This English version is provided for convenience. Only the German version is legally binding.
1. Controller
The controller responsible for the processing of personal data on this website and in AMZDelete is:
Selcuk Can Ekici
Kantstraße 97, 10627 Berlin
Phone: 0175 4540713
Email: info@amzdelete.com
2. Overview
We process personal data only to the extent necessary to operate the website and to provide our services. This privacy policy applies to visitors to the website, to our customers and to persons whose reviews on amazon.de we check on behalf of our customers.
3. Visiting the website
When you visit the website, the server processes technically necessary data: IP address, date and time, the page requested, the page you came from (referrer), the amount of data transferred, and your browser and operating system. This is necessary to deliver the website and to operate it in a stable and secure manner.
We store this log data in full, that is, with the complete IP address. We review it to detect errors and misuse, such as an unusual number of requests or attempted attacks, and to understand how visitors reach our pages and which pages they view. On our server, we derive the approximate country and city from the IP address so that we can categorize visits (for example, whether a visit comes from Germany) and offer visitors from abroad the English version of the website. For this we use a locally stored database (DB-IP, db-ip.com); the IP address is not transmitted to anyone in the process.
The legal basis is Art. 6(1)(f) of the General Data Protection Regulation (GDPR). Our legitimate interest lies in operating the website securely and in aligning our services with how they are actually used. We delete the log data after 7 days.
Hosting: Contabo GmbH, Aschauer Straße 32a, 81549 München, with servers in Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with the provider.
4. Cookies and tracking
We set only one technically necessary cookie: when you log in to the customer area, it keeps you logged in for up to 30 days. The legal bases are Section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG) and Art. 6(1)(b) GDPR. When you log out, the cookie is deleted.
In the customer area, your browser also stores two items of information only on your device: an order you have started, so that your entries are kept when the page is reloaded (deleted when you close the tab or log out), and whether you have dismissed the notice about the completed shop import. Both serve only the function you are currently using (Section 25(2) no. 2 TDDDG).
We do not use any analytics, advertising or tracking services. The fonts are hosted locally; no connection to Google or other font providers is established when you visit the website.
5. Checking reviews on amazon.de
When you enter an ASIN or a product link, we retrieve the publicly visible 1-star and 2-star reviews of this product on amazon.de. In doing so, we process the title and text of the review, the star rating and date, the displayed name of the author, the “Verified Purchase” or “Vine” label, the link to the review and a screenshot as evidence. We only store reviews that were posted on amazon.de. For troubleshooting, we also save the most recently retrieved page of a product and, in the event of retrieval errors, the affected page; we delete these saved copies 14 days after the last retrieval.
The purpose is to check whether reviews violate Amazon’s guidelines or applicable law, and to preserve them as evidence for a possible removal request. The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in enabling our customers to defend themselves against impermissible reviews, and in the establishment and defense of legal claims.
Regular re-checks
So that new reviews do not go unnoticed, we regularly retrieve the 1-star and 2-star reviews of the products in your account again, currently about every 7 days. We do this as long as you use AMZDelete, that is, if you have engaged our partner law firm, have turned on the emails about new reviews, or have signed up or logged in within the last 180 days. In doing so, we process the same data as above, for the same purpose and on the same legal basis. For each product, we also record the average star rating and the number of reviews at every check so that you can see how both develop. This history does not contain any information about authors.
For authors of reviews: The data comes from the public product page on amazon.de. You can object to this processing; see Right to object.
6. Quick preview without an account
If you enter an ASIN without an account, we retrieve a page of the product on amazon.de and show you its title, image, average rating and star distribution. We do not store reviews or their authors in the process. We keep the result in working memory for up to 12 hours so that the same product is not retrieved multiple times. The product image is loaded by our server; your browser does not connect to Amazon for this.
Instead of an ASIN, you can also enter a brand or product name, either without an account or while setting up your account. We then retrieve the first page of the amazon.de search results for this search text and show you up to 8 products with title, image and stars so that you can select yours. We keep the search text and the result in working memory for no more than one hour so that the same search is not retrieved multiple times. These images are also loaded by our server.
If you then go on to sign up with this product, we already look up the seller of the product on amazon.de while you do so: we read the product page, the public seller profile with its legal notice and the first page of the shop’s product list. This way, setting up your account can continue afterwards without any waiting time. We also keep this result only in working memory, for no more than 3 hours. If you create an account, we transfer it to your account; otherwise it expires.
To limit misuse, we count how many previews and searches are started from an IP address. For this purpose, we keep the IP address in working memory for no more than 24 hours and do not store it permanently. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in offering you the preview and protecting the service from overload.
7. Customer account, approval and engagement
For your account, we process your email address and your password, which we store only in encrypted form as a hash, as well as your company name, the name of your authorized representative, your address and the information you provide on individual cases, such as whether a review can be matched to an order, and any evidence you describe. The legal basis is Art. 6(1)(b) GDPR.
When you approve reviews, we transmit the cases and your information to our partner law firm. Within the scope of the engagement, the law firm processes this data as a controller in its own right, is bound by attorney-client confidentiality and informs you about its own processing. For the removal request, Amazon receives from the law firm the reviews concerned and the information needed to substantiate the request.
We send the law firm’s letters to Amazon by mail via the printing and mailing service LetterXpress of A&O Fischer GmbH & Co. KG, Maybachstraße 9, 21423 Winsen (Luhe). The service receives the letter with the information it contains, prints it, puts it in an envelope and hands it over to Deutsche Post. It processes the data as a processor pursuant to Art. 28 GDPR.
When you connect your shop, we read the public information in your seller profile on amazon.de (company name, address, commercial register, VAT ID, contact details as stated in the legal notice) and the products in your shop. Only the information that you confirm or change is adopted. We store your declaration that you are authorized to represent the company together with the time, IP address and customer account. The legal basis is Art. 6(1)(b) GDPR, and for the proof, Art. 6(1)(f) GDPR. Product images in the customer area are loaded by our server; your browser does not connect to Amazon for this.
When you engage the law firm and grant the power of attorney online, we store as proof the time, the IP address, the browser identifier and the customer account through which the declaration was made. This information does not appear on the documents; it can only be viewed by the law firm and serves to prove, in the event of a dispute, that the engagement and power of attorney were granted. The legal basis is Art. 6(1)(f) GDPR. We store it for as long as the engagement exists and thereafter until the retention period for the law firm’s case file expires.
8. AI-assisted initial assessment
So that our partner law firm can check cases more quickly, we have reviews automatically pre-assessed by the AI model Claude. The provider is Anthropic, PBC, San Francisco, USA. We transmit the title, text, star rating, date and the “Verified Purchase” or “Vine” label of the review, the product title, the public information on the product page (bullet points, technical details, description, selected variant, as well as product photos and manufacturer images, for comparison with the statements in the review) and, for commissioned cases, the information you have provided about the case. We do not transmit the name of the author or your contact details.
When we respond to an inquiry received via the contact form or by email, a draft of the response may be created with Claude. For this, we transmit your name, your company and the content of the conversation, but not your email address. A person reads the draft and sends it.
The result is a suggestion for the law firm and supplements the automatic flags in the customer area. The AI does not make decisions: you decide whether a case is commissioned, and the law firm decides whether and how it is pursued.
The legal basis is Art. 6(1)(f) GDPR, and for your information on commissioned cases and for responses to your inquiries, Art. 6(1)(b) GDPR. Anthropic processes the data as a processor pursuant to Art. 28 GDPR and, under its contractual terms, does not use it to train its models. The transfer to the USA is safeguarded by the standard contractual clauses of the European Commission.
9. Invoices and accounting
For invoices, we process the company name, address, email address, customer number and file number, the services invoiced and your payments. The legal basis is Art. 6(1)(b) GDPR, and for retention, Art. 6(1)(c) GDPR in conjunction with the retention obligations under commercial and tax law.
We do our accounting with Lexware Office of Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg. We transfer invoices and cancellation invoices containing this information to Lexware Office; Lexware matches incoming payments using the transactions in our business account. Haufe-Lexware processes the data as a processor pursuant to Art. 28 GDPR.
We issue the law firm’s portion of your invoice in the name of the partner law firm. The law firm receives it together with the invoice details for its own accounting and processes it as a controller in its own right.
10. Emails
We send you emails related to your account and your cases: confirmation of your email address, links for resetting your password, the notification that a check is complete, confirmation of your approval, updates on your cases, as well as invoices, cancellation invoices and payment reminders. The legal basis is Art. 6(1)(b) GDPR. We only send emails about new reviews with your consent. There is no newsletter. We keep a copy of every email for 6 months so that we can trace what was sent. Links for confirming or resetting are redacted in this copy.
The emails are handled by the mail server of TrafficPlex GmbH (lima-city), Konsul-Smidt-Str. 90, 28217 Bremen, as a processor pursuant to Art. 28 GDPR.
11. Emails about new reviews
If you turn this on in the customer area, we will email you as soon as we find new 1-star or 2-star reviews of your products during the regular re-check. The email is sent to the email address of your customer account. It lists the new reviews with star rating, title and product, shows whether a review has a flag for a possible violation, and contains a link to the customer area. We send no more than one email per re-check, and only if there is something new.
The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time with effect for the future: in the customer area under “Account”, or via the unsubscribe link in each of these emails. The re-checks then continue without emails; you can see new reviews in the customer area.
As proof, we store when and through which customer account you gave your consent or unsubscribed from the emails, the IP address from which you gave your consent, and the version of the consent text. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in being able to demonstrate your consent (Art. 7(1) GDPR). We store this information for as long as your account exists.
12. Contact form
We use the information you enter in the contact form (name, company, email, topic, message) to respond to your inquiry. The legal basis is Art. 6(1)(b) GDPR if your inquiry concerns a contract, otherwise Art. 6(1)(f) GDPR. We delete the inquiry 6 months after it has been dealt with, unless there is an obligation to retain it.
13. Visitor statistics without cookies
To see how our website is used, our server itself counts the visits to the public pages. For this we do not use cookies, do not store anything on your device and do not use any third-party services.
Only daily totals are recorded: how often each page was viewed, which website visitors came from (only the domain of the referrer) and whether a link contained campaign information (UTM parameters or the identifier of an ad), as well as whether the visit came from a mobile device. To avoid counting a visitor twice on the same day, the server creates a key from the IP address and browser identifier combined with a random value that is held only in working memory and changes daily. Neither IP addresses nor this key are stored; it is not possible to draw conclusions about individual persons. We also count clicks on the WhatsApp link only as a total.
The legal basis is Art. 6(1)(f) GDPR; our interest is to improve the website and our services. We delete the daily totals after 13 months.
14. Contact via WhatsApp
Our website contains links that you can use to message us via WhatsApp. As long as you do not click on them, nothing is transmitted to WhatsApp. Only when you open such a link does your device connect to WhatsApp, a service of WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
If you message us via WhatsApp, we process your phone number, your WhatsApp name and the content of the messages in order to respond to your inquiry. For this we use the WhatsApp Business app. In the process, WhatsApp processes its own usage data in accordance with its privacy policy, including in the USA; its parent company Meta Platforms, Inc. is certified under the EU-U.S. Data Privacy Framework. The legal basis is Art. 6(1)(b) GDPR if your inquiry concerns a contract, otherwise Art. 6(1)(f) GDPR (our interest in responding to inquiries through the channel you have chosen). We delete the chat history as soon as the inquiry has been dealt with and there is no obligation to retain it.
Please do not send confidential documents via WhatsApp. The customer area is there for documents relating to an order. You can also reach us at any time by email or via the contact form.
15. Letters to Amazon sellers
We send sellers who sell on amazon.de an offer from AMZDelete by mail. For this purpose, we process the business information from the public legal notice in their Amazon seller profile (company name, name of the authorized representative, business address) and public information about one of their products on amazon.de (title, ASIN, average rating and star distribution of the reviews). Each letter bears a personal code. If the code is accessed, we note in the seller’s record when and how often; we do not store the IP address in the process.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in informing businesses about an offer intended for them (direct marketing, Recital 47 GDPR). The letters are printed and sent via LetterXpress of A&O Fischer GmbH & Co. KG, Maybachstraße 9, 21423 Winsen (Luhe), as a processor pursuant to Art. 28 GDPR.
You can object to the use of your data for advertising at any time without giving reasons (Art. 21(2) GDPR), for example with a short message to info@amzdelete.com. We will then no longer write to you. To ensure that this also applies if we come across your shop again later, we permanently record the objection against your Amazon seller identifier (Seller ID).
16. Recipients
- our partner law firm, when you approve cases (see above), and, for its accounting, the law firm’s portion of your invoices
- our hosting provider as a processor: Contabo GmbH, München
- our email provider as a processor: TrafficPlex GmbH (lima-city), Bremen
- our accounting provider as a processor: Haufe-Lexware GmbH & Co. KG, Freiburg (Lexware Office)
- our printing and mailing service for letters to Amazon and for our letters to sellers, as a processor: A&O Fischer GmbH & Co. KG, Winsen (Luhe) (LetterXpress)
- Anthropic, PBC, USA, as a processor for the AI-assisted initial assessment and for drafts of responses to inquiries
- Amazon, as part of the removal request by the law firm
We transfer data to a country outside the EU only for the AI-assisted initial assessment (USA, safeguarded by standard contractual clauses) and, if you message us via WhatsApp, through WhatsApp (see Contact via WhatsApp).
17. Storage period
- Reviews that you do not approve: deleted 12 months after the product was last retrieved, or at the latest when you remove the product or close your account.
- Approved cases that did not lead to an invoice (not removed, or not taken on by the law firm): deleted 12 months after the case was closed. We then keep only the identifier of the review so that it does not appear as new again at the next retrieval. Removed reviews remain stored as long as your account exists, because the invoice is based on them.
- Account data: until the account is closed. We then delete your logins, products, reviews and screenshots.
- Invoices and accounting records: 8 years from the end of the calendar year in which they were issued, under Section 147 of the German Fiscal Code (AO) and Section 14b of the German Value Added Tax Act (UStG), even after the account is closed, together with the company data they contain.
- Engagement with power of attorney, fee agreement and proof, as well as the law firm’s letters to Amazon: as part of the law firm’s case file, 6 years from the end of the calendar year in which the engagement ends, under Section 50 of the German Federal Lawyers’ Act (BRAO).
- Proof of your consent to emails about new reviews: as long as your account exists.
- Information about sellers to whom we send letters: as long as their business is a potential candidate for our offer. We permanently record an objection against the seller identifier (Seller ID) so that we do not write again.
- Daily database backups: 7 days. Deleted data remains in the backups for this period.
18. No automated decision-making
The flags in AMZDelete are generated automatically, partly with the support of an AI model, but they are not a decision within the meaning of Art. 22 GDPR. Whether a case is approved is decided by the customer. Whether and how it is pursued is decided by the law firm.
19. Your rights
You have the right of access (Art. 15 GDPR), the right to rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). To exercise these rights, write to us via the contact form or by email.
20. Right to object
Where we process data on the basis of Art. 6(1)(f) GDPR, you can object at any time on grounds relating to your particular situation (Art. 21 GDPR). We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defense of legal claims.
You can object at any time, without giving reasons, to the use of your data for advertising, including advertising by mail (Art. 21(2) GDPR).
21. Complaint to a supervisory authority
You can lodge a complaint with a data protection supervisory authority, for example in your federal state or where the controller is based: Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information), Alt-Moabit 59-61, 10555 Berlin.
Last updated: October 2026