Privacy Policy of eLogix GmbH
Last updated 10/2026
This is a translation for your convenience. In case of any discrepancy, the German version prevails.
1. Controller and contact details
Thank you for your interest in our company and our website. Protecting your personal data is important to us. Personal data means any information relating to an identified or identifiable natural person.
The controller within the meaning of the General Data Protection Regulation (GDPR) for the processing described on this website is:
eLogix GmbH In der Welle 13 49565 Bramsche, Germany Email: datenschutz@elogix-fulfillment.com
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.
2. Data protection officer
You can reach our data protection officer at:
Valentin Lätzsch eLogix GmbH, address as above datenschutz@elogix-fulfillment.com
3. Security of data transmission
To protect the transmission of confidential content, our website uses SSL/TLS encryption. You can recognise an encrypted connection by the string “https://” and the padlock symbol in your browser's address bar.
4. Data collected when you visit our website (server log files)
If you use our website for information purposes only, that is, if you do not register or otherwise transmit information to us, we only collect the data that your browser automatically transmits to our server. This comprises:
- the page or file requested
- the date and time of access
- the volume of data transferred
- notification of successful retrieval
- the browser type and version used
- the operating system used
- the previously visited page (referrer)
- the IP address (where applicable in shortened/anonymised form)
This processing is carried out in accordance with Art. 6(1)(f) GDPR on the basis of our legitimate interest in the stability, security and functionality of our website. This data is not merged with other data sources and is not passed on to third parties. We reserve the right to review the log files retrospectively if there are specific indications of unlawful use.
5. Cookies
Our website uses cookies in places – small text files stored on your device. Some cookies are deleted automatically when you close your browser (session cookies); others remain stored and allow your browser to be recognised on a later visit (persistent cookies).
Technically necessary cookies required for the operation of the website are used on the basis of Art. 6(1)(f) GDPR. Where cookies are not technically necessary (for example for reach measurement), they are used exclusively on the basis of your consent pursuant to Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. You can withdraw this consent at any time with effect for the future via the settings in our cookie banner.
You can configure your browser to inform you when cookies are set, to allow cookies only in individual cases or to exclude them generally, and to activate automatic deletion when the browser is closed. Disabling cookies may limit the functionality of the website.
6. Contacting us
If you contact us (for example via a contact form, by email or by telephone), we process the personal data you provide exclusively in order to handle your enquiry and for the associated technical administration. Which data is collected when you use a contact form follows from the respective form.
The legal basis is our legitimate interest in responding to your enquiry pursuant to Art. 6(1)(f) GDPR. If your enquiry is aimed at concluding or performing a contract, Art. 6(1)(b) GDPR is an additional legal basis. We delete your data once your enquiry has been dealt with conclusively and no statutory retention obligations prevent deletion.
7. Processing in the context of our fulfillment services (processing on behalf of a controller)
As a fulfillment service provider, we perform logistics services for our business clients (hereinafter “clients”) such as storage, picking, packing, shipping and, where agreed, returns and customer service handling. This involves processing personal data of our clients' end customers. This processing is carried out exclusively on behalf of and on the instructions of the respective client on the basis of a data processing agreement pursuant to Art. 28 GDPR. The controller for this data is not eLogix GmbH but the respective client (the merchant or shop operator). The following information is provided for your transparency; the information obligations under Art. 13/14 GDPR are fulfilled by the respective client in their own privacy policy.
Origin of the data: We receive the data from the respective client, or it is transmitted to us automatically via the connected shop and ERP systems (see also section 11).
Categories of data processed:
- name as well as delivery and billing address
- contact details (for example email address, telephone number) where required for shipping, delivery notification or queries
- order and article data (goods ordered, quantities, order and customer numbers)
- data for shipment and delivery handling (tracking numbers, shipping status)
- returns and, where applicable, complaint data
- where we handle customer communication: the content of that correspondence
We do not process special categories of personal data (Art. 9 GDPR) in this context, unless this is required in an individual case by the nature of the goods delivered and has been agreed contractually.
Purposes of the processing: We process this data exclusively in order to provide the services agreed on behalf of the respective client, in particular: storage and inventory management, picking and packing of orders, creation of shipping and delivery documents, handover to the carrier, processing of returns and, where applicable, handling end-customer enquiries.
Recipients of the data: To the extent necessary, we pass data to the shipping and logistics partners commissioned with delivery (see section 9). To carry out the processing we also use carefully selected IT service providers as sub-processors (see section 11), who are in turn contractually bound in accordance with Art. 28 GDPR. End-customer data is not used for eLogix GmbH's own purposes beyond performing the order; data is neither sold nor passed on for advertising purposes.
Retention period: We process the data only for the duration and to the extent necessary to provide the agreed services. After the end of the engagement, the data is deleted or returned to the client in accordance with the contractual agreements, unless statutory retention obligations (in particular under commercial and tax law) require longer storage.
Data security: We take appropriate technical and organisational measures pursuant to Art. 32 GDPR to protect the data entrusted to us against unauthorised access, loss or misuse. Details are set out in the respective data processing agreement.
Your rights as an end customer: If you would like information about the processing of your data or wish to exercise other data subject rights (see section 14), please contact the company with which you placed your order – that company is the controller and its privacy notice applies. If your request reaches us directly, we will forward it to the responsible client without delay and support them in handling it.
8. Processing in the context of business relationships with clients and suppliers
In order to initiate, establish and perform contractual relationships with our clients, suppliers and other business partners, we process the personal data of the respective contact persons required for this purpose (for example name, function, business contact details, contract and billing data).
The legal basis is Art. 6(1)(b) GDPR (initiation and performance of a contract) and Art. 6(1)(f) GDPR, where the processing is necessary to safeguard our legitimate interests in efficient business handling and in maintaining the business relationship. Once the contractual relationship has been fully settled, the data is blocked in accordance with retention periods under tax and commercial law and deleted after those periods expire.
9. Transfer of data to shipping and logistics partners
To deliver the shipments we send, we pass the data required for this purpose (in particular the name and delivery address of the recipient) to the transport company commissioned in each case. This transfer takes place on the basis of the respective order relationship pursuant to Art. 6(1)(b) GDPR or on the instructions of the client within the scope of processing on their behalf (see section 7).
Depending on the shipping method selected, the following carriers are used:
- DHL – Deutsche Post AG, Charles-de-Gaulle-Straße 20, 53113 Bonn, Germany
- DPD Deutschland GmbH, Wailandtstraße 1, 63741 Aschaffenburg, Germany
- Österreichische Post AG, Bahnsteggasse 17-23, 1210 Vienna, Austria
- GLS Germany GmbH & Co. OHG, GLS Germany-Straße 1–7, 36286 Neuenstein, Germany
Where your email address or telephone number is transmitted to the carrier for a delivery notification or to arrange a delivery date, this is done on the basis of consent given during the client's order process pursuant to Art. 6(1)(a) GDPR. This consent can be withdrawn at any time with effect for the future.
10. Processing of data from Amazon marketplaces
Where a client ships via Amazon under the merchant fulfilled network (including Seller Fulfilled Prime), we retrieve the order data required for this from their Seller Central account via the Amazon Selling Partner API. The client sets up the connection themselves and can revoke it at any time. The controller within the meaning of the GDPR remains the client; we process the data exclusively as a processor on their instructions.
Which data we retrieve
We retrieve open merchant-fulfilled orders with the details required for shipping and shipment confirmation: order number, the articles and quantities ordered, and the name and delivery address of the recipient. We do not retrieve payment data.
What we use it for
We use personal data from Amazon orders exclusively to pick, pack and ship the respective order and to confirm the shipment back to Amazon with the tracking number and carrier. It is not used for our own purposes, not combined with other data holdings and not passed on to third parties – with the exception of transmitting the delivery address to the carrier delivering the parcel (see section 9).
Deletion
We delete data from Amazon orders no later than 30 days after the shipment has been delivered, unless a longer statutory retention obligation applies.
Protective measures
The data is encrypted in transit (TLS) and at rest. Access is limited to employees who need it to fulfill orders; all accounts are individual and protected by multi-factor authentication. Access and application events are logged centrally.
Security incidents
If there is a suspicion that data from Amazon orders is affected by a security incident, we report this to security@amazon.com within 24 hours of detection and inform the affected client without delay. Obligations under Art. 33 and 34 GDPR remain unaffected. Our incident response plan is described at https://elogix-fulfillment.com/en/security.
11. Software and IT service providers used (processing on our behalf)
To provide our fulfillment services we use specialised software and IT service providers that support us in connecting to our clients' systems, in order management and in warehouse and shipping handling. In the course of these processes, personal data (in particular order, address and shipment data of our clients' end customers) is processed. The service providers listed below act for us as processors within the meaning of Art. 28 GDPR; a data processing agreement has been concluded with each of them ensuring that processing takes place exclusively on our instructions and in accordance with the GDPR.
Our own platform (app.elogix-fulfillment.com)
We develop and operate the central software for order management, inventory, returns and billing ourselves. It is available at app.elogix-fulfillment.com. The connection to Amazon marketplaces runs directly between this platform and the client's Seller Central account; no middleware is involved. For the technical operation of the platform we use the service providers listed below.
FFN Connect
For connecting certain other shop and ERP systems of our clients (including transmission of order and inventory data and returns handling) we use the FFN Connect middleware. It is not used for the Amazon connection. The provider is FFN Connect GmbH, Am Eiswurmlager 4, 01189 Dresden, Germany. Further privacy information: https://ffn-connect.de/datenschutz
JTL-Software (ERP and warehouse management)
For merchandise management and for warehouse and shipping administration we use software from JTL-Software-GmbH (including JTL-Wawi and JTL-WMS). The provider is JTL-Software-GmbH, Rheinstr. 7, 41836 Hückelhoven, Germany. Further privacy information: https://www.jtl-software.com/de/datenschutz
These systems are hosted for us by ecomDATA GmbH, Rheinstr. 7, 41836 Hückelhoven, Germany.
Supabase (database)
The data of our platform is held in a managed PostgreSQL database provided by Supabase. The provider is Supabase, Inc., 970 Toa Payoh North, Singapore. The region we use is located in the European Union (Ireland).
Vercel (application hosting)
The application itself is operated with Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Execution takes place in the Dublin (Ireland) region.
Resend (email delivery)
For sending notifications and system messages by email we use Resend. The provider is Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA.
AI-assisted features
For individual features of our platform – such as classifying support enquiries and drafting replies for our team – we use a language model provided by Anthropic PBC, 548 Market St, PMB 90375, San Francisco, CA 94104, USA. No personal data of our clients' end customers is transmitted to this service; content is not used there to train models.
12. Job applications
If you apply to us, we process the application data you submit (for example contact details, CV, references) exclusively for the purpose of carrying out the application procedure. The legal basis is Section 26(1) BDSG in conjunction with Art. 6(1)(b) GDPR. If no employment relationship comes about, we delete your application documents no later than six months after the procedure has been concluded, unless longer retention is required or you have consented to longer storage (for example for a talent pool).
13. Transfers to third countries
Where personal data is transferred to recipients outside the EU or the EEA in the course of the processing described above, we ensure that an adequate level of data protection exists. This is achieved either on the basis of an adequacy decision of the EU Commission (for example the EU-U.S. Data Privacy Framework for certified US companies) or by appropriate safeguards pursuant to Art. 46 GDPR, in particular standard contractual clauses. On request we will provide you with information on the safeguards in place.
14. Your rights as a data subject
You have the following rights in relation to your personal data vis-à-vis the respective controller:
- access (Art. 15 GDPR) to the data processed about you
- rectification of inaccurate or incomplete data (Art. 16 GDPR)
- erasure (Art. 17 GDPR), unless statutory retention obligations prevent it
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)
To exercise these rights, please use the contact details given in section 1. Where your data is processed by us on behalf of one of our clients (section 7), please address your request to the respective client as the controller.
Right to object (Art. 21 GDPR): Where your personal data is processed on the basis of legitimate interests pursuant to Art. 6(1)(f) GDPR, you have the right to object to that processing at any time on grounds relating to your particular situation.
Right to lodge a complaint: Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence or of the place of the alleged infringement. The authority responsible for us is the State Commissioner for Data Protection of Lower Saxony (Landesbeauftragte für den Datenschutz Niedersachsen).
15. Retention period
For data from Amazon orders, the specific period in section 10 applies: we delete it no later than 30 days after the shipment has been delivered, unless a longer statutory retention obligation applies. Where no more specific retention period is stated in this policy, we delete personal data as soon as the purpose of the processing no longer applies and no statutory retention obligations (in particular under commercial and tax law, generally 6 or 10 years) prevent deletion. Where we process data on behalf of a controller, the retention period follows the instructions of the respective client and the contractual agreements.
16. Currency of this privacy policy and changes to it
This privacy policy is dated 10/2026. As our website and services develop further, or as a result of changed legal or regulatory requirements, it may become necessary to amend this privacy policy. You can retrieve the current version at any time on this page.
