Datazonia S.A.

Privacy Policy

Effective date: 24 August 2026 · Applies to the Datazonia platform and to datazonia.com

Read-only by design

Reporting software. Nothing else.

Datazonia is analytics, attribution and reporting software — by policy and by architecture.

  • Official APIs only. Datazonia reads campaign and clean-room reporting data exclusively through the official Amazon Ads API, with each advertiser's explicit authorization.
  • No campaign changes. The platform does not create, modify or delete campaigns, and never changes bids or budgets. There is no write path to your advertising accounts.
  • Your account data, only through official APIs. Advertiser account data enters Datazonia exclusively through the official Amazon APIs, under your explicit authorization. Independent market signals are built from publicly visible marketplace information only and never involve your accounts or credentials.
  • No credentials. We never ask for, store or proxy Amazon account passwords. Access is granted through Amazon's secure Login with Amazon (OAuth) consent flow and can be revoked by you at any time.

This Privacy Policy explains how Datazonia S.A. ("Datazonia", "we", "us") collects, uses, stores, protects, shares and deletes data — both on the Datazonia analytics platform (the "Platform") and on this website. Datazonia is a European company and processes data in accordance with the EU General Data Protection Regulation (GDPR) and with the Amazon Ads API Data Protection Policy.

1. Who we are

Datazonia S.A. provides a business-to-business (B2B), read-only analytics, multi-touch attribution and reporting platform for brands on Amazon: advertising measurement across Amazon Marketing Cloud (AMC), Amazon DSP and sponsored ads and, for authorizing selling partners, retail reporting through the Selling Partner API. Our corporate identifiers and registered office are published in the Legal notice. For all privacy and data-protection matters, contact developer@datazonia.com or stanislas.rieder@datazonia.com.

2. What data we process

2.1 Platform data (processed on behalf of our clients)

  • Advertising reporting data retrieved through the official Amazon Ads API with the advertiser's explicit authorization: campaign, ad-group and creative-level performance metrics for Amazon DSP and sponsored ads.
  • Amazon Marketing Cloud outputs: aggregated, pseudonymized results returned from Amazon's privacy-safe clean room. Queries are written to return aggregate measures only; no event-level or shopper-level record leaves the clean room. AMC data never contains directly identifying shopper information such as names, addresses or payment details, and Datazonia performs no re-identification of any kind.
  • Selling Partner API data retrieved through the official Selling Partner API with each selling partner's explicit authorization: catalog and listing content, pricing, inventory and sales analytics reports, including Brand Analytics search-terms and promotion-performance reports. Datazonia requests non-restricted roles only; no customer personally identifiable information is requested or processed.
  • Client-provided datasets a client chooses to bring to its own reporting (for example first-party campaign taxonomies), processed solely for that client.
  • Public marketplace signals: publicly visible marketplace information such as search-results composition, product content and share-of-shelf indicators, collected independently of any client account. These signals describe products and brands, contain no shopper personal data, and are combined with a client's account data only to produce that client's own reporting.

For Platform data, our client (the advertiser or selling partner) is the data controller and Datazonia acts as a data processor under Article 28 GDPR, on documented instructions and under a data processing agreement.

2.2 Account data

  • Business contact details of the client's authorized users: name, business e-mail address, role, and authentication identifiers. We never ask for, store or proxy Amazon account passwords; Platform access to Amazon data is granted exclusively through Amazon's Login with Amazon (OAuth) consent flow and is revocable by the client at any time.

2.3 Website data

  • This website sets no cookies, embeds no third-party trackers or analytics, and loads all resources — including fonts — from its own domain. If you e-mail us, we process the personal data contained in your message to answer you.

3. Why we process data (purposes and legal bases)

  • Providing the Platform — analytics, attribution and reporting for the contracting client (performance of contract, Art. 6(1)(b) GDPR; processor instructions for Platform data).
  • Securing our services — access control, threat detection, audit logging (legitimate interest, Art. 6(1)(f) GDPR).
  • Legal compliance — accounting, tax and regulatory obligations (Art. 6(1)(c) GDPR).
  • Answering enquiries — responding when you contact us (legitimate interest, Art. 6(1)(f) GDPR).

We do not sell data, rent data, or use one client's data for another client's benefit. We do not use client data to train machine-learning models, and we do not combine Amazon advertising data with data from other sources except at the documented instruction of the client that owns it.

4. How we protect data

Encryption everywhere. All client data is encrypted at rest using AES-256 and in transit via TLS 1.3 — between your browser and the Platform, between Platform services, and on every backup.

  • Tenant isolation. Each client's data is held in its own dedicated data-warehouse dataset, and raw storage is partitioned per client. Access is granted only to named service identities under IAM, and no client-facing query path exists that can return one client's data to another client.
  • EU cloud infrastructure, closed to the public internet. The Platform runs on secure Amazon Web Services and Google Cloud infrastructure located in the European Union: raw data lands in private AWS storage (account-level Block Public Access, bucket-owner-enforced object ownership with legacy ACLs disabled, and bucket policies that deny any non-HTTPS connection) and is warehoused and processed in private Google Cloud projects whose data stores are reachable only by named service identities under IAM and never from the public internet; the only public-facing component is the HTTPS Login with Amazon consent callback.
  • Least-privilege access. Production access is granted on a strict need-to-know basis through scoped IAM roles — no shared administrative credentials, no wildcard permissions on data stores.
  • Credential hygiene. Amazon Ads API developer credentials are stored in a managed secrets vault, are never embedded in client-side code, and are never shared with third parties.

5. How long we keep data

  • AMC query results, as retrieved from the clean room, are retained for a maximum of 30 days from retrieval. Once transformed into Datazonia's aggregated reporting, the retrieved results are deleted.
  • Aggregated reporting (which contains no event-level records) is retained for the duration of the client contract and in no case longer than 18 months, to provide period-over-period analysis.
  • Selling Partner API data (catalog, pricing, inventory, sales and Brand Analytics reporting) is retained for no longer than 18 months and is deleted on termination of the selling partner's authorization.
  • Upon termination of a client account, all of that client's data — raw and aggregated — is deleted immediately, and deletion is confirmed to the client. Encrypted backups roll off within the backup cycle and are never restored for any other purpose.
  • Account and billing records are kept only as long as required by applicable commercial and tax law.

6. Who we share data with

We use a deliberately short list of subprocessors: Amazon Web Services EMEA SARL (cloud infrastructure, raw-data landing and storage, EU region) and Google Cloud EMEA Limited (data warehousing, compute and credential storage for Platform data, EU region). We do not use advertising networks or third-party website analytics providers. We license public Amazon marketplace data from commercial data providers (Keepa, Jungle Scout); these providers receive no client data and no client identifiers. Subprocessors are bound by data processing agreements consistent with this policy, and we will update this section before adding any new subprocessor. Data may otherwise be disclosed only where the law requires it.

7. International transfers

Platform data is stored and processed in Amazon Web Services and Google Cloud regions located in the European Union. Where any transfer outside the EU/EEA ever becomes necessary, it will rely on an adequacy decision or on the European Commission's Standard Contractual Clauses, and this policy will be updated accordingly.

8. Your rights

Where we act as controller (for example for website enquiries and user account data), you may exercise the rights granted by Articles 15–22 GDPR: access, rectification, erasure, restriction, portability and objection. Write to developer@datazonia.com or stanislas.rieder@datazonia.com; we respond within one month. You also have the right to lodge a complaint with your supervisory authority. Where Datazonia acts as processor, we forward requests to the responsible client without undue delay and assist in fulfilling them.

9. Security incidents

We maintain an incident-response procedure. Where a personal-data breach is likely to result in a risk to individuals, we notify the competent supervisory authority within 72 hours as required by Article 33 GDPR, notify affected clients without undue delay, and — where Amazon advertising data is involved — notify Amazon in accordance with the Amazon Ads API Data Protection Policy.

10. Amazon API compliance and algorithmic transparency

Datazonia accesses advertiser and selling-partner account data exclusively through the official Amazon APIs (the Amazon Ads API and, where authorized, the Selling Partner API), under the applicable Amazon license agreements and the Amazon Ads Data Protection Policy, with each client's explicit Login with Amazon (OAuth) authorization. The Platform is read-only toward client accounts: it does not create, modify or delete campaigns, bids, budgets, listings or prices. Authorizations are revocable at any time and are refreshed through renewed consent at least every 365 days. Amazon data retrieved for a client is processed solely to provide that client's reporting; it is never sold, never shared with unassociated third parties, and never aggregated across clients to publish platform-wide intelligence about Amazon.

10.1 Algorithmic and AI transparency

The Platform computes derived metrics and scores from the data described in section 2: for example share-of-voice and share-of-shelf indicators, visibility and conversion scores, attribution and incrementality models, and a composite 360° scorecard. Where machine-assisted classification is used (for example matching products to brands), classifications follow deterministic rules first, with model assistance, and remain reviewable by the client. Reporting data freshness is documented per module inside the Platform. Client data is not used to train machine-learning models.

11. Changes to this policy

We will update this page when our practices change and revise the effective date above. Material changes affecting Platform clients are announced to them directly.

12. Contact

DATAZONIA S.A., Compliance & Data Protection
69, Avenue de la Faïencerie, L-1510 Luxembourg, Grand Duchy of Luxembourg
developer@datazonia.com · stanislas.rieder@datazonia.com · +352 691 641 844
R.C.S. Luxembourg B311077 · Full identifiers: see the Legal notice.