ComplyShelf
Bulk GPSR fix Flat file checker GPSR guide
Menu
Bulk GPSR fix Flat file checker GPSR guide
Sign in Start now

Draft for legal review

Privacy Policy

How ComplyShelf handles account, workspace, product-compliance, and website data.

Draft date
18 July 2026
Draft version
2026-09-07
Not approved for production. This draft matches the version prepared for registration, but public registration must remain closed until the business address, VAT details, processor terms, vendor disclosures, and legal review are complete.

This Privacy Policy explains how ComplyShelf collects, uses, shares, stores, and protects personal data when you visit our website, create or use an account, communicate with us, or use the ComplyShelf service.

ComplyShelf is operated by Denys Holda, trading under the ComplyShelf brand, an individual business established in Italy, registered with the Business Register held by the Camera di Commercio Monte Rosa Laghi Alto Piemonte under REA BI-325108, VAT number to be confirmed before publication, with registered address at to be confirmed before publication.

For personal data that we process for our own purposes, the data controller is:

Denys Holda, trading as ComplyShelf
Address: to be confirmed before publication
Privacy contact: hello@complyshelf.com
PEC: not yet designated for publication

1. Scope and our data-protection roles

This Policy applies to:

  • public ComplyShelf websites and marketing pages;
  • the ComplyShelf web application and user accounts;
  • registration, email verification, login, password recovery, and profile functions;
  • customer workspaces;
  • imports, reports, exports, hosted documents, product-safety pages, and QR codes;
  • support, security, and service communications; and
  • any integration that expressly refers to this Policy.

Our role depends on the data and purpose.

1.1 ComplyShelf as controller

We act as controller when we decide why and how to process data for purposes such as account administration, authentication, security, legal-document acceptance, customer support, service operations, billing if introduced, product communications, and compliance with our legal obligations.

1.2 ComplyShelf as processor

Customers may upload or create files and records containing personal data, for example names and business contact details of manufacturers, suppliers, importers, EU Responsible Persons, authorised representatives, employees, or other contacts.

When we process such personal data solely to provide the Service on a Customer’s instructions, the Customer is generally the controller and ComplyShelf acts as processor. In that situation, the Customer is responsible for the lawfulness of the data and instructions, and the processing must be governed by an applicable Data Processing Addendum before production-scale processing. Contact hello@complyshelf.com for the current status.

This Privacy Policy primarily describes the processing for which ComplyShelf acts as controller. Individuals whose data appears only in Customer Content should normally direct requests to the relevant Customer. We will assist that Customer as required by applicable law and the Data Processing Addendum.

2. Personal data we collect

The data we collect depends on how you use the Service.

2.1 Account and profile data

We may collect:

  • full name;
  • work email address;
  • company or workspace name;
  • password hash, but never your plaintext password;
  • email-verification status and timestamps;
  • profile and account preferences;
  • workspace membership, role, and permissions;
  • account creation, login, and update timestamps; and
  • pending email-change information where relevant.

2.2 Legal and consent records

When you register or accept updated documents, we may record:

  • the document type and version accepted;
  • date and time of acceptance;
  • user and workspace identifiers;
  • IP address;
  • browser or user-agent information; and
  • evidence needed to demonstrate the acceptance.

Where non-essential cookies or optional communications require consent, we may also record your choices and changes to those choices.

2.3 Customer workspace and product-compliance data

Depending on the features you use, the Service may process:

  • product names, descriptions, brands, SKUs, ASINs, GTINs, listing status, marketplace, and other catalogue data;
  • imported Amazon reports, spreadsheets, templates, processing reports, and raw or normalised rows;
  • manufacturer, importer, distributor, supplier, and EU Responsible Person information;
  • names, business addresses, countries, email addresses, telephone numbers, websites, and other organisation contact details;
  • declarations, certificates, test reports, manuals, safety warnings, mandates, risk documents, images, labels, and other evidence;
  • file names, file types, sizes, checksums, storage identifiers, versions, and assignment metadata;
  • marketplace error codes, messages, submission status, notes, and remediation history;
  • generated reports, helper files, export batches, hosted links, safety pages, and QR codes; and
  • audit and activity records relating to workspace actions.

Some of this information may be personal data even where it relates to a business contact.

2.4 Public page and hosted-link data

When a Customer publishes a product-safety page or hosted document, we process the information selected for publication and an opaque link token. Public pages may display business contact information for economic operators and links to safety documents.

When someone visits a public page, we may receive ordinary web request data such as IP address, request time, browser information, requested URL, and security logs. We do not require an account for public safety pages.

2.5 Technical, device, and usage data

We may collect:

  • IP address;
  • browser type, device type, operating system, and language;
  • date and time of requests;
  • pages, routes, and features used;
  • session identifiers and authentication events;
  • cookie and CSRF-token information;
  • referring URL where provided by the browser;
  • application, queue, import, export, and error logs;
  • rate-limit, abuse-prevention, and security events; and
  • diagnostic information needed to maintain the Service.

We aim to avoid placing Customer Content or sensitive document contents in telemetry and routine logs.

2.6 Communications and support data

If you contact us, we may process your name, email address, organisation, message, attachments, support history, and any information needed to respond.

We also process delivery and interaction data for transactional emails such as verification and password-reset messages, to the extent provided by our email service provider.

2.7 Payment and transaction data

If paid features are introduced, we may process billing name, business address, VAT details, plan, invoices, payment status, and transaction references. Payment-card details should be processed directly by the selected payment provider and not stored by ComplyShelf, except for limited tokens or references needed to manage billing.

2.8 Data from integrations and third parties

If you enable a supported integration, we may receive account identifiers, marketplace information, listing data, authorisation metadata, and other information made available through that integration.

We process integration data only after you enable or request the integration and subject to the third party’s terms and permissions. ComplyShelf does not currently require you to provide ordinary account passwords for Amazon or other marketplaces.

3. How we obtain personal data

We obtain personal data:

  • directly from you during registration, account use, uploads, forms, and communications;
  • from other authorised users in your workspace;
  • from files and records uploaded by or for the Customer;
  • from public-page visitors and ordinary server requests;
  • from supported third-party services when an authorised integration is enabled; and
  • from publicly available business sources where necessary to verify or complete our own business records, subject to applicable law.

4. Why we process data and our legal bases

We process personal data only where we have a valid legal basis.

4.1 Providing and administering the Service

Purposes: create accounts and workspaces; verify email addresses; authenticate users; provide imports, records, reports, exports, hosting, public pages, support, and requested features; manage plans and billing if introduced.

Legal basis: performance of a contract or steps taken at your request before entering into a contract; where the account represents an organisation, our legitimate interest in performing the contract with that organisation and administering authorised users.

4.2 Security, fraud prevention, and service integrity

Purposes: protect accounts and workspaces; enforce tenant isolation; detect abuse; investigate incidents; maintain logs; rate limit requests; prevent malicious uploads; secure public links; and protect legal rights.

Legal basis: our legitimate interests in operating a secure and reliable B2B service, protecting customers and third parties, and establishing or defending legal claims; compliance with legal obligations where applicable.

4.3 Transactional communications

Purposes: send verification, password-reset, security, service, account, and material-policy notices; respond to support requests.

Legal basis: performance of the contract, legitimate interests in administering the Service, and legal obligations where applicable.

4.4 Legal-document acceptance and compliance records

Purposes: record acceptance of Terms and Privacy versions; keep evidence of the agreement; respond to legal requests; comply with accounting, tax, business, and data-protection duties.

Legal basis: performance of the contract, compliance with legal obligations, and legitimate interests in documenting and enforcing agreements.

4.5 Product improvement and diagnostics

Purposes: understand whether features work, diagnose failures, improve usability, measure service reliability, and plan capacity.

Legal basis: our legitimate interests, provided the processing is necessary and proportionate. Where device storage or access, cross-site tracking, profiling, or non-essential analytics require consent, we rely on consent and do not activate them before consent.

4.6 Marketing communications

Purposes: send requested updates, product news, or offers.

Legal basis: consent where required; in limited B2B contexts, legitimate interests may apply where permitted by law and with a clear right to object. Transactional messages are not marketing.

You may unsubscribe from marketing at any time. We may retain a minimal suppression record to respect the opt-out.

4.7 Public safety pages and document links

Purposes: publish information selected by the Customer and serve the requested public content.

Legal basis: performance of the contract and our legitimate interests in providing the publishing feature. The Customer is responsible for the lawful basis and accuracy of personal data it chooses to publish.

4.8 Legal claims and regulatory requests

Purposes: comply with binding requests, audits, legal duties, and court orders; establish, exercise, or defend legal claims.

Legal basis: legal obligation and legitimate interests in protecting our rights and the rights of others.

5. Cookies and similar technologies

ComplyShelf uses cookies or similar browser storage that are strictly necessary to provide and secure the website and application. These may include:

  • session cookies that keep you signed in;
  • security and CSRF-protection cookies or tokens;
  • load-balancing, rate-limit, or infrastructure cookies where necessary; and
  • preference cookies needed to remember a setting you requested.

Strictly necessary technologies do not require consent where they are used only to transmit communications or provide a service explicitly requested by the user, but we still describe them transparently.

At the date of this Policy, ComplyShelf intends to use only strictly necessary cookies unless the cookie settings or banner state otherwise.

If we introduce non-essential analytics, advertising, profiling, or third-party tracking, we will update this Policy and, where required, obtain prior consent. Non-essential technologies will remain disabled until a valid choice is made. You will be able to refuse or withdraw consent as easily as you gave it.

Browser settings may let you delete or block cookies, but blocking necessary cookies can prevent login or other requested functions.

6. When we share personal data

We do not sell personal data.

We may share personal data with the following categories of recipients only as necessary:

  • hosting and infrastructure providers that host the application, databases, backups, networks, or object storage;
  • email delivery providers that send verification, password-reset, service, and support messages;
  • security, monitoring, logging, and error-diagnostic providers used to protect and maintain the Service;
  • payment and billing providers if paid plans are introduced;
  • support and communication providers used to manage requests;
  • professional advisers, including lawyers, accountants, auditors, and insurers;
  • authorities, courts, or other recipients where disclosure is legally required or necessary to protect rights and safety; and
  • a buyer, investor, or successor in connection with a genuine corporate transaction, subject to appropriate confidentiality and data-protection safeguards.

Service providers that process personal data for us must be bound by appropriate contractual and confidentiality obligations.

A current list of subprocessors used for Customer Content will be published before production-scale processing. Contact hello@complyshelf.com for the current status. Where required by the Data Processing Addendum, Customers will be informed of relevant changes and may exercise the rights stated there.

7. International data transfers

We aim to use providers and data locations in the European Economic Area where reasonably possible. Some providers or their support personnel may process data outside the EEA.

Where personal data is transferred to a country that has not received an adequacy decision, we use an appropriate transfer mechanism, such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where required. We may also rely on another lawful mechanism available under Chapter V of the GDPR.

Details relevant to Customer Content will be included in the Data Processing Addendum or subprocessor information. You may contact hello@complyshelf.com for information about applicable safeguards.

8. Data retention

We retain personal data only for as long as necessary for the purposes described above, including providing the Service, maintaining security, resolving disputes, and meeting legal obligations.

Unless a longer period is required by law or justified by a specific dispute, incident, or instruction, the intended baseline periods are:

  • account, profile, and workspace administration data: while the account is active and for up to 90 days after closure;
  • Customer Content, imported files, product records, exports, and active hosted assets: while the account is active and for up to 90 days after closure or a valid deletion request;
  • backup copies: isolated and overwritten or deleted according to the backup cycle, normally within a further 90 days;
  • authentication, application, and security logs: normally up to 12 months, or longer where needed to investigate an incident or protect legal rights;
  • support communications: normally for 24 months after the issue is closed, unless needed for the account relationship or a legal claim;
  • legal acceptances, contract evidence, invoices, and tax or accounting records: for the period required by applicable law, which may be up to 10 years in Italy;
  • marketing records: until consent is withdrawn, an objection is received, or the contact has been inactive for 24 months, with a minimal suppression record retained as needed to honour the opt-out; and
  • public safety pages and document links: until the Customer unpublishes or revokes them, the account closes, or they are removed under the Service rules, subject to temporary caching and copies made by third parties.

Deletion from active systems may not immediately remove data from immutable backups. Backup data is protected, not used for ordinary business purposes, and removed through the normal backup lifecycle.

We may retain de-identified or aggregated information that no longer identifies an individual.

9. Security

We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, and disclosure. Depending on the risk and feature, these measures may include:

  • account authentication, and email verification when an address is changed;
  • password hashing;
  • server-side workspace authorisation and tenant isolation;
  • encryption in transit;
  • restricted administrative access;
  • private file storage by default;
  • opaque and revocable public-link tokens;
  • logging, rate limiting, and abuse prevention;
  • backups and recovery procedures;
  • dependency and security maintenance; and
  • contractual controls for service providers.

No internet service is completely secure. You are responsible for protecting your credentials, choosing what to upload, and deciding what to publish through public links.

Please report suspected security issues to hello@complyshelf.com.

10. Your data-protection rights

Subject to applicable law and the circumstances of the processing, you may have the right to:

  • obtain confirmation whether we process your personal data and access a copy;
  • correct inaccurate or incomplete data;
  • request deletion;
  • request restriction of processing;
  • object to processing based on legitimate interests or to direct marketing;
  • receive certain data in a structured, commonly used, machine-readable format and transmit it to another controller;
  • withdraw consent at any time, without affecting processing already carried out lawfully; and
  • lodge a complaint with a supervisory authority.

To exercise a right concerning data for which ComplyShelf is controller, contact hello@complyshelf.com. We may ask for information needed to verify your identity and protect the account.

We normally respond without undue delay and within one month. The period may be extended by up to two additional months where permitted because of complexity or the number of requests; if so, we will explain the extension within the initial month.

Rights are not absolute. For example, we may retain data required by law, needed to establish or defend claims, or necessary to protect the rights of others.

Data contained in a Customer workspace

If your data was uploaded by a ComplyShelf Customer and we process it only on that Customer’s behalf, please contact that Customer first. If you contact us, we may forward the request to the Customer or ask for information that identifies the relevant workspace, and we will assist the Customer as required.

11. Right to complain

If you believe our processing infringes data-protection law, you may lodge a complaint with the supervisory authority in the country of your habitual residence, workplace, or the place of the alleged infringement.

Our lead supervisory authority in Italy is:

Garante per la protezione dei dati personali
Piazza Venezia 11
00187 Rome, Italy

We encourage you to contact us first at hello@complyshelf.com so that we can try to address the issue.

12. Automated decision-making and AI-assisted features

ComplyShelf does not use account or workspace data to make solely automated decisions that produce legal effects or similarly significant effects on individuals.

The Service may use deterministic rules or, in future, optional AI-assisted functions to suggest mappings, classifications, explanations, or draft text. Such outputs are assistive and must be reviewed by the Customer. They do not constitute a legal decision, compliance certification, or marketplace decision.

If we introduce processing that falls within Article 22 GDPR, we will provide the required information and safeguards before using it.

13. Children

The Service is intended for business and professional users and is not directed to children. You must be at least 18 years old to create an account.

If we learn that a child has provided personal data contrary to this Policy, we will take appropriate steps to delete it.

14. Links and third-party services

Our website or Customer public pages may link to Amazon, service providers, manufacturer sites, documents, or other third-party resources. Those third parties process data under their own policies. We are not responsible for third-party privacy practices.

15. Changes to this Policy

We may update this Policy to reflect changes in the Service, vendors, law, or our processing practices. The current version and effective date will always be shown at the top.

For material changes, we will provide reasonable notice through the Service, by email, or on the website where appropriate. We may ask registered users to accept a new version where the change affects the account agreement or processing.

16. Contact

For privacy questions or requests:

Controller: Denys Holda, trading as ComplyShelf
Address: to be confirmed before publication
Privacy email: hello@complyshelf.com
PEC: not yet designated for publication

We have not appointed a Data Protection Officer unless this section is later updated to identify one.

On this page

  1. Scope and roles
  2. Data we collect
  3. Purposes and legal bases
  4. Cookies
  5. Data sharing
  6. Retention
  7. Your rights
  8. Contact
Terms of Service Privacy Policy Contact ComplyShelf
ComplyShelf
Home Bulk GPSR fix Flat file checker GPSR guide Which file to upload Inactive listings Upload errors Terms Privacy Sign in

ComplyShelf is an operational tool that helps Amazon EU sellers organise product data, documents, and bulk remediation work. It is not a law firm, does not provide legal advice, is not an EU Responsible Person service, and does not guarantee that any product or listing is legally compliant with the GPSR or any other regulation. The seller remains responsible for the accuracy of the data they submit to Amazon. Regulatory dates and requirements are provided as context only and may change.