Data Processing Agreement (DPA)

Last updated: September 23, 2026

1. Introduction

This Data Processing Agreement ("DPA") is incorporated into the Terms of Service (the "Agreement") between OMGL LTD ("the Processor", "RefundShield") and the relevant Customer ("the Controller").

The Controller shall be considered the controller in relation to the processing of Personal Data. The Processor shall be considered a data processor and will process Personal Data on behalf of the Controller in connection with the supply of the Service under the Agreement.

Accordingly, the Parties have agreed to this DPA, which has been executed in accordance with the General Data Protection Regulation (EU) 2016/679, and other applicable data privacy legislation (below referred to as "Data Privacy Laws"). "Personal Data", "Data Subjects", and other defined terms used herein shall have the meanings set forth in applicable Data Privacy Laws.

2. Instructions

The Processor shall process the Personal Data in accordance with the Controller's instructions. The purpose of the processing is for the sole purpose of supplying the agreed Service, which includes handling App Store Server Notifications, Google Play Real-time Developer Notifications, and managing refund statuses. The character of the processing involves receiving and storing data provided by Apple's and Google's APIs. The duration of the processing is for the term of the Agreement.

3. Security measures

The Processor shall maintain at all times appropriate technical and organizational measures to protect the Personal Data, including encryption of sensitive credentials and secure data transmission. The Processor shall ensure that only authorized persons who need access to the Personal Data have access to it and that they are bound by a confidentiality undertaking.

The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data Breach and shall assist the Controller in ensuring compliance with the Controller's obligations under Data Privacy Laws.

4. Subprocessors

The Controller hereby provides a general authorization to the Processor for using third parties for performing the whole or part of the processing ("Subprocessors"). The Subprocessors currently used by the Processor include cloud hosting providers (e.g., DigitalOcean) and payment processors (e.g., Stripe).

Where the Processor intends to engage a new Subprocessor, the Processor will inform the Controller thereof. The Processor will be liable for all actions or omissions of a Subprocessor, as for its own actions or omissions.

5. The Processor's obligations to assist the Controller

The Processor shall assist the Controller in the fulfillment of the Controller's obligations to ensure that Data Subjects may exercise their rights under Data Privacy Laws. In case a Data Subject, Supervisory Authority or other third party requests information from the Processor in relation to the processing of Personal Data, the Processor shall refer such request to the Controller and await further instructions.

6. Audit Rights

The Controller shall be entitled, on reasonable prior written notice, to carry out an audit of the Processor's processing of the Personal Data. The Processor shall assist the Controller and make available any information and documentation that is necessary in order for the Controller to carry out such an audit. The Controller shall bear all costs for such audit.

7. Liability

Each Party will be liable for any administrative fines imposed on that Party by a Supervisory Authority due to that Party's breach of applicable Data Privacy Laws. The regulations on liability, including limitations of liability, set forth in the Agreement shall apply.

8. Deletion of Personal Data

Upon the expiry or termination of the Agreement, or at the earlier point of time when the Controller presents such a request, the Processor shall automatically cease with the processing of Personal Data and delete the Personal Data in accordance with the Agreement.

9. Term and Termination

This DPA shall apply from the commencement of processing of Personal Data by the Processor on behalf of the Controller, and shall cease when the Processor has deleted the Personal Data in accordance with the above.

10. Governing Law and dispute resolution

The same governing law and dispute resolution mechanism as set forth in the Agreement shall apply also for this DPA.


If you have any questions about this DPA, please contact us at [email protected].