Privacy policy
Last updated: 2 August 2026
1. Data controller
- Controller: Pilot Partners S.L.
- Tax ID (CIF): B88929195
- Address: Calle Finestrelles 35, Staircase A, Floor 1, Door 2, 08950 Esplugues de Llobregat, Barcelona, Spain
- Data protection contact email: hello@pilot-partners.com
You can write to that address with any question about how we process your personal data or to exercise your rights.
2. Scope
This policy applies to the personal data we process through:
- This website, including the contact form.
- The client tool platform.
- Our contractual relationship with clients and suppliers.
It does not apply to third-party sites we link to, which are governed by their own policies.
3. Our dual role: controller and processor
It is important to distinguish two very different situations, because the obligations and rights differ in each.
We act as controller for the data of people who contact us, of our clients and of platform users — that is, when we decide why and how that data is processed.
We act as processor for the data we access inside a client’s Amazon account in order to deliver the service. In that case the client is the controller and we process the data solely on their behalf and following their instructions, under the data processing agreement required by article 28 GDPR.
Amazon-specific clause: when we provide services to Amazon sellers, we access seller data through the Amazon Selling Partner API (SP-API) solely on their behalf and under their instructions, in accordance with the Amazon Data Protection Policy and the applicable Acceptable Use Terms. We do not share data between clients, we do not use it for our own purposes beyond delivering the service, and we do not disclose it to unauthorised third parties.
4. Data we process
A. Our own data, where we are the controller
- *Lead contact data*: name, email, brand or company, and the content of the message you send through the form.
- *Client data*: identifying and billing details, contact person, and correspondence arising from the relationship.
- *Platform account data*: user identifier, email and credentials managed by our authentication provider. We do not store passwords in plain text.
- *Technical connection data*: IP address, browser type and server logs, processed to serve the site and protect it against abuse.
B. Data in the client’s Amazon account, where we act as processor
Through SP-API we access, according to the permissions the client authorises, business information such as orders, sales, inventory, catalogue, advertising metrics and reviews.
When the client contracts functionality that requires it —FBM shipping management, connection with their invoicing system, or post-purchase communication with buyers— we additionally access personal data of end buyers, limited to what is strictly necessary for that functionality: name, shipping or billing address, and the messaging channels Amazon makes available to the selling partner.
That access is subject to the following safeguards:
- It is carried out through Amazon Restricted Data Tokens, short-lived and scoped to the specific operation.
- The data is stored encrypted with AES-256 and segregated from the rest of the business information.
- It is automatically deleted within a maximum of 30 days from order delivery, save for any legal retention obligation falling on the selling partner itself.
- It is excluded from application logs and every access is audited.
- It is never sent to our artificial intelligence providers.
- It is not used to contact buyers on our own initiative, but solely on behalf of the selling partner and through the channels and templates Amazon authorises.
We do not process special categories of data under article 9 GDPR.
5. Purposes and legal bases
Each processing activity relies on a legal basis under article 6 GDPR:
| Purpose | Legal basis |
|---|---|
| Answering your enquiry sent through the form | Consent (art. 6(1)(a)), given when you submit it |
| Delivering the contracted services and managing the relationship | Performance of a contract (art. 6(1)(b)) |
| Issuing invoices and meeting accounting and tax obligations | Legal obligation (art. 6(1)(c)) |
| Providing access and support on the tool platform | Performance of a contract (art. 6(1)(b)) |
| Keeping the site secure and preventing abuse | Legitimate interest (art. 6(1)(f)) |
| Sending commercial communications about our services to existing clients | Legitimate interest (art. 6(1)(f)), with the right to object at any time |
We do not make automated decisions with legal effects on you, nor do we carry out profiling for that purpose.
6. Recipients and sub-processors
We do not sell personal data and we do not disclose it to third parties for advertising purposes. To operate we rely on providers acting as processors or sub-processors, all bound by contract under article 28 GDPR:
Infrastructure and website
- Vercel Inc. — hosting of the website and the platform.
- Make.com (Celonis SE) — contact form automation.
Tool platform
- Clerk Inc. — authentication and user management.
- Supabase Inc. — application database.
- Google Cloud Platform (Google Ireland Ltd.) — BigQuery, Cloud Storage, Vertex AI and Google Drive.
- Amazon Services Europe — data access via the Selling Partner API.
AI processing and market data
- Vercel AI Gateway, OpenAI Ireland Ltd. and fal.ai — text and image generation for listing content.
- Apify Technologies s.r.o., Rainforest API and Keepa GmbH — collection of public product and review data.
These providers process product and listing content only. They never receive buyer personal data obtained via SP-API.
Invoicing
- Holded (Grupo Holded S.L.) — connection with the client’s invoicing system for issuing invoices for Amazon orders.
Internal communication
- Slack Technologies — internal operational notifications.
We may also disclose data to legal and tax advisers, banks and public authorities where legally required.
7. International transfers
Some of the providers above are established outside the European Economic Area or may process data on servers located in the United States, including Vercel, OpenAI, fal.ai, Slack and certain Google Cloud services.
In those cases the transfer relies on one of the safeguards in Chapter V GDPR:
- The European Commission’s adequacy decision for entities certified under the EU–US Data Privacy Framework, where the provider is certified.
- Standard Contractual Clauses (SCC) approved by the European Commission, supplemented where appropriate with additional technical and organisational measures following a transfer impact assessment.
You can ask us about the safeguards applying to a specific provider by writing to hello@pilot-partners.com.
8. Retention periods
| Data | Period |
|---|---|
| Lead enquiries that do not become clients | 1 year from last contact |
| Client data and contractual correspondence | For the duration of the contract |
| Accounting records and invoices | 6 years from the end of the financial year (art. 30, Spanish Commercial Code) |
| Tax-relevant data | 4 years (art. 66, Spanish General Tax Law) |
| Business data obtained via Amazon SP-API | Deleted within 30 days of the end of the contract, as set out in the service agreement |
| Buyer personal data obtained via SP-API | Automatically deleted within a maximum of 30 days from delivery of the order, save for any retention obligation incumbent on the seller |
| Technical server logs | Short periods defined by the hosting provider |
Once those periods elapse, data is deleted or irreversibly anonymised.
9. Data security
We apply technical and organisational measures appropriate to the risk, including: encryption in transit via TLS, encryption at rest on services that support it, role-based access control on a least-privilege basis, authentication for administrative access, and activity logging.
Buyer personal data accessed via SP-API is subject to reinforced measures: access via Restricted Data Tokens, encryption at rest with AES-256, segregation from other business information, exclusion from application logs, and auditing of all access. Section 4.B sets out the detail.
Amazon SP-API access tokens are stored encrypted and are revoked immediately at the client’s request or when the contract ends, and are deleted within a maximum of 24 hours.
If a security breach occurs that poses a risk to your rights, we will notify the supervisory authority within 72 hours and the affected individuals where GDPR requires it.
10. Your rights
You may exercise the following rights at any time:
- Access: find out what data we process about you and obtain a copy.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion when the data is no longer necessary.
- Objection: object to processing based on our legitimate interest, including commercial communications.
- Restriction: ask us to restrict processing while a claim is resolved.
- Portability: receive your data in a structured, commonly used format.
- Withdrawal of consent: where processing is based on consent, without affecting the lawfulness of prior processing.
How to exercise them: write to hello@pilot-partners.com stating the right you are exercising. We will reply within one month, extendable by a further two months in complex cases, informing you of the extension.
If your data sits inside the Amazon account of one of our clients, we act as processor: in that case address your request to the seller acting as controller, and we will assist them in handling it.
Complaint to the supervisory authority: if you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid — www.aepd.es.
California residents (CCPA/CPRA): you have the right to know what personal information we collect, to request its deletion and to opt out of its sale. We do not sell personal information.
12. Children’s privacy
Our services are aimed exclusively at professionals and businesses. They are not intended for minors and we do not knowingly collect data from children under 14. If we find that we have received a child’s data, we will delete it.
13. Changes to this policy
We may update this policy to reflect legal, technical or organisational changes. The last updated date appears at the top. If a change materially affects how we process your data, we will inform you by an appropriate means before it takes effect.