Privacy Policy

Privacy Policy

Last updated: 5 September 2026

1. Who we are

This website, azzrecovery.com (the “Website”), and the AzzRecovery service are operated by:

Azzgency SL (“AzzRecovery”, “we”, “us”)
Tax ID (CIF): B-88149067
Registered office: Calle Ana Mariscal 5, 28223 Pozuelo de Alarcón, Madrid, Spain
Email: privacy@azzrecovery.com

AzzRecovery is a trading name of Azzgency SL, part of Azzgency Group.

If you have any question about how we handle personal data, write to privacy@azzrecovery.com. You do not need to justify your request or send a copy of your ID document to contact us.

2. Scope — and the two roles we act in

This is the most important section of this policy. Depending on the data involved, we act in one of two different legal capacities.

2.1 As a data controller

We are the controller of personal data relating to:

  • visitors to this Website;
  • people who request a free audit, use the recovery estimator, contact us, or subscribe to our communications;
  • contact persons at our client, prospect and supplier companies;
  • applicants to our partner programme;
  • job applicants.

This policy governs those activities in full.

2.2 As a data processor

When you engage our recovery services, we access your Amazon Vendor Central account under a limited-permission invitation in order to audit deductions, build disputes and track credits.

The data we extract and process is transactional, not personal: invoice and purchase order numbers, ASINs, quantities, amounts, dates, deduction reason codes, remittance lines and claim statuses. None of it identifies an individual.

The only personal data we process in connection with your account is the business contact details of the people you designate as our contacts — name, business email address, phone number and job role — used to administer the engagement and to communicate with you.

We do not extract, store, request or use delivery documentation, proofs of delivery, carrier or driver records, or the identity of any Amazon personnel. Some personal data may nevertheless be incidentally visible in the Vendor Central interface we access — for example the user list of your account, or names appearing in case correspondence. We do not download, retain, process or make any use of that data.

In relation to the data described in this section we act as a processor on your behalf. You remain the controller. Our processing is governed not by this policy but by the Data Processing Agreement (DPA) we sign with you, which sets out the subject matter, duration, nature and purpose of the processing, the categories of data and data subjects, our security obligations, our use of sub-processors, breach notification, assistance with data subject rights, and the return or deletion of data when our engagement ends.

The DPA is signed before we are given any access, together with the NDA and before the free audit begins. You can request a copy of our standard DPA at any time from privacy@azzrecovery.com.

Section 12 sets out how we handle client account data in that capacity.

3. What personal data we collect

3.1 Data you give us

Where

Data

Free audit form

First and last name, work email, phone number, company name, job role, country, annual Amazon Vendor revenue band, Amazon marketplaces

Recovery estimator

None — the estimate is calculated in your browser and no data is sent to us

Contact form / email

Name, work email, phone, company, and the content of your message and our reply

Partner programme

Name, work email, company, website, country, business model, client portfolio information

Careers

The data contained in your CV and application

Client onboarding

Contact details of your designated contacts, and the signatory data on our contracts

3.2 Data we collect automatically

Standard web server logs record IP address, browser and device type, operating system, referring URL and the pages requested, for security and to keep the Website running. Beyond that, we use Google Analytics 4 and Google Ads, loaded through Google Tag Manager, to measure audience and campaign performance — device and browser type, language, referring URL, pages viewed, time on page and interaction events. These are collected only to the extent you have consented through our cookie banner. See our Cookie Policy for the full list and for how to change your choices.

3.3 Data from third parties

We may obtain business contact data from public professional sources (company websites, professional networks, business registries, trade publications) for direct B2B outreach, and from partners who refer you to us. Where we do, we tell you the source in our first communication and give you a one-click way to opt out.

We do not collect special categories of data (health, biometrics, political opinions, trade union membership or similar) and ask you not to send them to us.

4. Why we use your data, and on what legal basis

Purpose

Legal basis (GDPR Art. 6)

Retention

Operating and securing the Website

Legitimate interest — running a safe, functioning site

Server logs: 12 months

Responding to your free audit request, contact form or call booking

Steps taken at your request prior to entering a contract (Art. 6.1.b)

24 months from last contact, unless you become a client

Preparing and delivering the free audit report

Pre-contractual steps (Art. 6.1.b) + our DPA where account data is involved

Report and supporting extract: 12 months if no contract follows, then deleted

Providing the recovery service and administering the contract

Performance of a contract (Art. 6.1.b)

Duration of the contract

Invoicing, accounting and tax records

Legal obligation (Art. 6.1.c) — Spanish commercial and tax law

6 years (Commercial Code), 4 years from the end of the limitation period for tax purposes

Marketing emails and commercial communications

Consent (Art. 6.1.a); or legitimate interest for existing clients on similar services, under Art. 21.2 LSSI

Until you withdraw consent or object

B2B outreach to business contacts

Legitimate interest (Art. 6.1.f), balanced against your rights and limited to business roles and business contact details

12 months from last engagement, or until you object

Analytics and audience measurement

Consent (Art. 6.1.a)

Per the Cookie Policy

Advertising and remarketing

Consent (Art. 6.1.a)

Per the Cookie Policy

Partner programme applications

Pre-contractual steps (Art. 6.1.b)

24 months

Recruitment

Pre-contractual steps (Art. 6.1.b) and consent for talent pool retention

12 months, extendable only with your consent

Establishing, exercising or defending legal claims

Legitimate interest (Art. 6.1.f)

Until the relevant limitation period expires

Where we rely on legitimate interest, we have carried out and documented a balancing assessment. You may request a summary of it at privacy@azzrecovery.com, and you have the right to object at any time (Section 9).

5. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Our recovery estimator is an indicative calculator based on aggregate historical ranges; it does not evaluate you personally and produces no decision about you.

Our audit technology processes account transaction data at scale to flag potentially recoverable deductions, but every claim is reviewed and filed by a member of our team.

6. Who we share data with

We share personal data only with:

Service providers acting as our processors, each under a written contract meeting Article 28 GDPR:

Category

Purpose

Website hosting and CDN

Operating the Website — Amazon Web Services (AWS), data hosted in the EU (eu-west-1, Ireland)

Email and productivity

Business communications — Google Workspace

CRM and marketing automation

Managing enquiries and communications — Pipedrive (website contact forms and CRM)

Analytics

Audience measurement — Google Analytics 4, loaded via Google Tag Manager

Advertising platforms

Campaign delivery and measurement — Google Ads, loaded via Google Tag Manager

Accounting and billing

Invoicing and statutory records — our external accounting and tax adviser

E-signature

Contract execution — our e-signature provider

The current list of sub-processors used in the delivery of our recovery services is provided on request from privacy@azzrecovery.com and forms part of our DPA. Clients are notified in advance of any change and may object.

Other Azzgency Group entities, where necessary to deliver a service you have requested in a market covered by a local group entity, on the basis of an intra-group data transfer agreement.

Amazon, where you have instructed us to act on your behalf in your Vendor Central account. Amazon acts as an independent controller in respect of its own processing, under its own terms and privacy notice.

Public authorities, courts, auditors and legal advisers, where required by law or necessary to establish, exercise or defend legal claims.

We never sell personal data, and we never share it with third parties for their own marketing purposes.

7. International transfers

Our primary infrastructure and the data we process in delivering the recovery service are located within the European Economic Area.

Some of our providers, and some Azzgency Group entities and team members supporting clients in the United States, Mexico and Brazil, are located outside the EEA. Where personal data is transferred outside the EEA, we rely on:

  • an adequacy decision of the European Commission, where one exists for the destination country; or
  • the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914), supplemented where necessary by additional technical and organisational measures following a documented transfer impact assessment.

You may request a copy of the safeguards applied to a specific transfer at privacy@azzrecovery.com.

Transfers of client account data processed under our DPA are governed by the transfer terms of that agreement, and clients are informed of the location of processing before onboarding.

8. Security

We maintain technical and organisational measures appropriate to the risk, including:

  • encryption of data in transit and at rest;
  • role-based access control, with access to client account data restricted to the named team assigned to that client and reviewed periodically;
  • multi-factor authentication on all systems holding client or personal data;
  • logging of access to client account data;
  • segregation of client data;
  • confidentiality undertakings binding on all personnel;
  • documented backup, retention and secure deletion procedures;
  • a documented incident response and breach notification procedure;
  • periodic security testing and supplier assessment.

Our information security certification status and full security documentation are available on request from privacy@azzrecovery.com.

Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, we notify the Spanish Data Protection Agency (AEPD) within 72 hours of becoming aware of it, and affected individuals without undue delay where the risk is high. Where we act as a processor, we notify the client controller without undue delay.

No transmission over the internet can be guaranteed to be entirely secure, but we apply industry-standard measures to protect data in transit and once received.

9. Your rights

You have the right to:

  • access the personal data we hold about you;
  • rectify inaccurate or incomplete data;
  • erase your data (“right to be forgotten”), where the conditions apply;
  • restrict processing in the circumstances set out in Article 18 GDPR;
  • data portability — receive data you provided to us in a structured, machine-readable format, and have it transmitted to another controller where technically feasible;
  • object to processing based on legitimate interest, including profiling; and to object at any time, absolutely and without justification, to processing for direct marketing;
  • withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
  • not be subject to decisions based solely on automated processing producing legal or similarly significant effects.
 

To exercise any of these rights, write to privacy@azzrecovery.com. We will respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month.

We will not ask for a copy of your identity document as a matter of routine. We will only request additional information if we have reasonable doubts about your identity, and only what is strictly necessary to resolve that doubt.

Complaints. If you believe we have not handled your data correctly, you may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos), C/ Jorge Juan 6, 28001 Madrid — www.aepd.es — or with the supervisory authority of your country of residence. We would appreciate the opportunity to address your concern first.

If your personal data sits inside a client’s Vendor Central account and we process it as a processor, please direct your request to that client, who is the controller. If you contact us, we will forward it to them without undue delay and assist them in responding.

10. Retention

We keep personal data only for as long as necessary for the purpose it was collected for, as set out in Section 4. When a retention period ends, we delete the data or irreversibly anonymise it.

Data may be retained beyond those periods, blocked and accessible only to competent authorities, for as long as liability arising from the processing may be enforced.

11. Cookies

We use strictly necessary technical cookies to operate the Website, and analytics and advertising cookies only where you consent through our cookie banner. Before you choose, Google’s tags run in a restricted, cookie-less mode. You can change or withdraw your preferences at any time through the “Manage consent” link at the bottom of any page.

Full details of every cookie, its purpose, provider and duration are set out in our Cookie Policy.

12. Client account data — how we handle it as a processor

Because this is the question our clients ask most often, we set it out here in summary. The binding terms are in the DPA.

Access. We request a Vendor Central invitation with limited permissions, scoped to deduction, remittance and dispute data. We do not request or use access to pricing, catalogue, purchase order management or advertising functions. We do not install software in your environment, and we do not connect via API or EDI unless you specifically ask us to.

Data scope. What we extract is transactional data — invoice and PO numbers, ASINs, quantities, amounts, dates, deduction reason codes, remittance lines and claim statuses. The only personal data we hold in connection with your account is the business contact details of the people you designate. We do not extract or retain delivery documentation, proofs of delivery, carrier or driver records, or the identity of Amazon personnel, and we do not process any end-customer data.

Purpose limitation. We process your account data only to audit deductions, prepare and file disputes, track credits and report to you. We do not use it for any other purpose, do not use it to train models, and do not use it for our own commercial analysis or benchmarking unless you have separately agreed in writing to the use of anonymised aggregate data.

People. Access is limited to the named team assigned to your account. All personnel are bound by confidentiality obligations that survive termination.

Sub-processors. Provided on request from privacy@azzrecovery.com. We give advance notice of changes and you may object.

Retention and deletion. We hold your account data for the duration of the engagement plus the period needed to complete claims already filed and to substantiate our invoicing. On termination, we return or delete the data at your choice within 30 days, retaining only what law requires us to keep.

Your rights as controller. You may audit our compliance, request assistance with data subject requests, and require our cooperation on impact assessments and prior consultations, on the terms set out in the DPA.

13. Minors

Our services are directed exclusively at businesses and professionals. The Website is not intended for anyone under 18, and we do not knowingly collect their data. If you believe a minor has provided us with personal data, write to privacy@azzrecovery.com and we will delete it.

14. Changes to this policy

We may update this policy to reflect changes in our services, our providers or applicable law. The version in force is always the one published here, with its date at the top. Where a change is material, we will notify registered users and clients by email at least 30 days before it takes effect.

Previous versions are available on request.

15. Third-party websites

The Website may link to sites we do not control. This policy does not apply to them, and we are not responsible for their privacy practices. We recommend reading their policies before providing them with any data.