Privacy Notice Detailing Consent Requirements
| Version | 1.0 |
| Effective Date | April 2026 |
| Review Cycle | Annual |
| Document Owner | Chief Information Security Officer (CISO) |
| Classification | CONFIDENTIAL — Internal Use Only |
| Applicable Standard | SOC 2 Type II |
1. Privacy Notice — DCKAP Integrator
Effective Date: June 27, 2026 | Last Reviewed: June 27, 2026
This Privacy Notice explains how DCKAP (the company behind DCKAP Integrator) collects, uses, and processes personal information, and sets out when explicit consent is required — along with the consequences of not providing it.
2. Who We Are
DCKAP operates the DCKAP Integrator platform, an Integration Middleware service that enables businesses to transfer and transform data between their enterprise software systems (such as eCommerce platforms and ERP systems). In providing this service, DCKAP acts as a Data Processor on behalf of its customers (Data Controllers).
3. When Explicit Consent is Required
3.1 Situations Requiring Explicit Consent
| Situation | Consent Requirement | Consequence of Refusal |
|---|---|---|
| Marketing communications from DCKAP | Explicit opt-in required (checkbox) | No marketing emails sent — service unaffected |
| Processing special category data (e.g., health-related product data tagged as sensitive) | Explicit written consent from Data Controller required | Feature/flow cannot be activated |
| Sharing data with new sub-processors | Data Controller notified; 30-day objection window | Customer may terminate DPA without penalty |
| Processing personal data outside the agreed scope | Explicit written instruction from Data Controller | Processing will not proceed |
| Cookies (non-essential) on dckap.com portal | Cookie consent banner opt-in | Non-essential cookies not set |
3.2 When Explicit Consent is NOT Required
- Processing of personal data strictly necessary to deliver the contracted integration service (lawful basis: contract performance).
- Processing required by applicable law (lawful basis: legal obligation).
- Processing for DCKAP’s legitimate security and operational interests where not overridden by data subject rights (lawful basis: legitimate interest).
4. Legal Basis for Processing
| Processing Activity | Legal Basis | GDPR Article |
|---|---|---|
| Deliver integration service | Contract performance | Art. 6(1)(b) |
| Security monitoring and fraud prevention | Legitimate interest | Art. 6(1)(f) |
| Legal / regulatory compliance | Legal obligation | Art. 6(1)(c) |
| Marketing emails (with consent) | Consent | Art. 6(1)(a) |
| Special category data (if any) | Explicit consent | Art. 9(2)(a) |
5. Your Rights
- Right to access your personal data.
- Right to rectification of inaccurate data.
- Right to erasure (‘right to be forgotten’) where applicable.
- Right to restrict processing.
- Right to data portability.
- Right to withdraw consent at any time (where consent is the legal basis).
- Right to lodge a complaint with a supervisory authority.
To exercise these rights, contact: privacy@dckap.com
6. Placement in Product
| Product Location | Screen / Page | Audience |
|---|---|---|
| Public Website | dckap.com/privacy (publicly accessible) | All Data Subjects |
| Product Portal | Footer → Privacy Notice (every page) | All Portal Users |
| Sign-up / Onboarding | Presented and acknowledged during account creation | New Customers |
| Cookie Banner | First portal visit — consent collection | All Portal Visitors |
| Compliance Folder | SOC 2 Evidence → Privacy Notice | External Auditors |