Privacyverklaring

Wij respecteren je privacy en gaan zorgvuldig om met persoonsgegevens. Op deze pagina leggen we uit welke gegevens we verzamelen en verwerken, waarom we dat doen, hoe lang we gegevens bewaren, met wie we gegevens delen, en hoe we gegevens beveiligen.

English version below (for Amazon SP-API and international compliance).

Privacy & Data Handling Policy

Website
Company
BRR
Address
Hullerpad 26B
Chamber of Commerce (KVK)
09094315
VAT number
NL806446134B01
Last updated
2026-01-20

1. Scope

This Privacy & Data Handling Policy explains how BRR Nederland / Black Rhythm Records (“we”, “us”, “our”) collects, processes, stores, uses, shares, and disposes of personal data.

This policy also covers data obtained through Amazon Selling Partner API (SP-API) and/or Seller Central that may include Personally Identifiable Information (PII), such as buyer name, address, telephone number, email address, and order-related information.

2. Categories of personal data we process

Depending on how you interact with us, we may process the following categories of personal data:

2.1 Customer and order information

2.2 Amazon SP-API data

If we sell products through Amazon marketplaces, we may process Amazon customer/order data provided through SP-API for:

We do not use Amazon PII for marketing or profiling.

2.3 Website usage data (if applicable)

We only process personal data for legitimate business purposes, including:

  1. Order fulfillment and delivery
    prepare shipment, generate shipping labels, handle carrier handover
  2. Customer service
    respond to delivery issues, returns, questions, complaints
  3. Compliance with legal obligations
    tax/accounting retention requirements, fraud prevention, dispute handling
  4. Security and integrity
    protect systems, detect unauthorized access or misuse Legal bases include:

4. Data minimization and acceptable use

We follow the principles of:

Amazon SP-API restricted data (PII) is used strictly for operational purposes related to Amazon selling activities.

5. How data is collected

We may collect personal data through:

6. Storage and processing

Personal data is processed and stored within company-controlled systems, including:

Where possible, sensitive data is not stored longer than necessary and is removed/anonymized after its operational use.

7. Data sharing and third parties

We only share personal data when necessary for operational purposes, including:

7.1 Logistics and carriers

We may share limited personal data with shipping carriers (e.g., name/address) to deliver orders.

7.2 Service providers (if applicable)

We may use service providers for hosting, backups, or security. When used, such providers are bound by confidentiality and data protection obligations.

We do not sell personal data.

8. Data retention and disposal

We retain personal data only as long as necessary.

8.1 Operational retention (server/application)

Certain data such as invoices and accounting records are retained for the legally required period.

8.3 Disposal

At the end of retention:

9. Security controls (technical and organizational measures)

We take security seriously and apply measures to protect personal data against unauthorized access, disclosure, alteration, or destruction.

9.1 Access controls (least privilege)

9.2 Encryption

9.3 Logging and monitoring

We log and monitor relevant security events, including:

Suspicious activity triggers investigation and containment procedures.

9.4 Credential and password management

9.5 Incident response

We maintain an incident response process including:

10. International transfers

Where data is processed outside the EU/EEA by third parties (if applicable), appropriate safeguards are applied.

11. Your rights

Depending on applicable law (e.g., GDPR), you may have rights such as:

Requests can be submitted via: privacy@< domein >. nl

12. Changes to this policy

We may update this policy periodically. The most recent version will always be published on this page.