Array42
Privacy Policy
Effective 23 April 2026

Privacy Policy

Array42 is a web development and digital agency based in Portugal. This policy explains what personal data we collect, how we use it, and the rights you have over it. It applies to our website and to the applications and integrations we build and operate for our clients.

We comply with the General Data Protection Regulation (GDPR) and Portuguese Law 58/2019.

Who we are

Array42 is the data controller for data collected directly by us. You can reach us at info@array42.com. For privacy and security matters, use security@array42.com.

What we collect

How we use your data

We do not sell personal data, do not use it for advertising, and do not share it with third parties other than the subprocessors listed below.

Amazon Information

When a client authorizes Array42 to access their Amazon Selling Partner account, we process data obtained through Amazon APIs and through the client's systems that synchronise with Amazon. This may include order identifiers, buyer billing information, tokenized buyer email addresses, order line items, and tax data. We refer to this data collectively as "Amazon Information".

Amazon Information is:

Subprocessors

We rely on the following subprocessors to operate our services, all bound by a Data Processing Agreement:

An up-to-date list is available on request.

Retention

We keep personal data only for as long as necessary. Invoicing and accounting records are kept for 10 years as required by Portuguese tax law. Operational data is deleted within 30 days of contract termination or merchant disconnection. Security logs are kept for up to 13 months.

Your rights

Under GDPR you have the right to access, correct, delete, restrict, and export your personal data, and to object to processing based on legitimate interest. You can also complain to the Portuguese Data Protection Authority (CNPD).

To exercise any of these rights, email info@array42.com. We respond within 30 days.

When we process data on behalf of a client as a processor, the client is the data controller. We will forward your request to them.

Security

We encrypt data in transit and at rest, enforce multi-factor authentication on all administrative accounts, keep secrets in dedicated secret storage (never in code), log access to personal data, and operate a documented Incident Response Plan. Incidents affecting Amazon Information are reported to security@amazon.com within 24 hours of detection.

Cookies

Our website uses only strictly necessary cookies. We do not deploy tracking or advertising cookies without explicit consent.

Changes

We may update this policy to reflect changes in our practices or the law. The effective date at the top shows when the current version took effect.

Contact

Questions about this policy: info@array42.com.
Security incidents: security@array42.com.