Skip to content
Revokeflow

Legal

Privacy policy

Last updated 1 October 2026.

Revokeflow is operated by Altix Code Ltd, a company incorporated in and governed by the law of the Republic of Cyprus (“we”, “us”, “Altix Code”). This policy explains what personal data we process when you use Revokeflow, in which capacity, and what rights you have over it.

Revokeflowis a business-to-business service: our direct customer (“you”, “the trader”, “the organisation”) is a merchant using the Service to compute and document EU right-of-withdrawal periods, deadlines and confirmations for contracts with its own consumers. That split — our direct relationship with you, and your relationship with the people who buy from you — runs through this whole policy, because our legal role is different in each case.

1. Two roles, not one

Data-protection law asks who decides why and how personal data is processed (the “controller”) and who processes it on that party’s instructions (the “processor”). We are both, depending on whose data it is:

We are the controller of your account data

Your own sign-up details, your organisation’s identity, who on your team has access and what they can do, and your billing relationship with us. We decide why this is processed (to run and bill for the Service, to secure your account, to respond to you) and we are directly accountable to you for it.

We are a processor of the withdrawal-case data you record

Every withdrawal case you open names one of your own consumers — their email, sometimes their name, what they bought, what they paid, and the dates and declarations that determine their statutory deadlines. That is personal data about your customer, you decide to put it into the Service, and you are its controller. We process it only to provide the Service to you: computing the period, rendering the Annex I.B model form, the withdrawal receipt and the refund confirmation, and operating the consumer-facing withdrawal link. Section 14 sets out the processing terms that apply to this data.

2. What we process, and why

Account and billing data (we are controller)

  • Identity and credentials — name, email address, a bcrypt hash of your password (never the password itself), and email-verification status. Legal basis: performance of the contract to provide you an account (Art. 6(1)(b) GDPR).
  • Organisation identity— your organisation’s name, legal name, address, contact email, phone number and consumer-facing language, which you supply because they are printed on every confirmation document your consumers receive. Legal basis: performance of the contract.
  • Team membership— who on your team has access, at which of the three permission levels (owner, admin, member), and the record of invitations sent, accepted or revoked. Legal basis: performance of the contract and our legitimate interest in keeping access to your organisation’s data under your control.
  • Billing data — your plan, and identifiers linking your organisation to a Stripe customer and subscription. Card numbers are never seen or stored by us: Stripe collects and holds them directly. Legal basis: performance of the contract and compliance with our own accounting obligations.
  • Security and audit records— sign-in activity, API key usage metadata (never the key itself, only a one-way hash of it), and an append-only log of who invited, promoted, removed or deleted what, and when. Legal basis: our legitimate interest in account security and in being able to show what happened on your organisation’s account, including after it is closed — see Section 5.

Withdrawal-case data (we are processor)

  • Your consumer’s email address and, where you supply it, name.
  • Your own order reference, a description of what was sold, the amount and currency, delivery charges, and the dates that determine the statutory period: conclusion, delivery, and (where relevant) when withdrawal information was supplied.
  • What happened afterwards — a declaration of withdrawal, return dispatch or receipt, a refund, a refusal and the exemption claimed for it — and the durable-medium PDF documents issued along the way, which embed the facts above.
  • A capability token that lets your consumer reach the withdrawal function for their own case without an account, as (EU) 2023/2673 requires.

We do not use withdrawal-case data for any purpose of our own — not analytics, not marketing, not training — and we never contact your consumers directly except by serving the withdrawal-portal page the capability link points to.

3. Who we share data with

We do not sell personal data. We share it only with the following categories of recipient, each acting as our sub-processor under a data processing agreement or, for Stripe, its own standard terms:

  • Stripe (Stripe Payments Europe, Ltd. and its affiliates) — processes your billing contact details and payment instrument to run your subscription. Stripe may process data outside the European Economic Area; where it does, it does so under Standard Contractual Clauses. Stripe never receives withdrawal-case data.
  • Our email delivery provider— sends account-related transactional email on our behalf: email verification, password reset, and team invitations. These emails go only to your organisation’s own users, never to your consumers.
  • Cloudflare, Inc. — provides the Turnstile challenge that protects our sign-up, sign-in and password-reset forms from automated abuse, where enabled. Turnstile is loaded only on those pages and processes connection metadata, not the content of your forms.
  • Hetzner Online GmbH — our infrastructure host. We provision our servers within the European Union.

We disclose data to a government or regulatory authority only where we are legally compelled to, and, where the law permits it, we tell you first.

4. How long we keep it

Account data and withdrawal-case data are kept for as long as your organisation exists on the Service. We do not run any automatic expiry of withdrawal-case data while your organisation is active — case records are a trader’s own compliance evidence, and we do not decide on your behalf when you no longer need them.

Deleting your organisation (available to an owner at any time, in Settings) is immediate and permanent: your account data, your team’s memberships, your API keys, and every withdrawal case, event, exemption claim and confirmation document it holds are deleted straight away. We do not hold a recovery or grace-period copy.

The one exception is the security and audit record described in Section 2: the entry recording that your organisation requested deletion, and the entries recording what happened to it before that, are kept for 24 months after deletion, then permanently erased. These entries are not linked to a live account after deletion and exist solely so that a security incident affecting your organisation before it closed can still be investigated and so that we can demonstrate, to you or to a supervisory authority, that a deletion you requested actually happened. Invoices Stripe has already issued are retained by Stripe under its own, independent record-keeping obligations and are unaffected by deleting your organisation.

5. Security

Passwords are hashed with bcrypt and never stored or logged in plain text. API keys and invitation, password-reset and email-verification links are stored only as a one-way SHA-256 digest of a value you alone receive once; we cannot look up or recover the original value from our database. Secrets that must be reversible to function — such as a webhook-signing secret you give us — are encrypted at rest with AES-256-GCM under a key held only in our server environment. Data in transit is encrypted with TLS.

6. Your rights

If you are an individual whose data we hold as controller— our direct customer’s own account holders and team members — you may, subject to the conditions the law attaches to each right, ask us to:

  • confirm what personal data of yours we hold, and access a copy of it;
  • correct it if it is inaccurate or incomplete;
  • erase it, or restrict our processing of it;
  • receive it in a portable, machine-readable format;
  • object to processing based on our legitimate interest;
  • withdraw a consent you previously gave, at any time.

Reach us at privacy@altixcode.com to exercise any of these. You also have the right to lodge a complaint with a supervisory authority — in Cyprus, the Office of the Commissioner for Personal Data Protection, or the authority in the EU member state where you live or work.

If you are a consumer whose withdrawal caseis recorded in the Service by a trader who uses it — we are that trader’s processor, not the controller of your data, so the trader is who must answer a rights request about it in the first instance. If you are unsure who that is or cannot reach them, contact privacy@altixcode.com with the order reference or the withdrawal-portal link you were given; we will identify the responsible trader and either forward your request or, where we are able to verify it is yours to make, act on it directly.

7. Cookies

We use only cookies that are strictly necessary for the Service to work, and we do not show a cookie banner because none of them require consent under the ePrivacy rules: a session cookie that keeps you signed in, and, on our sign-up, sign-in and password-reset pages where enabled, a cookie set by Cloudflare Turnstile to tell a human visitor from an automated one. We run no analytics or advertising cookies and do not use cookies to track you across other websites. You can block cookies in your browser settings; doing so will prevent you from staying signed in.

8. International transfers

Our infrastructure is provisioned within the European Union. Where a sub-processor listed in Section 3 processes data outside the European Economic Area, we rely on that provider’s Standard Contractual Clauses or an equivalent safeguard recognised under Chapter V GDPR.

9. Children

The Service is offered to businesses, not to consumers, and is not directed at children. We do not knowingly collect personal data from anyone under 16 in connection with an Revokeflow account.

10. Changes to this policy

We will update this page if what we process, who we share it with, or why changes, and update the date at the top when we do. We will tell active account owners by email of a change that materially reduces your rights.

11. Processing terms for withdrawal-case data

This section is the data processing agreement between you (the controller of your consumers’ withdrawal-case data) and Altix Code Ltd (the processor), and applies whenever you use the Service to process that data.

  • We process withdrawal-case data only on your documented instructions — given by the way you use the dashboard and API — and for the purpose of providing the Service, unless EU or member-state law requires otherwise, in which case we will tell you before processing unless the law prohibits it.
  • Our staff with access to withdrawal-case data are bound by confidentiality.
  • We implement the technical and organisational measures described in Section 5, appropriate to the risk of processing contract and delivery details and a consumer’s contact information.
  • Our sub-processors for this data are limited to the infrastructure host listed in Section 3; we do not hand withdrawal-case data to Stripe, our email provider or Cloudflare. We will give you reasonable notice before adding a new sub-processor that would process it, so you can object.
  • We will assist you, to the extent reasonably required, in responding to a data subject request or a supervisory authority inquiry concerning data we process on your behalf, and in meeting your own obligations around security and breach notification under Articles 32–36 GDPR.
  • On deletion of your organisation, we delete withdrawal-case data immediately rather than returning it first — see Section 4. If you need an export, take it before deleting; we do not retain a post-deletion copy to export later.
  • We will notify you without undue delay if we become aware of a breach affecting withdrawal-case data we process for you.