Privacy policy
This policy says what data KI-Elch Seller Console handles, why, where it is kept, who can see it, how long it stays, and how it is deleted. It is written to be checked against the running service. Where a control is enforced by code, the policy says so.
1. Who is responsible
Waller GmbHPantaleonsmühlengasse 28–30, 50676 Köln, Germany
Managing director: Floris Litjens
floris@wallerlitjens.de · +49 151 2980 2708
Waller GmbH is the controller for the website and for the accounts of the people who sign in to the console. For the seller data read from Amazon on a seller's instruction, Waller GmbH acts as a processor on behalf of the seller, who remains the controller. A data-processing agreement under Art. 28 GDPR is available on request.
2. This website
The website is static. It sets no cookies, loads no fonts, scripts or images from third parties, and uses no analytics. The web server writes an access log with the requesting IP address, time, requested path, user agent and referrer. The log is kept for twelve months for security monitoring and then deleted. Legal basis: Art. 6(1)(f) GDPR, our interest in operating the site securely.
If you e-mail or phone us, we keep the correspondence as long as needed to deal with it and for as long as commercial law requires us to retain business letters. Legal basis: Art. 6(1)(b) and (c) GDPR.
3. Console accounts
To use the console a person needs an account. We store:
| Data | Purpose | Kept |
|---|---|---|
| E-mail address, display name | Sign-in, invitations, contact about the account | Life of the account |
| Password, stored only as a salted hash; the last ten hashes for reuse checks | Sign-in | Life of the account |
| Time-based one-time-password secret (TOTP) | Second factor, required for every account | Life of the account |
| Session records, failed sign-in counters | Keeping you signed in; locking an account after eight failed attempts in fifteen minutes | Sessions expire; counters reset after fifteen minutes |
The console sets one cookie, a signed session identifier. It is strictly necessary for signing in and needs no consent. Legal basis for account data: Art. 6(1)(b) GDPR, the contract with you or your organisation.
4. Seller data read from Amazon
When a seller authorises the app in Seller Central, Amazon issues a refresh token. With it the service reads, on the seller's instruction, the data that Amazon's Selling Partner API exposes under the roles the app holds: Product Listing, Pricing, Inventory and Order Tracking, Selling Partner Insights, Brand Analytics and, once granted, Tax Invoicing.
What is stored
| Data | Where | Kept |
|---|---|---|
| Amazon refresh token, marketplace, seller identifier | An encrypted store (AES-256-GCM). The encrypting key is held only in memory on the server and never written to disk. | Until the seller revokes the authorisation or asks us to remove the account. Revocation destroys the token. |
| Daily snapshots: SKU, your price, Buy Box price and winner, stock quantity, listing status | A database on the server in Frankfurt | At most eighteen months; a retention job prunes older rows |
| Audit log: which tool was called, by whom, with which inputs. Credentials and tokens are redacted before writing. Responses are not logged. | Append-only log files on the server | Twelve months |
| Generated reports and exports (audit report, VAT export) | Written to the server's export folder when you request them | Until you delete them or the account is removed |
What is not stored: buyer data
Orders contain personal data of the seller's customers. The service removes buyer names, addresses, phone numbers and e-mail aliases before an order leaves the tool, keeping only the destination city, region and country. VAT transaction reports are aggregated into period and country buckets, and buyer VAT numbers are masked. A caller can opt in to see unmasked buyer details for a single call; that choice is recorded in the audit log, and the data is shown, not stored. A retention job scans every audit-log entry for buyer fields and fails if any appear. Because no buyer data is retained, Amazon's requirement to delete such data within thirty days of delivery has nothing to act on.
Legal basis for processing seller data: Art. 6(1)(b) GDPR, the contract with the seller, and the seller's instruction given by authorising the app. Amazon's Data Protection Policy and Acceptable Use Policy for developers apply in addition.
5. Where the data is and who can reach it
The service runs on Amazon Web Services in the eu-central-1 region (Frankfurt, Germany). There is no SSH access to the server; administration goes through AWS Systems Manager with an audited identity. Volume snapshots are taken daily and kept for 35 days as backups; a restore test is run quarterly. Network access is limited to HTTPS.
Within the service every seller account carries an owner. A person sees only the accounts they own or were invited to. A lookup without an identity fails rather than returning data. Administrators of Waller GmbH can reach all accounts for support and operation; such access is written to the audit log.
6. Who else receives data
| Recipient | What | Why |
|---|---|---|
| Amazon Services Europe S.à r.l. and Amazon.com Services LLC (Selling Partner API) | API requests carrying your seller identifier and the token Amazon issued | Reading your seller data on your instruction |
| Amazon Web Services EMEA SARL | Everything the service stores, on servers in Frankfurt | Hosting; bound by AWS's data-processing addendum |
| An AI assistant you connect yourself (for example Claude) | The results of the tools you call in that conversation | Only if you connect one; the assistant's provider is then your processor under your own terms |
We do not sell data and do not use it for advertising. We share it with nobody else unless the law requires it.
7. Deletion
- Revoking the app in Seller Central ends the connection. Our copy of the token is destroyed; snapshots for that account are pruned by the retention job.
- Asking us to remove an account (by e-mail) deletes the account record, its tokens, snapshots and exports. Audit-log entries remain for their twelve-month retention because they are the security record of what was accessed.
- Deleting a console user removes the e-mail address, password hashes and TOTP secret.
8. Your rights
Under the GDPR you can ask for access to your data, correction, deletion, restriction, portability, and you can object to processing based on our legitimate interest. Write to floris@wallerlitjens.de. You can also complain to a supervisory authority; ours is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen.
If you are a customer of one of our sellers and want to exercise your rights over order data, please contact the seller. We hold no buyer data that we could act on ourselves.
9. Changes
When the service changes in a way that affects data handling, this page is updated and the version date at the top changes. Account holders are told by e-mail about changes that matter to them.