ANNAPURNA PUBLISHING

Annapurna Publishing · Legal

Amazon Information & Data Protection Policy

Ultimo aggiornamento: 23 August 2026

This policy describes how ANNAPURNA SRLS, trading as Annapurna Publishing, collects, processes, stores, uses, shares and disposes of Amazon Information obtained through the Amazon Selling Partner API ("SP-API"). It applies to our private, self-authorized applications, including Annapurna Invoicing, used solely to operate our own Amazon Seller Central accounts. We do not provide Amazon Information services to third-party sellers.

1. Organization and responsibility

The organization responsible for this processing is ANNAPURNA SRLS, Via Lago Maggiore 6, 36077 Altavilla Vicentina (VI), Italia, VAT and Tax ID 04366730242, REA VI-398767. Access to Amazon Information is governed by Amazon's applicable agreements, Acceptable Use Policy and Data Protection Policy, as well as applicable privacy, accounting and tax law.

2. Amazon Information we process

Depending on the authorized SP-API roles and the transaction, we may process order, shipment, fulfilment, return, refund and transaction identifiers; buyer or business-customer name and contact details; billing and shipping information; tax and electronic-invoicing identifiers; marketplace, SKU, ASIN, quantity, price, VAT and currency data; invoice and credit-note data; processing status; and security or technical audit events.

We collect only the fields required for the approved purpose. We do not use Amazon Information to build advertising profiles, perform marketing, sell data or enrich unrelated databases.

3. Purposes and permitted use

Amazon Information is used only to:

  • retrieve and reconcile Amazon sales, shipments, returns and refunds;
  • generate, validate and archive invoices, credit notes and related tax records;
  • transmit required documents to Amazon and, where legally required, to competent tax or electronic-invoicing systems;
  • support Amazon fulfilment and Multi-Channel Fulfilment operations for our own orders;
  • investigate processing errors, prevent abuse, maintain security and provide internal operational support; and
  • comply with binding legal, accounting and tax obligations.

4. Data minimization, retention and disposal

Raw SP-API reports and operational copies containing personally identifiable information are deleted or irreversibly anonymized within 30 days after successful processing, unless temporarily required to resolve a documented error, security incident or legal hold.

Invoices, credit notes and the data forming part of statutory fiscal records are retained for the period required by applicable law, normally up to 10 years in Italy. This longer retention applies only to the legally required record, not to unrestricted reuse of raw Amazon data. Security and access audit logs are retained for at least 12 months and are designed to avoid or redact unnecessary PII. Backups inherit the applicable retention schedule and expire through managed lifecycle rules. At the end of the applicable period, data is securely deleted or anonymized.

5. Storage, encryption and key management

Amazon Information is processed only on approved systems. Data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256, or an equivalent or stronger industry-standard control. Encryption keys are managed separately through a managed key management system with restricted access, logging and rotation. Passwords, SP-API credentials, refresh tokens and cryptographic secrets are kept in an approved secrets-management system and are never hard-coded in source code or committed to repositories.

Production databases, file stores and administrative services are not exposed directly to the public internet. Public traffic is limited to the endpoints necessary to operate the application and is protected by network controls such as firewalls, web-application filtering, rate limits and restricted security groups.

6. Access control and workforce security

Every authorized person is identified through an individual account. Access is granted according to least privilege, role and documented need to know, protected by multi-factor authentication and reviewed regularly. Shared accounts are prohibited. Access is revoked promptly when responsibilities change or employment ends.

Amazon Information may be accessed only from approved, managed and security-maintained devices. Copying it to personal devices, removable media, personal email, consumer storage or unauthorized messaging services is prohibited. Security controls and audit logs are used to detect and alert on unauthorized access or transfer attempts.

7. Secure development and change management

Development, test and production environments are separated. Production PII is not used for routine testing; synthetic or irreversibly anonymized data is used instead. Application and infrastructure changes follow a documented process covering authorization, peer review, testing, verification and production approval. The people able to approve and deploy changes are limited by role.

Source code, dependencies and secrets are scanned before each release. Systems handling Amazon Information undergo vulnerability scanning at least every 30 days and independent penetration testing at least annually. Findings are tracked to closure, with critical findings remediated within 7 days and high-severity findings within 30 days, or faster where required by Amazon policy.

8. Logging, monitoring and resilience

Access, administrative actions, authentication events, data exports, application errors and relevant security events are recorded in tamper-resistant audit logs. Automated monitoring identifies suspicious activity and generates alerts for investigation. Security logs are reviewed at least biweekly and retained for a minimum of 12 months.

Encrypted backups are access-controlled, lifecycle-managed and held in geographically separate approved locations where appropriate. Restoration procedures are documented and tested. Recovery objectives are defined according to the service's operational and legal requirements.

9. Sharing and service providers

We do not sell, rent, license or disclose Amazon Information for advertising or unrelated commercial purposes. Information is shared only when necessary with Amazon, competent authorities and electronic-invoicing or tax systems, or with approved infrastructure, security and processing providers acting under written obligations of confidentiality, data protection and limited purpose.

Providers receive only the minimum access required. They are reviewed before use and monitored according to risk. We maintain records of processing and approved providers and update Amazon as required before material changes. Processing is kept in the European Union or European Economic Area where practicable; any permitted transfer outside it is protected by an applicable adequacy decision, standard contractual clauses or another lawful safeguard.

10. Security incidents

Annapurna Publishing maintains a documented incident-response plan covering unauthorized access, credential compromise, database intrusion, data loss and accidental disclosure. The process includes containment, credential and key rotation, evidence preservation, scope assessment, recovery, corrective action and a post-incident review. Incidents involving Amazon Information are escalated to the incident contact and reported to Amazon through the current channel and within the timeframe required by the Amazon Data Protection Policy, including within 24 hours where applicable. Competent authorities and affected individuals are notified when required by law.

11. Data-subject requests

Requests for access, correction, restriction, objection or deletion may be sent to info@annapurnapublishing.site. Requests are assessed under applicable law. Data that must remain in statutory invoices or accounting records cannot be deleted before the mandatory retention period expires, but access and use remain restricted to the legal purpose.

12. Contact and policy changes

Privacy and incident-management point of contact: Matteo Attianese info@annapurnapublishing.site.

This policy is reviewed periodically and whenever the application, authorized SP-API roles, providers or applicable requirements change. The current version and effective date are always published at this URL.


Version 1.0. Effective 23 August 2026.