Amazon Data Privacy & Data Handling Policy
Veiligheids-Sloten.nl B.V. – Amazon Selling Partner API
Laatst bijgewerkt: 25-11-2025
1. Inleiding en scope
Deze pagina beschrijft hoe Veiligheids-Sloten.nl B.V. (“wij”, “ons”) omgaat met Amazon-gegevens die wij verwerken via de Amazon Selling Partner API (SP-API) en via Amazon Seller Central. Deze policy is een aanvulling op ons algemene privacybeleid en richt zich specifiek op de verwerking van Amazon Information in de zin van de Amazon Data Protection Policy en de Acceptable Use Policy.
Deze policy is van toepassing op:
-
Bestellingen die via Amazon worden geplaatst
-
De koppeling tussen Amazon en ons warehouse management systeem (Picqer)
-
Alle systemen, processen en medewerkers die toegang hebben tot Amazon-gegevens
Wij zijn gevestigd aan:
Veiligheids-Sloten.nl B.V.
Schulpplein 15
3087 NA Rotterdam
Nederland
2. Rollen en verantwoordelijkheden
-
Ten opzichte van Amazon zijn wij Selling Partner en verwerken wij Amazon Information in overeenstemming met de Amazon-voorwaarden.
-
Ten opzichte van de eindklant (Amazon-koper) zijn wij in de meeste gevallen verwerkingsverantwoordelijke in de zin van de AVG/GDPR, omdat wij de bestelling uitleveren.
-
Onze integratiepartner Brixxs B.V. en onze SaaS-leveranciers (zoals Picqer) handelen als verwerkers (data processors) namens ons en verwerken data uitsluitend volgens onze instructies.
Wij verkopen Amazon-gegevens niet en gebruiken deze niet voor profiling of marketing buiten Amazon om.
3. Welke Amazon-gegevens verwerken we?
We beperken ons tot de gegevens die nodig zijn om bestellingen goed af te handelen en onze administratie te voeren. In hoofdlijnen gaat het om:
3.1 Bestel- en productgegevens
-
Amazon Order ID
-
Besteldatum en tijd
-
Bestelstatus (bijv. Unshipped, Shipped)
-
Producten (ASIN, SKU, titel, aantal, prijs)
-
Verzendwijze en service level
-
Totaalbedragen, BTW-informatie, verzendkosten
3.2 Persoonsgegevens (PII) voor fulfilment
Alleen voor zover door Amazon verstrekt en strikt noodzakelijk voor levering:
-
Naam van de ontvanger
-
Bezorgadres (straat, postcode, stad, land, eventuele adresregels)
-
Optioneel: telefoonnummer, e-mailadres (voor bezorgupdates/transport)
Wij gebruiken deze gegevens uitsluitend om:
-
de bestelling te kunnen verwerken en verzenden;
-
de zending te kunnen volgen;
-
eventuele klantenservice/retouren te kunnen afhandelen;
-
te voldoen aan wettelijke verplichtingen (bijv. fiscale bewaarplicht).
3.3 Customization / configuratiegegevens (niet-PII)
Bij producten met custom opties (bijv. cilindermaat, knauf, aantal sleutels) kan Amazon een customization-URL of JSON aanleveren (BuyerCustomizedInfo/CustomizedURL). Deze gebruiken wij om:
-
de gekozen configuratie uit te lezen;
-
deze om te zetten naar onze interne SKU-structuur in Picqer;
-
ervoor te zorgen dat we precies de juiste samenstelling produceren en uitleveren.
We behandelen deze configuratie-informatie als productconfiguratie, niet als PII, en koppelen het alleen aan de betreffende order.
3.4 Technische loggegevens
Voor beveiliging en troubleshooting verwerken we:
-
Timestamps van API-calls
-
Technische identifiers (request-ID’s, foutcodes)
-
Inlog- en toegangslogs (welk account wanneer welke actie heeft uitgevoerd)
We proberen te vermijden dat PII in logs terechtkomt. Indien dit toch nodig is, minimaliseren we dat en beschermen we de logs extra.
4. Doeleinden en rechtsgrond (GDPR)
We verwerken Amazon-gegevens alleen voor:
-
Uitvoering van de overeenkomst
-
Het ontvangen, verwerken en uitleveren van bestellingen die via Amazon zijn geplaatst.
-
Het aanmaken van pick- & pack-opdrachten in Picqer.
-
Het aanmaken en doorgeven van Track & Trace-gegevens.
-
-
Wettelijke verplichtingen
-
Fiscale bewaarplicht (bijv. facturen, boekhouding).
-
Mogelijke verplichtingen rondom garantie of productveiligheid.
-
-
Gerechtvaardigd belang
-
Beveiliging van onze systemen (logging, fraudedetectie, misbruikpreventie).
-
Beperkte statistiek/rapportage op geaggregeerd en geanonimiseerd niveau.
-
Wij gebruiken Amazon-gegevens niet voor:
-
Direct marketing buiten Amazon om
-
Verkoop of verhuur van data aan derden
-
Profiling op basis van gedrag buiten het fulfilmentproces
5. Herkomst van de gegevens
We krijgen Amazon-gegevens uitsluitend via:
-
Amazon Seller Central (handmatige inzage/download)
-
Amazon Selling Partner API (SP-API) via beveiligde API-calls
We halen geen Amazon-gegevens op via derde partijen, scrapers, “data brokers” of andere niet-officiële kanalen.
6. Delen en ontvangers (third parties)
We delen Amazon Information alleen wanneer dat nodig is voor fulfilment of technische afhandeling:
-
Brixxs B.V.
-
Integratiepartner voor de koppeling tussen Amazon en Picqer.
-
Verwerkt alleen de gegevens die nodig zijn om de integratie te bouwen en te draaien.
-
Met Brixxs hebben we een verwerkersovereenkomst (DPA).
-
-
Picqer
-
SaaS warehouse management systeem.
-
Ontvangt order-, product- en adresgegevens om bestellingen te picken, packen en verzenden.
-
Handelt als verwerker namens ons.
-
-
Vervoerders / logistieke partners
-
Ontvangen adresgegevens en contactgegevens voor de bezorging en Track & Trace.
-
-
IT- en hostingproviders
-
Hosting, backups, logging, beveiliging; toegang is strikt beperkt en contractueel vastgelegd.
-
We delen Amazon-gegevens niet met andere partijen. Amazon Information wordt nooit verkocht en niet gebruikt voor advertentiedoeleinden.
7. Bewaartermijnen
We hanteren de volgende termijnen:
-
PII uit Amazon-orders
-
Operationeel gebruik (fulfilment / klantenservice): zo kort mogelijk.
-
Maximale bewaartermijn voor PII in operationele systemen: maximaal 30 dagen na levering.
-
Daarna: verwijderen of anonimiseren, tenzij we het langer moeten bewaren op grond van een wettelijke verplichting (bijv. in financiële administratie, waar minder detail nodig is).
-
-
Customization / configuratiegegevens
-
Bewaren we zolang nodig is voor het kunnen reproduceren van de order en voor garantie/klachtenafhandeling, daarna waar mogelijk geanonimiseerd.
-
-
Log- en beveiligingsgegevens
-
Bewaartermijn: in principe 12 maanden, tenzij een incidentonderzoek of wettelijke verplichting een langere termijn vereist.
-
Wanneer wettelijke bewaartermijnen (bijv. 7 jaar voor boekhouding) gelden, zorgen we ervoor dat de data waar mogelijk geanonimiseerd is en niet direct tot een persoon herleidbaar.
8. Beveiligingsmaatregelen
We nemen technische en organisatorische maatregelen om Amazon-gegevens te beschermen tegen ongeautoriseerde toegang, verlies of misbruik.
Versleuteling
-
Alle communicatie met Amazon en Picqer verloopt via TLS (HTTPS).
-
Gevoelige data (zoals PII) wordt versleuteld opgeslagen (bijv. via database- of disk-encryptie, minimaal AES-256 of gelijkwaardig), inclusief back-ups.
Toegangsbeheer en authenticatie
-
Toegang tot systemen met Amazon-gegevens is beperkt tot medewerkers die dit nodig hebben voor hun functie (least privilege, role-based access).
-
Accounts zijn persoonlijk; geen gedeelde logins.
-
Voor beheerders- en productiesystemen wordt multi-factor authenticatie (MFA) gebruikt waar mogelijk.
-
Wachtwoordbeleid: sterke wachtwoorden (minimale lengte en complexiteit) en beleid tegen hergebruik.
Endpoint- en netwerkbeveiliging
-
Gebruik van up-to-date besturingssystemen en beveiligingsupdates.
-
Antivirus/EDR waar passend.
-
Firewall- en netwerksegmentatie: databronnen zijn niet rechtstreeks publiek bereikbaar.
Logging en monitoring
-
Belangrijke acties en API-calls worden gelogd.
-
We monitoren op opvallend gedrag (bijv. ongebruikelijke toegangspatronen) en onderzoeken verdachte events.
-
Logs zijn alleen toegankelijk voor geautoriseerde medewerkers.
Backups en herstel
-
Backups zijn versleuteld en worden periodiek getest op herstelbaarheid.
-
Toegang tot backups is beperkt en gelogd.
Secure development
-
Waar mogelijk wordt code gecontroleerd op kwetsbaarheden.
-
Productie- en testomgevingen worden gescheiden gehouden; testomgevingen gebruiken geen live PII.
9. Incident response
Ondanks alle maatregelen kan er nooit 100% zekerheid zijn. Daarom hebben wij een proces voor het omgaan met beveiligingsincidenten:
-
Detectie en melding – Via monitoring, meldingen van medewerkers of partners.
-
Beoordeling en afscherming – Snel inschatten van impact en het beperken van verdere schade (bijv. toegang intrekken, systemen isoleren).
-
Onderzoek – Analyseren wat er precies is gebeurd en welke gegevens mogelijk geraakt zijn.
-
Communicatie – Waar nodig informeren we betrokkenen, toezichthouders en – indien van toepassing – Amazon (via de voorgeschreven contactkanalen).
-
Herstel en voorkomen – Herstellen van systemen en doorvoeren van verbeteringen om herhaling te voorkomen.
-
Documentatie – Het incident en de acties worden vastgelegd.
10. Rechten van betrokkenen
Als Amazon-klant heeft u – voor zover van toepassing en voor zover wij daadwerkelijk verwerkingsverantwoordelijke zijn – de volgende rechten onder de AVG/GDPR:
-
Recht op inzage in uw persoonsgegevens
-
Recht op rectificatie
-
Recht op beperking of bezwaar tegen verwerking
-
Recht op gegevenswissing (voor zover dit niet in strijd is met wettelijke bewaarplichten)
-
Recht op dataportabiliteit
In de praktijk loopt veel communicatie over uw gegevens via Amazon als primair aanspreekpunt. Waar wij zelf verwerkingsverantwoordelijke zijn (bijv. in onze eigen administratie), kunt u contact opnemen via onderstaande gegevens.
11. Internationale doorgifte
Waar mogelijk worden Amazon-gegevens binnen de EU/EER opgeslagen en verwerkt.
Indien een subverwerker buiten de EER wordt gebruikt, zorgen we voor passende waarborgen (bijv. Standard Contractual Clauses) en een passend beschermingsniveau volgens de AVG.
12. Contact
Voor vragen over deze policy of over de verwerking van Amazon-gegevens kunt u contact opnemen met:
Veiligheids-Sloten.nl B.V.
E-mail: support@veiligheids-sloten.nl
Adres: Schulpplein 15, 3087 NA Rotterdam, Nederland
Amazon Data Privacy & Data Handling Policy
Veiligheids-Sloten.nl B.V. – Amazon Selling Partner API
Last updated: 25 November 2025
1. Introduction and scope
This page describes how Veiligheids-Sloten.nl B.V. (“we”, “us”) handle Amazon data that we process via the Amazon Selling Partner API (SP-API) and Amazon Seller Central. This policy supplements our general privacy policy and specifically covers the processing of Amazon Information as defined in the Amazon Data Protection Policy and Acceptable Use Policy.
This policy applies to:
-
Orders placed via Amazon
-
The integration between Amazon and our warehouse management system (Picqer)
-
All systems, processes and staff that have access to Amazon data
Our company details:
Veiligheids-Sloten.nl B.V.
Schulpplein 15
3087 NA Rotterdam
The Netherlands
2. Roles and responsibilities
-
With respect to Amazon, we act as a Selling Partner and process Amazon Information in accordance with Amazon’s policies.
-
With respect to end customers (Amazon buyers), we are in most cases a data controller under GDPR, because we fulfil and ship the order.
-
Our integration partner Brixxs B.V. and our SaaS providers (such as Picqer) act as data processors, processing data solely on our behalf and under our instructions.
We do not sell Amazon data and do not use Amazon data for profiling or marketing outside of Amazon.
3. What Amazon data do we process?
We limit ourselves to data that is necessary to correctly process orders and manage our operations.
3.1 Order and product data
-
Amazon Order ID
-
Order date and time
-
Order status (e.g. Unshipped, Shipped)
-
Products (ASIN, SKU, title, quantity, price)
-
Shipping method and service level
-
Totals, VAT information, shipping charges
3.2 Personally Identifiable Information (PII) for fulfilment
Only insofar as provided by Amazon and strictly necessary for delivery:
-
Recipient name
-
Shipping address (street, postal code, city, country, address lines)
-
Optional: phone number, email address (for delivery updates / carrier communication)
We use this information solely to:
-
Process and ship the order
-
Provide and track delivery (Track & Trace)
-
Handle customer service, returns and warranty
-
Comply with legal obligations (e.g. bookkeeping and tax)
3.3 Customization / configuration data (non-PII)
For products with custom options (e.g. cylinder size, knob option, number of keys), Amazon may provide a customization URL or JSON payload (BuyerCustomizedInfo/CustomizedURL). We use this only to:
-
Read the selected configuration
-
Map the configuration to our internal SKU structure in Picqer
-
Ensure we assemble and ship the exact configuration ordered
We treat this data as product configuration, not as PII, and only link it to the relevant order.
3.4 Technical and log data
For security and troubleshooting we also process:
-
Timestamps of API calls
-
Technical identifiers (request IDs, error codes)
-
Login and access logs (which account performed which action and when)
We avoid storing PII in logs wherever possible. If it is unavoidable, we minimise it and protect such logs accordingly.
4. Purposes and legal basis (GDPR)
We process Amazon data only for the following purposes:
-
Performance of a contract
-
Receiving, processing and fulfilling orders placed via Amazon
-
Creating pick & pack tasks in Picqer
-
Generating and providing Track & Trace information
-
-
Legal obligations
-
Complying with tax and accounting requirements (e.g. record retention for invoices)
-
Fulfilling obligations related to product safety, warranty and recalls
-
-
Legitimate interest
-
Securing our systems (logging, fraud detection, abuse prevention)
-
Limited statistics and reporting at an aggregated and anonymised level
-
We do not use Amazon data for:
-
Direct marketing outside of Amazon
-
Selling or renting data to third parties
-
Behavioural profiling unrelated to fulfilment and support
5. Source of the data
We obtain Amazon data exclusively from official Amazon channels:
-
Amazon Seller Central (manual viewing / downloads)
-
Amazon Selling Partner API (SP-API) via authenticated, encrypted API calls
We do not obtain Amazon data from any third-party brokers, scrapers or other unofficial sources.
6. Sharing and recipients (third parties)
We share Amazon Information only where necessary to fulfil orders or operate the integration:
-
Brixxs B.V.
-
Integration partner for the connection between Amazon and Picqer
-
Processes only the data required to build and run the integration
-
Bound by a data processing agreement (DPA)
-
-
Picqer
-
SaaS warehouse management system
-
Receives order, product and address data to pick, pack and ship orders
-
Acts as data processor on our behalf
-
-
Carriers / logistics partners
-
Receive address and contact details required for delivery and Track & Trace
-
-
IT and hosting providers
-
Provide infrastructure, backups, logging and security services
-
Access to data is strictly limited and governed by contractual and technical safeguards
-
Amazon data is not shared with any other parties. Amazon Information is never sold and not used for advertising networks or unrelated marketing purposes.
7. Retention periods
We apply the following retention rules:
-
PII from Amazon orders
-
Operational use (fulfilment / customer service): as short as possible
-
Maximum retention of PII in operational systems: no more than 30 days after delivery
-
After that: deletion or anonymisation, unless a longer retention is required by law (e.g. for accounting); in that case we keep only the minimum necessary information in a less identifiable form.
-
-
Customization / configuration data
-
Retained as long as reasonably necessary to reproduce the order configuration for warranty, complaints or audits, and then anonymised wherever possible.
-
-
Log and security data
-
Typically retained for 12 months, unless a longer period is required for incident investigation or legal reasons.
-
Where statutory retention requirements apply (e.g. 7-year retention for financial records), we ensure that stored information is reduced to what is strictly necessary and is not used as a general customer profile.
8. Security measures
We implement technical and organisational measures to protect Amazon data against unauthorised access, loss and misuse.
Encryption
-
All communication with Amazon and Picqer uses TLS (HTTPS).
-
Sensitive data, including PII and backups, is encrypted at rest (e.g. via database or disk encryption such as AES-256 or equivalent).
Access control and authentication
-
Access to systems containing Amazon data is restricted to staff who need it to perform their job (least privilege, role-based access control).
-
Accounts are personal; shared logins are not allowed.
-
For administrative and production access we use multi-factor authentication (MFA) wherever possible.
-
We enforce strong password policies and discourage reuse of passwords.
Endpoint and network security
-
Systems are kept up to date with security patches.
-
Appropriate endpoint protection (e.g. antivirus/EDR) is used where relevant.
-
Databases and internal services are not directly exposed to the public internet and are protected by firewalls and network segmentation.
Logging and monitoring
-
Key actions and API calls are logged.
-
We monitor for abnormal patterns (e.g. login anomalies, unusual traffic volumes or data access patterns) and investigate suspicious events.
-
Access to logs is restricted to authorised staff.
Backups and recovery
-
Backups are encrypted and periodically tested for successful restoration.
-
Access to backups is limited and logged.
Secure development practices
-
Where applicable, code is reviewed and scanned for vulnerabilities before deployment.
-
Production and test environments are separated; test environments do not use live PII.
9. Incident response
We maintain an incident response process for security and data protection incidents involving Amazon data:
-
Detection and reporting – Through monitoring tools, internal reports or partner notifications
-
Assessment and containment – Quickly assessing impact and taking measures to stop or limit further impact (e.g. revoking access, isolating systems)
-
Investigation – Analysing root cause, affected systems and data
-
Notification – Where required, informing affected parties, supervisory authorities and Amazon via the channels defined in their policies
-
Remediation and prevention – Restoring systems to a secure state and implementing improvements to prevent recurrence
-
Documentation – Recording the incident, decisions and corrective actions
10. Data subject rights
Where we act as data controller (e.g. in our own records), individuals may have rights under GDPR, including:
-
Right of access
-
Right to rectification
-
Right to erasure (where compatible with legal obligations)
-
Right to restriction or objection
-
Right to data portability
In many cases, Amazon remains the primary contact point for Amazon customers. Requests received by us will be handled in coordination with Amazon where applicable and in line with contractual and legal requirements.
11. International transfers
Where possible, we store and process Amazon data within the EU/EEA.
If a sub-processor outside the EEA is used, we ensure appropriate safeguards are in place (such as Standard Contractual Clauses) and that the level of protection meets GDPR requirements.
12. Contact
For questions about this policy or our handling of Amazon data, you can contact us at:
Veiligheids-Sloten.nl B.V.
Email: support@veiligheids-sloten.nl
Address: Schulpplein 15, 3087 NA Rotterdam, The Netherlands















