Legal document
Data processing agreement
Last updated: 8 October 2026
This is an English translation provided for convenience. If it differs from the Romanian version, the Romanian version prevails.
This agreement forms part of the Retragere.ro Terms and conditions and applies automatically to every shop that uses the withdrawal form (the “Customer”, controller). The provider is EANmatch, CVR DK-39223090, Hesteskoen 9, 9480 Løkken, Denmark (the “Provider”, processor).
1. Subject matter and duration
The Provider processes personal data on behalf of the Customer in order to provide the digital contract withdrawal function (OUG 18/2026). The agreement lasts for as long as the Customer uses the service.
2. Nature of the processing
| Data subjects | the Customer’s customers who submit a withdrawal request |
|---|---|
| Categories of data | name, email address, order number; optionally: returned products, reason, IBAN, notes; date and time of the request; technical data (irreversibly hashed IP address, browser type) |
| Operations | collection through the form, storage, sending the confirmation to the data subject and the copy to the Customer, deletion |
| Sensitive data | no special categories of data (Art. 9 GDPR) are processed |
3. The Provider’s obligations
- Process the data only on the Customer’s documented instructions, contained in this agreement and in the form’s setup.
- Ensure confidentiality: only the people who need it have access to the data, and they are bound by confidentiality.
- Apply appropriate technical and organisational measures (Art. 32 GDPR), at least: encrypted connections (HTTPS), storage in the European Union, restricted access, anti-bot protection and request rate limits, IP addresses stored only as an irreversible hash.
- Help the Customer respond to data subject requests (access, erasure, etc.) and meet its obligations under Art. 32-36 GDPR.
- Notify the Customer without undue delay, within 48 hours of becoming aware of it, of any personal data breach.
- When the service ends, at the Customer’s choice, return the data (export) or delete it within 30 days, unless the law requires it to be kept.
- Make available to the Customer the information needed to demonstrate compliance with this agreement, and allow reasonable audits with prior notice.
4. Sub-processors
The Customer gives general authorisation for the following sub-processors:
| Company | Role | Data location |
|---|---|---|
| Cloudflare, Inc. | hosting, database, anti-bot protection | European Union (EU jurisdiction for the database) |
| Resend (Plus Five Five, Inc.) | sending confirmation and notification emails | sending from the EU region (Ireland) |
The Provider announces any change to the list by email at least 30 days in advance. Within that period the Customer may object and, if no solution is found, stop using the service. The Provider imposes on sub-processors data protection obligations equivalent to those in this agreement.
5. Transfers outside the EEA
Any transfers to countries outside the European Economic Area take place only on the basis of the European Commission’s standard contractual clauses or another mechanism under Chapter V GDPR.
6. The Customer’s obligations
- Is responsible for the lawfulness of the processing and for informing its own customers (the shop’s privacy policy).
- Provides accurate setup data (email for requests, return address, identification details).
- Handles the withdrawal requests received, within the legal deadlines.
7. Final provisions
The parties’ liability is as set out in the Terms and conditions. In case of conflict between this agreement and the Terms, this agreement prevails as regards data protection. On request, the Provider will also send this agreement in signed form.