Privacy Policy

Last Updated: 2026-05-03

1. About This Policy

This Privacy Policy describes how Databrill UK Limited, a company registered in England and Wales (“Databrill”, “we”, “us”, “our”), collects, uses, and shares personal information in connection with the Databrill Core software-as-a-service product and associated software, libraries, command-line tools, web interfaces, and documentation (together, the “Service”).

Databrill Core is a business-to-business product. The Service is sold to organizations (“Customers”) that use it to extract data from Amazon Selling Partner and Advertising APIs into a database the Customer controls. This Policy applies to:

Different parts of this Policy apply to each of those groups. Section 2 explains who is responsible for which data.

If you are an end consumer of one of Databrill’s Customers (for example, a buyer whose order data appears in the Customer’s Amazon account), Databrill processes that information on the Customer’s behalf. Please contact the Customer first; we will support the Customer in responding to you.

2. Data Controller and Data Processor

Databrill is the data controller for:

Databrill is a data processor, acting on the Customer’s instructions, for:

The processor terms governing Databrill’s handling of Amazon Information and Customer Data are set out in the Data Processing Addendum (DPA), available on request and incorporated by reference into the agreement between Databrill and the Customer.

3. Information We Collect

3.1 Information You Provide

When you create an account or use the Service, we collect:

3.2 Information Collected Automatically

When you use the Service we automatically collect:

3.3 Amazon Information

When the Service runs on the Customer’s behalf, it extracts data from Amazon’s Selling Partner API and Advertising API. That data may include personal information of third parties (for example, buyer names and shipping addresses on order records, or recipient details on return records). Databrill processes this information solely on the Customer’s instructions and only as necessary to provide the Service.

3.4 Information from Third Parties

We may receive information about you from third-party sources where you have authorized them to share it with us, including identity providers used for single sign-on, our payment processor, and Amazon when you authorize the Service to connect to your Amazon accounts.

4. How We Use Information

We use personal information for the following purposes, in each case relying on the legal bases set out in Section 5.

To provide the Service:

To operate, secure, and improve the Service:

To communicate with you:

To comply with law:

We do not sell personal information. We do not use Amazon Information for advertising or marketing. We do not use Amazon Information or Customer Data to train any machine-learning model without the Customer’s prior written consent.

We rely on the following legal bases:

Where Databrill processes personal information as a processor on the Customer’s behalf, the Customer is responsible for identifying the legal basis for that processing.

6. Sharing Personal Information

We share personal information with:

We do not sell personal information.

7. International Transfers

Databrill is established in the United Kingdom. Some of our subprocessors are established in the European Economic Area, the United States, and other jurisdictions. Where we transfer personal information out of the United Kingdom or the European Economic Area, we use appropriate transfer mechanisms, including the UK International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses), and the EU Standard Contractual Clauses, as applicable. Copies are available on request.

8. Retention

We keep personal information only for as long as necessary for the purposes described in this Policy.

9. Cookies and Similar Technologies

The Databrill Core product uses a small number of first-party cookies and similar technologies (including a small amount of browser localStorage) that are strictly necessary to operate the Service, including authentication, session management, security, and remembering your interface preferences (such as your dark / light mode choice and whether you are currently signed in, so the navigation bar can render the correct button without a flash on page load). These do not require consent under UK and EU law because they are strictly necessary.

Where we use any non-essential cookies (for example, optional analytics), we will request consent first and offer a way to manage your preferences. The marketing pages may use a small number of analytics cookies, governed by our Cookie Policy.

You can configure your browser to block or delete cookies. If you block strictly necessary cookies, parts of the Service may not work.

10. Your Rights

Depending on where you are located, you may have the following rights in respect of personal information that Databrill holds about you as controller:

To exercise these rights, contact us at the address in Section 13. We will respond within the time required by applicable law (typically one month under UK GDPR).

If you are an end consumer (for example, a buyer whose data appears in a Customer’s Amazon account), please contact the Customer first; they are the controller of that data and we will support them in responding to you.

11. Security

We implement administrative, physical, and technical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. Safeguards include encryption of credentials at rest, encryption in transit (HTTPS / TLS) between the Service and Amazon’s APIs and between the Service and Customer endpoints, role-based access controls, and audit logging of access to sensitive systems. Specific security commitments are described in the Documentation and the DPA.

No system is perfectly secure. If we become aware of a personal data breach affecting personal information we hold, we will notify affected Customers and, where required, supervisory authorities, in accordance with applicable law and the DPA.

12. Children

The Service is intended for use by businesses and is not directed to children. We do not knowingly collect personal information from children under 16 (or any higher minimum age in your jurisdiction). If you believe we have collected personal information from a child, please contact us so we can delete it.

13. Contact

For privacy questions or to exercise your rights, contact us at:

If we are unable to resolve your concern, you have the right to complain to a data-protection supervisory authority. In the United Kingdom, that is the Information Commissioner’s Office (ico.org.uk).

14. Changes to This Policy

We may update this Policy from time to time. The “Last Updated” date at the top of this page reflects the most recent revision. Where the changes are material, we will give you reasonable advance notice (for example, by email to account holders or by a notice in the product) before they take effect.