Privacy policy
This policy explains what data Artificiale Seller Analytics accesses through the Amazon Selling Partner API, why, where it is kept, and how it is deleted. Last updated 2026-09-02.
Who is responsible
- Data controller
- TAGA EVENTS SRL
- CUI
- 40054662
- Trade Register
- J23/5185/2018
- Registered office
- Strada Caisului 40, Tămași, Ilfov 077066, Romania
- Contact
- amazonadstrategist@gmail.com
What we collect
Only aggregated business performance data belonging to sellers who have authorised our application:
- Sessions, page views, ordered product sales, units ordered, conversion rate and Buy Box percentage, by day and by ASIN or SKU
- Sales, refunds and, subject to availability in the seller's dataset, advertising spend, fee breakdowns, seller-entered cost of goods and net proceeds
- The encrypted authorisation credential issued by Amazon, and the seller's Amazon identifier and marketplace
No buyer personally identifiable information or restricted Amazon data
We do not request, receive or store buyer names, addresses, email addresses, phone numbers, order recipient details, buyer messages or payment information. The roles we request — Brand Analytics and Selling Partner Insights — are not restricted roles and do not grant access to that data. We do not collect Amazon sign-in credentials.
Separately from the Amazon data above, our web server records standard access logs when someone visits this website. Those logs temporarily contain the visitor's IP address; see This website below.
Why we use it
Solely to produce advertising and profitability reporting for the seller the data belongs to, as part of the managed service that seller has contracted from us. We do not use it for any other purpose, and we do not use one client's data to inform work for another.
Lawful basis. The Amazon data we retrieve is business performance data of a corporate seller and is not, in general, personal data. Where personal data is nevertheless processed, the basis depends on whose data it is:
- Where our client is a sole trader or the data otherwise identifies the client themselves, we rely on performance of the contract with that client, Article 6(1)(b) GDPR.
- Where the data relates to individuals connected with a corporate client — for example an employee named as our contact — Article 6(1)(b) does not apply to them, because they are not party to the contract. For those individuals we rely on our legitimate interests in administering the engagement, Article 6(1)(f), balanced against their rights.
- For website access logs we rely on legitimate interests in the security and integrity of our server, Article 6(1)(f).
This allocation is our own assessment and is kept under review; it is not legal advice.
Where it is stored and how it is protected
- Stored on a private virtual server operated by us in Romania, hosted by our infrastructure provider Cyber_Folks SRL.
- Amazon authorisation credentials are encrypted at rest with AES-256-GCM.
- Access to the server is restricted to named administrators using key-based authentication over a private network.
- The application holds no write permission against any Amazon account.
Who we share it with
We do not sell, rent, trade or otherwise share seller data with third parties. We use Cyber_Folks SRL (Romania) as our hosting subprocessor. It does not access seller data in the ordinary course, but may access infrastructure only where necessary to provide or support the hosting service, maintain security, or comply with legal obligations. We disclose data to public authorities only where legally compelled.
How long we keep it and how it is deleted
- Performance data is retained for the duration of the engagement, and for up to 24 months of history to allow year-on-year comparison.
- If a seller revokes authorisation, or an engagement ends, we delete the stored credential immediately and the retrieved data within 30 days.
- A seller may request deletion at any time by writing to the address above; we complete it within 30 days.
Your rights
Under GDPR you may request access to your data, correction, erasure, restriction of processing, or portability, and may object to processing. Write to amazonadstrategist@gmail.com. You also have the right to lodge a complaint with the Romanian supervisory authority, ANSPDCP.
This website
This website sets no cookies, runs no JavaScript, loads no fonts, scripts or images from third parties, and contains no analytics or tracking of any kind. Visiting it leaves nothing on your device and builds no profile of you.
It is not, however, anonymous. Like any web server, ours writes an access log entry for each request, and that entry temporarily contains your IP address alongside the time, the URL requested, the response status and your browser's user-agent string. We use these logs only to operate and secure the server. They are rotated once a day and each rotated file is deleted once it is 14 days old, so a log entry survives approximately 14 days — at most 15, counting the day it is still being written. They are never combined with Amazon seller data or used to profile visitors.