1. Data controller
Corso Strada Nuova, 112 A, 27100 Pavia (PV), Italy
Person responsible for processing: Sergio Baldaro
Privacy contact and data requests: info@mondobimbi.net
Amazon SP-API developer account: Mondobimbi
This policy describes how Mondobimbi (hereinafter "we", the "Controller" or the "Provider") collects, processes, stores, uses, shares and deletes data, with particular regard to data originating from Amazon and obtained through the Amazon Selling Partner API (SP-API), in compliance with Regulation (EU) 2016/679 (GDPR) and with Amazon's policies (Acceptable Use Policy and Data Protection Policy).
2. Scope and role in processing
DEDALO is a software-as-a-service (SaaS) platform that assists Amazon sellers ("Customers") with European VAT obligations: computation of daily sales records, the OSS scheme, logistics transfers and Intrastat filings.
With respect to its Customers' Amazon data, the Controller acts as a data processor on behalf of the selling Customer, who remains the data controller of their own sales data. Amazon data is processed exclusively on the Customer's instructions and for the purposes set out below.
3. Amazon data collected
Access takes place only after the seller's explicit authorisation, through Amazon's OAuth authorisation flow (SP-API) or through reports that the Customer uploads manually to the platform. We process only the data strictly necessary for VAT compliance.
| Data category | Examples | Source |
|---|---|---|
| VAT transaction data | amounts, rates, country of departure/arrival, transaction type, currency, date | SP-API / Amazon tax reports (e.g. Amazon VAT Transactions Report) |
| Logistics data | origin/destination fulfilment centre, movements between EU countries | SP-API / Amazon reports |
| Goods identifiers | ASIN/SKU, product description, quantity | SP-API / Amazon reports |
| Seller account data | seller identifier (Selling Partner ID), marketplace | SP-API authorisation |
3.1 SP-API reports and roles requested
Within the Amazon Selling Partner API integration, the Controller requests only the roles strictly necessary to deliver the service, in accordance with the data minimisation principle of Amazon's Acceptable Use Policy:
| Report | SP-API role | Purpose |
|---|---|---|
GET_VAT_TRANSACTION_DATA | Tax Invoicing | Computing daily sales records and the OSS return |
SC_VAT_TAX_REPORT | Tax Invoicing | Verifying applied VAT rates and invoice numbers |
GET_LEDGER_DETAIL_VIEW_DATA | Amazon Fulfillment | Detecting transfers between EU fulfilment centres |
GET_FBA_STORAGE_FEE_CHARGES_DATA | Amazon Fulfillment | Allocating storage costs to the correct period |
| Settlement report | Finance and Accounting | Reconciling payouts and fees |
| All Orders report | Inventory and Order Tracking | Matching transactions to their corresponding orders |
Reports classified by Amazon as restricted are retrieved exclusively by means of the Restricted Data Tokens (RDT) defined in the SP-API documentation. The Controller does not request or use the Brand Analytics role and does not process consumer behaviour data, search term data or brand performance data.
4. Purposes and legal bases of processing
Amazon data is used exclusively to provide the Customer with the features of the service:
- determination and summary of VAT sales records by country;
- processing of the OSS (One Stop Shop) scheme;
- management of intra-community logistics transfers and Intrastat obligations;
- production of registers, summaries and documents (PDF/archives) for the Customer's accountant or for the Italian Revenue Agency.
Data is not used for marketing, profiling, model training, resale, or for any purpose other than those stated above.
Legal bases (GDPR art. 6): performance of the service contract with the Customer (art. 6.1.b); compliance with legal and tax obligations (art. 6.1.c); limited legitimate interest in the security and maintenance of the service (art. 6.1.f).
5. Processing arrangements
Processing takes place on dedicated application servers. Each Customer operates within an
isolated container (dedalo_server_{customer}) with dedicated
databases; there is no data sharing between different accounts. Processing is automated
(VAT computation, aggregation, document generation) and does not involve decisions producing
legal effects based solely on automated processing within the meaning of GDPR art. 22.
6. Storage and data location
- Per-tenant isolated databases: each Customer has its own MongoDB and MariaDB databases; no commingling between customers.
- EU location: data is hosted exclusively in datacentres located within the European Union (Germany — providers such as Hetzner / IONOS). No data is transferred outside the European Economic Area.
- Encryption in transit: all communications use HTTPS/TLS; SP-API authorisation and API calls use encrypted connections.
- Encryption at rest: storage volumes and backups reside on encrypted storage; credentials and access tokens (including SP-API credentials) are stored encrypted and separately from operational data.
- Backups: backups are encrypted, retained within the EU and subject to the same retention and deletion policy as primary data.
7. Data sharing
The Controller does not sell, rent or transfer Amazon data to third parties, nor share it for marketing or advertising purposes. Data may be processed solely by:
- infrastructure sub-processors (EU hosting providers), bound by an agreement pursuant to GDPR art. 28 and limited to the provision of infrastructure;
- the Customer and parties authorised by the Customer (e.g. their accountant), through export of the generated documents;
- competent authorities, exclusively where required by a legal obligation.
No Amazon data is transmitted to other sellers, to unauthorised third-party systems, or to parties outside the EU.
8. Data retention
Amazon data is retained for the duration of the contractual relationship with the Customer and for the period necessary to fulfil applicable tax and accounting obligations (in Italy, as a rule up to 10 years for documents relevant for tax purposes, as required by law). After those periods, data is deleted or anonymised.
The demonstration environment (demo.vatmarketplace.it) is reset every night: data
entered there is not retained.
9. Data deletion and disposal
- The Customer may request deletion of their data at any time by writing to info@mondobimbi.net.
- Upon termination of the relationship, the Customer's data and the related SP-API tokens are revoked and deleted from databases, containers and backups according to rotation schedules, except for data subject to a statutory retention obligation.
- Revocation of the SP-API authorisation by the seller (from Seller Central) results in immediate cessation of data access and initiation of the deletion procedure for data no longer required.
- Deletion is performed securely and irreversibly on production systems and on backups.
10. Security measures
- Access control based on the principle of least privilege; access to production data limited to strictly necessary personnel.
- Strong authentication: user access with password and OTP code (two-factor authentication).
- Multi-tenant isolation through dedicated containers and databases per Customer.
- Encryption in transit (TLS) and at rest; encrypted management of secrets and SP-API tokens.
- Access logging and audit logs of relevant operations.
- Security updates and periodic infrastructure maintenance.
11. Incident management (data breach)
A security incident management procedure is in place. In the event of a personal data breach, the Controller promptly adopts containment measures and notifies the breach, where applicable, to the supervisory authority (the Italian Data Protection Authority) within 72 hours and to the data subjects/Customers concerned, pursuant to GDPR arts. 33-34. Incidents involving Amazon data are additionally handled in accordance with the timelines and notification obligations set out in Amazon's Data Protection Policy.
12. Rights of data subjects
Data subjects may exercise the rights provided for by GDPR arts. 15-22 (access, rectification, erasure, restriction, portability, objection) by writing to info@mondobimbi.net. It is also possible to lodge a complaint with the competent supervisory authority (in Italy, the Garante per la protezione dei dati personali — garanteprivacy.it).
13. Compliance with Amazon policies
Processing of data obtained through the Amazon Selling Partner API is carried out in compliance with the Amazon Acceptable Use Policy and the Amazon Data Protection Policy. In particular: Amazon data is used only for the purposes authorised by the seller, is not shared with unauthorised third parties, is encrypted in transit and at rest, is retained only for as long as strictly necessary and is deleted when no longer needed or upon request.
14. Changes to this policy
This policy may be updated. The version in force is always published at this address, with an indication of the date of last update. Material changes will be communicated to Customers.