ReturnKits

Data Processing Agreement

Last updated: August 2026

This Data Processing Agreement ("DPA") forms part of, and should be read alongside, our Terms of Service and Privacy Policy. It applies whenever ReturnKits Ltd ("Processor", "we") processes personal data on behalf of a business customer ("Controller", "you") in the course of providing the ReturnKits service. If your organisation needs a countersigned copy for its own compliance records, contact legal@returnkits.com.

1. Definitions

"Data Protection Legislation" means the UK GDPR and the Data Protection Act 2018, as amended or replaced from time to time. "Personal Data", "Processing", "Data Subject", "Controller", "Processor", and "Sub-processor" have the meanings given in the Data Protection Legislation.

2. Subject matter and duration

The Processor processes Personal Data on the Controller's behalf for the duration of the Controller's ReturnKits account, and thereafter only for the retention periods set out in our Privacy Policy.

3. Nature and purpose of processing

Personal Data is processed to dispatch and collect IT hardware recovery kits, coordinate courier handoff and delivery/return tracking, and administer payment for kit orders, prepaid credits, and optional Enhanced Cover on the Controller's behalf.

4. Categories of data subjects

The Controller's current and former employees, contractors, or other individuals nominated to receive or return a device ("Recipients"), and the Controller's own authorised portal users.

5. Types of personal data

Name, work or personal email address, phone number, and delivery/collection address of Recipients; name, email address, and company details of portal users. No special category data is processed as part of the service.

6. Processor obligations

  • Process Personal Data only on the Controller's documented instructions, including regarding international transfers, unless required to do otherwise by law.
  • Ensure that any person authorised to process Personal Data is subject to a duty of confidentiality.
  • Implement appropriate technical and organisational security measures, including encrypted connections, database-level tenant isolation, role-based access controls, and audit logging.
  • Not engage a new Sub-processor without informing the Controller of the change and giving the Controller the opportunity to object. Current Sub-processors are listed in section 7 below.
  • Assist the Controller, taking into account the nature of processing, in responding to requests from Data Subjects exercising their rights under the Data Protection Legislation.
  • Assist the Controller in meeting its obligations relating to security, breach notification, and data protection impact assessments, taking into account the information available to the Processor.
  • At the Controller's choice, delete or return all Personal Data at the end of the provision of services, save where retention is required by law.
  • Make available to the Controller information reasonably necessary to demonstrate compliance with this DPA, and permit audits on reasonable notice, subject to confidentiality.

7. Sub-processors

  • Supabase — database, authentication, and application hosting (UK, London region). Hosts all customer and order data.
  • Lovable — application platform the customer portal runs on. Hosts and serves the portal application.
  • Retool — internal operations dashboard. Staff-only access to order and customer data for fulfilment.
  • Stripe — payment processing. Card payments, invoicing, and prepaid credit purchases.
  • Sendcloud — shipping coordination. Courier label and tracking data.
  • Resend — transactional email delivery. Order confirmation, dispatch, and check-in emails.

8. International transfers

Where a Sub-processor processes Personal Data outside the UK, the transfer is made subject to Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism recognised under the Data Protection Legislation.

9. Breach notification

The Processor will notify the Controller without undue delay, and in any event within 72 hours of becoming aware, of any Personal Data breach affecting the Controller's data.

10. Liability

Each party's liability under this DPA is subject to the limitation of liability set out in our Terms of Service.

11. Term and termination

This DPA takes effect on the date the Controller's ReturnKits account is created and continues for as long as the Processor processes Personal Data on the Controller's behalf.

12. Governing law

This DPA is governed by the laws of England and Wales.