Acordo de tratamento de dados
Última atualização: August 9, 2026
Esta página está em inglês. Não existem versões traduzidas para esta língua.
This Data Processing Agreement ("DPA") forms part of the MarginLock Terms of Service and governs the processing of personal data that MarginLock carries out on your behalf when you use the MarginLock service. It is entered into under Article 28 of Regulation (EU) 2016/679 ("GDPR") and, where applicable, the equivalent provisions of the UK GDPR.
This DPA takes effect when you accept the Terms of Service and create a MarginLock account. No separate signature is required for it to apply. If your organisation requires an executed counterpart, write to support@marginlock.io and we will provide one.
Parties
Controller ("you", "Customer"): the legal entity that has entered into the Terms of Service with us and on whose behalf personal data is processed.
Processor ("we", "MarginLock"): Kenderson Tripaldi, Via Ettore Fico 7, 10090 Castiglione Torinese (TO), Italy. Contact: support@marginlock.io.
You act as the controller of the personal data you submit to, or generate through, the service. We act as your processor and process that personal data only on your behalf.
Subject matter and duration
The subject matter of the processing is the provision of the MarginLock service: fulfilment, inventory, compliance, and margin analysis for Amazon selling accounts, as described in the Terms of Service.
The processing lasts for the term of your MarginLock account. It ends when your account is deleted, subject to the deletion and return terms below.
Nature and purpose of the processing
We process personal data to operate the service you have subscribed to. That includes: authenticating your users, retrieving and storing data from the Amazon Selling Partner API accounts you connect, computing fulfilment plans, fee and margin analytics, reading box dimensions and scale readings from the measurement photos your warehouse users capture, sending transactional and service email, providing support, and maintaining the security, availability, and integrity of the platform.
We do not process personal data for our own purposes, do not sell it, and do not use it to train models.
Categories of personal data and data subjects
Categories of data subjects: your personnel who hold MarginLock user accounts, and any individuals identifiable within the Amazon Seller Central data you connect to the service.
Categories of personal data: account and contact details (name, business email address, role, organisation); authentication and session metadata; usage and device data such as IP addresses and request logs; billing contact and billing address data; photos your warehouse users capture when measuring shipments; and the Amazon selling-account data you connect, which may include recipient and order-level information. Payment card numbers are never processed by us — billing is handled by our payment subprocessor.
We do not require, and the service is not designed to receive, special categories of personal data under Article 9 GDPR.
Your instructions
We process personal data only on your documented instructions, including with regard to transfers to a third country, unless we are required to do otherwise by Union or Member State law. Where we are subject to such a requirement, we will inform you before processing unless that law prohibits it on important grounds of public interest.
Your use of the service, together with this DPA and the Terms of Service, constitutes your complete documented instructions. Any other processing requires a separate written agreement.
We will inform you if, in our opinion, an instruction you give infringes the GDPR or other applicable data protection law.
Confidentiality
We ensure that every person authorised to process personal data under this DPA is bound by an obligation of confidentiality, whether contractual or statutory, and that access is limited to what each person needs in order to perform their role.
Security measures
We implement appropriate technical and organisational measures under Article 32 GDPR. Our current measures — including TLS 1.2 or higher in transit, AES-256 encryption at rest, application-level AES-256-GCM encryption of Amazon SP-API tokens with keys held separately from the database, passwordless authentication with short-lived hashed tokens, least-privilege SP-API scopes, and infrastructure managed as reviewed code — are published and kept current on our security page, which forms part of this DPA.
Publishing the measures in one place, rather than restating them here, is deliberate: it means the commitments you rely on and the commitments we maintain cannot drift apart. We may update these measures over time, provided the level of protection is not reduced.
Subprocessors
You give us general written authorisation to engage subprocessors. The complete, current list of subprocessors — with the purpose, the categories of data, the processing region, and each subprocessor's own data processing terms — is published on our subprocessor list.
We notify you in writing at least 30 days before adding or replacing a subprocessor. You may object to a new subprocessor on reasonable data protection grounds within that period; if we cannot accommodate your objection, you may terminate the affected part of the service and receive a pro-rated refund of prepaid fees for the unused term.
We impose data protection obligations on every subprocessor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
International transfers
Some of our subprocessors process personal data outside the European Economic Area. Each such transfer relies on the transfer mechanism published by that subprocessor in its own data processing terms — an adequacy decision, EU-US Data Privacy Framework certification, or Standard Contractual Clauses — which is linked for every subprocessor from our subprocessor list. Where Standard Contractual Clauses apply to a transfer we make as your processor, the Clauses are incorporated into this DPA by reference, with the module appropriate to the transfer.
Assistance with data subject rights
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests to exercise data subject rights under Chapter III GDPR — access, rectification, erasure, restriction, portability, and objection.
If a data subject contacts us directly about personal data we process on your behalf, we will not respond substantively; we will forward the request to you without undue delay. Ask us for assistance at support@marginlock.io.
Assistance with your obligations under Articles 32 to 36
Taking into account the nature of the processing and the information available to us, we assist you in ensuring compliance with your obligations under Articles 32 to 36 GDPR, including security of processing, personal data breach notification, data protection impact assessments, and prior consultation with a supervisory authority.
Personal data breaches
We notify you without undue delay after becoming aware of a personal data breach affecting personal data processed on your behalf. Our notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned so far as known, the likely consequences, the measures taken or proposed, and a contact point for further information. Where we cannot provide all of that at once, we will provide it in phases without further undue delay.
Notifying your supervisory authority and, where required, the affected data subjects remains your responsibility as controller.
Deletion and return of data
While your account is active, the service offers downloadable CSV exports for specific reports, such as settlement reconciliation, restock recommendations, and fee-change impact. For a copy of the personal data we process on your behalf beyond those reports, write to support@marginlock.io and we will provide it in a structured, commonly used, machine-readable format.
On termination of the service, and at your choice, we delete or return all personal data processed on your behalf. Following account deletion, customer data is purged within 30 days, except where Union or Member State law requires us to retain it — in which case we retain only what that law requires, for only as long as it requires, and continue to protect it under this DPA.
Audits and information rights
We make available to you all information necessary to demonstrate compliance with Article 28 GDPR, and we allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
In the first instance, we will respond to reasonable written requests for information about our processing and security measures. Where that is insufficient for your compliance obligations, we will accommodate an audit on at least 30 days' written notice, no more than once in any 12-month period unless required by a supervisory authority or following a personal data breach, during business hours, subject to confidentiality, and conducted so as not to disrupt the service or the data of other customers.
Governing language
This DPA is published in English. The English text is the authoritative version and governs its interpretation. Any translation is provided for convenience only and has no legal effect. Where a translated copy conflicts with this English text, this English text prevails.
Precedence and governing law
This DPA forms part of the Terms of Service. In the event of a conflict between this DPA and the Terms of Service in respect of the processing of personal data, this DPA prevails. In the event of a conflict between this DPA and the Standard Contractual Clauses where those apply, the Standard Contractual Clauses prevail.
The governing law and the venue for disputes are those stated in the Terms of Service, which are the law and the courts of the place where the Owner is based — Italy.
Changes to this agreement
We may update this DPA to reflect changes in the service, in our subprocessors, or in applicable law, provided no update reduces the level of protection afforded to personal data. Material changes are published on this page with an updated "Last updated" date, and we notify account owners by email.
Questions about this agreement go to support@marginlock.io.