Privacy & Data Protection Policy
This policy describes how Flexibles y Accesorios Gobe, S.L. (trading as "FlexigoTech") collects, processes, stores, uses, shares and deletes personal data, in compliance with Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 (LOPDGDD) and, with respect to the Amazon integration, Amazon's Data Protection Policy and Acceptable Use Policy for the Amazon API (SP-API). Last updated: July 2026.
1. Data Controller
2. Scope
This policy applies to (i) data from visitors and customers of our websites, and (ii) data that our software (Odoo modules and connectors) processes on behalf of our customers, including data obtained through the Amazon API (SP-API). When processing Amazon data, FlexigoTech acts as the software developer; the data is processed and stored within the customer's (seller's) own Odoo instance.
3. What data we process
a) Website and contact data: name, email, phone number and messages you provide through contact forms, as well as technical browsing data.
b) Data obtained from Amazon (SP-API) through our connector:
- Order data (identifiers, products, amounts, status, marketplace).
- For orders fulfilled by the seller (FBM): the buyer's name and shipping address, necessary to generate shipping labels and dispatch the order.
- For invoicing: the buyer's tax and billing data (e.g. VAT/tax ID on B2B/Amazon Business orders), necessary to issue invoices compliant with tax regulations.
4. Purposes and legal basis
We process Amazon data solely to provide the connector's functionality: importing orders into the ERP, generating shipping labels and confirming shipment/tracking, managing inventory, returns and messaging, issuing invoices and reconciling settlements. Legal bases: performance of a contract (provision of the service to the seller), legal obligation (accounting/tax retention of orders and invoices) and legitimate interest (security and proper operation). We do not use Amazon data for any other purpose, nor for profiling or marketing.
5. Where and how data is stored
Amazon data is stored exclusively within the seller's own Odoo instance, hosted on Odoo.sh (infrastructure within the European Union, certified ISO 27001, SOC 2 and GDPR-compliant). The following safeguards apply: encryption in transit (TLS/HTTPS) and at rest (AES‑256 at the infrastructure level, with key management handled by the platform); role-based access control on a least-privilege basis (only the Amazon administrator role can view credentials and personal data); encrypted, geographically replicated backups; and audit logs.
6. Retention and deletion
We retain personal data for as long as the service relationship is in place and for the periods required by applicable accounting and tax regulations (in Spain, generally 4–6 years for orders and invoices). Once those periods have elapsed, or upon a data subject's request where applicable, the data is securely deleted or anonymized.
7. Recipients and data processors
We do not transfer or sell personal data to third parties for commercial purposes. To provide our services (website, store and customer accounts) we rely on the following data processors, each under the corresponding processing agreement (Art. 28 GDPR):
| Provider | Purpose | Location / safeguards |
|---|---|---|
| Odoo S.A. / Odoo.sh | Hosting of the customer's and demo Odoo instances | EU · ISO 27001 / SOC 2 |
| Netlify | Hosting of the static website | US · Standard Contractual Clauses (SCC) |
| Render | Store backend (orders and module delivery) | EU region (Frankfurt) · SCC |
| Supabase | Customer accounts (sign-up, sign-in, two-factor verification) | EU region · SCC |
| Brevo (Sendinblue) | Transactional emails (confirmation, delivery, password recovery) | EU (France) |
| GitHub (Microsoft) | Encrypted storage of the order log and module source code | US · SCC / Data Privacy Framework |
| Stripe | Payment processing (we do not store card data) | US/EU · SCC · PCI‑DSS |
| Google (Analytics / Ads) | Web analytics and campaign measurement — only with your consent | US · SCC · Data Privacy Framework · anonymized IP |
Some providers are based in the US; in those cases, international transfers are safeguarded by Standard Contractual Clauses approved by the European Commission and/or the Data Privacy Framework, with the adequate safeguards required by the GDPR. Data obtained from Amazon is never shared with any external source, nor obtained from any source other than the official Amazon API.
7 bis. Cookies and web analytics
Our site uses two types of cookies and similar technologies:
- Technical / necessary (always active): remember your language and consent preferences. No consent is required as they are essential for the site to function.
- Analytics (Google Analytics 4): help us understand, in aggregate, how the site is used. No analytics cookie is loaded or set until you accept it via the banner (Google Consent Mode v2, with anonymized IP). If you decline, Google Analytics is never activated.
You can accept or reject analytics cookies with a single click on the banner, and change your decision at any time via the "Cookies" link in the footer. Your choice is stored locally in your browser.
8. Amazon data — specific compliance (Amazon Data Protection Policy)
With respect to information obtained through the Amazon API (SP-API), we commit to:
- Use Amazon information only for authorized purposes (managing and fulfilling the seller's orders) and in accordance with Amazon's Acceptable Use Policy and Data Protection Policy.
- Not store personally identifiable information (PII) beyond what is necessary to fulfill orders and meet legal obligations, and delete it once it is no longer needed.
- Encrypt PII in transit and at rest, and restrict access on a least-privilege basis.
- Report any security incident affecting Amazon information to security@amazon.com within 24 hours of detection, in accordance with our Incident Response Plan.
- Not share Amazon information with unauthorized third parties.
9. Security measures
We apply technical and organizational measures under Art. 32 GDPR and Amazon's Data Protection Policy: encryption in transit and at rest; multi-factor authentication (MFA) and password policies; role-based access control; secure credential storage (never in code or public repositories); audit logs and monitoring; encrypted backups; testing changes in dedicated environments before production; code vulnerability scanning; and a documented Incident Response Plan, reviewed periodically.
10. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability by writing to comercial@flexigobe.com. For data processed on behalf of a seller (data controller), we will forward your request to the corresponding seller. You have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
11. Changes to this policy
We may update this policy to reflect legal or technical changes. The current version will always be published on this page, indicating the date of the last update.
12. Contact
comercial@flexigobe.com · +34 616 809 504 · Calle Roger de Lluría 54, 08009 Barcelona, Spain.