Skip to content

ithappens / SmoothReturns Data Processing Agreement

SmoothReturns Data Processing Agreement

Agreement on the processing of personal data between ithappens and merchants using the returns portal, under Article 28 of the GDPR.

This is a translation provided for convenience. The Norwegian version at ithappens.no/databehandleravtale is the legally binding text. Where the two differ, the Norwegian governs.

Version 1.0, 31 July 2026. This agreement was drafted by the supplier and has not been reviewed by external legal counsel. It follows Article 28(3)(a)–(h) of the GDPR. It is signed by both parties before the portal is taken into use; electronic signature is sufficient. Request a copy at henrik@ithappens.no.

1. Parties and roles

The controller is the merchant using the returns portal ("the Customer").

The processor is SillySanta AS, org. no. 916 896 050 MVA, Lilletorget 1, 0184 Oslo, Norway, trading as ithappens ("the Processor").

The Customer determines the purposes and means of the processing. The Processor processes personal data solely on the Customer's documented instructions, as set out in this agreement, in the settings the Customer configures in the portal, and in any subsequent written instructions.

2. Subject matter and duration

The subject matter is the provision of a portal for returns, exchanges and warranty claims, including generation of shipping labels, communication with the end customer, and settlement against the Customer's e-commerce platform.

This agreement runs for as long as the Customer uses the portal and terminates together with the agreement governing use of the portal ("the main agreement"). The provisions on confidentiality and deletion survive termination.

3. Types of personal data

  • Name
  • Email address
  • Postal address
  • Telephone number
  • Order number and line items
  • Return reason and any free text from the end customer
  • Images the end customer uploads as documentation for a warranty claim
  • Tracking number and delivery status
  • Refund and exchange amounts (not card details)

The portal processes no card numbers or other payment details. Refunds are executed by the Customer's own e-commerce platform against the original payment.

On special categories under Article 9, see clause 13.

4. Categories of data subjects

  • The Customer's end customers who register a return or a warranty claim
  • The Customer's own staff with administrator access to the portal

5. Obligations of the Processor

The Processor shall:

  • process personal data only on the Customer's documented instructions, unless otherwise required by EEA or Norwegian law — in which case the Customer is notified before the processing, unless such notification is prohibited;
  • ensure that anyone with access is bound by confidentiality;
  • implement appropriate technical and organisational measures under Article 32, as described in Annex A;
  • assist the Customer in meeting its obligations under Articles 32–36, including data protection impact assessments;
  • assist the Customer in responding to requests for access, rectification, erasure, restriction, portability and objection;
  • make available the documentation necessary to demonstrate that the obligations in Article 28 are met.

If the Processor considers an instruction to infringe data protection law, the Customer is notified immediately.

6. Security

The measures are described in Annex A and expanded on the security page. Key points: AES-256-GCM encryption of sensitive merchant settings, TLS in transit, isolation between merchants enforced at the data model level, short-lived access tokens and daily backups.

7. Sub-processors

The Customer hereby gives general written authorisation for the use of sub-processors. The current list is published at /en/subprocessors and forms Annex B to this agreement.

The Processor notifies the Customer at least 30 days before engaging a new sub-processor or replacing an existing one. The Customer may object in writing on reasonable grounds within that period. If the parties do not reach agreement, the Customer may terminate the main agreement at no cost, effective from the date the change was to take effect.

The Processor imposes on every sub-processor the same obligations as apply under this agreement, and remains liable to the Customer for the sub-processor's performance.

8. Transfers to third countries

Returns data is stored within the EEA. The application runs in Ireland, the database in Sweden, and error monitoring in Germany.

Two supporting services operate from the United States: delivery of email to the end customer (SendGrid/Twilio) and administrator sign-in (Stytch). These transfers are made on the basis of the European Commission's Standard Contractual Clauses with supplementary measures. The scope is described in Annex B.

The Processor does not transfer personal data to any other third country without prior written agreement with the Customer and a valid transfer mechanism under Chapter V of the GDPR.

9. Audit and documentation

The Processor makes available all information necessary to demonstrate that the obligations under Article 28 of the GDPR are met, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.

The Processor makes the following available on request:

  • a completed security self-assessment in the format the Customer uses (for example CAIQ Lite or SIG Lite);
  • a description of technical and organisational measures;
  • a list of sub-processors with processing locations;
  • a description of backup and restore procedures, including the date of the last restore test;
  • a summary of any security incidents in the period.

Inspections are notified in writing at least 30 days in advance and carried out during normal business hours. They shall be no more intrusive than necessary, and everyone involved is bound by confidentiality. Inspections may be carried out once per calendar year. That limit does not apply following a security breach, on suspicion of breach of this agreement, or where a supervisory authority so requires.

Each party bears its own costs. The Processor may recover documented additional costs for inspections beyond the annual one, but may not make the inspection conditional on such recovery.

10. Personal data breaches

In the event of a personal data breach, the Processor notifies the Customer without undue delay and no later than 24 hours after becoming aware of it.

The notification describes, so far as known:

  • the nature of the breach, and the categories and approximate number of data subjects affected;
  • the likely consequences;
  • measures taken and planned;
  • a point of contact for further follow-up.

The Processor does not notify a supervisory authority or data subjects on the Customer's behalf unless separately agreed in writing.

11. Deletion and return on termination

On termination the Customer chooses whether personal data is deleted or returned. The Customer gives notice within 30 days of termination. If no notice is given, the data is deleted.

Return is made in a structured, commonly used and machine-readable format.

Deletion from active systems takes place within 90 days of termination. Personal data held in backups is deleted at the ordinary expiry of each backup; it is not restored in the meantime, and remains covered by this agreement until deleted.

12. Rights and obligations of the Customer

The Customer has the right to:

  • give the Processor documented instructions on the processing, and to change them in writing;
  • receive documentation demonstrating that the obligations under Article 28 are met, and to conduct audits and inspections under clause 9;
  • object to new sub-processors under clause 7, and terminate at no cost if the parties do not reach agreement;
  • choose whether personal data is deleted or returned on termination, under clause 11;
  • request a full export of its own data in machine-readable format at any time, including during the term;
  • terminate this agreement if the Processor materially breaches its obligations under it.

The Customer is responsible for:

  • having a valid legal basis for the data processed in the portal;
  • informing its end customers under Article 13, including about the use of a processor;
  • designing return reasons and free-text fields so that end customers are not invited to supply special categories of personal data;
  • administering its own users' access and removing those who leave.

13. Special categories of personal data

The portal is not designed for special categories under Article 9, and the Customer shall not instruct the Processor to process such data.

If the Processor becomes aware that an end customer has, on their own initiative, supplied such data in a free-text field or an uploaded image, the Processor shall

  • use it for no purpose other than completing the return or warranty claim in question;
  • notify the Customer without undue delay where the extent warrants the Customer considering further measures;
  • delete it on the Customer's instruction.

Such data is covered by the same technical and organisational measures as all other personal data, per Annex A.

14. Records of processing activities

The Processor maintains records of processing activities carried out on behalf of the Customer, in accordance with Article 30(2) of the GDPR. The records are made available to the Customer and to a supervisory authority on request.

15. Automated decision-making

The portal may flag returns for manual review according to rules the Customer sets. A flag halts the automation and places the case in the Customer's queue. It does not in itself result in a claim being rejected.

Rejections are set solely by one of the Customer's own administrators, or by the Customer tagging the order accordingly in its own e-commerce platform. The portal rejects no claim automatically.

16. Governing law and venue

This agreement is governed by Norwegian law. Venue is Oslo District Court, unless mandatory law provides otherwise.

Annex A — technical and organisational measures

  • Encryption in transit: TLS on all traffic, HSTS enabled.
  • Encryption at rest: AES-256-GCM with a random initialisation vector and authentication tag per value, on sensitive merchant settings.
  • Isolation: each merchant's data is separated by a mandatory merchant identifier on every database query, enforced by hooks on the data models so that a query without a valid identifier fails rather than returning data.
  • Access control: access tokens with a 15-minute lifetime, refresh tokens in httpOnly cookies, shared authentication middleware on all administrator endpoints.
  • Production access: limited to one named individual.
  • Backups: daily automatic copies, stored in the same region as the database.
  • Logging and monitoring: error and event logging with alerting.
  • Vulnerability management: dependencies updated continuously; security updates prioritised.

Annex B — sub-processors

The current list, with processing locations, data types and each supplier's own certifications: /en/subprocessors. The list forms an integral part of this agreement.

Questions about this?Talk directly with the person who builds the products.