LastRetry
How it worksPricingSign inStart free

Data processing agreement

Last updated 3 October 2026. LastRetry is operated by Muida Tech AS (org. no. 927 533 464), Fosshauggutua 2, 2864 Fall. Questions: i.josuekongolo@gmail.com.

This agreement (GDPR Art. 28) is between you, the business using LastRetry (controller), and Muida Tech AS (processor), and forms part of the terms of service.

1. Subject and duration

We process your customers' personal data only to recover failed payments for you, for as long as your account exists.

2. Data and data subjects

Your end customers: name, email address, Stripe customer id, invoice amounts and payment failure reasons, and records of the emails we sent and links they opened. Card numbers are entered on Stripe's page and never reach us.

3. Our obligations

  • Process only on your documented instructions — these terms and your settings in the app.
  • Ensure everyone with access is bound by confidentiality.
  • Keep appropriate security: encrypted transport, access limited to what operating the service requires, no card data stored.
  • Help you answer data subject requests and meet your obligations under Art. 32–36.
  • Notify you without undue delay, and within 48 hours, after becoming aware of a personal data breach affecting your data.
  • Delete your data when you delete your account, except where law requires us to keep it.
  • Make available the information needed to demonstrate compliance, and allow reasonable audits on 30 days' notice.

4. Sub-processors

You authorise these sub-processors. We will give 30 days' notice before adding or replacing one, and you may object by ending the agreement.

  • Stripe, Inc. / Stripe Payments Europe Ltd. — Reading invoices on your Stripe account, retrying payments, hosting the card entry page, billing our fees
  • Resend, Inc. — Sending recovery emails and sign-in links
  • Railway Corporation — Application hosting and database
  • Twilio Inc. — Sending text messages to high-value customers, only for accounts that turn SMS on
  • Anthropic, PBC — Drafting email copy from the product description you write — no customer data is sent
  • Functional Software, Inc. (Sentry) — Error monitoring, when enabled — configured to collect no request data

5. Transfers

Where sub-processors are outside the EEA, transfers rely on the EU Standard Contractual Clauses or the EU–US Data Privacy Framework.

© 2026 LastRetry
TermsPrivacyDPA