SellersOS Logo SellersOS SELLERSOS LLC
← Back to site

Data Processing Addendum

Version 2.0 · Effective 16 September 2026 · Last updated 16 September 2026

This Addendum supplements the Terms of Service between SELLERSOS LLC (“Processor”, “SellersOS”) and the customer (“Controller”, “you”). Where any conflict arises regarding the processing of personal data or Amazon seller data, this Addendum shall prevail.

1. Roles and responsibilities

For Amazon seller data accessed on your behalf via authorized Amazon APIs, you are the Controller and SellersOS is the Processor. For our direct customer account records, billing contacts, and technical support correspondence, SellersOS acts as Controller. SellersOS processes operational and personal data strictly on your documented instructions, conveyed through your configuration of the Service and these agreements.

2. Subject matter, duration and scope

Item Detail
Subject matter Provision of analytics, inventory replenishment forecasting, fee reconciliation, listing management, and authorized advertising automation for Amazon selling accounts
Duration The duration of the active subscription, plus the 30-day deletion period specified in Section 7
Nature of processing Ingestion via official Amazon APIs, storage, normalization, aggregation, computation, display, and — where explicitly enabled — writing authorized updates to Amazon
Categories of data subjects Authorized customer team members and administrators; incidentally, order identifiers associated with transactions
Categories of personal data User names, business email addresses, account credentials, order IDs and financial ledger entries. Buyer names, street addresses, buyer emails and phone numbers are excluded at ingestion.
Special categories None. The Service is not intended for and must not be used to process special-category or sensitive personal data.

3. Processor obligations

4. Sub-processors

You grant general authorization for the sub-processors identified in our Privacy Policy (including Amazon Web Services, Inc., Cloudflare, Inc., Namecheap, Inc., and Stripe, Inc.). Each sub-processor is bound by written data-protection agreements imposing standards no less protective than those set forth in this Addendum. Customers will receive at least 30 days’ advance notice before any new sub-processor with access to Amazon Information is engaged.

5. Technical and organizational security measures

Control Domain Technical Specification & Amazon DPP (August 2026) Standard
Encryption in Transit TLS 1.2 or higher (TLS 1.3 preferred) for all data in transit with strict HSTS; unencrypted HTTP rejected at edge
Encryption at Rest AES-256 volume, database, and backup encryption at rest via AWS Key Management Service (AWS KMS); scheduled credential rotation
Web Application Firewall (WAF) All internet-facing public endpoints and API gateways protected by WAF with managed rule sets defending against OWASP Top 10 and Layer 7 DDoS
Workforce Device Encryption All workforce laptops and administrative devices enforce full-disk storage encryption (BitLocker, FileVault, or LUKS with AES-256)
Automatic Screen Locking All workforce and administrative devices enforce automatic screen locking after no more than 15 minutes of inactivity
Access Control & Lockout Mandatory MFA for all customer accounts, team members, and administrative accounts; 12+ character complex passwords with 10-history restriction, username/brand exclusion, minimum 1-day age and 365-day expiration; temporary account lockout of at least 30 minutes after no more than 10 failed login attempts within 30 minutes; quarterly access reviews
Workforce Endpoint Protection Workforce devices maintain centrally managed endpoint protection / anti-malware (EDR) with automated definition updates
Tenant Isolation Strict logical tenant separation at database layer; tenant partition keys; complete isolation preventing cross-account access; zero cross-tenant data pooling
Data Minimization (Zero Buyer PII) Buyer PII is dropped at ingestion; customer names, shipping addresses, emails, and phone numbers are never stored in persistent databases
Network Isolation Databases deployed in private VPC subnets with no direct public internet listener, accepting connections only from authorized application security groups
Vulnerability Management Automated monthly vulnerability scans; Critical vulnerabilities remediated within ≤ 7 calendar days; High vulnerabilities remediated within ≤ 30 calendar days
Audit Logging & Retention Append-only audit logging of automated actions and API calls; security logs retained for at least 12 months in tamper-resistant storage, excluding PII

6. Personal data breach & Amazon incident notification

In the event of a confirmed personal data breach affecting customer data, SellersOS will notify the affected customer without undue delay and within 72 hours of becoming aware.

Amazon Incident Notification: Where a security incident involves Amazon Information or developer credentials, SellersOS will notify Amazon at security@amazon.com within 24 hours of detection, and will provide full cooperation in the investigation and remediation of the incident.

7. Data retention, return and deletion

8. Audit and compliance verification

Upon reasonable prior written notice, SellersOS will make available documentation demonstrating compliance with the technical and organizational measures described herein. Audits shall be conducted during normal business hours without disrupting ongoing operations or compromising other customers' confidential data.

9. International transfers

Primary processing takes place in the United States (Amazon Web Services, AWS Region us-east-1). Where international transfers occur from the EEA, the UK, or Switzerland, the parties agree that the European Commission’s Standard Contractual Clauses (SCCs) are incorporated by reference and apply to such transfers.

10. Contact information

SELLERSOS LLC
30 N Gould St Ste N, Sheridan, WY 82801, United States
Privacy & Data Protection Contact: privacy@sellersos.net
Security Team: security@sellersos.net

\n