This Data Processing Addendum (the "DPA") forms part of the agreement between Rooni and the Customer for the use of Rooni Trust Signal. It applies where Rooni processes personal data on behalf of the Customer in connection with Trust Signal.
1. Parties
This DPA is between the Customer (the organisation or person using Rooni Trust Signal) and the Processor (Rooni). The Customer and Rooni are each a "party" and together the "parties".
2. Relationship with the Terms
This DPA forms part of the Rooni Trust Signal Terms & Conditions. If there is a conflict between this DPA and the Terms, this DPA will apply to the extent the conflict relates to the processing of personal data on behalf of the Customer. If the parties have signed a separate data processing agreement, that signed agreement will apply instead of this DPA.
3. Definitions
"Applicable Data Protection Laws" means all data protection and privacy laws that apply to the processing of personal data under this DPA, including where applicable the GDPR, UK GDPR, Data Protection Act 2018, ePrivacy laws, PECR, and relevant national implementing laws. "Controller", "processor", "personal data", "personal data breach", "processing", "data subject", and "sub-processor" have the meanings given to them under Applicable Data Protection Laws. "Customer Personal Data" means personal data processed by Rooni on behalf of the Customer through Rooni Trust Signal. "Services" means Rooni Trust Signal and related services provided by Rooni to the Customer.
4. Roles of the parties
For Customer Personal Data processed through Trust Signal, the Customer is the controller and Rooni is the processor. Rooni will process Customer Personal Data only on documented instructions from the Customer, unless required to do otherwise by law. The Customer is responsible for ensuring that its use of Trust Signal complies with Applicable Data Protection Laws.
5. Customer instructions
The Customer instructs Rooni to process Customer Personal Data as necessary to provide Trust Signal; manage consent banners and preference centres; store and retrieve consent choices; generate consent signals; provide dashboards, analytics, logs, and reports; support website scans and configuration tools; provide customer support; maintain platform security; and comply with the Customer's lawful instructions. The Customer may provide additional instructions through the platform, configuration settings, support requests, or written instructions. Rooni may decline an instruction if it reasonably believes the instruction violates Applicable Data Protection Laws.
6. Details of processing
| Item | Description |
|---|---|
| Subject matter | Processing of personal data through Rooni Trust Signal for consent management and related privacy tooling. |
| Duration | For the duration of the Customer's subscription, plus any retention period required by the Terms, this DPA, Customer configuration, or applicable law. |
| Nature of processing | Collection, recording, storage, retrieval, consultation, structuring, transmission, deletion, anonymisation, aggregation, and analysis. |
| Purpose | Providing consent management, preference management, consent records, cookie/script scanning, analytics, reporting, and related support. |
| Data subjects | Customer account users, Customer staff, website visitors, app users, end users who interact with Trust Signal on Customer websites or services. |
| Personal data | Email address, name, account identifiers, IP address, device/browser data, consent choices, consent timestamps, region or jurisdiction, preference records, cookie identifiers, technical logs, configuration data. |
| Special category data | Trust Signal is not designed to process special category data. Customer must not intentionally submit special category data unless expressly agreed in writing. |
| Frequency | Continuous or as required to provide the Services. |
| Retention | According to Customer configuration (12–120 months for consent records), the Terms, this DPA, and Rooni's retention settings. |
7. Customer obligations
The Customer must have a lawful basis for processing Customer Personal Data; provide required privacy notices to end users; ensure consent banner wording and preference centre content is accurate; ensure scripts, cookies, tags, SDKs, and vendors are correctly configured; ensure only appropriate personal data is submitted to Trust Signal; respond to data subject requests where the Customer is controller; ensure its own use of Trust Signal complies with Applicable Data Protection Laws; and keep account access secure.
8. Rooni obligations
Rooni will process Customer Personal Data only on documented Customer instructions; ensure persons authorised to process Customer Personal Data are subject to confidentiality obligations; implement appropriate technical and organisational measures; assist the Customer with data subject requests where required and reasonably possible; assist the Customer with security, breach notification, DPIAs, and regulatory consultations where required by law; make available information reasonably necessary to demonstrate compliance with this DPA; delete or return Customer Personal Data at the end of the Services, subject to legal retention requirements; and comply with Article 28 processor obligations where GDPR or UK GDPR applies.
9. Confidentiality
Rooni will ensure that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations.
10. Security measures
Rooni will implement appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures may include access controls, role-based permissions, authentication controls, encryption in transit, encryption at rest where supported, logging and monitoring, backup and recovery processes, secure development practices, vulnerability management, incident response procedures, vendor management, staff confidentiality obligations, environment separation, and least-privilege access. The exact measures may evolve over time provided the overall level of protection is not materially reduced.
11. Sub-processors
The Customer gives Rooni general written authorisation to use sub-processors to provide the Services. Rooni maintains a list of sub-processors in the Privacy & Cookie Notice. Rooni will impose data protection obligations on sub-processors that provide an equivalent level of protection for Customer Personal Data as required by this DPA. Where required by Applicable Data Protection Laws, Rooni will notify Customers of intended changes to sub-processors and give Customers an opportunity to object on reasonable data protection grounds.
12. Objection to new sub-processors
If the Customer objects to a new sub-processor, the Customer must notify Rooni in writing within 30 days of receiving notice. The objection must explain the reasonable data protection grounds for the objection. Rooni will use reasonable efforts to resolve the objection, which may include providing additional information, using an alternative sub-processor where commercially reasonable, allowing the Customer to disable affected functionality, or permitting termination of the affected Services where no reasonable alternative is available.
13. International transfers
Rooni may process Customer Personal Data in countries outside the Customer's country, the UK, or the European Economic Area where necessary to provide the Services. Where required, Rooni will use appropriate transfer safeguards, which may include adequacy decisions, Standard Contractual Clauses, the UK International Data Transfer Addendum, transfer risk assessments, or other lawful transfer mechanisms.
14. Data subject requests
Taking into account the nature of the processing, Rooni will provide reasonable assistance to the Customer to help respond to data subject requests, including access, deletion, correction, restriction, objection, portability, and withdrawal requests where the relevant data is processed through Trust Signal. If Rooni receives a request directly from an end user relating to Customer Personal Data, Rooni may redirect the request to the Customer unless prohibited by law.
15. Personal data breaches
Rooni will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notification will include available information reasonably required to help the Customer meet its own breach notification obligations, where applicable. Rooni will take reasonable steps to investigate, contain, and mitigate the breach.
16. Assistance with compliance
Taking into account the nature of processing and the information available to Rooni, Rooni will provide reasonable assistance to the Customer with security obligations, personal data breach notifications, data protection impact assessments, and prior consultation with supervisory authorities where required.
17. Return or deletion of data
At the end of the Services, Rooni will delete or return Customer Personal Data, at the Customer's choice, unless applicable law requires continued storage. Where self-service export or deletion tools are available, the Customer is responsible for using those tools before termination. Rooni may retain limited data where required for legal, accounting, security, backup, dispute, or compliance purposes.
18. Audits and information
Rooni will make available information reasonably necessary to demonstrate compliance with this DPA. Where required by Applicable Data Protection Laws, Rooni will allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor appointed by the Customer. Audits must be subject to reasonable prior notice; conducted during normal business hours; limited to once per year unless there is a confirmed personal data breach or legal requirement; conducted in a way that does not compromise security, confidentiality, or other customers' data; and at the Customer's expense unless required by law. Rooni may satisfy audit obligations by providing security documentation, certifications, summaries, questionnaires, or third-party audit reports where appropriate.
19. Customer configuration and responsibility
The Customer acknowledges that Trust Signal is a configurable platform. The Customer is responsible for choosing consent categories; configuring consent signals; approving banner and preference centre wording; deciding whether consent is required for specific technologies; determining retention settings; ensuring third-party tags and scripts behave according to consent choices; validating cookie or script scan results; and maintaining accurate privacy and cookie disclosures. Rooni is not responsible for unlawful tracking, incorrect consent collection, or inaccurate disclosures caused by Customer configuration, Customer websites, Customer vendors, or third-party scripts outside Rooni's control.
20. Liability
Liability under this DPA is subject to the limitations and exclusions in the Terms, unless prohibited by Applicable Data Protection Laws.
21. Changes to this DPA
Rooni may update this DPA from time to time. If changes materially reduce Customer protections, Rooni will take reasonable steps to notify affected Customers. Continued use of the Services after the effective date of updated terms means the updated DPA applies, unless otherwise prohibited by law or agreed in writing.
22. Contact
Questions about this DPA can be sent to the Rooni Privacy Team at privacy@rooni.io.
Annex 1 — Technical and organisational measures
| Area | Measures |
|---|---|
| Access control | Role-based access, least-privilege access, authentication controls. |
| Data protection | Encryption in transit, controlled access to production systems, backup controls. |
| Availability | Monitoring, backups, recovery procedures. |
| Confidentiality | Staff confidentiality obligations, restricted access to Customer data. |
| Integrity | Logging, change controls, deployment controls. |
| Security operations | Incident response, vulnerability monitoring, abuse detection. |
| Vendor management | Sub-processor review, contractual data protection terms. |
| Product security | Secure development practices, environment separation. |
| Auditability | Logs, administrative records, support records where applicable. |
Annex 2 — Approved sub-processors
The Customer authorises Rooni to use the sub-processors listed in the Privacy & Cookie Notice.
For questions, contact us at support@rooni.io.