This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (“Controller”, “Merchant”) and Yoyo (“Processor”, “we”, “us”). It sets out the terms on which we process personal data on your behalf when you use the Yoyo service.
This DPA is designed to meet the requirements of the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and other applicable data protection legislation.
1. Definitions
- “Personal Data” means any information relating to an identified or identifiable natural person, as defined in the GDPR.
- “Processing” means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
- “Data Subject” means the individual to whom the Personal Data relates (typically your customers).
- “Sub-processor” means a third party engaged by Yoyo to process Personal Data on your behalf.
2. Scope and Roles
- You (the Merchant) are the data controller. You determine the purposes and means of processing your customers’ personal data.
- Yoyo is the data processor. We process personal data only on your instructions, as necessary to provide the Service.
- This DPA applies to all personal data processed by Yoyo in connection with the Service.
3. Categories of Data Processed
| Category | Data elements | Data subjects |
|---|
| Order data | Order number, items, amounts, dates, shipping address | Your customers |
| Customer identity | Name, email address | Your customers |
| Return data | Return reason, selected items, outcome, refund amounts | Your customers |
| Shipping data | Tracking numbers, carrier, delivery status, return address | Your customers |
| Merchant data | Store name, email, Shopify access tokens | You (the Merchant) |
4. Our Obligations as Processor
Yoyo shall:
- Process Personal Data only on your documented instructions, including with respect to transfers outside the UK/EEA
- Ensure that persons authorised to process Personal Data have committed to confidentiality
- Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (see Section 7)
- Not engage a Sub-processor without your prior general written authorisation (see Section 5)
- Assist you in responding to Data Subject requests (access, rectification, erasure, portability, objection)
- Assist you in ensuring compliance with your obligations regarding data security, breach notification, impact assessments, and prior consultation
- At your choice, delete or return all Personal Data upon termination of the Service, and delete existing copies unless required by law to retain them
- Make available all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits conducted by you or your auditor
5. Sub-processors
You provide general authorisation for Yoyo to engage Sub-processors. We will inform you of any intended changes to Sub-processors with at least 14 days’ notice, giving you the opportunity to object.
Current Sub-processors:
| Sub-processor | Purpose | Location |
|---|
| Shopify Inc. | E-commerce platform, billing, order data | Canada / Global |
| Anthropic | AI processing (return triage, categorisation, and image analysis, when enabled) | United States |
| Sendcloud | Return shipping labels and tracking | Netherlands |
| PostNord | Return shipping labels and tracking (Nordic markets, when configured) | Sweden |
| Bring (Posten Bring AS) | Return shipping labels and tracking (Nordic markets, when configured) | Norway |
| Quiqup | Return collection and tracking (Gulf markets, when configured) | United Arab Emirates |
| Aramex | Return shipping labels and tracking (Gulf markets, when configured) | United Arab Emirates |
| Klaviyo | Transactional return status emails (when enabled) | United States |
| Twilio | WhatsApp return notifications (when enabled) | United States |
| Plausible Analytics | Anonymised website analytics (no personal data) | EU |
6. International Transfers
Where Personal Data is transferred outside the UK or EEA, we ensure appropriate safeguards are in place:
- Transfers to countries with an adequacy decision are permitted without additional safeguards
- All other transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission and/or the UK Information Commissioner’s Office
- We conduct transfer impact assessments where required
7. Security Measures
Yoyo implements the following technical and organisational measures:
- Encryption of data in transit (TLS 1.2+) and at rest
- Access controls with role-based permissions
- Shopify OAuth 2.0 authentication (no password storage)
- Regular dependency audits and vulnerability scanning
- Server-side log retention limited to 30 days
- Incident response procedures with defined escalation paths
8. Data Breach Notification
In the event of a Personal Data breach, Yoyo shall:
- Notify you without undue delay, and in any event within 48 hours of becoming aware of the breach
- Provide sufficient information to enable you to meet your obligations to notify the supervisory authority and affected Data Subjects
- Take reasonable steps to mitigate the effects of the breach and prevent recurrence
- Cooperate with you and any supervisory authority in investigating the breach
9. Data Subject Rights
Yoyo will assist you in responding to Data Subject requests. If we receive a request directly from one of your customers, we will promptly redirect them to you unless instructed otherwise.
10. Data Retention and Deletion
- Return and order data is automatically deleted 12 months after the return is closed (refunded, denied, or cancelled); other Personal Data is retained for the duration of the Service
- Upon termination, we will delete all Personal Data within 30 days unless you request earlier deletion or applicable law requires longer retention
- You may request data export at any time during the subscription period
11. Audits
You have the right to audit our compliance with this DPA. Audits shall be conducted with reasonable notice (at least 14 days) and during normal business hours. We may charge reasonable costs for audits beyond one per 12-month period.
12. Liability
Each party’s liability under this DPA is subject to the limitations set out in the Terms of Service.
13. Term and Termination
This DPA takes effect when you install the Yoyo Shopify app and remains in effect for as long as we process Personal Data on your behalf. It survives termination of the Terms of Service to the extent we continue to hold Personal Data.
14. Contact
For questions about this DPA or to exercise your rights, contact us at:
Yoyo
Email: hello@yoyoreturns.com
Stow-on-the-Wold, United Kingdom