Privacy Policy

Last update: 2025-08-19 Controller: Elatos srl

Privacy Notice

This notice explains how Elatos srl (“we”, “our”, “us”) collects, uses, stores, protects, shares and deletes personal data (PII) processed via our Amazon integration (Seller / SP-API) and our ERP systems (Elatos), in compliance with GDPR and Amazon Data Protection Policies.

1) Who we are & contacts

Elatos srl — Registered office: Via Adua 3, Desenzano del Garda (IT)

Privacy contact email: privacy@elatos.net

If appointed, DPO: [Name / Email].

2) Categories of data processed

Data minimization: we only process what is strictly necessary to ship and invoice.
  • • Identifying/logistics data (from Amazon): first/last name, shipping address and (if present) billing address; order ID; order lines (SKU/qty/non-sensitive descriptions).
  • • Tax data (where required by law): legal entity name, VAT/Tax ID, billing address.

We do not collect or store card numbers, Amazon credentials, or special categories of data. We do not use email/phone for marketing.

3) Purposes and legal bases

  • • Order and shipping management (GDPR art. 6(1)(b) — contract performance).
  • • Invoicing/legal obligations (GDPR art. 6(1)(c) — tax/accounting duties).
  • • Security and anti-fraud (GDPR art. 6(1)(f) — legitimate interest, with minimization and balancing).

We do not use Amazon data for profiling or resale.

4) Retention and deletion

  • • Operational Amazon PII (shipping): retained only to fulfill the order and removed within 30 days after shipment completion.
  • • Tax data: retained for 10 years (Italian law). Stored separately and encrypted.
  • • Backups: encrypted; limited retention; no copies on unencrypted removable media.

Upon expiry, data is deleted or anonymized through controlled, recorded procedures.

5) Security measures

Encryption
  • • In transit: TLS 1.2/1.3.
  • • At rest: AES-256 for DB and backups.
  • • Secrets management: AWS Secrets Manager and/or Windows DPAPI/Certificate Store.
Defense-in-depth
  • • Regular OS/app/dependency hardening & patching.
  • • EDR and centralized SIEM/logs with anomaly alerts.
  • • Network segmentation/VPN and managed firewalls.
Application security
  • • Periodic SAST/DAST scans.
  • • Injection/XSS/CSRF prevention; secret scanning.
  • • Testing in dedicated environments with dummy data.
Business continuity
  • • Encrypted backups and restore tests.
  • • Documented recovery procedures.
  • • No exports to unmanaged devices.

6) Access and internal controls

  • • Least privilege and role separation; MFA for admin accounts.
  • • Unique, non-shared accounts; immediate revocation upon offboarding.
  • • Access to PII systems only from managed corporate endpoints; no personal devices.
  • • Access audit trail and logging of sensitive operations.

7) Sharing with third parties

No sale or resale of PII. We share only when necessary:

  • • Carriers/logistics: only data strictly required for delivery.
  • • Infrastructure providers (cloud/hosting): processors under GDPR agreements.
  • • Competent authorities where required by law.

8) Data subject rights

You may exercise rights of access, rectification, erasure (where applicable), restriction, objection and portability.

To exercise your rights: privacy@elatos.net. You may lodge a complaint with the Supervisory Authority.

Where data originates from Amazon, some requests may need coordination with Amazon as an independent controller.

9) Incident response

  • • Trigger the response plan, contain and assess impacts.
  • • Notify Amazon at security@amazon.com without undue delay when Amazon data is involved.
  • • Notify authorities/data subjects when required.
  • • Post-incident analysis and documented corrective actions.

10) Location and transfers

Primary systems are hosted in Italy/EU. Any extra-EEA transfers occur only when necessary and under appropriate safeguards (SCCs plus supplementary measures).

11) Children

The service is not intended for children under 16; we do not knowingly collect data from minors.

12) Data governance, logs & vulnerabilities

Access Management & Least Privilege
  • • Formalized provisioning/de-provisioning; periodic access reviews.
  • • Strong password policy; credential rotation; no hard-coded secrets.
  • • Secure secret storage (AWS Secrets Manager / DPAPI/Certificate Store).
Logging & Monitoring
  • • Centralized security/access logs with alerts.
  • • Technical logs without PII unless strictly necessary.
  • • Log retention aligned to minimization and defense.
Vulnerability Management
  • • Periodic scans; timely remediation for critical issues.
  • • Secure SDLC: code reviews, SAST/DAST, updated dependencies.
  • • Change management with approvals and testing in separate environments using test data.
Backups & Encryption
  • • Scheduled, encrypted backups (AES-256); keys stored separately.
  • • Periodic restore tests; recorded outcomes.
  • • No export to unencrypted removable media.

Appendix – Commitments to Amazon

  • • PII minimization: only first/last name, addresses and order data strictly needed.
  • • Operational retention: Amazon PII deleted within 30 days; tax data separately retained for 10 years.
  • • Logical separation: Amazon data encrypted and isolated; access tracked and reviewed.
  • • Encryption: TLS 1.2/1.3 in transit; AES-256 at rest; secrets in secure vaults.
  • • Prohibited uses: no marketing, profiling or resale.
  • • Audit & logging: evidence of access/processing; regular scans and remediation.
  • • Security notification: incidents reported to Amazon (security@amazon.com).
Contacts

Elatos srl

Registered office: Via Adua 3 - Desenzano del Garda (IT)

Phone: +39 030 2071562

Email: commerciale@elatos.net — Privacy: privacy@elatos.net