1. Data Protection at a Glance
The following information provides a comprehensive overview of what happens to your personal and
business data when you use our website and services. We take the protection of your data —
both personal and commercial — extremely seriously. AMZ Marketing processes all data in
accordance with the General Data Protection Regulation (GDPR) and applicable German data protection
laws.
2. Data Controller
The data controller responsible for data processing on this website and within our services is:
David Wiedenau Einzelunternehmen
Dechant-Fröls-Straße 2
52351 Düren
Email:
[email protected]
Tel: 015757202226
3. Data Collection on This Website
Server log files: When you visit our website, our hosting provider automatically
collects and stores information in server log files that your browser transmits to us. This
includes: browser type and version, operating system, referrer URL, hostname of the accessing
device, time of the server request, and IP address. This data is not merged with other data sources.
The basis for data processing is Art. 6 (1) (f) GDPR, which permits the processing of data for the
purposes of fulfilling a contract or pre-contractual measures.
Contact and order forms: When you submit information through our website (e.g., to
request a listing optimization), we collect the data you provide, including your name, email
address, product information, and any additional details you share. This data is processed solely
for the purpose of fulfilling your order and communicating with you about your project.
4. Customer Business Data
In the course of providing our listing optimization and maintenance services, we process
business-related data that you provide or that we generate through our analysis. This includes but
is not limited to:
• Product information and product descriptions
• Listing content (titles, bullet points, descriptions, backend keywords)
• Keyword research data and keyword rankings
• Competitor analysis data
• Sales data and conversion metrics you share with us
• PPC and advertising performance data
• Product images and brand assets
This data is processed exclusively for the purpose of delivering the services you have contracted us
for. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract).
5. Confidentiality of Your Business Data
We understand that your listing data, keyword strategies, competitor insights, and ranking
information represent significant commercial value. We commit to the following strict
confidentiality measures:
No disclosure to third parties: Your business data — including product
information, keywords, rankings, competitor research, and listing content — will never be
shared with, sold to, or disclosed to any third party. This includes other clients, competitors,
partners, or any external entity.
Internal access restrictions: Access to your data within AMZ Marketing is strictly
limited to the team members directly working on your project. No other personnel will have access to
your business information.
No cross-client usage: Data, insights, keywords, or strategies developed for your
project will never be used for, applied to, or shared with any other client's project. Each client
engagement is treated as fully independent and confidential.
Competitive separation: If we work with multiple clients in the same product niche,
each project is handled in complete isolation. No competitive intelligence, keyword data, or
strategic insights are transferred between client projects under any circumstances.
6. AI Training & Data Usage Policy
AMZ Marketing uses proprietary AI technology as part of our listing optimization process. We maintain
the following strict policies regarding AI and your data:
No training on customer data: Your data — including product information,
listing content, keywords, rankings, competitor data, and any other information you provide or that
we generate in the course of our services — will never be used to train, fine-tune, improve,
or otherwise develop our AI models or any third-party AI systems.
No machine learning from your data: We do not use your data to build, refine, or
enhance any machine learning models, neural networks, language models, or algorithmic systems,
whether proprietary or third-party.
Processing only, no retention for AI purposes: When our AI processes your data to
generate listing optimizations, the data is used solely for that immediate task. It is not stored in
any training dataset, knowledge base, or model memory that persists beyond the scope of your
project.
Third-party AI services: If any third-party AI tools are used as part of our
workflow, we ensure that your data is not used by those providers for training purposes either. We
only use services that contractually guarantee the exclusion of customer data from model training.
7. Data Retention & Deletion
Active project data: During the active phase of your project, all data is stored
securely on our servers for the purpose of delivering our services.
Post-project deletion: All project-related data — including product
information, listing content, keyword research, competitor analysis, rankings, and any generated
materials — will be fully and permanently deleted from our servers within 7 days after you
accept the final result. This includes all backups and copies.
Maintenance service data: For clients subscribed to our weekly maintenance service,
data is retained for the duration of the active subscription. Upon cancellation of the maintenance
service, all data will be deleted within 7 days of the end of the subscription period.
Invoicing and legal obligations: Financial records (invoices, payment records) are
retained for the legally required period under German tax law (currently 10 years as per §147
AO). These records contain only transactional data, not your product or listing information.
Deletion upon request: You may request the deletion of your data at any time during
or after the project. We will comply within 72 hours, except where retention is required by law.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal and business
data against unauthorized access, alteration, disclosure, or destruction. This includes:
• Encrypted data transmission (SSL/TLS) for all website and service communications
• Encrypted storage of sensitive business data at rest
• Access controls limiting data access to authorized personnel only
• Regular security reviews of our systems and processes
• Secure deletion procedures ensuring complete data removal
9. Your Rights Under GDPR
Under the General Data Protection Regulation, you have the following rights regarding your personal
data:
Right of access (Art. 15 GDPR): You have the right to request confirmation of
whether we process your personal data and, if so, to access that data and obtain information about
the processing.
Right to rectification (Art. 16 GDPR): You have the right to request the correction
of inaccurate personal data or the completion of incomplete data.
Right to erasure (Art. 17 GDPR): You have the right to request the deletion of your
personal data where one of the grounds specified in the GDPR applies.
Right to restriction (Art. 18 GDPR): You have the right to request the restriction
of processing of your personal data under certain conditions.
Right to data portability (Art. 20 GDPR): You have the right to receive your
personal data in a structured, commonly used, and machine-readable format.
Right to object (Art. 21 GDPR): You have the right to object to the processing of
your personal data at any time, on grounds relating to your particular situation.
Right to lodge a complaint: You have the right to lodge a complaint with a
supervisory authority, in particular in the EU member state of your habitual residence, place of
work, or place of the alleged infringement.
10. Cookies
This website does not use tracking cookies, analytics cookies, or advertising cookies. We may use
strictly necessary technical cookies to ensure the basic functionality of the website. These do not
require consent under GDPR as they are essential for the operation of the website.
11. Third-Party Services
Google Fonts: This website uses fonts provided by Google Fonts. When you access our
website, your browser loads the required fonts from Google's servers. This may transmit your IP
address to Google. For more information, see Google's privacy policy. The use is based on Art. 6 (1)
(f) GDPR (legitimate interest in uniform font presentation).
Hosting provider: Our website is hosted by a third-party hosting provider. All
personal data collected on this website is processed on the provider's servers. We have entered into
a data processing agreement (DPA) with our hosting provider in accordance with Art. 28 GDPR.
12. Changes to This Privacy Policy
We reserve the right to update this privacy policy to reflect changes in our practices or applicable
law. Any significant changes will be communicated through our website. We encourage you to review
this policy periodically.
13. Contact for Data Protection Inquiries
If you have any questions about this privacy policy, our data handling practices, or wish to exercise
any of your rights, please contact us at:
David Wiedenau Einzelunternehmen
Dechant-Fröls-Straße 2
52351 Düren
Email:
[email protected]
Last updated: April 2026