revokerie

Data processing addendum

Effective 23 September 2026

This addendum forms part of the terms of service between the business that installs Revokerie - EU Withdrawal Form (the "controller") and Errie Studios, Markerkant 13-11, 1314 AL Almere, the Netherlands, KvK 80513573 (the "processor"). It meets the requirements of Article 28 of the General Data Protection Regulation (GDPR) and applies as long as the app is installed.

1. Details of the processing

Subject and purposeProviding the withdrawal function in the controller's Shopify store: receiving withdrawal statements, matching them to orders, sending the acknowledgment of receipt, notifying the controller and keeping a record.
DurationWhile the app is installed, plus the deletion period in section 9.
Data subjectsCustomers of the controller who use the withdrawal function.
Personal dataName, email address, order number, chosen products and quantities, optional comment, the withdrawal statement, date and time of submission, reference and email delivery status. Order data read from Shopify to match the order.
Special categoriesNone intended.

2. Instructions

The processor processes the personal data only on documented instructions of the controller. The terms, the app's features and the settings the controller chooses in the app are those instructions. The processor informs the controller if it believes an instruction breaks data protection law.

3. Confidentiality

Everyone who can access the personal data on behalf of the processor is bound by confidentiality.

4. Security

The processor takes appropriate technical and organisational measures, including: TLS encryption in transit; encryption at rest of the database and, additionally, of Shopify access tokens with AES-GCM; storage of withdrawal records in the European Union; verification of every request with Shopify signatures or session tokens; showing order details only after order number and email match; rate limiting; the minimum set of Shopify permissions; and access to production systems limited to authorised personnel with two-factor authentication.

5. Sub-processors

The controller authorises the processor to use Cloudflare, Inc. for hosting, database, email sending and network security. The processor binds sub-processors to obligations at least as protective as this addendum, and announces new or replaced sub-processors at least 30 days in advance on this page and by email, so the controller can object. If the objection cannot be resolved, the controller may uninstall the app.

6. International transfers

Withdrawal records are stored in the European Union. Where Cloudflare handles data outside the European Economic Area, the transfer relies on the EU-US Data Privacy Framework or the European Commission's standard contractual clauses.

7. Assistance

The processor helps the controller respond to requests from data subjects and meet its obligations under Articles 32 to 36 GDPR, as far as reasonable. The app itself supports this with a record of every withdrawal, a CSV export and automatic handling of Shopify's customer data and erasure requests.

8. Personal data breaches

The processor notifies the controller without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach, with the information the controller needs to meet its own obligations.

9. Deletion at the end

When the app is uninstalled, access tokens are deleted immediately and all personal data of the controller's store is deleted when Shopify sends its store erasure request, 48 hours after uninstalling. Backups of the database expire within 30 days. The controller can export its records (CSV, on every plan) before uninstalling.

10. Information and audits

The processor makes available the information needed to demonstrate compliance with this addendum and allows reasonable audits, announced at least 30 days in advance, at the controller's expense, no more than once a year unless a breach gives cause.

11. Liability and precedence

The liability provisions of the terms of service apply to this addendum. If this addendum conflicts with the terms of service regarding personal data, this addendum prevails.