Data Processing Agreement

Effective date: 29 July 2026

This Data Processing Agreement (“DPA”) forms part of the agreement governing the use of EU Withdrawal Button Made Easy (“App”).

It is entered into between:

gl6.com, trading as Growth Labs 6, of Dudley (“Growth Labs 6”, “Processor”, “we”, “us” or “our”);

and

the Shopify merchant installing or using the App (“Merchant”, “Controller” or “you”).

By selecting the checkbox confirming acceptance of this DPA and continuing to use the App, the Merchant confirms that it has authority to enter into this DPA and agrees to its terms.

1. Scope of this DPA

This DPA applies only where Growth Labs 6 processes personal data on behalf of the Merchant through EU Withdrawal Button Made Easy.

It does not apply to other Growth Labs 6 apps or services unless expressly stated.

The Merchant acts as the Controller because it determines why and how personal data relating to its customers is processed.

Growth Labs 6 acts as the Processor when it processes personal data through the App on the Merchant’s behalf.

Growth Labs 6 may act as an independent controller for limited information processed for its own legitimate business purposes, such as merchant account administration, security, fraud prevention, legal compliance and support communications. Such processing is governed by the Growth Labs 6 Privacy Policy.

2. Applicable data-protection laws

The parties will comply with all data-protection laws applicable to their use of the App, including where applicable:

  • Regulation (EU) 2016/679, the General Data Protection Regulation;
  • the UK General Data Protection Regulation;
  • the UK Data Protection Act 2018; and
  • any replacement or supplementary data-protection legislation.

3. Processing instructions

Growth Labs 6 will process personal data only:

  • on the Merchant’s documented instructions;
  • as necessary to provide, secure, maintain and support the App;
  • as described in this DPA;
  • as configured or requested by the Merchant through the App; or
  • where required by applicable law.

The Merchant’s installation, configuration and use of the App constitute documented processing instructions.

If Growth Labs 6 believes that an instruction infringes applicable data-protection law, we may suspend the relevant processing and notify the Merchant, unless the law prevents us from doing so.

4. Details of the processing

4.1 Subject matter

The App enables Shopify merchants to provide customers with a way to submit withdrawal requests relating to eligible orders.

4.2 Nature and purpose

Growth Labs 6 may process personal data to:

  • connect the App to the Merchant’s Shopify store;
  • verify order information provided by a customer;
  • receive and store withdrawal requests;
  • display submitted requests in the Merchant’s App dashboard;
  • record the status of each request;
  • record relevant submission and status timestamps;
  • enable the Merchant to approve or reject requests;
  • send service-related notifications;
  • provide support;
  • prevent misuse and unauthorised access;
  • maintain the performance and security of the App; and
  • comply with applicable legal obligations.

4.3 Duration

Processing continues while:

  • the Merchant has the App installed;
  • a withdrawal request remains pending;
  • personal data remains subject to the retention period described in Section 11; or
  • retention is required by applicable law.

4.4 Categories of data subjects

The App may process information relating to:

  • the Merchant;
  • authorised staff members of the Merchant;
  • customers of the Merchant’s Shopify store;
  • individuals submitting withdrawal requests; and
  • individuals contacting Growth Labs 6 for support.

4.5 Categories of personal data

Depending on the information submitted and the Shopify permissions granted to the App, the following information may be processed:

  • Shopify shop ID and shop domain;
  • Merchant contact information;
  • order number and order identifier;
  • information used to verify an order;
  • customer name;
  • customer email address;
  • order date;
  • purchased products or order-line information;
  • information entered into a withdrawal request;
  • the customer’s withdrawal reason or message;
  • request status;
  • request submission timestamp;
  • approval or rejection timestamp;
  • App configuration information;
  • support correspondence; and
  • limited technical and security information generated while operating the App.

The App is not designed to collect special-category personal data, payment-card details, passwords or government identification documents.

The Merchant must not instruct customers to submit unnecessary sensitive personal data through the App.

5. Merchant responsibilities

The Merchant is responsible for:

  • establishing a lawful basis for processing customer personal data;
  • providing all legally required privacy notices;
  • ensuring that its use of the App complies with applicable law;
  • ensuring that instructions given to Growth Labs 6 are lawful;
  • responding to customer withdrawal requests appropriately;
  • deciding whether a request should be approved or rejected;
  • maintaining the security of its Shopify account;
  • restricting App access to authorised personnel;
  • avoiding the submission of unnecessary personal data; and
  • responding to requests from individuals concerning their personal data.

The Merchant confirms that it is entitled to provide personal data to Growth Labs 6 for processing under this DPA.

6. Confidentiality

Growth Labs 6 will ensure that persons authorised to process Merchant personal data:

  • access personal data only where necessary for their responsibilities;
  • process it only in accordance with this DPA;
  • are informed of its confidential nature; and
  • are subject to an appropriate confidentiality obligation.

7. Security measures

Growth Labs 6 will implement appropriate technical and organisational measures designed to protect personal data against:

  • accidental or unlawful destruction;
  • loss;
  • alteration;
  • unauthorised disclosure;
  • unauthorised access; and
  • other unlawful processing.

Measures may include, as appropriate:

  • encrypted HTTPS connections;
  • authenticated access to the App dashboard;
  • restricted access to production systems;
  • least-privilege access controls;
  • secure storage of application credentials and secrets;
  • separation of Merchant records;
  • database access restrictions;
  • software and dependency updates;
  • security logging and monitoring;
  • vulnerability and incident management;
  • controlled deployment procedures; and
  • automatic enforcement of the retention rule described in Section 11.

No internet-based service can guarantee absolute security. Growth Labs 6 will nevertheless maintain safeguards appropriate to the nature of the data and the risks presented by the processing.

8. Subprocessors

The Merchant gives Growth Labs 6 general written authorisation to appoint subprocessors where necessary to operate the App.

Growth Labs 6 will:

  • use subprocessors only where reasonably necessary;
  • require them to protect personal data under obligations providing an equivalent level of protection;
  • remain responsible for the performance of their processing obligations; and
  • notify Merchants of material additions or replacements before the change takes effect.

The Merchant may object to a new subprocessor on reasonable data-protection grounds by contacting privacy@gl6.com.

Current subprocessors include:

Railway

Purpose: Application hosting and infrastructure
Location or processing region: EU West (Amsterdam, Netherlands)

Neon

Purpose: Managed database hosting
Location or processing region: AWS Europe West 2 (London)

Resend

Purpose: Transactional or service-related email delivery
Location: Ireland (eu-west-1)

9. International transfers

Where personal data is transferred outside the United Kingdom or European Economic Area to a country that does not benefit from an applicable adequacy decision, Growth Labs 6 will ensure that an appropriate legal transfer mechanism is used where required.

This may include:

  • European Commission Standard Contractual Clauses;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to the European Commission Standard Contractual Clauses; or
  • another legally recognised safeguard.

Growth Labs 6 will take reasonable steps to ensure that subprocessors provide appropriate protection for transferred personal data.

10. Assistance with individual rights

Taking into account the nature of the processing, Growth Labs 6 will provide reasonable assistance to help the Merchant respond to requests concerning:

  • access;
  • correction;
  • deletion;
  • restriction;
  • objection;
  • data portability; and
  • other applicable data-protection rights.

Where Growth Labs 6 receives a request directly from a customer concerning personal data controlled by the Merchant, we will ordinarily refer the customer to the Merchant unless applicable law requires us to respond directly.

The Merchant remains responsible for determining how to respond to the request.

11. Data retention and automatic deletion

11.1 Pending requests

A withdrawal request may be retained while its status remains Pending, so that the Merchant can review and respond to it.

11.2 Approved and rejected requests

When a withdrawal request is marked Approved or Rejected, the App records the status and the date and time of that status change.

The withdrawal request and associated personal data are automatically deleted after the request has remained in an Approved or Rejected state for 60 days.

Where a request’s status is subsequently changed, the 60-day retention period begins again from the date and time on which it was most recently placed into an Approved or Rejected state.

Once deleted, the request will no longer be available through the Merchant dashboard and may not be recoverable.

11.3 Earlier deletion

Information may be deleted earlier where:

  • the Merchant provides a lawful deletion instruction;
  • Growth Labs 6 receives a valid Shopify customer-erasure request;
  • Growth Labs 6 receives a Shopify shop-erasure request following uninstallation;
  • deletion is required under applicable law; or
  • continued processing is no longer necessary or lawful.

11.4 Termination and uninstallation

Following termination or uninstallation of the App, Growth Labs 6 will delete or return personal data in accordance with the Merchant’s lawful instructions and applicable Shopify privacy requirements, unless retention is required by law.

Shopify sends a shop/redact privacy request after an app is uninstalled so that app developers can erase the relevant shop and customer data.

Personal data retained solely because of a legal obligation will be isolated from ordinary use and deleted when that obligation ends.

12. Personal – data breaches

Growth Labs 6 will notify the Merchant without undue delay after becoming aware of a personal-data breach affecting personal data processed under this DPA.

Where reasonably available, the notice will include:

  • the nature of the breach;
  • the categories of data and individuals affected;
  • the likely consequences;
  • measures taken or proposed to address the breach;
  • steps taken to reduce possible harm; and
  • relevant contact details.

Growth Labs 6 will reasonably assist the Merchant with investigating the incident and meeting applicable notification obligations.

The Merchant is responsible for determining whether notification to customers or a supervisory authority is legally required.

13. Compliance assistance

Taking into account the nature of the processing and the information available, Growth Labs 6 will provide reasonable assistance with:

  • data-protection impact assessments;
  • consultations with supervisory authorities;
  • security assessments;
  • records of processing;
  • breach investigations; and
  • other applicable controller obligations.

14. Information and audits

Growth Labs 6 will make available information reasonably necessary to demonstrate compliance with this DPA.

The Merchant may request a reasonable audit where necessary to verify compliance.

Unless a supervisory authority requires otherwise, an audit must:

  • be requested with reasonable advance notice;
  • occur no more than once in any 12-month period;
  • take place during normal business hours;
  • avoid unreasonable disruption;
  • protect Growth Labs 6 and third-party confidential information; and
  • be limited to systems and information relevant to the Merchant’s personal data.

Growth Labs 6 may satisfy an audit request by providing relevant policies, security documentation, subprocessor information or independent assurance materials where these reasonably address the request.

15. Subprocessor and regulatory cooperation

Growth Labs 6 will reasonably cooperate with:

  • the Merchant;
  • applicable supervisory authorities; and
  • other legally authorised bodies

in relation to processing performed under this DPA.

Growth Labs 6 will inform the Merchant where legally binding requests for Merchant personal data are received, unless prohibited by law.

16. Deletion or return of personal data

At the end of the processing relationship, and subject to applicable law, Growth Labs 6 will, at the Merchant’s choice:

  • delete the Merchant’s personal data; or
  • provide a reasonable return or export of personal data that remains available.

Existing copies will also be deleted unless applicable law requires continued storage.

This section does not require Growth Labs 6 to retain personal data beyond the ordinary retention periods solely so that it can later be returned.

17. Liability

Each party remains responsible for complying with its obligations under applicable data-protection law.

Any liability arising under this DPA is subject to the applicable limitations and exclusions contained in the Growth Labs 6 Terms of Service, except where such limitation is prohibited by law.

Nothing in this DPA excludes liability that cannot lawfully be excluded.

18. Term and termination

This DPA takes effect when the Merchant accepts it and continues for as long as Growth Labs 6 processes personal data on the Merchant’s behalf.

Obligations relating to confidentiality, security, deletion, liability and regulatory cooperation survive termination where necessary.

19. Changes to this DPA

Growth Labs 6 may update this DPA where reasonably necessary to:

  • reflect changes to the App;
  • reflect changes to processing activities;
  • comply with legal or regulatory requirements;
  • update subprocessors; or
  • improve data-protection safeguards.

Where an update materially affects the Merchant’s rights or processing instructions, Growth Labs 6 will provide reasonable notice and may require the Merchant to accept the updated version before continuing to use the App.

Each version will display its effective date and version number.

20. Order of precedence

If this DPA conflicts with another agreement between Growth Labs 6 and the Merchant concerning the processing of personal data, this DPA takes precedence to the extent of that conflict.

21. Governing law and jurisdiction

This DPA is governed by the laws of England and Wales, unless another applicable agreement between the parties specifies a different governing law.

The courts of England and Wales will have jurisdiction, except where applicable law gives the Merchant or a data subject the right to bring proceedings elsewhere.

22. Contact details

Questions, instructions and requests relating to this DPA should be sent to:

Growth Labs 6
Legal operator: gl6.com
Location: Dudley
Email: privacy@gl6.com

Scroll to Top