This policy explains how personal data is processed on the Kommerzdock website and SaaS service.
1. Controller
Juchi Europe GmbH, Gutenbergstraße 39/1, 72555 Metzingen, Germany. Managing Director: Haifeng Ma. Contact: [email protected], +49 7121 6952098. No DPO is named while the statutory appointment requirement remains under review.
2. Scope and roles
This covers website visitors, customer accounts and staff, and recipients or end customers whose data merchants import.
Juchi Europe GmbH is generally controller for website, account, contract, support, security and billing data. For merchant-imported order, recipient, logistics and product data, Kommerzdock generally acts as processor on the merchant's instructions under the DPA.
3. Website and security
IP address, time, route, browser/device data and security events are processed for delivery, security, abuse prevention and troubleshooting under Art. 6(1)(f) GDPR. Target retention: 30 days, with isolated longer retention for incidents, legal duties or legal holds.
4. Account and contract
Name, business email, company, account, plan and support data are processed to establish and perform the B2B contract under Art. 6(1)(b), (c) and (f) GDPR. Required registration and authentication data must be provided to open an account.
5. Order and recipient data
Order numbers, names, contact and delivery details, products, prices, status, carrier and tracking data come from connected shops or customer imports. They are not used for Kommerzdock marketing and are processed only on customer instructions.
6. Customer-selected AI (BYOK)
The customer selects and contracts with the AI provider and supplies its key. Kommerzdock sends the data shown for a function only after an active user request. Recipient name, address, phone, email and payment data are excluded by default.
Juchi Europe GmbH does not train models on customer content. Provider retention, training and transfers depend on its terms and customer settings. AI output is a draft requiring human review before publication.
7. Recipients and infrastructure
AWS provides cloud infrastructure, hosting, storage and application logs; primary region eu-central-1. Cloudflare provides DNS/CDN and may process IP and request metadata at its global edge. PayPal is not a current recipient.
8. International transfers
Our subprocessors must use an adequacy decision, EU SCCs or another Chapter V GDPR safeguard with supplementary measures where required. Customers assess providers they select and contract directly.
9. Retention and deletion
- Online account/business data: no later than 30 days after termination.
- Application/security logs: target 30 days.
- Backups: rolling-expiry target no later than 90 days.
- AI keys: connection period; deletion on disconnect/account deletion.
- Invoice/tax records: separate German statutory periods.
10. Cookies
Only essential authentication, security and user-requested interface storage is currently used. There are no website analytics or marketing trackers.
11. Rights
Subject to GDPR conditions, individuals may request access, correction, deletion, restriction and portability, object, or withdraw consent. Contact [email protected]. For merchant data, contact the merchant first.
12. Complaint
The competent private-sector authority is Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg: https://www.baden-wuerttemberg.datenschutz.de/.
13. Automated decisions
There are no solely automated decisions with legal or similarly significant effects. AI product content is a user-requested draft requiring human review.
14. Changes
The date and version appear above. Material changes will be notified in-app or by email where appropriate.