Sellantica Logo
  • Home
  • About
  • Features
  • Pricing
  • Contact
  • Blog
  • News
  • Legal notice
    • DeutschDE
    • EnglishEN
    • EspañolES
    • FrançaisFR
    • ItalianoIT

Privacy Policy

Information pursuant to Art. 13, 14 GDPR

Last updated: July 31, 2026

This is a non-binding English translation. The German version is legally authoritative — see the German original.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

hof digital
Sebastian Hof
Hohenzollernallee 29
40235 Düsseldorf
Germany

Phone: +49 211 5420 2330
Email: info@hof-digital.de
Data Protection: privacy@hof-digital.de

2. General Information

The following information provides a simple overview of what happens to your personal data when you visit our website or use our Sellantica service. Personal data is any data by which you can be personally identified.

Sellantica is a professional Amazon PPC Analytics Software that works exclusively with official Amazon SP-API interfaces. We do not process personal data (PII) of Amazon end customers; we exclusively process campaign and performance data of Amazon Selling Partners registered with us.

3. Data Collection on This Website

3.1 Hosting

This website and the Sellantica application are hosted with Amazon Web Services (AWS):

Amazon Web Services EMEA SARL
38 Avenue John F. Kennedy
L-1855 Luxembourg

Data Center: AWS eu-central-1 (Frankfurt, Germany)

AWS processes data on our behalf pursuant to Art. 28 GDPR. A Data Processing Agreement (DPA) has been concluded. More information: AWS GDPR Center

3.2 Server Log Files

The provider of the pages automatically collects and stores information in server log files:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of the server request
  • IP address (anonymized after 7 days)

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security and stability of our services)

Storage period: 90 days, then automatically deleted

3.3 Contact Form & Demo Requests

When using our contact form or submitting a demo request, we process the following data:

  • Name
  • Email address
  • Company (optional)
  • Monthly ad spend (optional)
  • Message (optional)

Purpose: Responding to your inquiry, providing a demo, business initiation

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures), Art. 6(1)(f) GDPR (legitimate interest)

Storage period: Until complete processing of your inquiry, then 3 years for documentation purposes

Recipients: No disclosure to third parties except technical service providers (AWS)

3.4 Consent Management, Cookies and Similar Technologies

We use the locally integrated Klaro consent-management tool to store your selection. The required sellantica_consent cookie applies to .sellantica.ai and is stored for up to 365 days. This allows the same selection to be respected on the website and its subdomains.

Google Tag Manager is loaded as a technical control layer with Google Consent Mode v2 denied by default. The CMP passes your decision to Google Consent Mode and provides separate grant and withdrawal events for tags managed in GTM. Effective blocking requires the GTM container to use these consent and trigger rules correctly. Optional services are configured for use only after your selection and are offered only where Sellantica has actually enabled the service in the relevant context:

  • Analytics: Google Analytics for website statistics, PostHog Cloud EU for product analytics, and Hotjar/Contentsquare for optional behaviour and usage analytics
  • Marketing: Google Ads and optional Meta marketing for campaign measurement and, where applicable, ad personalisation
  • Required: Tawk.to support chat where it is offered
  • External content & reviews: optional ProvenExpert review seal

You may decline optional categories individually without losing basic access to the website or product; only the corresponding optional feature will then be unavailable.

You can change or withdraw consent there at any time with effect for the future. Withdrawal does not affect the lawfulness of processing before withdrawal. Klaro initiates deactivation and removal of known cookies accessible to it on .sellantica.ai; data already transmitted to a provider is not automatically erased as a result.

Legal basis: Art. 6(1)(f) GDPR and, where applicable, Section 25(2)(2) TDDDG for technically required processing; your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG for optional analytics, marketing and external-content technologies.

Specific service and storage inventory

The entries for optional storage apply only where you have consented and the relevant service is in use. Project and container identifiers are shown as placeholders below.

Service / categoryCookie or browser storageMaximum durationUse
Klaro / requiredsellantica_consent, cookie on .sellantica.ai365 daysStores the consent selection; always active.
Google Tag Manager / requiredNo separate Sellantica cookie–Consent Mode denied by default; optional tags also require matching consent rules in GTM.
Google Analytics / analytics_ga, _ga_<ID>, _gid, potentially _gat* / _dc_gtm_<ID>up to 2 years; _gid 24 hours; rate-limit cookies about 1 minuteOnly after analytics consent, via GTM.
PostHog Cloud EU / analyticsph_<project-key>_posthog as a cookie and local-storage entry (including distinct, device and session IDs)up to 365 daysOnly after analytics consent; product analytics hosted in the EU.
Hotjar/Contentsquare / analytics_hjSessionUser_*, _hjSession_*, _hjAbsoluteSessionInProgress, _hjFirstSeen, _hjIncludedInSessionSample_*, _hjSessionRejected, _hjSessionResumed, _hjHasCachedUserAttributes, _hjUserAttributesHash, test cookies (_hjCookieTest, _hjLocalStorageTest, _hjSessionStorageTest, _hjTLDTest) and, where used, survey/feedback cookies (_hjClosedSurveyInvites, _hjDonePolls, _hjMinimizedPolls, _hjShownFeedbackMessage); _hjUserAttributes and hjActiveViewportIds in local storage, hjViewportId in session storageuser and survey identifiers up to 365 days; sessions typically 30 minutes; tests usually deleted immediately; local storage without a fixed duration or until withdrawal or deletionOnly after analytics consent, via GTM; analysis of page views, clicks, scrolling and session journeys.
Google Ads / marketing_gcl_au, _gcl_awtypically up to 90 daysOnly after marketing consent, via GTM.
Meta / marketing_fbp, potentially _fbcup to 90 daysOnly after marketing consent and only when Meta marketing is configured.
Tawk.to / requiredtawk_uuid_*, twk_idm_key, TawkConnectionTime; twk_token_* in local storage; including PreviousNav in session storage. Account or profile data is not passed automatically; you enter the content of a chat message yourself.recognition up to 6 months; connection/session until session end; local storage until deletionRequired for the offered support chat.
ProvenExpert / external content & reviewsProvider-dependent cookies or similar browser storage may be used; the IP address, requested URL and browser, device and referrer information are also transmitted.As specified by ProvenExpert; the script and embedded content are removed upon withdrawal.Review seal and review content only after consent.
Google Fonts / presentation (always loaded)No cookies according to Google; the browser cache may retain font filesCache duration depends on the browserRetrieval cannot be disabled through optional categories; the IP address and technical headers are transmitted to Google.
Font Awesome via cdnjs / presentation (always loaded)No Sellantica cookies; the browser cache may retain CSS and font filesCache duration depends on the browserRetrieval from the Cloudflare-operated cdnjs CDN cannot be disabled through optional categories; Cloudflare receives technical connection data.
Mollie / paymentNo Mollie cookies on the public website; required storage on Mollie's hosted checkout domain under its policyAs specified by Mollie or the selected payment methodOnly when you actively start a payment.
Microsoft Bookings, Outlook & Teams / appointment schedulingNo Microsoft storage before your action on the public website; after clicking, cookies and browser storage on the Microsoft domain apply.Under the applicable Microsoft 365, account and browser retention rules.Only when you actively open the external booking link and use the appointment service; not controlled by the Sellantica CMP.
AWS & Sentry / server-sideNo separate browser analytics cookie from this processingUnder the applicable server, security and error-retention periodsAWS delivers the services; Sentry processes server-side error and diagnostic data only when corresponding events occur.

Other required or user-initiated services

AWS: The website and application run in the AWS Frankfurt region. AWS processes connection, log and content data required for delivery, contract performance, security and stability. Depending on the context, the legal bases are Art. 6(1)(b) and (f) GDPR.

Google Fonts: When externally hosted font files are retrieved, Google receives in particular the IP address, requested URL and browser, operating-system and referrer information. According to the provider, Google Fonts does not set cookies. The legal basis is Art. 6(1)(f) GDPR (interest in consistent, performant presentation).

Font Awesome via cdnjs: The Font Awesome CSS and font files required for presentation are always retrieved from the Cloudflare-operated cdnjs CDN and cannot be disabled through optional CMP categories. Cloudflare receives in particular the IP address, requested URL, browser, device and referrer information. The legal basis is Art. 6(1)(f) GDPR (interest in consistent and performant presentation).

Sentry: Sentry is used exclusively server-side for error diagnostics and stability. Only when a corresponding error or diagnostic event occurs may error messages, stack traces, timestamps, technical request metadata and any IP address contained in them be processed. The public website does not set a Sentry analytics cookie for this purpose. The legal basis is Art. 6(1)(f) GDPR (security and troubleshooting).

Hotjar/Contentsquare: The Hotjar tracking code is activated through Google Tag Manager only after your analytics consent. It may process page and referrer URLs, browser, device and connection data, and interactions such as clicks, scrolling and session journeys to identify usage patterns and improve usability. Form input and sensitive page content are intended to be suppressed or masked through provider features. The legal basis is your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG. The provider is Hotjar Limited, Malta, a Contentsquare group company whose parent Contentsquare SAS is based in France; affiliated companies and subprocessors may be involved. Withdrawal stops future activation and removes Hotjar storage accessible to Klaro, but does not automatically erase data already transmitted.

Mollie: When you actively start a payment, you are redirected to Mollie's hosted checkout. Mollie then processes transaction, payment, contact and technical data required for payment and fraud prevention. The legal bases are Art. 6(1)(b) GDPR and legal obligations under Art. 6(1)(c) GDPR. Required cookies and payment services on Mollie's domain are not controlled by the Sellantica CMP.

ProvenExpert: The Expert Systems AG review seal is loaded only after your consent. In particular, the IP address, requested URL, time and browser, device and referrer information and interactions with the seal may be processed, and provider-dependent cookies or similar storage may be used. The purpose is to display verified reviews. The legal basis is Art. 6(1)(a) GDPR and Section 25(1) TDDDG. On withdrawal, we remove the embedded script and widget content; data already transmitted is not automatically erased.

Microsoft Bookings, Outlook and Teams: When you actively open the external booking link on the appointment page, you leave the Sellantica website and use Microsoft Bookings. Before that click, this appointment service does not set optional Microsoft storage on our public website, so it is not part of the CMP. Appointment selection, the Outlook invitation and the Teams meeting may involve your name, email address, appointment date and time, time zone and, where requested, phone number, company, notes and answers to booking questions, as well as technical connection data. The Teams meeting also creates invitation, attendee and meeting metadata; if you use the relevant features, chat, audio, video and screen-sharing content may also be processed. Recipients are Microsoft Ireland Operations Limited and the relevant appointment staff at hof digital. Processing serves the appointment and communication you requested and is based on Art. 6(1)(b) GDPR. Microsoft's own privacy and storage settings apply on Microsoft domains.

4. Data Processing When Using Sellantica

4.1 Amazon SP-API Integration

Sellantica is a registered Amazon Selling Partner Application. After your authorization via "Login with Amazon", we process the following data:

  • Amazon Seller Account ID
  • Campaign data (Sponsored Products, Brands, Display)
  • Keyword and Search Term Performance
  • Budget and bid information
  • ACoS, ROAS, conversion metrics
  • Brand Analytics data (if authorized)

Purpose: Providing PPC analytics, bid optimization, campaign management

Legal basis: Art. 6(1)(b) GDPR (contract performance)

Storage period: During the contract term plus 90 days for reporting purposes

4.2 No Processing of Personal Customer Data (PII)

Important: Sellantica does not process personal data of Amazon end customers (e.g., names, addresses, payment information). We exclusively receive aggregated campaign and performance metrics via the SP-API.

In accordance with the Amazon Acceptable Use Policy (Sections 4.4 and 4.5), we exclusively process:

  • Campaign performance data of the Seller
  • Aggregated keyword and search term statistics
  • Financial metrics (ad spend, sales, ACoS)

4.3 Data Separation Between Sellers

Each Amazon Seller has exclusive access to their own data. No aggregation or mixing of data from different sellers takes place. Tenant separation is achieved through:

  • Separate S3 buckets per seller account
  • IAM roles with least-privilege principle
  • Encrypted database partitioning
  • Multi-factor authentication for all access

5. Data Disclosure and Recipients

Depending on the requested function, your selection and the actual configuration, the following recipients or service providers may receive data. Where required, they are contractually engaged under Art. 28 GDPR; where a provider acts as an independent controller, its own privacy information also applies.

Recipient Purpose Location
Amazon Web Services (AWS) Hosting, storage, computing EU (Frankfurt)
Amazon SP-API Data retrieval EU
Google LLC (Tag Manager, Fonts; optional Analytics and Ads) Tag control and font delivery; analytics and advertising measurement only with consent EU / USA
PostHog, Inc. (PostHog Cloud EU) Optional product analytics; only after analytics consent EU data region (Frankfurt)
Hotjar Limited / Contentsquare SAS Optional behaviour and usage analytics using page, device, connection and interaction data; only after analytics consent EU (Malta / France) / potentially third countries through affiliated companies or subprocessors
Meta Platforms Ireland Ltd. Optional campaign measurement and potentially ad personalisation; only after marketing consent and where configured EU / potentially USA
Tawk.to Required support chat where offered. Account or profile data is not transferred automatically; chat content is transferred only when you send a message. Potential third countries
Expert Systems AG (ProvenExpert) Optional review seal; technical connection, device, referrer and interaction data only after consent Germany / potentially other recipients under the provider's disclosures
Cloudflare, Inc. (cdnjs / Font Awesome) Always-loaded presentation resources; technical connection data including the IP address, requested URL, browser, device and referrer information EU / potentially USA
Mollie B.V. Mollie-hosted payment processing; only when a payment is actively started EU (Netherlands)
Microsoft Ireland Operations Limited (Bookings, Outlook, Teams) User-initiated appointment booking, calendar invitation and online meeting; contact, appointment, form, connection and, where used, meeting content EU / potentially other Microsoft locations
Functional Software, Inc. (Sentry) Server-side error diagnostics and stability; no client-side website analytics Potentially EU / USA

With some providers, data may be transferred to or accessed from third countries, particularly the United States. Where required, we rely on an adequacy decision or appropriate safeguards, in particular the EU Standard Contractual Clauses and supplementary measures. PostHog's EU data region is used for product analytics. Your Sellantica customer data is not disclosed to other Amazon sellers or competitors.

6. Data Security

We implement the following technical and organizational measures (TOMs):

  • Encryption: TLS 1.3 in transit, AES-256 at rest
  • Access control: IAM Least-Privilege, Multi-Factor Authentication
  • Monitoring: AWS CloudTrail, GuardDuty, CloudWatch Alarms
  • Backup: Daily automatic backups with 30-day retention
  • Incident Response: 24/7 escalation chain, documented playbooks
  • Logging: Immutable audit logs for 12 months

All employees are bound to data confidentiality and receive regular data protection training.

7. Your Rights as a Data Subject

You have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR): You may request information about the data we store about you
  • Right to rectification (Art. 16 GDPR): You may request the correction of inaccurate data
  • Right to erasure (Art. 17 GDPR): You may request the deletion of your data ("right to be forgotten")
  • Right to restriction (Art. 18 GDPR): You may request a restriction on the processing of your data
  • Right to data portability (Art. 20 GDPR): You may receive your data in a structured format
  • Right to object (Art. 21 GDPR): You may object to the processing of your data
  • Right to withdraw consent (Art. 7(3) GDPR): You may withdraw any consent given at any time

To exercise your rights, please contact:
privacy@hof-digital.de

Right to lodge a complaint: You have the right to lodge a complaint with a data protection supervisory authority:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2-4, 40213 Düsseldorf
www.ldi.nrw.de

8. Storage Duration

We store your data only for as long as is necessary for the respective purposes:

  • Campaign data: During contract term + 90 days
  • Contract data: 10 years (statutory retention obligation under HGB)
  • Invoice data: 10 years (statutory retention obligation under AO)
  • Server logs: 90 days
  • Contact inquiries: 3 years

After the storage period expires, data is automatically deleted unless statutory retention obligations apply.

9. Automated Decision-Making

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. All optimization suggestions by the Sellantica software are recommendations that must be manually confirmed by the seller before implementation.

10. Changes to This Privacy Policy

We reserve the right to adapt this privacy policy to ensure it always complies with current legal requirements or to reflect changes to our services. The new privacy policy will apply on your next visit.

In the event of material changes, we will inform you by email (if you are registered with us) or by a prominent notice on our website.

Further Legal Information

Imprint Terms & Conditions Contact
Back to Home

© 2026 Sellantica by hof digital. All rights reserved.

  • DeutschDE
  • EnglishEN
  • EspañolES
  • FrançaisFR
  • ItalianoIT
Legal notice Privacy Terms