Data processing agreement
Last updated: 29 August 2026
This DPA applies between the merchant (controller) and A.K.B.S. ApS (trading as Nexly), Gammel Skovvej 6, 2770 Kastrup, Denmark, CVR 44457415. Contact: help@nexly.dk. (processor) whenever Nexly processes personal data on the merchant's behalf, under Art. 28 GDPR.
1. Subject matter and duration
Nexly processes personal data to operate the merchant's returns, exchange and cancellation flows, for as long as the merchant's subscription is active.
2. Nature, purpose and data subjects
Processing covers collection, storage, use, transmission to carriers and Shopify, and deletion. Data subjects are the merchant's end customers and staff users.
- Categories: name, email, phone, shipping address, order and line-item data, return reason and comments, tracking numbers and labels.
- No special categories of personal data are intended to be processed.
3. Processor obligations
- Process only on documented instructions from the controller.
- Ensure confidentiality commitments for all personnel with access.
- Implement the technical and organisational measures described in the Privacy policy, section 8.
- Assist with data subject requests, DPIAs and breach notification.
- Notify the controller without undue delay after becoming aware of a personal data breach.
- Delete or return personal data at the end of the agreement, subject to statutory retention.
- Make information available to demonstrate compliance and allow audits, once per year or after a breach.
4. Sub-processors
The controller gives general authorisation to the sub-processors listed on the Sub-processors page. We give at least 30 days' notice of new sub-processors, and the controller may object on reasonable data-protection grounds.
5. Transfers
Any transfer outside the EU/EEA is made on the Standard Contractual Clauses with supplementary measures.
6. Signature
Accepting the Nexly terms constitutes acceptance of this DPA. A countersigned copy is available on request at help@nexly.dk.