Retørn

Data Processing Agreement — Retørn

This Data Processing Agreement ("DPA") forms part of, and is subject to, the Retørn Terms & Conditions between the Merchant and Sambeso ApS (operator of Retørn). It governs Retørn's processing of personal data on the Merchant's behalf.

Last updated: 8 July 2026

1. Definitions

2. Subject matter & scope

Retørn processes personal data solely to provide the returns/exchanges/claims service: end-customer name, email, order and address data, return reasons, uploaded photos, and return/refund status (see the Privacy Policy for the full list). Processing lasts for the term of the Merchant's subscription.

3. Obligations of the Data Controller (Merchant)

The Merchant warrants that: processing is carried out in accordance with the GDPR and applicable law; data subjects have been duly informed (purpose, rights, recipients, privacy policy); it has a lawful basis to share the data with Retørn; and it will respond promptly to data-protection-authority and data-subject requests, giving Retørn appropriate instructions.

4. Obligations of the Data Processor (Retørn)

Retørn undertakes to:

5. Sub-processors

The Merchant authorizes Retørn to engage sub-processors. The current sub-processors are:

Sub-processor Purpose
Shopify Source of order/customer data; billing
Fly.io Hosting + database (EU region)
Resend Transactional email delivery
Shipmondo Return-label generation + carrier hand-off

Retørn will inform the Merchant in advance of any intended addition or replacement of a sub-processor, giving the Merchant a reasonable period to object. Retørn imposes data-protection obligations on each sub-processor no less protective than this DPA and remains liable to the Merchant for its sub-processors' performance.

6. Personal Data Breach

Retørn will notify the Merchant without undue delay and at the latest within 72 hours of becoming aware of a personal-data breach affecting the Merchant's data, with the information the Merchant needs to meet its own notification obligations, and will take reasonable steps to identify the cause and remediate.

7. Security measures

Retørn maintains appropriate technical and organizational measures at all times to prevent unauthorized access to or use of personal data, no less than those required by applicable law — including encryption in transit, access controls, per-tenant data isolation, least-privilege API scopes, and audit logging. Personal data is treated as confidential.

8. Return / deletion of data

On termination of the service (uninstall), Retørn deletes the Merchant's personal data after a short reinstall window (up to 48 hours), honouring Shopify's shop/redact webhook, unless retention is required by law. Retørn also honours customers/redact to erase or anonymize a specific end-customer's data on request.

9. International transfers

Personal data is hosted in the EU. Any transfer outside the EEA relies on an adequacy decision or the European Commission's Standard Contractual Clauses.

10. Governing law

This DPA is governed by Danish law and is subject to the jurisdiction of the Danish courts.