Privacy Policy

Effective 2026-08-16 · Version 1.0

This policy explains how personal data is processed on the Kommerzdock website and SaaS service.

1. Controller

Juchi Europe GmbH, Gutenbergstraße 39/1, 72555 Metzingen, Germany. Managing Director: Haifeng Ma. Contact: [email protected], +49 7121 6952098. No DPO is named while the statutory appointment requirement remains under review.

2. Scope and roles

This covers website visitors, customer accounts and staff, and recipients or end customers whose data merchants import.

Juchi Europe GmbH is generally controller for website, account, contract, support, security and billing data. For merchant-imported order, recipient, logistics and product data, Kommerzdock generally acts as processor on the merchant's instructions under the DPA.

3. Website and security

IP address, time, route, browser/device data and security events are processed for delivery, security, abuse prevention and troubleshooting under Art. 6(1)(f) GDPR. Target retention: 30 days, with isolated longer retention for incidents, legal duties or legal holds.

4. Account and contract

Name, business email, company, account, plan and support data are processed to establish and perform the B2B contract under Art. 6(1)(b), (c) and (f) GDPR. Required registration and authentication data must be provided to open an account.

5. Order and recipient data

Order numbers, names, contact and delivery details, products, prices, status, carrier and tracking data come from connected shops or customer imports. They are not used for Kommerzdock marketing and are processed only on customer instructions.

6. Customer-selected AI (BYOK)

The customer selects and contracts with the AI provider and supplies its key. Kommerzdock sends the data shown for a function only after an active user request. Recipient name, address, phone, email and payment data are excluded by default.

Juchi Europe GmbH does not train models on customer content. Provider retention, training and transfers depend on its terms and customer settings. AI output is a draft requiring human review before publication.

7. Recipients and infrastructure

AWS provides cloud infrastructure, hosting, storage and application logs; primary region eu-central-1. Cloudflare provides DNS/CDN and may process IP and request metadata at its global edge. PayPal is not a current recipient.

8. International transfers

Our subprocessors must use an adequacy decision, EU SCCs or another Chapter V GDPR safeguard with supplementary measures where required. Customers assess providers they select and contract directly.

9. Retention and deletion

  • Online account/business data: no later than 30 days after termination.
  • Application/security logs: target 30 days.
  • Backups: rolling-expiry target no later than 90 days.
  • AI keys: connection period; deletion on disconnect/account deletion.
  • Invoice/tax records: separate German statutory periods.

10. Cookies

Only essential authentication, security and user-requested interface storage is currently used. There are no website analytics or marketing trackers.

11. Rights

Subject to GDPR conditions, individuals may request access, correction, deletion, restriction and portability, object, or withdraw consent. Contact [email protected]. For merchant data, contact the merchant first.

12. Complaint

The competent private-sector authority is Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg: https://www.baden-wuerttemberg.datenschutz.de/.

13. Automated decisions

There are no solely automated decisions with legal or similarly significant effects. AI product content is a user-requested draft requiring human review.

14. Changes

The date and version appear above. Material changes will be notified in-app or by email where appropriate.