Trust Center

Security, privacy, and compliance at DataDoe.

A single place for everything that governs how we build, operate, and protect DataDoe — the policies you agree to, how we handle your data, who we work with to deliver the service, and the controls that keep it all together.

EncryptionAES-256-GCM · TLS 1.3At rest and in transit, everywhere
ComplianceGDPR · UK GDPR · CCPADPA with EU SCCs and UK IDTA
AmazonSP-API Data Protection PolicyPII access opt-in, 30-day deletion
Breach SLA48-hour notificationDocumented incident response plan
01 — What we cover

Four pillars of trust.

Concrete controls and commitments, not marketing language. Every claim below maps to a specific clause in our Terms of Service, Privacy Policy, or DPA.

Security

  • AES-256-GCM at rest, TLS 1.3 in transit
  • MFA enforced for all admin & cloud access
  • Secrets in AWS Secrets Manager, never in code
  • Least-privilege IAM, quarterly access reviews
  • 12-month audit log retention
  • Dark-web monitoring on company assets

Privacy

  • Never sell or share your data — ever
  • No AI/ML training on customer data
  • PII is opt-in; default accounts get no PII
  • 30-day deletion after account termination
  • Buyer PII deleted within 30 days of delivery
  • Tenant isolation & data attribution at source

Compliance

  • GDPR, UK GDPR, and CCPA aligned
  • Amazon SP-API Data Protection Policy assessment
  • Article 28 DPA with EU SCCs & UK IDTA
  • CCPA Service Provider contractual terms
  • Controls referenced to ISO 27001 / NIST CSF
  • CCPA opt-out via Global Privacy Control signal

Transparency

  • Full public subprocessor list with regions
  • Right to object under the DPA
  • Self-serve DPA download — no sales gating
  • 48-hour security breach notification
  • Public policy effective dates & version notes
  • Direct contact line, no ticket maze
02 — Policies & agreements

The contracts behind the platform.

Plain English where possible, legal precision where it matters. Each document is versioned and timestamped; material changes are emailed to you in advance.

03 — Frequently asked

Direct answers to the questions buyers ask.

If something isn't covered here, email contact@datadoe.com. Security questionnaires and bespoke compliance questions are welcomed.

Where is my data stored?

All customer data — including Amazon Information — is stored and processed on AWS and GCP infrastructure located in the United States.

Encryption: AES-256-GCM at rest, TLS 1.3 in transit. Secrets and API keys are stored in AWS Secrets Manager and never hardcoded in source.

Do you sell my data or share it with third parties?

No. DataDoe does not sell, rent, or license customer data or Amazon Information for any purpose.

We share data only with vetted subprocessors — AWS, GCP, Stripe, AWS RUM, and AI inference providers (Anthropic, OpenAI, Google) — each contractually bound to use it only to deliver the specific service we contract for. The full list is in our Privacy Policy.

Do you use my data to train AI or machine-learning models?

No. Your data is never used to train AI/ML models — not our own, and not those of any third-party AI provider we route inference through.

AI inference is per-request and ephemeral. Prompts and responses are not retained by inference providers for model improvement.

Do you offer a Data Processing Addendum (DPA)?

Yes. Our DPA is GDPR Article 28-compliant and incorporates the EU Standard Contractual Clauses (Module 2, Controller-to-Processor) and the UK International Data Transfer Addendum.

You can read or download the DPA directly — no sales gating. Counter-signed copies are available on request to contact@datadoe.com.

How long do you keep my data?

Customer data: retained for the duration of your subscription plus 30 days after termination, after which it is permanently deleted from our active systems. Backups are overwritten on standard rotation.

Buyer PII from Amazon orders: retained no longer than 30 days after order delivery, in line with Amazon's SP-API Data Protection Policy.

Security & audit logs: retained for a minimum of 12 months, scrubbed of PII where not legally required.

How is buyer PII from Amazon orders handled?

By default, DataDoe accounts do not receive buyer PII from Amazon's APIs. PII fields (customer names, shipping addresses) are only retrieved when you explicitly enable the Amazon PII access add-on.

When enabled, PII is retained no longer than 30 days after order delivery, in line with Amazon's SP-API Data Protection Policy. PII is tagged at the source for data attribution and isolated per tenant.

What happens if there's a security incident?

DataDoe maintains a documented Incident Management Plan covering detection, classification, containment, eradication, recovery, and post-incident review. The plan is reviewed every six months and after any material infrastructure change.

If we become aware of a confirmed security incident affecting your data, we notify you without undue delay — within 48 hours of confirmed awareness — with information sufficient for you to meet your own notification obligations (such as the 72-hour GDPR deadline).

Who are your subprocessors?

AWS (hosting, storage, secrets), Google Cloud Platform (BigQuery dataset sharing), Stripe (payments), AWS RUM (observability), and Anthropic, OpenAI, and Google for AI model inference. All based in the United States.

List in our Privacy Policy and DPA Annex C. The list is updated when a change occurs; customers can monitor it directly and have a right to object under the DPA.

What encryption do you use?

At rest: AES-256-GCM on all AWS and GCP storage. In transit: HTTPS with TLS 1.3 on internal and external networks.

Secrets, API keys, and database credentials are stored in AWS Secrets Manager — never hardcoded in source. S3 buckets enforce Secure Transport; public access is blocked at the account level.

How do I exercise my GDPR or CCPA rights?

Email contact@datadoe.com with the right you want to exercise: access, correction, deletion, restriction, portability, opt-out of sale or sharing, or withdrawal of consent.

We respond to verified requests within the timeframes required by applicable law. Full details of your rights are in our Privacy Policy. Customers acting as data controllers should also see the DPA Section 8.

Contact

Questions or a security questionnaire?

For anything related to these policies, your data, security questionnaires, or vendor due diligence, reach out below. We respond to legitimate security and compliance requests within two business days.

CompanyDataDoe, Inc.
Address1111B S Governors Ave
STE 29271
Dover, DE 19904, USA