# Data Processing Agreement

**Version:** 1.3
**Last updated:** 20 September 2026
**Effective date:** 20 September 2026
**Status:** Publication version

This Data Processing Agreement (“DPA”) forms part of the agreement governing the use of EUWithdraw between the merchant using the EUWithdraw service (“Controller”) and LAUDATUS LTD, registered in England and Wales, company number 17453960, with registered office at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ, operating EUWithdraw (“Processor”). It applies when the Controller installs or uses EUWithdraw; the authenticated app may also record explicit acceptance for the merchant account.

Earlier versions and their acceptance records are preserved. Acceptance of an earlier version is not acceptance of this version.

This DPA governs the processing of Personal Data by the Processor on behalf of the Controller and is intended to satisfy the requirements of Article 28 of Regulation (EU) 2016/679 (“EU GDPR”) and the UK GDPR where applicable (together, “GDPR”).

## 1. Roles of the Parties

For Personal Data submitted to, retrieved by or otherwise processed through EUWithdraw in connection with a merchant’s customers, orders, withdrawal requests, communications and associated workflows:

* the Merchant acts as **Controller**; and
* EUWithdraw acts as **Processor**.

The Controller determines the purposes for which such Personal Data is processed and instructs EUWithdraw to process that Personal Data through the configuration and use of the EUWithdraw service.

EUWithdraw may act as an **independent Controller** for limited processing that it determines for its own legitimate business or legal purposes, including:

* merchant account administration;
* subscription and billing records;
* fraud and abuse prevention;
* security monitoring;
* access and authentication records;
* legal and regulatory compliance;
* establishment, exercise or defence of legal claims; and
* administration of its contractual relationship with merchants.

Processing performed by EUWithdraw as an independent Controller falls outside the processor obligations of this DPA and is governed by the EUWithdraw Privacy Policy and applicable data protection law.

The role of each external provider shall be determined by reference to the actual processing activity and contractual relationship. A provider is treated as a Subprocessor under this DPA only where EUWithdraw engages that provider to process Personal Data on behalf of the Controller.

Shopify shall therefore not automatically be classified as an EUWithdraw Subprocessor where the Controller maintains its own direct contractual relationship with Shopify.

## 2. Subject Matter and Processing Instructions

The Processor shall process Personal Data solely:

1. to provide and operate EUWithdraw;
2. to execute the Controller's documented configuration and instructions;
3. to process withdrawal and related customer requests;
4. to obtain or update relevant Shopify order and customer information where authorised;
5. to deliver communications requested or configured by the Controller;
6. to maintain evidence and audit records necessary for the operation and security of the service;
7. to assist the Controller in complying with applicable data protection obligations; and
8. where processing is required by applicable Union or Member State law.

The Controller's use and configuration of EUWithdraw constitutes documented instructions to the Processor.

The Processor shall not process Personal Data for its own advertising, profiling or unrelated commercial purposes while acting as Processor.

If the Processor considers that an instruction infringes applicable data protection law, it shall inform the Controller without undue delay and may suspend the affected processing until the instruction is clarified or corrected.

Where the Processor is legally required to process Personal Data contrary to or outside the Controller's instructions, it shall inform the Controller before such processing unless applicable law prohibits such notification.

## 3. Categories of Data Subjects

Processing may concern:

* customers of the Controller;
* persons making or participating in withdrawal, return or related requests;
* authorised merchant users;
* merchant employees and contractors;
* support correspondents; and
* persons whose information is contained in relevant order or communication records.

## 4. Categories of Personal Data

Depending on the Controller's configuration and use of EUWithdraw, Personal Data may include:

* name;
* email address;
* telephone number where supplied;
* customer or Shopify identifiers;
* order identifiers and order information;
* product and transaction information;
* withdrawal and return information;
* customer communications;
* timestamps;
* request status and workflow history;
* merchant configuration information;
* message delivery information;
* IP address and limited device/security metadata;
* authentication and access metadata;
* audit records;
* privacy/DSAR request records;
* appeal or manual-review records; and
* other Personal Data supplied by the Controller or data subject through the service.

EUWithdraw is not intended to require the processing of special categories of Personal Data under Article 9 GDPR. Controllers shall not intentionally provide such data unless specifically supported and lawfully authorised.

## 5. Duration of Processing

Processing shall continue for the duration of the Controller's use of EUWithdraw and for the applicable periods or objective criteria described in the EUWithdraw Privacy Policy and Data Retention Policy.

Personal Data shall not be retained indefinitely.

Retention periods shall be technically enforced through the EUWithdraw retention system where applicable.

Temporary exports and temporary processing artefacts shall automatically expire in accordance with the applicable retention configuration.

Following termination of the service, Personal Data processed on behalf of the Controller shall be deleted or returned in accordance with Section 12, unless continued retention is required by applicable law.

## 6. Confidentiality

The Processor shall ensure that persons authorised to process Personal Data:

* are subject to an appropriate duty of confidentiality;
* receive access only where necessary for their responsibilities;
* process Personal Data only in accordance with authorised instructions; and
* have their access removed or modified when it is no longer required.

Access to production systems and Personal Data shall be restricted according to the principle of least privilege.

## 7. Security of Processing

The Processor shall implement and maintain technical and organisational measures appropriate to the risks associated with the processing.

Such measures shall include, as appropriate:

* encryption of data in transit;
* encryption at rest where supported by the relevant infrastructure;
* access controls and role-based permissions;
* authentication and secure session controls;
* least-privilege access;
* protection and rotation procedures for credentials and secrets;
* segregation of production and development environments;
* audit logging of security-sensitive and privacy-sensitive actions;
* protection against unauthorised access and privilege escalation;
* input validation and application-layer security controls;
* secure webhook authentication and processing;
* rate limiting where appropriate;
* dependency and vulnerability management;
* backup and recovery procedures;
* incident detection and response procedures;
* availability and resilience measures;
* logging designed to avoid unnecessary exposure of Personal Data;
* access revocation procedures;
* secure software development practices; and
* periodic testing and evaluation of relevant security controls.

The current technical and organisational measures are further described in:

`docs/security/security-evidence-index.md`

and associated security documentation.

The Processor may update its security measures to reflect technical developments, provided that such changes do not materially reduce the overall level of protection.

## 8. Personal Data Breaches

The Processor shall notify the Controller **without undue delay** after becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of the Controller.

Where practicable, the Processor shall provide an initial notification within 24 hours after confirming that a Personal Data Breach affecting Controller Personal Data has occurred.

The notification shall include, to the extent known at the time:

* the nature of the incident;
* categories of affected data;
* categories and approximate number of affected data subjects where reasonably ascertainable;
* likely consequences;
* containment or remediation measures taken or proposed;
* relevant incident timestamps; and
* a contact point for further information.

Information may be provided in phases where all relevant details are not immediately available.

The Processor shall reasonably assist the Controller in meeting applicable breach-notification and documentation obligations.

Notification under this section does not constitute an admission of fault or liability.

## 9. Data Subject Rights

Taking into account the nature of the processing, the Processor shall provide reasonable technical and organisational assistance to enable the Controller to respond to requests concerning rights under applicable data protection law.

EUWithdraw shall support, where applicable:

* access;
* rectification;
* erasure;
* restriction;
* portability/export;
* objection; and
* withdrawal of consent where the relevant processing is based on consent.

Where EUWithdraw receives a request directly from a data subject concerning Personal Data processed solely on behalf of a Controller, EUWithdraw shall not independently determine the substantive response unless legally required to do so.

The request shall instead be routed to or handled in coordination with the relevant Controller.

EUWithdraw shall maintain appropriate verification and audit controls to prevent disclosure or deletion of Personal Data in response to fraudulent or unauthorised requests.

## 10. Subprocessors

The Controller grants the Processor general written authorisation to engage Subprocessors where necessary to provide the service.

EUWithdraw shall maintain an up-to-date public list identifying applicable Subprocessors and the processing functions they provide.

Current Subprocessors shall be documented at `https://app.euwithdraw.eu/subprocessors`; the source-controlled register is https://app.euwithdraw.eu/subprocessors (repository source: `docs/legal/subprocessors.md`).

Before appointing a new Subprocessor that will materially process Controller Personal Data, EUWithdraw shall provide reasonable advance notice to affected Controllers.

The Controller may raise a reasonable data-protection objection to the appointment of a new Subprocessor.

The Processor shall impose data-protection obligations on each Subprocessor that provide a level of protection materially equivalent to the obligations applicable to the Processor under this DPA, insofar as relevant to the services performed by that Subprocessor.

EUWithdraw remains responsible to the Controller for the performance of its Subprocessors' data-protection obligations as required by applicable law.

## 11. International Data Transfers

Personal Data shall not be transferred to a country outside the European Economic Area unless an appropriate transfer mechanism or lawful derogation applies.

Where required, transfers shall rely on mechanisms such as:

* an applicable European Commission adequacy decision;
* the applicable European Commission Standard Contractual Clauses;
* another transfer mechanism recognised under Chapter V GDPR; or
* a lawful derogation where its legal requirements are satisfied.

Where Standard Contractual Clauses are required, the applicable modules and supplementary safeguards shall be determined according to the relevant parties, destination and processing activity.

Subprocessor locations and applicable transfer mechanisms shall be recorded in the Subprocessor Register.

## 12. Return and Deletion of Personal Data

Upon termination of the services, the Processor shall, at the Controller's choice and subject to the technical functionality made available by the service:

* return/export relevant Controller Personal Data; and/or
* delete Personal Data processed on behalf of the Controller.

Deletion shall cover active production systems and associated operational storage within the Processor's control, subject to:

* technically necessary backup lifecycle periods;
* legal retention obligations;
* security records that must legitimately be retained;
* prevention of fraud or abuse where legally justified; and
* establishment, exercise or defence of legal claims where applicable.

Personal Data remaining temporarily in protected backups shall not be restored into ordinary production use except as necessary for disaster recovery and shall expire according to the applicable backup lifecycle.

Where backup restoration occurs, previously applicable deletion requirements shall be reapplied as technically feasible.

## 13. Records, Demonstration of Compliance and Audits

The Processor shall make available information reasonably necessary to demonstrate compliance with its obligations under this DPA and Article 28 GDPR.

The Processor shall maintain appropriate evidence concerning:

* data flows;
* processing activities;
* security measures;
* Subprocessors;
* retention controls;
* access controls;
* privacy requests;
* security incidents;
* relevant automated decisions; and
* audit events.

The Controller may request reasonable compliance information.

Where such information is insufficient to demonstrate compliance, the Controller may request an audit subject to reasonable confidentiality, security, scope and frequency limitations.

Audits shall, where reasonably possible, first rely on available policies, security evidence, reports and remote documentation review before requiring an on-site inspection.

Nothing in this provision limits the powers of a competent supervisory authority.

## 14. Assistance with GDPR Compliance

Taking into account the nature of the processing and information available to it, the Processor shall provide reasonable assistance to the Controller concerning:

* security of processing;
* Personal Data Breach assessment and response;
* data-subject requests;
* Data Protection Impact Assessments;
* prior consultation with supervisory authorities where required; and
* information reasonably necessary to demonstrate compliance.

The Controller remains responsible for determining whether its own use of EUWithdraw requires a DPIA, a particular lawful basis, notices to data subjects or other Controller-specific compliance measures.

## 15. Automated Decisions and Human Review

EUWithdraw shall not use Personal Data processed on behalf of the Controller to make unrelated decisions about data subjects for EUWithdraw's own purposes.

Where the service provides automated blocking, risk detection or other automated workflow decisions that may materially affect a user, the service shall provide, where legally or operationally appropriate:

* a recorded reason for the decision;
* an audit trail;
* a review or appeal mechanism;
* authorised manual review; and
* the ability for an authorised reviewer to override the automated outcome where appropriate.

Security controls that are strictly necessary to protect the service against fraud, abuse or unlawful access are not required to provide an unsafe bypass merely for the purpose of presenting an “opt-out”.

## 16. Controller Responsibilities

The Controller is responsible for:

* providing lawful instructions;
* determining the lawful basis for processing;
* providing required privacy information to data subjects;
* ensuring that data supplied to EUWithdraw is lawfully obtained;
* configuring the service consistently with applicable law;
* determining appropriate Controller-specific retention obligations;
* responding substantively to data-subject requests;
* ensuring that authorised merchant users have appropriate permissions; and
* ensuring that it does not instruct EUWithdraw to process Personal Data unlawfully.

## 17. Conflict

If there is a conflict between this DPA and another agreement between the parties concerning the protection of Personal Data, this DPA shall prevail to the extent of that conflict.

Mandatory provisions of applicable data protection law shall prevail over conflicting contractual provisions.

---

# Annex I — Processing Details

**Subject matter:**
Operation of the EUWithdraw withdrawal, customer-request, merchant-workflow, notification and supporting compliance functionality.

**Nature and purpose:**
Collection, retrieval, organisation, storage, consultation, communication, modification, export, restriction and deletion of Personal Data as necessary to provide the EUWithdraw service on the documented instructions of the Controller.

**Data subjects:**
Merchant customers, withdrawal requesters, merchant personnel, authorised users and relevant correspondents.

**Personal Data:**
Contact information, account/customer identifiers, order information, withdrawal and return information, communications, workflow records, configuration data and security/audit metadata as described in this DPA.

**Special-category data:**
Not intentionally required or requested as part of the standard service.

**Processing duration:**
Duration of the service relationship plus the applicable documented retention periods or objective criteria.

---

# Annex II — Technical and Organisational Measures

The detailed technical and organisational measures maintained by EUWithdraw are documented in the security-control and evidence package, including:

* access control;
* authentication;
* least privilege;
* encryption;
* secure development;
* vulnerability management;
* logging and monitoring;
* webhook security;
* incident response;
* backup and recovery;
* retention enforcement;
* DSAR controls;
* production access management;
* secret management; and
* business continuity.

Primary evidence index:

`docs/security/security-evidence-index.md`

The evidence index shall distinguish between controls that are implemented, partially implemented or dependent on an organisational action and shall not represent unimplemented controls as operational.

---

# Annex III — Subprocessors and International Transfers

EUWithdraw shall maintain the authoritative Subprocessor Register at:

`docs/legal/subprocessors.md`

For every Subprocessor, the register shall identify at minimum:

* legal entity/provider;
* service provided;
* categories of Personal Data processed;
* processing purpose;
* processing location(s);
* applicable transfer mechanism where required; and
* relevant contractual/privacy documentation.

The production Subprocessor Register must reflect the actual deployed infrastructure and must not contain speculative providers.

---

# Execution

**Controller / Merchant**

Legal name: ______________________________
Registered address: _______________________
Authorised representative: _________________
Title: __________________________________
Date: ___________________________________
Signature: _______________________________

**Processor / EUWithdraw**

Contracting entity: LAUDATUS LTD, registered in England and Wales, company number 17453960
Registered office: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
Contact: support@euwithdraw.eu
Authorised representative: _________________
Title: __________________________________
Date: ___________________________________
Signature: _______________________________

---

## Changelog

- **1.3 — 20 September 2026:** identify Laudatus Ltd as Processor; clarify applicable EU/UK GDPR and preserve earlier policy/acceptance records.

- **1.2 — 4 September 2026:** prepared the publication version, identified the individual Processor and removed internal release placeholders.
- **1.1-draft — 4 September 2026:** launch-readiness revision.
- **1.0-draft — 30 August 2026:** initial repository draft.
