Last updated: July 5, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Friros AB (org. nr 559100-9047, Svampvägen 3A, 705 10 Örebro, Sweden) ("Processor", operating the Returner service) and the customer merchant ("Controller") and reflects the parties' agreement on the processing of personal data under Article 28 of the EU General Data Protection Regulation ("GDPR"). A countersigned copy is available on request from [email protected]; absent a separately negotiated agreement, this DPA governs.
For end-customer personal data processed through the Returner service, the merchant is the Controller and Friros AB is the Processor. For merchant-account data (staff identities, billing), Friros AB is an independent Controller as described in the Privacy Policy. This DPA governs the Processor's processing of Controller Personal Data. The subject matter, duration, nature, purpose, data types, and categories of data subjects are set out in Annex 1.
The Processor shall process Controller Personal Data only on the Controller's documented instructions, including the instructions embodied in the Terms of Service and the configuration choices the Controller makes in the Service, unless required otherwise by EU or member-state law (in which case the Processor will inform the Controller before processing, unless the law prohibits it). The Processor shall not sell Controller Personal Data or process it for its own purposes. The Processor shall promptly inform the Controller if, in its opinion, an instruction infringes the GDPR.
The Processor ensures that persons authorised to process Controller Personal Data are bound by an obligation of confidentiality and are granted access only on a need-to-know basis, subject to the Processor's access-control and least-privilege measures.
Taking into account the state of the art and the risks of processing, the Processor implements appropriate technical and organisational measures under Article 32 GDPR, described in Annex 2. These include tenant isolation, encryption of data in transit and encryption at rest of sensitive fields and credentials, least-privilege access, structured PII-scrubbing logging, audit logging, and a documented incident-response process.
The Controller grants general authorisation for the Processor to engage the sub-processors listed in the Sub-Processor Register. The Processor imposes data-protection obligations on each sub-processor no less protective than those in this DPA and remains liable for their performance. The Processor will give the Controller advance notice of any intended addition or replacement of a sub-processor (subscribe at [email protected]), allowing the Controller to object on reasonable data-protection grounds.
Taking into account the nature of the processing, the Processor assists the Controller by
appropriate technical and organisational measures, insofar as possible, in fulfilling the
Controller's obligation to respond to requests to exercise data-subject rights (access,
rectification, erasure, restriction, portability, objection). The Service provides self-service
export and erasure tooling and honours Shopify's mandatory customers/data_request, customers/redact, and shop/redact flows.
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting Controller Personal Data, and provides the information the Controller reasonably needs to meet its own notification obligations under Articles 33–34 GDPR. The Processor maintains an incident register and a 72-hour breach-assessment process.
The Processor provides reasonable assistance to the Controller with data protection impact assessments and prior consultations with supervisory authorities under Articles 35–36 GDPR, taking into account the nature of processing and the information available to the Processor.
Primary application data is hosted in the EU. Where processing involves a transfer of Controller Personal Data to a third country (for example, US-based sub-processors), the Processor relies on an adequacy decision, EU Standard Contractual Clauses, or another valid Chapter V transfer mechanism, and applies supplementary measures as appropriate. Transfer details are in the Sub-Processor Register.
On termination of the Service, and at the Controller's choice, the Processor deletes or returns Controller Personal Data and deletes existing copies, unless retention is required by EU or member-state law (for example, statutory accounting records). Following an app uninstall, tenant data is deleted within the period stated in the Privacy Policy. Data is otherwise subject to the retention schedule and the automated storage-limitation job described in the Privacy Policy.
The Processor makes available to the Controller information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable notice, confidentiality, and frequency limits. The Processor may satisfy audit requests by providing its compliance documentation and third-party attestations where available.