Data Processing Agreement — Retørn
This Data Processing Agreement ("DPA") forms part of, and is subject to, the Retørn Terms & Conditions between the Merchant and Sambeso ApS (operator of Retørn). It governs Retørn's processing of personal data on the Merchant's behalf.
Last updated: 8 July 2026
1. Definitions
- Personal data — any information relating to an identified or identifiable natural person.
- Data subject — a natural person whose personal data is processed (here, a store's end-customer).
- Data Controller — the Merchant, who determines the purposes and means of processing.
- Data Processor — Sambeso ApS (Retørn), which processes personal data on the Merchant's instructions and on its behalf.
- Processing — any operation performed on personal data (collection, storage, use, transmission, erasure, etc.).
- Personal Data Breach — a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.
2. Subject matter & scope
Retørn processes personal data solely to provide the returns/exchanges/claims service: end-customer name, email, order and address data, return reasons, uploaded photos, and return/refund status (see the Privacy Policy for the full list). Processing lasts for the term of the Merchant's subscription.
3. Obligations of the Data Controller (Merchant)
The Merchant warrants that: processing is carried out in accordance with the GDPR and applicable law; data subjects have been duly informed (purpose, rights, recipients, privacy policy); it has a lawful basis to share the data with Retørn; and it will respond promptly to data-protection-authority and data-subject requests, giving Retørn appropriate instructions.
4. Obligations of the Data Processor (Retørn)
Retørn undertakes to:
- process personal data only on the Merchant's documented instructions and for the purposes above;
- ensure persons authorized to process the data are bound by confidentiality and trained appropriately;
- apply privacy by design and by default;
- notify the Merchant if, in its opinion, an instruction infringes the GDPR or other data-protection law;
- assist the Merchant, as far as possible, in responding to data-subject requests (access, rectification, erasure, restriction, portability, objection);
- assist the Merchant with security, breach-notification and impact-assessment obligations;
- at the Merchant's choice, delete or return all personal data at the end of the service (see §8);
- make available information necessary to demonstrate compliance and allow for reasonable audits.
5. Sub-processors
The Merchant authorizes Retørn to engage sub-processors. The current sub-processors are:
| Sub-processor | Purpose |
|---|---|
| Shopify | Source of order/customer data; billing |
| Fly.io | Hosting + database (EU region) |
| Resend | Transactional email delivery |
| Shipmondo | Return-label generation + carrier hand-off |
Retørn will inform the Merchant in advance of any intended addition or replacement of a sub-processor, giving the Merchant a reasonable period to object. Retørn imposes data-protection obligations on each sub-processor no less protective than this DPA and remains liable to the Merchant for its sub-processors' performance.
6. Personal Data Breach
Retørn will notify the Merchant without undue delay and at the latest within 72 hours of becoming aware of a personal-data breach affecting the Merchant's data, with the information the Merchant needs to meet its own notification obligations, and will take reasonable steps to identify the cause and remediate.
7. Security measures
Retørn maintains appropriate technical and organizational measures at all times to prevent unauthorized access to or use of personal data, no less than those required by applicable law — including encryption in transit, access controls, per-tenant data isolation, least-privilege API scopes, and audit logging. Personal data is treated as confidential.
8. Return / deletion of data
On termination of the service (uninstall), Retørn deletes the Merchant's personal data after a short
reinstall window (up to 48 hours), honouring Shopify's shop/redact webhook, unless retention is
required by law. Retørn also honours customers/redact to erase or anonymize a specific end-customer's
data on request.
9. International transfers
Personal data is hosted in the EU. Any transfer outside the EEA relies on an adequacy decision or the European Commission's Standard Contractual Clauses.
10. Governing law
This DPA is governed by Danish law and is subject to the jurisdiction of the Danish courts.