Last updated: 5 September 2026
This website, azzrecovery.com (the “Website”), and the AzzRecovery service are operated by:
Azzgency SL (“AzzRecovery”, “we”, “us”)
Tax ID (CIF): B-88149067
Registered office: Calle Ana Mariscal 5, 28223 Pozuelo de Alarcón, Madrid, Spain
Email: privacy@azzrecovery.com
AzzRecovery is a trading name of Azzgency SL, part of Azzgency Group.
If you have any question about how we handle personal data, write to privacy@azzrecovery.com. You do not need to justify your request or send a copy of your ID document to contact us.
This is the most important section of this policy. Depending on the data involved, we act in one of two different legal capacities.
We are the controller of personal data relating to:
This policy governs those activities in full.
When you engage our recovery services, we access your Amazon Vendor Central account under a limited-permission invitation in order to audit deductions, build disputes and track credits.
The data we extract and process is transactional, not personal: invoice and purchase order numbers, ASINs, quantities, amounts, dates, deduction reason codes, remittance lines and claim statuses. None of it identifies an individual.
The only personal data we process in connection with your account is the business contact details of the people you designate as our contacts — name, business email address, phone number and job role — used to administer the engagement and to communicate with you.
We do not extract, store, request or use delivery documentation, proofs of delivery, carrier or driver records, or the identity of any Amazon personnel. Some personal data may nevertheless be incidentally visible in the Vendor Central interface we access — for example the user list of your account, or names appearing in case correspondence. We do not download, retain, process or make any use of that data.
In relation to the data described in this section we act as a processor on your behalf. You remain the controller. Our processing is governed not by this policy but by the Data Processing Agreement (DPA) we sign with you, which sets out the subject matter, duration, nature and purpose of the processing, the categories of data and data subjects, our security obligations, our use of sub-processors, breach notification, assistance with data subject rights, and the return or deletion of data when our engagement ends.
The DPA is signed before we are given any access, together with the NDA and before the free audit begins. You can request a copy of our standard DPA at any time from privacy@azzrecovery.com.
Section 12 sets out how we handle client account data in that capacity.
Where | Data |
Free audit form | First and last name, work email, phone number, company name, job role, country, annual Amazon Vendor revenue band, Amazon marketplaces |
Recovery estimator | None — the estimate is calculated in your browser and no data is sent to us |
Contact form / email | Name, work email, phone, company, and the content of your message and our reply |
Partner programme | Name, work email, company, website, country, business model, client portfolio information |
Careers | The data contained in your CV and application |
Client onboarding | Contact details of your designated contacts, and the signatory data on our contracts |
Standard web server logs record IP address, browser and device type, operating system, referring URL and the pages requested, for security and to keep the Website running. Beyond that, we use Google Analytics 4 and Google Ads, loaded through Google Tag Manager, to measure audience and campaign performance — device and browser type, language, referring URL, pages viewed, time on page and interaction events. These are collected only to the extent you have consented through our cookie banner. See our Cookie Policy for the full list and for how to change your choices.
We may obtain business contact data from public professional sources (company websites, professional networks, business registries, trade publications) for direct B2B outreach, and from partners who refer you to us. Where we do, we tell you the source in our first communication and give you a one-click way to opt out.
We do not collect special categories of data (health, biometrics, political opinions, trade union membership or similar) and ask you not to send them to us.
Purpose | Legal basis (GDPR Art. 6) | Retention |
Operating and securing the Website | Legitimate interest — running a safe, functioning site | Server logs: 12 months |
Responding to your free audit request, contact form or call booking | Steps taken at your request prior to entering a contract (Art. 6.1.b) | 24 months from last contact, unless you become a client |
Preparing and delivering the free audit report | Pre-contractual steps (Art. 6.1.b) + our DPA where account data is involved | Report and supporting extract: 12 months if no contract follows, then deleted |
Providing the recovery service and administering the contract | Performance of a contract (Art. 6.1.b) | Duration of the contract |
Invoicing, accounting and tax records | Legal obligation (Art. 6.1.c) — Spanish commercial and tax law | 6 years (Commercial Code), 4 years from the end of the limitation period for tax purposes |
Marketing emails and commercial communications | Consent (Art. 6.1.a); or legitimate interest for existing clients on similar services, under Art. 21.2 LSSI | Until you withdraw consent or object |
B2B outreach to business contacts | Legitimate interest (Art. 6.1.f), balanced against your rights and limited to business roles and business contact details | 12 months from last engagement, or until you object |
Analytics and audience measurement | Consent (Art. 6.1.a) | Per the Cookie Policy |
Advertising and remarketing | Consent (Art. 6.1.a) | Per the Cookie Policy |
Partner programme applications | Pre-contractual steps (Art. 6.1.b) | 24 months |
Recruitment | Pre-contractual steps (Art. 6.1.b) and consent for talent pool retention | 12 months, extendable only with your consent |
Establishing, exercising or defending legal claims | Legitimate interest (Art. 6.1.f) | Until the relevant limitation period expires |
Where we rely on legitimate interest, we have carried out and documented a balancing assessment. You may request a summary of it at privacy@azzrecovery.com, and you have the right to object at any time (Section 9).
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Our recovery estimator is an indicative calculator based on aggregate historical ranges; it does not evaluate you personally and produces no decision about you.
Our audit technology processes account transaction data at scale to flag potentially recoverable deductions, but every claim is reviewed and filed by a member of our team.
We share personal data only with:
Service providers acting as our processors, each under a written contract meeting Article 28 GDPR:
Category | Purpose |
Website hosting and CDN | Operating the Website — Amazon Web Services (AWS), data hosted in the EU (eu-west-1, Ireland) |
Email and productivity | Business communications — Google Workspace |
CRM and marketing automation | Managing enquiries and communications — Pipedrive (website contact forms and CRM) |
Analytics | Audience measurement — Google Analytics 4, loaded via Google Tag Manager |
Advertising platforms | Campaign delivery and measurement — Google Ads, loaded via Google Tag Manager |
Accounting and billing | Invoicing and statutory records — our external accounting and tax adviser |
E-signature | Contract execution — our e-signature provider |
The current list of sub-processors used in the delivery of our recovery services is provided on request from privacy@azzrecovery.com and forms part of our DPA. Clients are notified in advance of any change and may object.
Other Azzgency Group entities, where necessary to deliver a service you have requested in a market covered by a local group entity, on the basis of an intra-group data transfer agreement.
Amazon, where you have instructed us to act on your behalf in your Vendor Central account. Amazon acts as an independent controller in respect of its own processing, under its own terms and privacy notice.
Public authorities, courts, auditors and legal advisers, where required by law or necessary to establish, exercise or defend legal claims.
We never sell personal data, and we never share it with third parties for their own marketing purposes.
Our primary infrastructure and the data we process in delivering the recovery service are located within the European Economic Area.
Some of our providers, and some Azzgency Group entities and team members supporting clients in the United States, Mexico and Brazil, are located outside the EEA. Where personal data is transferred outside the EEA, we rely on:
You may request a copy of the safeguards applied to a specific transfer at privacy@azzrecovery.com.
Transfers of client account data processed under our DPA are governed by the transfer terms of that agreement, and clients are informed of the location of processing before onboarding.
We maintain technical and organisational measures appropriate to the risk, including:
Our information security certification status and full security documentation are available on request from privacy@azzrecovery.com.
Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, we notify the Spanish Data Protection Agency (AEPD) within 72 hours of becoming aware of it, and affected individuals without undue delay where the risk is high. Where we act as a processor, we notify the client controller without undue delay.
No transmission over the internet can be guaranteed to be entirely secure, but we apply industry-standard measures to protect data in transit and once received.
You have the right to:
To exercise any of these rights, write to privacy@azzrecovery.com. We will respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month.
We will not ask for a copy of your identity document as a matter of routine. We will only request additional information if we have reasonable doubts about your identity, and only what is strictly necessary to resolve that doubt.
Complaints. If you believe we have not handled your data correctly, you may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos), C/ Jorge Juan 6, 28001 Madrid — www.aepd.es — or with the supervisory authority of your country of residence. We would appreciate the opportunity to address your concern first.
If your personal data sits inside a client’s Vendor Central account and we process it as a processor, please direct your request to that client, who is the controller. If you contact us, we will forward it to them without undue delay and assist them in responding.
We keep personal data only for as long as necessary for the purpose it was collected for, as set out in Section 4. When a retention period ends, we delete the data or irreversibly anonymise it.
Data may be retained beyond those periods, blocked and accessible only to competent authorities, for as long as liability arising from the processing may be enforced.
We use strictly necessary technical cookies to operate the Website, and analytics and advertising cookies only where you consent through our cookie banner. Before you choose, Google’s tags run in a restricted, cookie-less mode. You can change or withdraw your preferences at any time through the “Manage consent” link at the bottom of any page.
Full details of every cookie, its purpose, provider and duration are set out in our Cookie Policy.
Because this is the question our clients ask most often, we set it out here in summary. The binding terms are in the DPA.
Access. We request a Vendor Central invitation with limited permissions, scoped to deduction, remittance and dispute data. We do not request or use access to pricing, catalogue, purchase order management or advertising functions. We do not install software in your environment, and we do not connect via API or EDI unless you specifically ask us to.
Data scope. What we extract is transactional data — invoice and PO numbers, ASINs, quantities, amounts, dates, deduction reason codes, remittance lines and claim statuses. The only personal data we hold in connection with your account is the business contact details of the people you designate. We do not extract or retain delivery documentation, proofs of delivery, carrier or driver records, or the identity of Amazon personnel, and we do not process any end-customer data.
Purpose limitation. We process your account data only to audit deductions, prepare and file disputes, track credits and report to you. We do not use it for any other purpose, do not use it to train models, and do not use it for our own commercial analysis or benchmarking unless you have separately agreed in writing to the use of anonymised aggregate data.
People. Access is limited to the named team assigned to your account. All personnel are bound by confidentiality obligations that survive termination.
Sub-processors. Provided on request from privacy@azzrecovery.com. We give advance notice of changes and you may object.
Retention and deletion. We hold your account data for the duration of the engagement plus the period needed to complete claims already filed and to substantiate our invoicing. On termination, we return or delete the data at your choice within 30 days, retaining only what law requires us to keep.
Your rights as controller. You may audit our compliance, request assistance with data subject requests, and require our cooperation on impact assessments and prior consultations, on the terms set out in the DPA.
Our services are directed exclusively at businesses and professionals. The Website is not intended for anyone under 18, and we do not knowingly collect their data. If you believe a minor has provided us with personal data, write to privacy@azzrecovery.com and we will delete it.
We may update this policy to reflect changes in our services, our providers or applicable law. The version in force is always the one published here, with its date at the top. Where a change is material, we will notify registered users and clients by email at least 30 days before it takes effect.
Previous versions are available on request.
The Website may link to sites we do not control. This policy does not apply to them, and we are not responsible for their privacy practices. We recommend reading their policies before providing them with any data.