Voidless
Data processing agreement
The Article 28 terms between a merchant using Voidless and the company operating it.
Last updated 9 September 2026
Parties and roles
This agreement is between the merchant who installs Voidless (the controller) and Jaime Andia Cintora, Fueros de Aragón 58, 50500 Tarazona, Zaragoza, Spain (the processor). It takes effect when the app is installed and ends when it is uninstalled.
It forms part of the terms under which the app is provided. Where it conflicts with those terms on the processing of personal data, this document wins.
What is processed, and why
Subject matter: measuring the empty space in the merchant's parcels against Article 24 of Regulation (EU) 2025/40, and producing the documentation that regulation expects.
Nature and purpose: reading catalogue and order data from the merchant's Shopify store, computing an assessment from it, and storing the results and the merchant's own packaging records.
Categories of data subject: customers of the merchant, only to the extent that an order they placed is counted. No customer is identified.
Types of personal data: order identifiers, order timestamps, and the quantities and variants on each order line. No name, email address, telephone number or postal address of any customer is processed. Under GDPR an order identifier is personal data because it can be linked back to a person, which is why it is named here even though nothing we hold makes that link.
Duration: order data is processed transiently and not retained. Derived records are retained for the life of the installation.
Our obligations
We process personal data only on the merchant's documented instructions, which for this app means: only to perform the audit and produce its documentation. Installing the app is the instruction.
Anyone with access is bound by confidentiality.
We do not transfer personal data outside the European Economic Area. Processing happens in Frankfurt.
If we are ever required by law to process data beyond those instructions, we tell the merchant first unless the law forbids it.
Security
Data is encrypted at rest and in transit, and the database refuses unencrypted connections.
The database is not exposed to the public internet through any API. Row level security is enabled on every table with no policies, so the only route in is the application's own server-side connection.
Access tokens are stored per shop and scoped to the four permissions the app asks for: read products, write products, read inventory and read orders. The app does not request permission to read customer records, and does not request the optional protected fields — name, email, phone or address.
The smallest possible amount of data is the primary control here. Most of what could go wrong with customer data cannot go wrong with data we never hold.
Sub-processors
The merchant authorises the following sub-processors:
Vercel Inc. — hosting. The app's server functions run in Frankfurt (eu-central-1).
Supabase Inc. — the database, hosted on AWS in Frankfurt (eu-central-1), encrypted at rest, and reachable only over TLS.
Anthropic PBC — optional, and off unless the merchant's installation has been given a key. When on, it receives a product title, a variant title and a weight in order to guess packed dimensions. It never receives order or customer data.
We will give notice before adding or replacing a sub-processor, and the merchant may object. Objecting means uninstalling, since the app cannot run without hosting and a database.
Helping the merchant meet their own obligations
We assist with requests from data subjects, with data protection impact assessments, and with prior consultation of a supervisory authority, so far as the data we hold is relevant. In practice we hold nothing that identifies a customer, so the assistance we can give is mostly to confirm that.
If we become aware of a personal data breach affecting the merchant's data, we notify them without undue delay and with what we know: what happened, which data, likely consequences, and what we are doing about it.
Deletion
On uninstall, and on a shop redaction request from Shopify, every record belonging to that shop is deleted. Order data is never retained, so there is nothing of it to delete.
The merchant can ask for deletion at any time without uninstalling. We do not keep copies afterwards, except where retention is required by law.
Audit
We make available the information needed to demonstrate that these obligations are met, and allow audits by the merchant or an auditor they mandate, on reasonable notice and no more than once a year unless an incident warrants it.
The application's source is not public, but the specific claims in this document — which fields are read, what is stored, where it runs — can be evidenced on request.
Law
This agreement is governed by the law of Spain, without prejudice to the merchant's own mandatory rights or to the GDPR.