Privacy Policy
Privacy Notice
This notice explains how Elatos srl (“we”, “our”, “us”) collects, uses, stores, protects, shares and deletes personal data (PII) processed via our Amazon integration (Seller / SP-API) and our ERP systems (Elatos), in compliance with GDPR and Amazon Data Protection Policies.
Contents
1) Who we are & contacts
Elatos srl — Registered office: Via Adua 3, Desenzano del Garda (IT)
Privacy contact email: privacy@elatos.net
If appointed, DPO: [Name / Email].
2) Categories of data processed
- • Identifying/logistics data (from Amazon): first/last name, shipping address and (if present) billing address; order ID; order lines (SKU/qty/non-sensitive descriptions).
- • Tax data (where required by law): legal entity name, VAT/Tax ID, billing address.
We do not collect or store card numbers, Amazon credentials, or special categories of data. We do not use email/phone for marketing.
3) Purposes and legal bases
- • Order and shipping management (GDPR art. 6(1)(b) — contract performance).
- • Invoicing/legal obligations (GDPR art. 6(1)(c) — tax/accounting duties).
- • Security and anti-fraud (GDPR art. 6(1)(f) — legitimate interest, with minimization and balancing).
We do not use Amazon data for profiling or resale.
4) Retention and deletion
- • Operational Amazon PII (shipping): retained only to fulfill the order and removed within 30 days after shipment completion.
- • Tax data: retained for 10 years (Italian law). Stored separately and encrypted.
- • Backups: encrypted; limited retention; no copies on unencrypted removable media.
Upon expiry, data is deleted or anonymized through controlled, recorded procedures.
5) Security measures
Encryption
- • In transit: TLS 1.2/1.3.
- • At rest: AES-256 for DB and backups.
- • Secrets management: AWS Secrets Manager and/or Windows DPAPI/Certificate Store.
Defense-in-depth
- • Regular OS/app/dependency hardening & patching.
- • EDR and centralized SIEM/logs with anomaly alerts.
- • Network segmentation/VPN and managed firewalls.
Application security
- • Periodic SAST/DAST scans.
- • Injection/XSS/CSRF prevention; secret scanning.
- • Testing in dedicated environments with dummy data.
Business continuity
- • Encrypted backups and restore tests.
- • Documented recovery procedures.
- • No exports to unmanaged devices.
6) Access and internal controls
- • Least privilege and role separation; MFA for admin accounts.
- • Unique, non-shared accounts; immediate revocation upon offboarding.
- • Access to PII systems only from managed corporate endpoints; no personal devices.
- • Access audit trail and logging of sensitive operations.
7) Sharing with third parties
No sale or resale of PII. We share only when necessary:
- • Carriers/logistics: only data strictly required for delivery.
- • Infrastructure providers (cloud/hosting): processors under GDPR agreements.
- • Competent authorities where required by law.
8) Data subject rights
You may exercise rights of access, rectification, erasure (where applicable), restriction, objection and portability.
To exercise your rights: privacy@elatos.net. You may lodge a complaint with the Supervisory Authority.
9) Incident response
- • Trigger the response plan, contain and assess impacts.
- • Notify Amazon at security@amazon.com without undue delay when Amazon data is involved.
- • Notify authorities/data subjects when required.
- • Post-incident analysis and documented corrective actions.
10) Location and transfers
Primary systems are hosted in Italy/EU. Any extra-EEA transfers occur only when necessary and under appropriate safeguards (SCCs plus supplementary measures).
11) Children
The service is not intended for children under 16; we do not knowingly collect data from minors.
12) Data governance, logs & vulnerabilities
Access Management & Least Privilege
- • Formalized provisioning/de-provisioning; periodic access reviews.
- • Strong password policy; credential rotation; no hard-coded secrets.
- • Secure secret storage (AWS Secrets Manager / DPAPI/Certificate Store).
Logging & Monitoring
- • Centralized security/access logs with alerts.
- • Technical logs without PII unless strictly necessary.
- • Log retention aligned to minimization and defense.
Vulnerability Management
- • Periodic scans; timely remediation for critical issues.
- • Secure SDLC: code reviews, SAST/DAST, updated dependencies.
- • Change management with approvals and testing in separate environments using test data.
Backups & Encryption
- • Scheduled, encrypted backups (AES-256); keys stored separately.
- • Periodic restore tests; recorded outcomes.
- • No export to unencrypted removable media.
Appendix – Commitments to Amazon
- • PII minimization: only first/last name, addresses and order data strictly needed.
- • Operational retention: Amazon PII deleted within 30 days; tax data separately retained for 10 years.
- • Logical separation: Amazon data encrypted and isolated; access tracked and reviewed.
- • Encryption: TLS 1.2/1.3 in transit; AES-256 at rest; secrets in secure vaults.
- • Prohibited uses: no marketing, profiling or resale.
- • Audit & logging: evidence of access/processing; regular scans and remediation.
- • Security notification: incidents reported to Amazon (security@amazon.com).
Contacts
Elatos srl
Registered office: Via Adua 3 - Desenzano del Garda (IT)
Phone: +39 030 2071562
Email: commerciale@elatos.net — Privacy: privacy@elatos.net