Data Processing Agreement (DPA)
Last updated: 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between COD CONFIRM OÜ ("Processor", "Company", "we", "our") and the customer using the Service ("Controller", "Customer").
This agreement describes how personal and operational data is processed when using the services available at https://www.codconfirm.com.
1. Roles of the Parties
For the purposes of applicable data protection laws, including the General Data Protection Regulation (GDPR):
Customer
Data Controller
COD CONFIRM OÜ
Data Processor
The Processor processes personal data only on behalf of and under the documented instructions of the Customer, except where otherwise required by applicable law.
2. Nature and Purpose of Processing
The Service provides software tools designed to support Cash on Delivery order confirmation workflows. Processing of data may occur solely for purposes such as:
- Connecting with e-commerce platforms and third-party systems
- Processing and managing order confirmation workflows
- Sending or triggering confirmation-related communications
- Synchronizing operational data with connected systems
- Supporting automation, workflow logic, and AI-assisted processing features
- Maintaining, securing, and operating the platform
- Providing customer support and service-related administration
3. Categories of Data Processed
The Service may process limited categories of information depending on the Customer's configuration and use of the Service.
Account Data
- Name
- Phone
- Company
Operational Data
- Orders
- Workflows
- Communications
- Logistics
Integration Data
- API credentials
- Access tokens
- Config data
The Service does not store full payment card information.
4. Sub-processors
To operate the Service, the Processor relies on sub-processors and third-party service providers, which may include:
These providers may process limited data as necessary to deliver their services.
5. Data Storage and Transfers
Data may be stored and processed on infrastructure operated by third-party providers.
Depending on the infrastructure and providers used, data may be processed in different jurisdictions, including the European Union, the United States, and other countries where relevant service providers operate.
Where required under applicable law, the Processor will rely on appropriate safeguards for international data transfers.
6. Security Measures
The Processor implements reasonable technical and organizational measures designed to protect personal data processed through the Service.
Such measures are intended to protect against unauthorized access, loss, misuse, disclosure, alteration, or destruction of data. However, no system can guarantee absolute security.
7. Data Retention and Deletion
Customer data is retained for as long as necessary to provide the Service and for as long as the Customer account remains active.
Upon account deletion or termination, associated personal data will be deleted or anonymized within thirty (30) days, unless retention is required for legal, accounting, security, dispute-resolution, or legitimate operational reasons.
8. Customer Responsibilities
The Customer is responsible for:
- Ensuring that it has the legal right and lawful basis to provide personal data to the Service
- Ensuring compliance with applicable data protection laws
- Providing any required notices to data subjects
- Obtaining any required consents where necessary
- Managing personal data under its control and configuring the Service in a compliant manner
9. Assistance and Data Subject Rights
Taking into account the nature of the processing, the Processor will provide reasonable assistance to the Customer in responding to requests related to:
- Access to personal data
- Correction of data
- Deletion of data
- Restriction or objection requests where applicable
- Export of data where applicable
Requests may be sent to:
support@codconfirm.com10. Updates to this Agreement
We may update this DPA from time to time to reflect legal, technical, or operational changes.
The updated version will be published on the website.
© 2026 COD CONFIRM OÜ. All rights reserved.