Returner
  • Exchanges Instant refunds Claims Automation Insights Fraud & risk EU compliance
  • Portal
  • Carriers
  • Developers
  • Pricing
Try the demo

Data Processing Agreement

Last updated: July 5, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Friros AB (org. nr 559100-9047, Svampvägen 3A, 705 10 Örebro, Sweden) ("Processor", operating the Returner service) and the customer merchant ("Controller") and reflects the parties' agreement on the processing of personal data under Article 28 of the EU General Data Protection Regulation ("GDPR"). A countersigned copy is available on request from [email protected]; absent a separately negotiated agreement, this DPA governs.

Contents

  1. 1. Roles & scope
  2. 2. Processing on instructions
  3. 3. Confidentiality
  4. 4. Security measures
  5. 5. Sub-processors
  6. 6. Data subject rights
  7. 7. Personal data breaches
  8. 8. Assistance & DPIAs
  9. 9. International transfers
  10. 10. Return & deletion
  11. 11. Audits
  12. 12. Annexes

1. Roles & scope

For end-customer personal data processed through the Returner service, the merchant is the Controller and Friros AB is the Processor. For merchant-account data (staff identities, billing), Friros AB is an independent Controller as described in the Privacy Policy. This DPA governs the Processor's processing of Controller Personal Data. The subject matter, duration, nature, purpose, data types, and categories of data subjects are set out in Annex 1.

2. Processing on documented instructions

The Processor shall process Controller Personal Data only on the Controller's documented instructions, including the instructions embodied in the Terms of Service and the configuration choices the Controller makes in the Service, unless required otherwise by EU or member-state law (in which case the Processor will inform the Controller before processing, unless the law prohibits it). The Processor shall not sell Controller Personal Data or process it for its own purposes. The Processor shall promptly inform the Controller if, in its opinion, an instruction infringes the GDPR.

3. Confidentiality

The Processor ensures that persons authorised to process Controller Personal Data are bound by an obligation of confidentiality and are granted access only on a need-to-know basis, subject to the Processor's access-control and least-privilege measures.

4. Security measures

Taking into account the state of the art and the risks of processing, the Processor implements appropriate technical and organisational measures under Article 32 GDPR, described in Annex 2. These include tenant isolation, encryption of data in transit and encryption at rest of sensitive fields and credentials, least-privilege access, structured PII-scrubbing logging, audit logging, and a documented incident-response process.

5. Sub-processors

The Controller grants general authorisation for the Processor to engage the sub-processors listed in the Sub-Processor Register. The Processor imposes data-protection obligations on each sub-processor no less protective than those in this DPA and remains liable for their performance. The Processor will give the Controller advance notice of any intended addition or replacement of a sub-processor (subscribe at [email protected]), allowing the Controller to object on reasonable data-protection grounds.

6. Data subject rights

Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligation to respond to requests to exercise data-subject rights (access, rectification, erasure, restriction, portability, objection). The Service provides self-service export and erasure tooling and honours Shopify's mandatory customers/data_request, customers/redact, and shop/redact flows.

7. Personal data breaches

The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting Controller Personal Data, and provides the information the Controller reasonably needs to meet its own notification obligations under Articles 33–34 GDPR. The Processor maintains an incident register and a 72-hour breach-assessment process.

8. Assistance & data protection impact assessments

The Processor provides reasonable assistance to the Controller with data protection impact assessments and prior consultations with supervisory authorities under Articles 35–36 GDPR, taking into account the nature of processing and the information available to the Processor.

9. International transfers

Primary application data is hosted in the EU. Where processing involves a transfer of Controller Personal Data to a third country (for example, US-based sub-processors), the Processor relies on an adequacy decision, EU Standard Contractual Clauses, or another valid Chapter V transfer mechanism, and applies supplementary measures as appropriate. Transfer details are in the Sub-Processor Register.

10. Return & deletion of data

On termination of the Service, and at the Controller's choice, the Processor deletes or returns Controller Personal Data and deletes existing copies, unless retention is required by EU or member-state law (for example, statutory accounting records). Following an app uninstall, tenant data is deleted within the period stated in the Privacy Policy. Data is otherwise subject to the retention schedule and the automated storage-limitation job described in the Privacy Policy.

11. Audits

The Processor makes available to the Controller information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable notice, confidentiality, and frequency limits. The Processor may satisfy audit requests by providing its compliance documentation and third-party attestations where available.

12. Annexes

Annex 1 — Details of processing

  • Subject matter: provision of the Returner returns-management service.
  • Duration: for the term of the Terms of Service, plus any legally required retention.
  • Nature & purpose: receiving, storing, and processing return requests, labels, refunds/exchanges, and related communications on the Controller's behalf.
  • Categories of data subjects: the Controller's end customers and, where applicable, the Controller's staff users.
  • Types of personal data: name, email, phone, shipping/billing/return address, order line items, return reason, condition photos, store-credit balances; for staff users, email, name, and role.
  • Special categories: none intended or required.

Annex 2 — Technical & organisational measures

  • Per-tenant isolation (row-level security posture with fail-closed boot checks).
  • Encryption in transit (TLS) and encryption at rest of sensitive identifiers and credentials.
  • Least-privilege access controls and audited administrative/impersonation actions.
  • Structured logging with PII scrubbing; error monitoring with PII scrubbing.
  • Webhook signature verification and idempotent processing on money/state changes.
  • Documented incident-response process with a 72-hour breach-assessment clock.
  • Automated data-retention/anonymisation and data-subject-rights tooling.
To request a countersigned DPA or discuss bespoke terms, contact [email protected]. See also our Sub-Processor Register and Privacy Policy.
Returner

Return portal infrastructure
for e-commerce.

Platform

  • Return portal
  • Exchanges
  • Claims
  • Carriers
  • Automation
  • Insights
  • Fraud & risk
  • EU compliance
  • Developers

Resources

  • Try the demo

Company

  • Contact
  • Privacy
  • AI Policy
  • Terms
  • DPA
  • Sub-processors

© 2026 Returner. Friros AB, Örebro, Sweden.

returner.me