropriate transfer mechanisms offered by those providers (for example standard contractual clauses).
10. Assistance & deletion
Upon written request to contact@cmpstack.com, we will assist with reasonable data subject requests and, after account closure, delete or return Customer personal data within commercially reasonable time, except where retention is required by law or for secure backups pending rotation.
11. Incident notice
If we become aware of a personal data breach affecting Customer data, we will notify Customer without undue delay and provide information reasonably available to help Customer meet legal obligations.
12. Contact
Privacy and DPA questions: CMPStack, Bangladesh. Email contact@cmpstack.com. For a countersigned copy for your vendor file, email us from your account address with your company legal name.