Back to home

Privacy Policy

Last updated: 28 July 2026

This policy explains what data Atlista OÜ processes, why, how long it is kept, who it is shared with, how it is protected, and how it is deleted. It covers both the Lisett Lees application and this website.

1. Who is responsible for your data

The data controller is:

  • Atlista OÜ
  • Põlva maakond, Põlva vald, Metste küla, Leesi, 63213, Estonia
  • Estonian registry code: 14403836
  • Email: hello@lisettlees.com

Atlista OÜ is an Estonian private limited company operated by Lisett Lees, providing freelance Amazon Advertising services. We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. Data protection enquiries go to the email address above.

2. What this policy covers

We process data in three distinct contexts, and they are treated differently:

  • Client advertising data — accessed through the Amazon Ads API on behalf of clients who have authorised us to manage their advertising accounts.
  • Business contact data — of prospective and existing clients who contact us.
  • Website visitors — this website sets no cookies and runs no analytics (see section 13), and its two forms send nothing to us on their own (see section 3.4).

3. What data we collect

3.1 Advertising data from the Amazon Ads API

When a client authorises the Lisett Lees application, we access the following categories of data from their Amazon advertising account:

CategoryExamples
Account identifiers Advertising profile IDs, marketplace, currency, account name, portfolio IDs
Campaign structure Campaigns, ad groups, product ads, keywords, product and audience targets, negative targets, bids, budgets, bidding strategies, states
Performance metrics Impressions, clicks, spend, orders, sales, units, conversion rate, ACOS, ROAS, cost per click, by day and by entity
Search-term data Customer search terms reported by Amazon against campaigns and keywords, with their aggregated performance
Product identifiers ASINs and SKUs that are advertised
Authorisation data OAuth access and refresh tokens issued by Amazon for the authorised account

What we never receive or store: we do not access shopper names, shipping or billing addresses, email addresses, phone numbers, payment details, or any other personally identifiable information about our clients' customers. Amazon's advertising reporting is aggregated, and the application does not request any scope that would expose buyer-level personal data. We also never collect our clients' Amazon login credentials — authorisation happens entirely on Amazon's own login screen.

3.2 Business contact data

If you email us or request a quote, we process the name, email address, company name and any details you choose to send us about your business — for example marketplaces, ASIN counts and advertising goals. If you become a client, we additionally process the contract and billing details required to invoice you.

3.3 Website visitors

This website is a static site. It sets no cookies, uses no local storage, embeds no third-party fonts, pixels or analytics, and does not profile visitors. Our hosting provider processes standard server request data (IP address, timestamp, requested URL, user agent) in short-lived technical logs, which is necessary to serve the site and protect it from abuse.

3.4 The forms on this website

This website has two forms: the quote configurator in the pricing section, and the general contact form. Both run entirely in your browser. What you enter is never transmitted to us or to anyone else by the website itself — each form only assembles your input into a draft message and hands that draft to your own email program, or to your clipboard if you choose to copy it instead. Nothing is stored, and nothing reaches us unless you personally send that email from your own mail account.

This is enforced technically, not just promised. The site's Content Security Policy sets connect-src 'none', which means the page is not permitted to make any network request at all — no form submission, no background upload, no third-party call is possible from it. The only script the site loads is our own form script, served from this domain.

Once you do send the email, we process what it contains as business contact data under section 3.2. Neither form sets a cookie or stores a draft.

4. Why we process this data, and on what legal basis

PurposeLegal basis (GDPR)
Managing and optimising a client's advertising account, and producing reporting Article 6(1)(b) — performance of our contract with the client
Storing and refreshing Amazon authorisation tokens so the app can operate Article 6(1)(b) — performance of the contract
Responding to enquiries and preparing quotes Article 6(1)(b) and Article 6(1)(f) — pre-contractual steps and our legitimate interest in responding
Keeping records for accounting and tax Article 6(1)(c) — legal obligation under Estonian law
Securing the application and detecting misuse Article 6(1)(f) — our legitimate interest in operating a secure service

5. What we do not do with advertising data

  • We do not sell, rent, license or trade advertising data.
  • We do not use one client's data to benchmark, advise or advantage another client.
  • We do not aggregate client data into market reports, indices or public datasets.
  • We do not use advertising data to train machine-learning models.
  • We do not use advertising data for our own advertising or marketing.
  • We do not transfer advertising data to any third party other than the infrastructure providers listed in section 7.

6. How the data is stored and protected

  • All data in transit is encrypted using HTTPS/TLS.
  • All data at rest is encrypted, including database storage and backups.
  • Amazon OAuth access and refresh tokens are stored encrypted and are never written to logs or displayed in the interface.
  • Access to the application and its data stores is restricted to Lisett Lees, protected by strong unique credentials and multi-factor authentication.
  • Each client's advertising data is logically separated, so it cannot be queried across accounts.
  • Write operations against the Amazon Ads API are recorded in an append-only change log, capturing what changed, when, and the previous value.
  • Software dependencies are kept current and security updates applied promptly.
  • Backups are encrypted and retained on a rolling, limited schedule.

No system can be guaranteed absolutely secure, but we apply the measures above as appropriate technical and organisational measures under Article 32 GDPR. If a personal data breach occurs that is likely to result in a risk to affected individuals, we will notify the Estonian Data Protection Inspectorate within 72 hours and inform affected clients without undue delay.

7. Who we share data with

We do not have a network of data recipients. Data is shared only with the infrastructure providers strictly necessary to run the service, each acting as a processor under a data processing agreement:

ProviderPurposeData location
Amazon Advertising (Amazon Europe Core S.à r.l. and affiliates) Source of the advertising data; the API we operate against Per Amazon's own terms
Vercel Inc. (United States) Hosting of the application, its database, and this website Data stored in Vercel's European region; delivered via a global content delivery network

We may also disclose data where we are legally required to do so, for example in response to a binding order from a competent authority.

8. International transfers

Advertising data is stored in Vercel's European region. However, Vercel Inc. is a company established in the United States, so it is capable of accessing that data from outside the European Economic Area, and content is delivered through a global network of edge locations. These transfers are covered by the data processing agreement we have in place with Vercel, which incorporates the European Commission's Standard Contractual Clauses. We will provide details of the relevant safeguard on request.

Amazon Advertising processes data according to its own terms and data protection commitments, which apply independently of ours.

9. How long we keep data

DataRetention period
Amazon OAuth access and refresh tokens Deleted immediately when an engagement ends or the client revokes authorisation
Advertising performance and campaign data For the duration of the engagement, plus up to 12 months afterwards for reporting continuity and year-on-year comparison. Deleted sooner on request.
Change log of write operations Up to 24 months, so past changes remain auditable
Enquiries that do not become engagements Up to 12 months
Invoices and accounting records 7 years, as required by Estonian accounting law
Website server logs Short-lived technical logs held by the hosting provider

10. Deleting your data

You can have your data deleted in two ways, and they work independently:

  • Revoke access at Amazon. You can withdraw the Lisett Lees application's authorisation from your Amazon account at any time, without telling us first. The app immediately loses the ability to read or write anything in your account.
  • Ask us to delete. Email hello@lisettlees.com and we will delete the advertising data we hold for your account, together with the stored tokens. Deletion is completed within 30 days of the request, and we confirm in writing once it is done.

The only data we retain after a deletion request is what we are legally obliged to keep — principally invoices and accounting records, for the statutory 7-year period. That data is not used for any other purpose.

11. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you, and receive a copy
  • Have inaccurate data corrected
  • Have your data erased ("right to be forgotten")
  • Restrict how we process your data
  • Receive your data in a portable, machine-readable format
  • Object to processing based on legitimate interests
  • Withdraw consent, where processing is based on consent

To exercise any of these, email hello@lisettlees.com. We respond within one month. There is no charge.

If you are not satisfied with how we handled your request, you can lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee/en, or with the supervisory authority in your own country of residence.

12. Our commitments regarding Amazon data

Atlista OÜ accesses Amazon advertising data solely through the official Amazon Ads API, and only for accounts whose owner has explicitly authorised us. In handling that data we comply with the Amazon Ads API terms, the Amazon Ads Partner Network policies, and Amazon's Acceptable Use and Data Protection policies. Specifically:

  • Data is used only to provide the advertising services the client engaged us for.
  • We request only the minimum API access needed for those services.
  • Data is not disclosed to any third party except as set out in section 7.
  • Data is deleted when it is no longer needed for the purpose it was collected for.
  • We do not attempt to re-identify individuals from aggregated Amazon reporting.

13. Cookies and tracking

This website uses no cookies, no local storage, no tracking pixels, no third-party fonts and no analytics. Nothing is loaded from an external domain. Because nothing is stored on your device and no profiling takes place, no cookie consent banner is required.

14. Children

The service is business-to-business. It is not directed at children and we do not knowingly process the data of anyone under 16.

15. Changes to this policy

If this policy changes materially, we update the date at the top of this page and, where the change affects an active engagement, notify the client directly by email. Earlier versions are available on request.

16. Contact

Atlista OÜ
Põlva maakond, Põlva vald, Metste küla, Leesi, 63213, Estonia
Estonian registry code: 14403836
Email: hello@lisettlees.com