Privacy Policy Codixio EU Revocation Button

1. Responsibility and roles

This privacy policy explains the data processing connected with the Shopware app Codixio EU Revocation Button. For the processing of shop customers' personal data within the operation of the app, the respective shop operator (merchant) is the controller within the meaning of Art. 4 No. 7 GDPR. In this respect, Codixio acts as a processor pursuant to Art. 28 GDPR; the basis is the data processing agreement available at https://legal.codixio.com/apps/eu-widerrufsbutton-shopware/dpa.en. For the processing of the merchant's registration, contract and tariff data, Codixio is an independent controller.

2. Controller and contact

Matthias Jakisch, Hauptstr. 34, OT Etingen, 39359 Oebisfelde-Weferlingen, Germany. Phone +49 39059 974988. E-mail general support@codixio.com, e-mail data protection/legal legal@codixio.com. Legal form: sole proprietorship (no commercial register entry), operating under the trade name Codixio. VAT identification number pursuant to Sec. 27a UStG: DE296346917. Tax status: small business under Sec. 19 UStG.

3. How the app works

The app provides a revocation button and a revocation form pursuant to Sec. 356a of the German Civil Code (BGB) in the merchant's shop. When a customer submits the form, the customer's browser transmits the entries directly to the Codixio backend (sw-codixioeuwiderrufsbuttonapp.api.codixio.com). The backend verifies the entries against the order in the merchant's shop, triggers the confirmation e-mails via the shop's own mail infrastructure and writes a pseudonymised verification record into the database of the merchant's shop. The backend itself does not store any customer data.

4. Processing in detail

Form data (transient): name, e-mail address, order number, optionally postcode, optionally the reason for revocation and optionally the selected order items are processed exclusively to verify the revocation against the order, to compose the confirmation e-mails and to prevent abuse. This data is not stored in the backend; it is discarded once the request has been completed.

Verification record (pseudonymised, in the merchant's shop): For each revocation request, a verification record is stored in the database of the merchant's shop. It contains the e-mail address and the IP address exclusively as HMAC-SHA256 digests (computed with a secret server key of at least 32 bytes; reversal to plain text is not possible without the key), plus timestamp, verification result, order number and the server-resolved revoked items. Plain-text e-mail and plain-text IP are never stored. These records are deleted automatically after 90 days.

IP address: The IP address of a request is processed for rate limiting (a maximum of five requests per ten minutes; the associated technical state is held only as a hash value and removed automatically after ten minutes at the latest) and stored as an HMAC digest in the verification record. The IP address is never stored or logged in plain text.

Merchant data (in the backend): Upon installation, the backend stores the technical registration data of the shop (shop identifier, shop URL, cryptographic access and signature credentials) and the tariff level. This data contains no personal data of shop customers and is deleted automatically and completely when the app is uninstalled.

E-mail dispatch: The confirmation e-mails to customer and merchant are sent exclusively via the mail infrastructure of the respective merchant's shop. Codixio does not operate its own mail dispatch and does not use any external mail service provider. The sender is the merchant's shop.

Technical caches and logs: The backend holds short-lived technical caches without personal data (public signature keys for a maximum of five minutes, technical access tokens for a maximum of ten minutes). The server logs contain no personal data, in particular no names, e-mail addresses or IP addresses.

5. Legal bases

The revocation data is processed on behalf of the merchant; the relevant legal bases on the merchant's side are Art. 6(1)(c) GDPR (compliance with the legal obligations under Sec. 356a BGB) and Art. 6(1)(b) GDPR (performance of the contract with the customer). The pseudonymisation of e-mail and IP in the verification record and the rate limiting serve abuse prevention and record keeping (on the merchant's side Art. 6(1)(c) and (f) GDPR). The processing of the merchant's registration and tariff data by Codixio as controller is based on Art. 6(1)(b) GDPR.

6. Recipients and sub-processors

Hosting: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Activity: hosting provider for application servers and Postgres database. Processing locations: data centres in Falkenstein (DE) and Nuremberg (DE). In addition, Coolify is used as a self-operated open-source container orchestration on Hetzner, not an external service provider.

To verify licence signatures, the backend retrieves public signature keys from api.shopware.com; no personal data is transmitted in doing so. Communication with the merchant's shop takes place via the shop's own admin interface. There are no further external recipients: no external mail service provider, no AI service, no analytics or tracking service, no external CDN.

7. Third-country transfer

No third-country transfer takes place. All processing occurs in data centres in Germany.

8. Cookies and device access

The app is entirely cookieless. No cookies are set, no local storage and no session storage are used, and no information is read from the device beyond what is technically required (Sec. 25 TDDDG). Only the form data consciously entered by the customer is transmitted.

9. No AI, no automated decision-making

The app does not use any artificial intelligence functions, does not transmit data to AI providers and does not make automated decisions within the meaning of Art. 22 GDPR. The verification of a revocation request is a rule-based comparison with the order; the legal handling of the revocation remains with the merchant.

10. Storage periods at a glance

Form data of the revocation request: no storage, transient processing. Pseudonymised verification record in the merchant's shop: 90 days, then automatic deletion. Rate-limiting state: a maximum of ten minutes. Merchant registration and tariff data in the backend: for the duration of the app usage, complete deletion upon uninstallation. No storage of personal data exceeds 24 months.

11. Data subject rights

Data subjects have the rights under Art. 15 to 21 GDPR (access, rectification, erasure, restriction, data portability, objection). For enquiries by shop customers, the respective merchant as controller is the correct point of contact; Codixio supports the merchant in responding. Note pursuant to Art. 11 GDPR: Codixio cannot attribute the HMAC values stored in the verification record to any person without additional information.

12. Supervisory authority

Landesbeauftragter für den Datenschutz Sachsen-Anhalt, Leiterstraße 9, 39104 Magdeburg, Germany. Phone +49 391 81803-0. E-mail poststelle@lfd.sachsen-anhalt.de. Website datenschutz.sachsen-anhalt.de.

13. Authoritative version

The current version of this privacy policy is available at https://legal.codixio.com/apps/eu-widerrufsbutton-shopware/privacy.en.