For Amazon seller data accessed on your behalf via authorized Amazon APIs, you are the Controller and SellersOS is the Processor. For our direct customer account records, billing contacts, and technical support correspondence, SellersOS acts as Controller. SellersOS processes operational and personal data strictly on your documented instructions, conveyed through your configuration of the Service and these agreements.
| Item | Detail |
|---|---|
| Subject matter | Provision of analytics, inventory replenishment forecasting, fee reconciliation, listing management, and authorized advertising automation for Amazon selling accounts |
| Duration | The duration of the active subscription, plus the 30-day deletion period specified in Section 7 |
| Nature of processing | Ingestion via official Amazon APIs, storage, normalization, aggregation, computation, display, and — where explicitly enabled — writing authorized updates to Amazon |
| Categories of data subjects | Authorized customer team members and administrators; incidentally, order identifiers associated with transactions |
| Categories of personal data | User names, business email addresses, account credentials, order IDs and financial ledger entries. Buyer names, street addresses, buyer emails and phone numbers are excluded at ingestion. |
| Special categories | None. The Service is not intended for and must not be used to process special-category or sensitive personal data. |
You grant general authorization for the sub-processors identified in our Privacy Policy (including Amazon Web Services, Inc., Cloudflare, Inc., Namecheap, Inc., and Stripe, Inc.). Each sub-processor is bound by written data-protection agreements imposing standards no less protective than those set forth in this Addendum. Customers will receive at least 30 days’ advance notice before any new sub-processor with access to Amazon Information is engaged.
| Control Domain | Technical Specification & Amazon DPP (August 2026) Standard |
|---|---|
| Encryption in Transit | TLS 1.2 or higher (TLS 1.3 preferred) for all data in transit with strict HSTS; unencrypted HTTP rejected at edge |
| Encryption at Rest | AES-256 volume, database, and backup encryption at rest via AWS Key Management Service (AWS KMS); scheduled credential rotation |
| Web Application Firewall (WAF) | All internet-facing public endpoints and API gateways protected by WAF with managed rule sets defending against OWASP Top 10 and Layer 7 DDoS |
| Workforce Device Encryption | All workforce laptops and administrative devices enforce full-disk storage encryption (BitLocker, FileVault, or LUKS with AES-256) |
| Automatic Screen Locking | All workforce and administrative devices enforce automatic screen locking after no more than 15 minutes of inactivity |
| Access Control & Lockout | Mandatory MFA for all customer accounts, team members, and administrative accounts; 12+ character complex passwords with 10-history restriction, username/brand exclusion, minimum 1-day age and 365-day expiration; temporary account lockout of at least 30 minutes after no more than 10 failed login attempts within 30 minutes; quarterly access reviews |
| Workforce Endpoint Protection | Workforce devices maintain centrally managed endpoint protection / anti-malware (EDR) with automated definition updates |
| Tenant Isolation | Strict logical tenant separation at database layer; tenant partition keys; complete isolation preventing cross-account access; zero cross-tenant data pooling |
| Data Minimization (Zero Buyer PII) | Buyer PII is dropped at ingestion; customer names, shipping addresses, emails, and phone numbers are never stored in persistent databases |
| Network Isolation | Databases deployed in private VPC subnets with no direct public internet listener, accepting connections only from authorized application security groups |
| Vulnerability Management | Automated monthly vulnerability scans; Critical vulnerabilities remediated within ≤ 7 calendar days; High vulnerabilities remediated within ≤ 30 calendar days |
| Audit Logging & Retention | Append-only audit logging of automated actions and API calls; security logs retained for at least 12 months in tamper-resistant storage, excluding PII |
In the event of a confirmed personal data breach affecting customer data, SellersOS will notify the affected customer without undue delay and within 72 hours of becoming aware.
Amazon Incident Notification: Where a security incident involves Amazon Information or developer credentials, SellersOS will notify Amazon at security@amazon.com within 24 hours of detection, and will provide full cooperation in the investigation and remediation of the incident.
Upon reasonable prior written notice, SellersOS will make available documentation demonstrating compliance with the technical and organizational measures described herein. Audits shall be conducted during normal business hours without disrupting ongoing operations or compromising other customers' confidential data.
Primary processing takes place in the United States (Amazon Web Services, AWS Region us-east-1). Where international transfers occur from the EEA, the UK, or Switzerland, the parties agree that the European Commission’s Standard Contractual Clauses (SCCs) are incorporated by reference and apply to such transfers.
SELLERSOS LLC
30 N Gould St Ste N, Sheridan, WY 82801, United States
Privacy & Data Protection Contact: privacy@sellersos.net
Security Team: security@sellersos.net