Legal

GDPR Compliance

Last updated July 10, 2026

How ResReturn handles personal data under the GDPR and KVKK — as a processor for the merchants who use our platform, and as a controller for our own website and account data.

1. Who we are

ResReturn (a YourSizer product) is a returns and exchange management platform for e-commerce merchants. Merchants on Shopify, Ticimax, ikas, and other platforms install ResReturn to run their returns process; their shoppers use a hosted returns portal to request returns, exchanges, store credit, or refunds.

This page explains how ResReturn complies with the EU General Data Protection Regulation (GDPR) and, where applicable, the Turkish Law No. 6698 on the Protection of Personal Data (KVKK). It supplements our Privacy Policy, which remains the primary description of how personal data is processed.

ResReturn is operated by YourSizer, Gümüşsuyu Mahallesi İnönü Caddesi Ulusal Apt. No:5 D:5, 34437 Beyoğlu/İstanbul, Türkiye. You can reach us at contact@resreturn.com.

2. Our roles: controller and processor

For shopper data processed through the returns portal — names, contact details, order information, return reasons, and resolution outcomes — the merchant is the data controller and ResReturn acts as a data processor. We process this data only on the merchant's documented instructions, as set out in our Data Processing Agreement.

For our own website, marketing, and merchant-account data — such as the business contact details, login credentials, and billing information of the merchants who sign up — ResReturn acts as the data controller.

This split matters in practice: shoppers who want to exercise their GDPR rights over return data should normally contact the merchant they bought from, and we will support the merchant in responding. Merchants and website visitors exercising rights over data we control should contact us directly.

3. What we process and on what lawful basis

As a processor for merchants, we process the shopper data needed to operate the returns flow: identifying and contact details, order and product information, return and exchange requests, store-credit and refund outcomes, and the signals used by our fraud-detection and returns-analytics features. The merchant's lawful basis is typically performance of its contract with the shopper and its legitimate interest in preventing return fraud.

As a controller, we process merchant-account data on the basis of contract performance, billing records on the basis of legal obligation, and website analytics and product-improvement data on the basis of legitimate interest or consent, depending on the tool.

We send marketing communications (product updates, offers, announcements) only with consent where the law requires it. You can withdraw marketing consent at any time — for example via the unsubscribe link in any email — without affecting your use of the Services, and we will stop the communications promptly.

For shoppers in the EU, the returns portal supports the withdrawal-of-contract flows introduced by Directive (EU) 2023/2673, including the withdrawal button, so that exercising a legal right of withdrawal is as simple as the original purchase.

5. Data minimization, retention, and deletion

In line with Article 5 GDPR and Article 4 KVKK, we collect only the data that is relevant, limited, and proportionate to running a return. Each category of personal data has a defined retention period tied to its purpose.

When a retention period ends, or the purpose for processing ceases, data is securely deleted, cryptographically destroyed, or irreversibly anonymized. Deletion covers backup media as well as live systems: backups are kept on a short rotation and are managed so they do not outlive the retention periods of the live data.

We may retain specific records for longer only where legislation requires it — for example tax, accounting, or legal-dispute obligations — and only for the legally mandated period.

6. Your rights as a data subject

Under the GDPR you have the right to access your personal data, to have it rectified, to have it erased, to receive it in a portable format, to restrict its processing, and to object to processing based on legitimate interest, including profiling. Equivalent rights exist under Article 11 KVKK.

Where our processing is based on consent, you may withdraw that consent at any time. Withdrawal takes effect for the future and does not affect processing that occurred before it.

To exercise your rights, email contact@resreturn.com. If your request concerns data we process on behalf of a merchant, you may also contact the merchant directly; we provide merchants with tools to fulfill access, correction, and erasure requests through the platform. We respond to verified requests within the statutory deadline (one month under the GDPR, extendable only where the law allows).

7. For merchants: our Data Processing Agreement

Every merchant using ResReturn is covered by our Data Processing Agreement (DPA), which incorporates the requirements of Article 28 GDPR: we process shopper data only on documented instructions, ensure confidentiality commitments from personnel, apply appropriate technical and organizational measures, assist with data-subject requests and breach obligations, and delete or return personal data at the end of the engagement.

A signed copy of the DPA is available on request at contact@resreturn.com.

8. Sub-processors

We use a limited set of third-party service providers — such as cloud hosting, email delivery, analytics, and payment processing — to operate the platform. Each sub-processor is bound by a written contract imposing data-protection obligations equivalent to those in our DPA, and downstream processors are held to the same standard.

We maintain a current list of sub-processors, including the country or region where each processes data, and make it available to merchants. Merchants are informed of intended changes to the list and may object on reasonable data-protection grounds.

9. International data transfers

Some of our service providers process data outside the European Economic Area or outside Türkiye. Where personal data is transferred to a country without an adequacy decision, we rely on appropriate safeguards — primarily the Standard Contractual Clauses (SCCs) approved by the European Commission and, for KVKK purposes, the standard contracts announced by the Turkish Personal Data Protection Board.

Transfers are further protected by technical and organizational measures such as encryption in transit and at rest, role-based access controls, access logging, and periodic review of transfer arrangements.

10. Security and breach notification

We protect personal data with encryption in transit and at rest, tenant-scoped access controls, role-based authorization, and logging, and we review these measures regularly.

If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by Article 33 GDPR. Where we act as a processor, we will notify the affected merchant without undue delay so the merchant can meet its own controller obligations. Affected individuals are informed when the breach is likely to result in a high risk to their rights and freedoms.

11. Complaints to a supervisory authority

If you believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or the place of the alleged infringement. In Türkiye, complaints may be lodged with the Personal Data Protection Authority (KVKK Kurumu).

We would appreciate the chance to address your concern first — contact us at contact@resreturn.com — but you are free to approach the authority directly at any time.

12. Contact

For any question about this page, our GDPR or KVKK compliance, data-subject requests, or our DPA and sub-processor list, contact us at contact@resreturn.com or by post at: ResReturn (a YourSizer product), Gümüşsuyu Mahallesi İnönü Caddesi Ulusal Apt. No:5 D:5, 34437 Beyoğlu/İstanbul, Türkiye.

Questions about this document? Contact us.