This is a translation for your convenience. The German version is legally authoritative.
Data Protection and Data Handling Policy for data obtained via the Amazon Selling Partner API (SP-API)
| Responsible company | Bäste GmbH |
|---|---|
| Registered office | Fröndenberg/Ruhr, Germany |
| Brand / business unit | budnuts |
| Document version | 1.1 |
| Last updated | 14 August 2026 |
| Owner of this policy | Management / Head of IT |
| Next review | annually, no later than 14 August 2027 |
1. Purpose and scope
This policy sets out, in binding terms, how Bäste GmbH collects, processes, stores, uses, shares and destroys data obtained via the Amazon Selling Partner API (SP-API).
It applies to:
- all employees, managing directors and processors of Bäste GmbH,
- all IT systems in which Amazon data is processed (in particular the self-hosted ERP system based on Frappe/ERPNext),
- all categories of Amazon data, in particular buyers’ personally identifiable information (“PII”).
This policy supplements and gives effect to our general obligations under Regulation (EU) 2016/679 (GDPR), the German Federal Data Protection Act (BDSG), the Amazon Services Data Protection Policy (DPP) and the Amazon Acceptable Use Policy. In the event of a conflict, the stricter requirement prevails.
2. Principles
Amazon data is processed in accordance with the following binding principles:
- Purpose limitation: Amazon data is used exclusively to fulfil orders placed on the Amazon marketplace and to meet the legal obligations connected with them.
- Data minimisation: only the data fields required for the specific processing purpose are retrieved and stored.
- Need to know: access is limited to the people who need the data for their work.
- Storage limitation: data is kept only as long as required for the purpose or by statutory retention obligations.
- Integrity and confidentiality: data is encrypted in transit and at rest and protected against unauthorised access.
- Accountability: every access and every change can be attributed to a natural person.
3. Collection of Amazon data
3.1 Data sources and legal basis
Amazon data is obtained exclusively via the official Amazon SP-API. No retrieval takes place via unauthorised interfaces, scraping or manual bulk exports.
The legal basis for processing buyer data is Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (compliance with legal obligations, in particular tax and commercial retention duties).
3.2 Categories of data collected
| Category | Examples | PII |
|---|---|---|
| Order data | order number, order date, items, quantity, price | no |
| Buyer identity | buyer’s name | yes |
| Delivery data | shipping address, country, postcode | yes |
| Contact data | anonymised Amazon buyer email address | yes |
| Shipping data | tracking number, carrier | no |
| Settlement data | fees, refunds, disbursements | no |
| Product and inventory data | ASIN, SKU, stock level, prices | no |
3.3 Express restrictions
- Payment data (credit card or bank details) is not retrieved via the SP-API and not stored.
- No PII fields are retrieved for which there is no specific processing purpose.
- Amazon data is not combined with data from other sales channels for profiling purposes.
- PII is not written to application, debug or error logs. Log entries reference technical identifiers only (e.g. order numbers).
4. Processing and use
4.1 Permitted purposes
Amazon data may be used exclusively for the following purposes:
- processing and shipping orders, including creating shipping labels,
- issuing invoices and meeting tax obligations,
- handling returns, refunds and customer enquiries relating to specific orders,
- inventory and merchandise management,
- aggregated, non-personal analysis of sales performance.
4.2 Expressly prohibited use
The following is prohibited in particular:
- using buyer data for marketing, advertising or newsletter purposes,
- contacting buyers outside Amazon’s communication channels and outside the purpose of order fulfilment,
- selling, renting, pledging or otherwise monetising Amazon data,
- enriching buyer data with data from external sources,
- using PII for testing, development or training purposes. Non-production environments use synthetic or anonymised test data only.
4.3 Processing location
Processing and storage take place exclusively on our own server infrastructure in a data centre in Germany. The web front ends are delivered via the content delivery network of Cloudflare, Inc. (USA), which processes technical connection data (including IP addresses); EU standard contractual clauses are in place for this. Beyond that, no Amazon data is transferred to third countries.
5. Storage and technical safeguards
5.1 Storage location
Amazon data is stored exclusively in the database of the self-hosted ERP system (Frappe/ERPNext). Internal notifications (e.g. in the team chat) do not contain buyer data either; they only reference the transaction in the ERP. Local storage on end devices, removable media or private cloud storage is prohibited; the ERP is used in the browser only, and data exports are restricted to authorised roles and logged.
5.2 Encryption
- In transit: TLS 1.2 or higher only; unencrypted requests are redirected to HTTPS, and the APIs are reachable via TLS only.
- At rest: the ERP database runs with transparent database encryption (encryption at rest, AES). Backups are additionally encrypted with AES-256; the backup key is kept separately from the backup destination. Company notebooks are rolled out with full-disk encryption (LUKS).
- API credentials: LWA client credentials and refresh tokens are stored server-side only, in an access-restricted configuration file outside the web root (file mode 0600, service account only), and are not visible to ERP users; credentials of other services stored in the database are encrypted with Fernet (AES-128-CBC + HMAC-SHA256). Rotation takes place at least annually and immediately upon suspected compromise or when administrators leave.
5.3 Access control
- Personalised user accounts, no shared accounts.
- Role-based access control (RBAC) on a need-to-know basis; order and address data is accessible only to roles with sales and shipping duties.
- Two-factor authentication for all ERP accounts.
- Administrative server access via SSH keys only; password login and root login are disabled. Login attempts are limited by an intrusion prevention system (fail2ban) with an aggressive lockout policy.
- Enforced password policy in the ERP (strength check, account lockout after failed attempts, automatic session expiry).
- Access reviews at least every six months and on every role change.
- Immediate deactivation of accounts when staff leave (offboarding process).
5.4 Logging
Access to and changes in the ERP are recorded in the system’s audit trail (user, timestamp, IP address, affected record) and retained for at least 90 days; per-record change histories are kept indefinitely. Server system and authentication logs are retained for at least 90 days and evaluated automatically (real-time brute-force detection, daily security report to the admin team). Log entries reference technical identifiers only and contain no PII.
5.5 Backups
Backups are automated and encrypted: local backups every six hours, plus a daily encrypted backup (AES-256) to a separate S3 object store. Retention is staggered (7 daily, 4 weekly, 6 monthly snapshots) with automatic pruning; after PII has been deleted, all backup snapshots are therefore overwritten as this cycle expires, at the latest after six months. Backups are subject to the same access rules as production data.
6. Disclosure to third parties
6.1 Principle
Amazon data is disclosed to third parties only where required to fulfil the order or to meet legal obligations.
6.2 Categories of recipients
| Recipient | Purpose | Data transferred | Legal basis |
|---|---|---|---|
| Shipping carriers | delivery of the order | name, shipping address, shipment data | Art. 6(1)(b) GDPR |
| Tax advisors / tax authorities | accounting, tax obligations | invoice data | Art. 6(1)(c) GDPR |
| IT service providers / hosting | operation and maintenance of the systems | technical access | Art. 28 GDPR (DPA) |
Data processing agreements pursuant to Art. 28 GDPR are in place with all processors, including confidentiality obligations and appropriate technical and organisational measures.
6.3 Exclusions
Amazon data is not shared with advertising networks, data brokers, analytics or tracking providers. No disclosure takes place for third parties’ own commercial purposes.
7. Retention and destruction
7.1 Retention periods
| Data category | Period | Basis |
|---|---|---|
| PII for order fulfilment (name, shipping address, contact data) | deletion within 30 days of complete delivery or completion of the order (automated daily deletion run) | Amazon DPP |
| Invoices and accounting records as well as commercial correspondence (order, delivery and shipping documents; these necessarily contain name and address) | 6 or 10 years | § 147 AO, § 257 HGB |
| Order and revenue data without personal reference | indefinitely, for analysis purposes | legitimate interest |
| Access and security logs | 90 days | IT security |
Note on statutory retention: where PII must be retained beyond the 30-day period due to commercial and tax law, it is kept only to the extent required by law, encrypted, with access restricted to what is necessary (need to know), and exclusively for the purpose of meeting those obligations. Any use of this data for other purposes is excluded.
7.2 Destruction procedures
- Database records: complete deletion or irreversible anonymisation (no “soft delete”) once the period expires, automated via a daily deletion run; every deletion is evidenced by a timestamp on the transaction.
- Storage media: destruction in accordance with DIN 66399 (at least protection class 2 / security level H-4 or E-3) or secure overwriting in accordance with NIST SP 800-88; for encrypted media additionally cryptographic erasure by destroying the key material.
- Paper documents: destruction in a shredder in accordance with DIN 66399, security level P-4 or higher.
- Evidence: records are kept of deletion runs and media destruction.
7.3 Deletion upon termination of Amazon access
If the SP-API authorisation is revoked, the Amazon seller relationship ends or Amazon so requests, all Amazon data is deleted within 30 days, except for records subject to statutory retention under section 7.1. Amazon receives written confirmation of deletion on request.
8. Data subject rights
Requests from data subjects (access, rectification, erasure, restriction, data portability, objection under Art. 15–21 GDPR) are handled without undue delay and at the latest within one month. Requests from Amazon buyers relating to the Amazon marketplace are answered in coordination with Amazon. The management of Bäste GmbH is responsible.
Contact: kontakt@baeste.eu
9. Security incident handling
- Detection and internal reporting: every employee is required to report a suspected security incident immediately to management and the head of IT.
- Immediate measures: containment, locking affected accounts, preserving evidence, root cause analysis.
- Notifying Amazon: any security incident affecting Amazon data is reported to Amazon within 24 hours of becoming known, to security@amazon.com and via the designated channel in Seller Central. We commit to cooperating with Amazon on investigation and remediation.
- Notifying the supervisory authority: where there is a risk to the rights and freedoms of data subjects, the competent supervisory authority is notified within 72 hours pursuant to Art. 33 GDPR; data subjects are informed pursuant to Art. 34 GDPR.
- Documentation: all incidents are documented, including measures taken and outcome.
10. Training and bindingness
- All employees with access to Amazon data are bound in writing to this policy and to the confidentiality obligation under Art. 32(4) GDPR before access is granted.
- Refresher training takes place at least annually and whenever this policy changes materially.
- Violations of this policy may result in consequences under employment law up to and including termination, as well as civil and criminal liability.
11. Review of this policy
This policy is reviewed and updated at least annually and on relevant occasions (changes in the law, Amazon requirements, IT architecture, or after a security incident). Changes are documented with version history.
Version history
| Version | Date | Change | Approved by |
|---|---|---|---|
| 1.0 | 14 Aug 2026 | Initial version | Management |
| 1.1 | 14 Aug 2026 | Alignment with the actual infrastructure before SP-API onboarding: encryption, access control, logging and backup statements corrected; CDN note (Cloudflare, EU standard contractual clauses); automated 30-day deletion run; commercial correspondence added to the retention table | Management |