Amazon’s privacy policy
1.Personal data protection policy
This Personal Data Protection Policy shall apply to all Systems and/or Files containing Personal Data that are subject to Processing by DoMobility S.L. considered as responsible and/or in charge of the processing of Personal Data.
In the exercise of these responsibilities and in order to establish the general principles that should govern the processing of personal data DoMobility S.L. has approved this Policy for the protection of personal data.
1.1 Purpose
The purpose of the Personal Data Protection Policy is to ensure respect for the right to honor and privacy in the processing of personal data of all persons related to DoMobility S.L. and, in particular, compliance with the applicable legislation in this area in each of the countries in which the organization operates.
1.2 Scope of Application
This Personal Data Protection Policy shall apply to DoMobility, S.L., its administrators, managers and employees, as well as to all persons related to the companies belonging to it. Se aplica también específicamente al tratamiento de datos relacionados con el uso de la plataforma WaveMarket y servicios vinculados a Amazon.
Persons acting as representatives of DoMobility S.L. in companies and entities shall observe the provisions of this Personal Data Protection Policy and shall promote, as far as possible, the application of its principles in those companies and entities in which they represent DoMobility S.L.
In development of the provisions of this Personal Data Protection Policy, DoMoibility S.L., together with its Data Protection Officer, will develop an internal regulation for the global management of data protection, which will be implemented by the Security Manager and will be mandatory for all managers and employees of DoMobility S.L.
The Data Protection Officer shall be responsible for ensuring that the internal regulations, practices and procedures are in accordance with the applicable data protection regulations in each case and shall disseminate and inform of the developments and new regulations in this area.
The Security Manager shall be responsible for implementing in the information systems, those controls and computer developments appropriate to ensure compliance with internal regulations on global management of data protection and shall ensure that such developments are updated at all times to ensure compliance.
2. Principles of personal data processing
The principles governing the Personal Data Protection Policy are as follows:
a) General Principles:
DoMobility S.L. will scrupulously comply with the legislation on protection of personal data in each country.
In addition, it will ensure compliance with the principle of data quality, which means that personal data will only be collected and processed when they are adequate, relevant and not excessive in relation to the scope and purposes for which they are collected or processed, which must be specific and legitimate, except in cases where applicable law provides otherwise.
DoMobility S.L. will ensure that the personal data collected are truthful and accurate.
DoMobility S.L. will promote that the principles contained in this Policy for the protection of personal data are taken into account:
(i) en el diseño e implementación de todos los procedimientos establecidos por la misma organización,
(ii) en los productos y servicios ofrecidos por estas,
(iii) en todos los contratos y obligaciones que formalicen o asuman y
(iv) en la implantación de cuantos sistemas y plataformas permitan el acceso de empleados o terceros y/o la recogida o tratamiento de datos de carácter personal.
b) Principles Regarding the Collection and Processing of Data:
To the extent required by applicable law, in the processes of collection and processing of personal data of shareholders, employees, customers, visitors and suppliers, the Company shall provide express, precise and unequivocal information, at least, about the existence of such process, the identity of those responsible for data processing and the purpose of data collection in accordance with the applicable regulations and the Privacy Management System.
Where required by applicable law, the consent of the data subjects must be obtained prior to collecting or processing their data.
DoMobility S.L. will not collect or process personal data relating to ideology, religion, beliefs, racial or ethnic origin, or sexual orientation, unless the collection of such data is required by applicable law, in which case they will be collected and processed in accordance with the provisions of that law.
c) Principles on Security and Confidentiality Measures:
DoMobility S.L. will design, implement, execute and maintain all organizational and technical security measures necessary to ensure that the collection and processing of data is carried out in compliance with the legally required standards.
Unless otherwise provided by applicable law:
(i) los datos recabados y tratados por DoMobility S.L. deberán ser conservados con la máxima confidencialidad y secreto, no pudiendo ser utilizados para otros fines que los que justificaron y permitieron su recogida y sin que puedan ser comunicados o cedidos a terceros fuera de los casos permitidos por la legislación aplicable en cada caso, y
(ii) los datos deberán ser cancelados cuando hayan dejado de ser necesarios o pertinentes para las finalidades para las cuales fueron recabados.
d) Principles on Data Disclosure:
It is forbidden to purchase or obtain personal data from illegitimate sources or in those cases where such data have been collected or transferred in contravention of the law or where their legitimate origin is not sufficiently guaranteed.
e) Principles on the Contracting of Data Processors:
Prior to contracting any service provider that accesses personal data that are the responsibility of DoMobility S.L. as well as during the term of the contractual relationship, the entity itself will verify that the service provider meets the necessary guarantees and complies with the security measures required in each jurisdiction.
f) International Data Transfers:
Any processing of personal data subject to European Union law involving a transfer of data outside the European Economic Area must be carried out in strict compliance with the requirements of the applicable law in the jurisdiction of origin.
g) Principles on the Rights of Affected Parties:
DoMobility S.L. will allow those affected to exercise their rights of access, rectification, deletion, opposition, limitation of processing, data portability and not to be subject to automated individualized decisions, which are applicable in each jurisdiction, establishing for this purpose the internal procedures that are necessary and appropriate, which must meet at least the legal requirements applicable in each case.
3. Control and evaluation
a) Control
It is the responsibility of the Data Protection Officer to supervise the application of the provisions of this Policy for the protection of personal data by DoMobility S.L.
b) Evaluation
The Data Protection Officer will evaluate, at least once a year, the compliance and effectiveness of this Personal Data Protection Policy and will report the result to DoMobility S.L., or to the management to which it is attached at all times.
Annex I – Specific Processing of Amazon Data
1. Services Used: DoMobility S.L. uses information obtained from Amazon Selling Partner API (SP-API) solely for internal operational purposes. Data is processed exclusively in connection with services provided to the sellers themselves and is not used for any other commercial purpose.
2. Security and Confidentiality: All access to Amazon data is restricted through technical and organizational controls. Access is limited to authorized personnel who have been trained in security and confidentiality best practices. Access to data is conducted exclusively via VPN and with two-factor authentication (2FA).
3. Access Logging: DoMobility S.L. maintains access and activity logs on systems processing information originating from Amazon, in order to detect unauthorized access and mitigate risks.
4. Data Retention: Amazon data is retained for the time strictly necessary to provide the requested service. Daily backups are performed with a default retention policy of 3 days.
5. Data Erasure: PII associated with Amazon orders is automatically purged 27 days after order delivery, anonymizing database records. Encrypted backups are deleted on a rolling 30-day cycle.
6. International Transfers: No international transfers of Amazon data are carried out outside the European Economic Area (EEA).
7. Incident Notification: In the event of an incident affecting Amazon information, DoMobility S.L. will notify Amazon within a maximum of 24 hours via security@amazon.com, including all details necessary for assessment and follow-up.
8. Impact Assessments: DoMobility S.L. conducts periodic risk assessments and, where appropriate, Data Protection Impact Assessments (DPIAs) in relation to systems and services processing Amazon data.
9. Collected Data: DoMobility S.L. processes information obtained through Amazon SP-API. It distinguishes between operational catalog/order data and buyer Personally Identifiable Information (PII) (name, shipping address, phone number, and email address).
10. Use and Purpose: Amazon buyer PII is used exclusively for merchant-fulfilled order shipping execution and compliance with legal/tax obligations. Its use for marketing campaigns, promotions, re-targeting, or transfer to third parties is strictly prohibited.
The legal notice was last updated on 24/09/2026