This Data Protection Policy (“DPP”) governs the treatment (for example, receipt, storage, use, transfer, and disposal) of data collected and retrieved by channelpromanager.com (Channel Pro Manager).
“Amazon Information” means seller-authorized data made available to Channel Pro Manager through the Amazon Selling Partner API in connection with the seller’s own Amazon account. This data is used solely to support internal order processing, inventory management, and fulfilment workflows. Channel Pro Manager does not aggregate or resell Amazon data, and does not access Amazon public-facing websites or scrape Seller Central.
“Customer” means an individual whose information is included in a seller-authorized Amazon order and is accessed solely to fulfil that order.
“Personally Identifiable Information” (“PII”) means information that can be used on its own or with other information to identify, contact, or locate an individual, or to identify an individual in context. This includes, but is not limited to, a customer’s or seller’s name, address, email address, phone number, gift-message content, survey responses, payment details, purchases, cookies, digital fingerprint (for example, browser or user device), IP address, geolocation, or an internet-connected device product identifier.
“Security Incident” means any actual or suspected unauthorized access to, collection, acquisition, use, transmission, disclosure, corruption, or loss of Amazon Information; or a breach of an environment containing Amazon Information or managed by Channel Pro Manager with controls substantially similar to those protecting Amazon Information.
“Seller” means any person or entity selling on Amazon’s public-facing websites.
“Channel Pro Manager” means the company that owns channelpromanager.com, its managers, or the services, depending on the context.
1. Data retention and recovery. Channel Pro Manager retains customer PII only for as long as necessary to fulfil seller-authorized orders. Customer PII is automatically deleted within 30 days after order shipment or completion. Application logs do not contain PII and are retained separately only for security monitoring.
2. Data governance. Channel Pro Manager’s privacy and data-handling policy governs the appropriate conduct and technical controls used to manage and protect information assets. Channel Pro Manager maintains an inventory of software and physical assets, such as computers and mobile devices, that can access PII and updates it regularly. Records of data-processing activities—including the data fields and how they are collected, processed, stored, used, shared, and disposed of—are maintained for all PII to establish accountability and regulatory compliance. Where applicable under the privacy policy, Channel Pro Manager can rectify, erase, or stop sharing or processing customer information.
3. Encryption and storage. All PII is encrypted at rest using industry best-practice standards, such as AES-128, AES-256, or RSA with a 2048-bit key or higher, depending on the server configuration. Cryptographic materials, including encryption and decryption keys, and cryptographic capabilities used to encrypt PII at rest are accessible only to the relevant processes and services. PII is not stored on removable media, such as USB devices, or unsecured public-cloud applications, such as publicly shared Google Drive links. Printed documents containing PII are securely disposed of. Channel Pro Manager implements a Key Management System covering the complete key lifecycle, including generation, secure storage, rotation at least annually, and revocation.
4. Least privilege principle. Channel Pro Manager has implemented fine-grained access-control mechanisms to grant rights to application users, for example access to a specific set of data in its custody, and to application operators, for example access to specific configuration and maintenance APIs such as kill switches, following the principle of least privilege. Application sections or features that provide PII are protected by a unique access role, and access is granted on a need-to-know basis.
5. Logging and monitoring. Channel Pro Manager gathers logs to detect security-related events, including access and authorization events, intrusion attempts, and configuration changes, across the application and systems. This logging is implemented on all channels providing access to Amazon Information, including service APIs, storage-layer APIs, and administrative dashboards. All logs have access controls to prevent unauthorized access and tampering throughout their lifecycle. Logs track event success or failure, date and time, access attempts, data changes, and system errors, but do not contain PII. They are retained for at least 12 months for reference in the event of a Security Incident. Logs are reviewed in real time using automated monitoring tools, such as SIEM, and through biweekly manual reviews. Channel Pro Manager monitors logs and system activity for suspicious actions, such as multiple unauthorized calls, unexpected request rates or retrieval volumes, and access to canary records. Monitoring alarms trigger documented investigation under the Incident Response Plan. Channel Pro Manager also monitors for data exfiltration beyond protected boundaries and the Dark Web for unauthorized exposure of Amazon Information.
6. Network protection. Channel Pro Manager has implemented network-protection controls, including network firewalls and access-control lists (ACLs), to deny access to unauthorized IP addresses. Network segmentation isolates production, staging, and development environments. Intrusion-detection and prevention systems (IDS/IPS) are deployed to identify and block malicious network activity through defense-in-depth methods. Anti-virus and anti-malware tools are deployed on all systems, updated at least monthly, and cannot be disabled by employees. Public access is limited to approved users who have completed data-protection and IT-security awareness training at least annually. Channel Pro Manager maintains secure coding practices across all development activities.
7. Access management. Channel Pro Manager assigns a unique ID to each person with computer access to Amazon Information. People with access to data do not create or use generic, shared, or default login credentials or user accounts. Multi-Factor Authentication (MFA) using TOTP is enforced on all accounts with access to Amazon Information. Channel Pro Manager reviews the list of people and services with access to Amazon Information regularly, at least quarterly, and removes accounts that no longer require access. Access for terminated employees is disabled within 24 hours. Employees are restricted from storing Amazon data on personal devices. Channel Pro Manager maintains and enforces account lockout by detecting anomalous usage patterns and login attempts, and by disabling accounts after 10 or fewer unsuccessful attempts.
8. Encryption in transit. Channel Pro Manager encrypts all Amazon Information in transit, for example when data traverses a network or is sent between hosts. This is achieved using TLS 1.2 or higher (HTTPS), SFTP, and SSH-2. Channel Pro Manager enforces this control on all applicable external endpoints used by customers, internal communication channels such as data propagation between storage-layer nodes, connections to external dependencies, and operational tooling. Communication channels that do not provide encryption in transit are disabled even if unused, for example by removing related dead code, configuring dependencies only with encrypted channels, and restricting credentials to encrypted-channel use. Channel Pro Manager uses message-level encryption where channel encryption, such as TLS, terminates in untrusted multi-tenant hardware, for example untrusted proxies.
9. Incident response plan. Channel Pro Manager maintains a plan to detect and handle Security Incidents. The plan identifies incident-response roles and responsibilities, defines incident types that may affect Amazon, defines response procedures for those incident types, and defines an escalation path and procedures for escalating Security Incidents to Amazon. Channel Pro Manager reviews and verifies the plan every six months and after any major infrastructure or system change. Each Security Incident is investigated and its description, remediation actions, and associated corrective process or system controls are documented to prevent recurrence. Channel Pro Manager informs Amazon within 24 hours of detecting a Security Incident. A chain of custody is maintained for all evidence and records collected during an investigation, and documentation is made available to Amazon upon request. An Incident Management Point of Contact (IMPOC) is designated for security incidents.
10. Request for deletion or return. No later than 30 days after Amazon’s request, Channel Pro Manager permanently and securely deletes, in accordance with industry-standard sanitization processes such as NIST 800-88, or returns Amazon Information as required by Amazon’s deletion or return notice. Channel Pro Manager also permanently and securely deletes all live, online, or network-accessible instances of Amazon Information within 90 days after Amazon’s notice. Non-PII Amazon Information is deleted within 18 months unless a longer retention period is required by applicable law. Channel Pro Manager provides written certification of destruction upon Amazon’s request.
11. Amazon Selling Partner API data. When a customer connects their Amazon Seller Central account to Channel Pro Manager, we access data through the Amazon Selling Partner API solely on that customer’s behalf and only for that customer’s internal business operations. We do not sell, rent, license, share, redistribute, aggregate, or otherwise provide access to Amazon data to any third party, and we do not combine Amazon data from different customers. Personally Identifiable Information (PII) obtained from Amazon orders is retained only as long as required to fulfil the order and meet legal and tax obligations, and is encrypted at rest and in transit. The data controller is Dynasun Italia Srl.