Privacy policy
What data we process, why, on what legal basis and for how long. No hidden clauses: if a seller is going to invoice through a partner, they are entitled to read this before the first meeting.
1. Independent entity declaration
zeOOs by Precode is operated by an independent Portuguese entity, identified in section 13. We are not partners, representatives, agents or resellers of any marketplace.
When we operate a seller account on a marketplace, we do so on that seller's behalf and with the authorisation they themselves grant. Marketplace brands and names appearing on this site are descriptive references to the channels we work with — they do not indicate partnership, sponsorship or endorsement by them.
2. Our role in processing
We have two distinct roles, and the distinction matters because it changes who answers for what.
- Controller — of the data you leave us on this site, and of your account data as a client. We decide what it is for and how long it stays.
- Processor — of the order data we handle on a seller's behalf. There the seller is the controller: we act on their instruction, within the contract, and put the data to no use of our own.
The purposes, legal bases and retention periods for each processing activity are in the table in section 8.
3. What data we collect, and how
We collect data in three distinct situations, and they are three different sets.
- From the form on this site, filled in by you: name, company, email, phone, website address, catalogue size, channels and countries you sell in, the system or integrator you use, and whatever you write in the message.
- While you are a client, provided by you: your account data and that of the people on your team who use the platform.
- When we operate your channels, handed over by the marketplaces: the order data — buyer name and address, delivery contacts and, where applicable, tax data for invoicing.
4. How we use Amazon data
When operating your Amazon account, the platform accesses the Selling Partner API with the authorisation the seller themselves grants, and only for the roles that operation requires: retrieving orders, preparing shipment and, where applicable, the tax data for invoicing on your behalf.
Personal order data obtained that way is not used for marketing, does not feed public aggregate analytics and is not shared beyond what the operation requires. It is deleted within 30 days of delivery, save where the law requires retention — tax law in particular.
The application registered with Amazon for this purpose is called Precode Zeoos.
5. Who accesses the data internally
Access is individual and limited to what the role requires.
- Each person has their own credentials. There are no shared accounts.
- Access requires multi-factor authentication and is reviewed periodically.
- People who leave lose access.
- Our processors — hosting and infrastructure — handle data on our instruction, under contract, and are not permitted any use of their own.
6. Restrictions and prohibitions
What we never do with the data, regardless of who asks.
- We do not sell, rent or transfer personal data to third parties.
- We do not use buyer data from your orders for our own marketing, nor to contact those buyers.
- We do not cross one client's data with another's.
- We do not use personal data to train artificial intelligence models.
- We do not extract marketplace data by unauthorised means, nor use it for any purpose other than operating on your behalf.
When we use language models to support the operation — for example, drafting a reply to a support request — personal data is masked before it leaves our systems.
7. Incident response plan
We have a named point of contact for security incidents, listed in section 13. If you find a vulnerability, write to us there.
Faced with an incident involving personal data, we notify the supervisory authority within 72 hours and, where the risk to data subjects is high, notify them as well. Where the incident involves data obtained through a marketplace, we additionally meet that channel's notification deadline — in Amazon's case, 24 hours.
8. Retention and deletion
Every purpose has a period. Once it passes, the data is deleted, save where the law requires retention.
Purposes, legal basis and retention
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Replying to a contact request | Name, company, email, phone, site, catalogue, channels, countries, system, message | Pre-contractual steps at the data subject's request | 24 months from last contact |
| Managing the client relationship | Account and contact data for the client's team | Performance of the contract | For the life of the contract, plus the legal period |
| Operating orders on the seller's behalf | Buyer name and address, delivery contacts | Performance of the contract (as the seller's processor) | Up to 30 days after delivery |
| Invoicing on the seller's behalf, where applicable | Tax data for the order | Legal obligation of the seller | The applicable tax period |
| Operational metrics and service improvement | Aggregate data, no buyer identification | Legitimate interest | Up to 18 months |
| Security and access logs | Technical logs, IP address | Legitimate interest | 12 months |
9. Transfers outside the European Union
Part of the technical team operates from Brazil, in Maringá. That means some data may be accessed from outside the European Economic Area.
Those transfers are made under the standard contractual clauses approved by the European Commission, with the technical and organisational measures that accompany them. You can ask us for a copy of the applicable safeguards through the contact in section 13.
10. Security
Information is encrypted in transit and at rest, database access is not publicly exposed, and security logs are retained so that an incident can be investigated.
12. Your rights
Under the General Data Protection Regulation, you have the right to:
- Know what data of yours we process, and get a copy.
- Correct data that is wrong or incomplete.
- Ask for erasure, where there is no basis for keeping it.
- Restrict or object to processing based on legitimate interest.
- Receive your data in a machine-readable format, and ask for it to be sent to another controller.
- Withdraw consent, where processing rests on it, without affecting what came before.
To exercise any of these rights, write to the contact at the top of this page. We reply within one month. If you believe we have not handled the matter properly, you may lodge a complaint with the Portuguese data protection authority (CNPD) or with the supervisory authority in your own country.
13. Contacts
For any question about this policy, or to exercise your rights, use the contacts below. We reply within one month.
- Data controller
- BPMG S.A. · NIF 516006983 · +351 912 579 716
- General contact
- sales@zeoos.com
- Data protection officer
- privacy@zeoos.com
- Security incidents
- pj@zeoos.com