Privacy Policy
Introduction
Protecting your personal data is very important to us. This privacy policy informs you about how we process data within the scope of our Software-as-a-Service (SaaS) offering in accordance with the General Data Protection Regulation (GDPR).
1. Controller
Stefan Reichel
Soulutions GmbH
Otto-Weidt-Platz 11
10557 Berlin
Email: info@soulutions.io
2. Processing of personal data via AWS Cognito
We use Amazon Web Services Cognito (AWS Cognito) to manage user accounts. The following personal data is processed:
- Name (optional)
- Email address
- Password (encrypted and stored in Cognito)
This data is processed and stored exclusively in AWS Cognito. Our employees do not have access to passwords or other sensitive authentication data. Storage takes place in data centers in Frankfurt am Main, Germany.
Legal basis: Art. 6 para. 1 lit. b GDPR (performance of a contract)
3. No storage or logging of IP addresses
We do not store or log IP addresses in the course of using our service. No profiling, tracking, or analysis based on IP addresses takes place.
4. Data processing via Amazon APIs
Our service processes data provided via the following interfaces:
- Amazon Seller Partner API
- Amazon Ads API
This data remains entirely within the Amazon ecosystem and is not stored outside the Amazon infrastructure. Only processed and aggregated data, which does not contain personal information, is stored on our systems in AWS Frankfurt.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in business analytics)
5. Hosting and infrastructure
Our entire infrastructure is operated by Amazon Web Services (AWS). All data is stored exclusively in data centers in Germany (Frankfurt). We have a data processing agreement (DPA) with AWS in accordance with Art. 28 GDPR.
6. Security – Technical and organizational measures (TOMs)
We implement extensive technical and organizational measures to protect data, including:
- TLS encryption of data transmission
- Access restrictions and role-based authorization
- Logging of administrative access (without personal data)
- Encryption of stored data
- Automated backups and monitoring
7. Your rights
You have the following rights under the GDPR:
- Right of access to your stored data (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to withdraw consent (Art. 7 para. 3 GDPR)
Please contact us at: info@soulutions.io
8. Changes
We reserve the right to update this privacy policy if our services or legal requirements change. The current version is always available on our website.