Trust & security
Data Security & Incident Response
eLogix GmbH processes order and shipping data on behalf of online sellers, including data retrieved from Amazon via the Selling Partner API. Protecting this data is part of our core service. This page summarizes the security controls and the incident response plan that apply to all data processed through our platform (app.elogix-fulfillment.com).
Security controls
- Least-privilege access: individual user accounts with multi-factor authentication; access to personal data only for employees who need it to fulfill orders.
- Encryption of data in transit (TLS) and at rest.
- Centralized access and application logging.
- Regular backups.
- Hosting on servers located in the European Union.
- Personal data from Amazon orders is used exclusively to fulfill and ship the respective order, shared only with the carrier delivering the parcel, and deleted no later than 30 days after delivery unless a longer retention period is required by law. See our Privacy Policy for details.
Incident response plan
Our incident response plan covers database breaches, unauthorized access and data leaks. It is owned by our Managing Director as incident lead, supported by our data protection officer (Valentin Lätzsch), our in-house development team and our hosting providers. It consists of six phases:
- 1
Preparation
Documented roles and contact lists, least-privilege access with individual accounts and multi-factor authentication, encryption of Amazon data in transit (TLS) and at rest, centralized access and application logging, and regular backups.
- 2
Detection and analysis
Monitoring of access logs, failed logins, unusual API activity and database queries; alerts from our hosting providers. Every suspected incident is logged immediately, classified by severity and checked for whether Amazon data or end-customer personal data is affected.
- 3
Containment
Immediate isolation of affected systems or accounts, revocation of compromised sessions, and rotation of all potentially exposed credentials, including SP-API/LWA client secrets and refresh tokens. If Amazon data may be affected, SP-API access is suspended until the system is secured.
- 4
Notification
Amazon is notified at security@amazon.com within 24 hours of detection. Affected clients (sellers) are informed without delay. Where required under Art. 33/34 GDPR, the competent supervisory authority is notified within 72 hours and affected individuals are informed.
- 5
Eradication and recovery
Root cause analysis, removal of the vulnerability or malicious access, restoration from clean backups, verification of data integrity, and controlled restart of services with enhanced monitoring.
- 6
Post-incident review
Documentation of the incident, its impact and the measures taken; lessons learned are fed into our security controls and the plan itself. The plan is reviewed at least once a year and after every significant incident.
Reporting a security issue
If you believe you have found a security vulnerability or suspect unauthorized access to data processed by eLogix, please contact us immediately at datenschutz@elogix-fulfillment.com.
Report a security issueeLogix GmbH · In der Welle 13 · 49565 Bramsche · Germany