Privacy policy

Last updated: 3 September 2026

This policy explains how [COMPANY NAME], [ADDRESS], VAT [VAT NUMBER] ("Kandyo", "we") processes personal data when you visit kandyo.com and when you use the Kandyo and Kandyo Ads applications (the "Services"). Kandyo is the data controller under Regulation (EU) 2016/679 ("GDPR").

1. Who we are and how to reach us

Controller: [COMPANY NAME]. Email: privacy@kandyo.com. Use the same address for requests about your rights.

2. Data we process

a) Account data. Name, email, password (stored only as a hash), settings, role within the organization, access logs (date, time, IP address) for security and abuse prevention.

b) Your Amazon account data (only if you connect a seller account through "Login with Amazon"). Orders, financial events, fees, refunds, inventory, listings, sales and traffic reports, advertising campaigns and their metrics. This data is obtained through Amazon's official APIs (Selling Partner API and Amazon Ads API) with the authorization you grant, which you can revoke at any time from Seller Central.

c) Personal data of your end customers (Amazon buyers). For order handling only, buyer name, shipping address, phone and email may pass through. Kandyo does not use this data for any other purpose, does not show it in aggregate analytics and deletes it automatically within 30 days of shipment, as required by Amazon's Data Protection Policy. For this data you are the controller and Kandyo the processor.

d) Technical data. Strictly necessary cookies (session, interface preferences). kandyo.com uses no profiling cookies and no third-party tracking tools.

3. Why we process it and on what basis

We do not sell data, we do not advertise with your data and we do not use it to train third-party models.

4. Amazon data: specific commitments

5. Who can see the data

Only authorized Kandyo staff, for support and maintenance, with logged access. Infrastructure providers (processors): hosting and virtual servers by OVHcloud (data centers in the United Kingdom and the European Union); client-side encrypted backups at Backblaze (backups are encrypted before leaving our servers; the provider cannot read them). We do not transfer readable data outside the European Economic Area or the United Kingdom.

6. For how long

7. How we protect it

Encryption in transit (TLS) and at rest (encrypted volumes), two-factor authentication, revocable sessions, key-only administrative access, automatic security updates, daily encrypted backups, data separation per organization, monitoring and access logging. In case of a breach posing risks to your rights we will notify you without undue delay, and inform Amazon according to its policies when Amazon data is involved.

8. Your rights

You can request access, rectification, erasure, restriction, data portability and object to processing by writing to privacy@kandyo.com. You may also lodge a complaint with the Italian Data Protection Authority (Garante). From the app settings you can export your data and close your account.

9. Cookies

The site and the apps use only technical cookies and local storage (login session, trusted device for two-factor authentication, interface preferences). They require no consent and do not track browsing on other sites.

10. Changes

We will update this policy when the Services or the law change. Material changes are communicated by email or in the app before taking effect.