Last updated: 24 August 2026 · Forms part of the Terms of Service
This Addendum applies between the merchant using the Withdrawl service (the Controller) and Mintagency OÜ, registry code 16972018, Tallinn, Estonia (the Processor), for personal data processed through the service. It implements Article 28 GDPR and applies automatically to every merchant account; a countersigned copy is available on request via privacy@withdrawl.eu.
The Processor receives, stores and relays right-of-withdrawal declarations submitted by the Controller's customers: presenting the withdrawal form, generating confirmations on a durable medium, notifying the Controller, and maintaining the audit record the Controller needs for consumer-protection compliance. Processing lasts as long as the Controller uses the service, plus the retention period below.
Data subjects: the Controller's customers who submit withdrawals. Categories: name, email address, order number; optionally phone number, item descriptions and withdrawal reason where the customer chooses to provide them. No special-category data is intended to be processed; the Controller instructs its customers not to include such data in free-text fields.
The Processor: (a) processes personal data only to provide the service and on the Controller's documented instructions, unless EU or member-state law requires otherwise; (b) ensures persons authorised to process the data are bound by confidentiality; (c) implements the technical and organisational measures in Section 7; (d) assists the Controller, insofar as reasonably possible, with data-subject requests (Articles 12–23) and with the Controller's obligations under Articles 32–36; (e) notifies the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's data; (f) makes available the information reasonably necessary to demonstrate compliance with Article 28 and allows audits as described in Section 8.
The Controller grants general authorisation for these sub-processors: Supabase (database and backend hosting, EU region eu-west-1); Resend (transactional email delivery); Vercel (application hosting/CDN); Shopify (where the Controller installs via Shopify); Stripe (where the Controller uses card billing — merchant billing data, not customer withdrawal data). The Processor announces sub-processor changes on this page at least 14 days in advance; the Controller may object on reasonable data-protection grounds, in which case the Controller may terminate the service.
Customer withdrawal data is stored in the European Union. Where a sub-processor processes limited data outside the EU/EEA, transfers rely on an adequacy decision or the European Commission's Standard Contractual Clauses as implemented by that sub-processor.
Encryption in transit (TLS 1.2+) and at rest; row-level security isolating each store's data; access to production data restricted to authorised personnel; HMAC-verified webhooks; rate limiting on public endpoints; logical separation of merchant accounts; backups managed by the hosting sub-processor in the EU region.
On written request, at most once per year unless a supervisory authority requires otherwise, the Processor provides documentation of its measures and sub-processor arrangements. Where this is insufficient, the Controller may conduct or mandate an audit at its own cost, on 30 days' notice, during business hours, without access to other controllers' data.
Withdrawal records are retained for 24 months from submission — the period the Controller needs them as statutory evidence — then deleted. On termination of the service, the Controller may export its records (CSV) beforehand; merchant account data is deleted within 30 days of uninstall as described in the Privacy Policy. Earlier deletion requests (including Shopify customers/redact / shop/redact) are honoured unless retention is required by law.
privacy@withdrawl.eu — Mintagency OÜ, Tallinn, Estonia.