Privacy and Data Handling Policy

DEDALO by Mondobimbi — Amazon VAT compliance for the European market
Version 1.1 · Last updated: 8 August 2026
This document also covers the processing of data obtained through the Amazon Selling Partner API (SP-API).
← Back to the site · Versione italiana

1. Data controller

MondobimbiDEDALO platform, software under the baldoweb brand
Corso Strada Nuova, 112 A, 27100 Pavia (PV), Italy
Person responsible for processing: Sergio Baldaro
Privacy contact and data requests: info@mondobimbi.net
Amazon SP-API developer account: Mondobimbi

This policy describes how Mondobimbi (hereinafter "we", the "Controller" or the "Provider") collects, processes, stores, uses, shares and deletes data, with particular regard to data originating from Amazon and obtained through the Amazon Selling Partner API (SP-API), in compliance with Regulation (EU) 2016/679 (GDPR) and with Amazon's policies (Acceptable Use Policy and Data Protection Policy).

2. Scope and role in processing

DEDALO is a software-as-a-service (SaaS) platform that assists Amazon sellers ("Customers") with European VAT obligations: computation of daily sales records, the OSS scheme, logistics transfers and Intrastat filings.

With respect to its Customers' Amazon data, the Controller acts as a data processor on behalf of the selling Customer, who remains the data controller of their own sales data. Amazon data is processed exclusively on the Customer's instructions and for the purposes set out below.

3. Amazon data collected

Access takes place only after the seller's explicit authorisation, through Amazon's OAuth authorisation flow (SP-API) or through reports that the Customer uploads manually to the platform. We process only the data strictly necessary for VAT compliance.

Data categoryExamplesSource
VAT transaction dataamounts, rates, country of departure/arrival, transaction type, currency, dateSP-API / Amazon tax reports (e.g. Amazon VAT Transactions Report)
Logistics dataorigin/destination fulfilment centre, movements between EU countriesSP-API / Amazon reports
Goods identifiersASIN/SKU, product description, quantitySP-API / Amazon reports
Seller account dataseller identifier (Selling Partner ID), marketplaceSP-API authorisation

3.1 SP-API reports and roles requested

Within the Amazon Selling Partner API integration, the Controller requests only the roles strictly necessary to deliver the service, in accordance with the data minimisation principle of Amazon's Acceptable Use Policy:

ReportSP-API rolePurpose
GET_VAT_TRANSACTION_DATATax InvoicingComputing daily sales records and the OSS return
SC_VAT_TAX_REPORTTax InvoicingVerifying applied VAT rates and invoice numbers
GET_LEDGER_DETAIL_VIEW_DATAAmazon FulfillmentDetecting transfers between EU fulfilment centres
GET_FBA_STORAGE_FEE_CHARGES_DATAAmazon FulfillmentAllocating storage costs to the correct period
Settlement reportFinance and AccountingReconciling payouts and fees
All Orders reportInventory and Order TrackingMatching transactions to their corresponding orders

Reports classified by Amazon as restricted are retrieved exclusively by means of the Restricted Data Tokens (RDT) defined in the SP-API documentation. The Controller does not request or use the Brand Analytics role and does not process consumer behaviour data, search term data or brand performance data.

Minimisation of personal data. The platform is designed for VAT compliance and does not require or retain personally identifiable information about end buyers (name, shipping address, email, phone, payment data). Where an Amazon report contains such fields, they are not used for the purposes of the service and are excluded from processing.

4. Purposes and legal bases of processing

Amazon data is used exclusively to provide the Customer with the features of the service:

Data is not used for marketing, profiling, model training, resale, or for any purpose other than those stated above.

Legal bases (GDPR art. 6): performance of the service contract with the Customer (art. 6.1.b); compliance with legal and tax obligations (art. 6.1.c); limited legitimate interest in the security and maintenance of the service (art. 6.1.f).

5. Processing arrangements

Processing takes place on dedicated application servers. Each Customer operates within an isolated container (dedalo_server_{customer}) with dedicated databases; there is no data sharing between different accounts. Processing is automated (VAT computation, aggregation, document generation) and does not involve decisions producing legal effects based solely on automated processing within the meaning of GDPR art. 22.

6. Storage and data location

🇪🇺 GDPR by design. Infrastructure entirely on European datacentres, per-customer isolation, no transfer outside the EU.

7. Data sharing

The Controller does not sell, rent or transfer Amazon data to third parties, nor share it for marketing or advertising purposes. Data may be processed solely by:

No Amazon data is transmitted to other sellers, to unauthorised third-party systems, or to parties outside the EU.

8. Data retention

Amazon data is retained for the duration of the contractual relationship with the Customer and for the period necessary to fulfil applicable tax and accounting obligations (in Italy, as a rule up to 10 years for documents relevant for tax purposes, as required by law). After those periods, data is deleted or anonymised.

The demonstration environment (demo.vatmarketplace.it) is reset every night: data entered there is not retained.

9. Data deletion and disposal

10. Security measures

11. Incident management (data breach)

A security incident management procedure is in place. In the event of a personal data breach, the Controller promptly adopts containment measures and notifies the breach, where applicable, to the supervisory authority (the Italian Data Protection Authority) within 72 hours and to the data subjects/Customers concerned, pursuant to GDPR arts. 33-34. Incidents involving Amazon data are additionally handled in accordance with the timelines and notification obligations set out in Amazon's Data Protection Policy.

12. Rights of data subjects

Data subjects may exercise the rights provided for by GDPR arts. 15-22 (access, rectification, erasure, restriction, portability, objection) by writing to info@mondobimbi.net. It is also possible to lodge a complaint with the competent supervisory authority (in Italy, the Garante per la protezione dei dati personali — garanteprivacy.it).

13. Compliance with Amazon policies

Processing of data obtained through the Amazon Selling Partner API is carried out in compliance with the Amazon Acceptable Use Policy and the Amazon Data Protection Policy. In particular: Amazon data is used only for the purposes authorised by the seller, is not shared with unauthorised third parties, is encrypted in transit and at rest, is retained only for as long as strictly necessary and is deleted when no longer needed or upon request.

14. Changes to this policy

This policy may be updated. The version in force is always published at this address, with an indication of the date of last update. Material changes will be communicated to Customers.