Sellantica Logo
  • Home
  • About
  • Features
  • Pricing
  • Contact
  • Blog
  • Legal notice
  • DE EN

Compliance & Data Sharing

Amazon SP-API Compliance, Acceptable Use Policy & Data Sharing (Section 4.6)

Last updated: December 7, 2024

This is a non-binding English translation. The German version is legally authoritative — see the German original.

Sellantica is Amazon SP-API compliant

This page documents our full compliance with the Amazon Acceptable Use Policy, SP-API Website Guidelines and Data Protection Policy. All information is transparently available for Amazon Selling Partners and the Amazon Solution Provider Team.

Table of Contents

1. Acceptable Use 4.4 & 4.5 2. Data Sharing (Section 4.6) 3. Data Protection & Security 4. Website Guidelines 5. Governance & Auditability 6. Incident Response

1. Amazon Acceptable Use Policy 4.4 & 4.5

Sellantica meets all requirements of the Amazon Acceptable Use Policy, in particular Sections 4.4 (Prohibited Activities) and 4.5 (Data Use Restrictions).

✓ Section 4.4 Compliance: No prohibited activities

  • No scraping: Exclusive use of official SP-API endpoints
  • No unauthorized access: All access is performed via Login-with-Amazon authorization
  • No manipulation: No falsification of Amazon data or metrics
  • No abusive use: Strict rate limiting and API quota monitoring

✓ Section 4.5 Compliance: Data protection & use restrictions

  • No PII processing: We do not process personal customer data (names, addresses, payment information)
  • Single-seller data processing: Each seller sees only their own campaign data
  • No data aggregation: No mixing of data from different sellers
  • No resale: Amazon information is not sold or rented to third parties
  • Purpose-limited use: Data is used exclusively for campaign optimization of the respective seller

What we process (permitted):

  • Sponsored Products/Brands/Display campaign data
  • Keyword and Search Term performance metrics
  • ACoS, ROAS, CTR, conversion rates
  • Budget and bid information
  • Brand Analytics data (where authorized)

What we do NOT process:

  • ❌ Customer names, email addresses, phone numbers
  • ❌ Shipping addresses or billing addresses
  • ❌ Payment information (credit cards, bank accounts)
  • ❌ Order details of individual end customers
  • ❌ Reviews or customer communication

2. Data Sharing (Amazon AUP Section 4.6)

Amazon information is shared only with the infrastructure service providers listed below. No disclosure whatsoever is made to marketing, analytics or consulting companies.

Recipient Purpose Which data Location Legal basis
Amazon Web Services (AWS) Cloud hosting, storage, computing (Lambda, S3, RDS, CloudFront) All campaign data, account data, logs EU (Frankfurt, eu-central-1) Processing on behalf (DPA pursuant to Art. 28 GDPR)
Amazon SP-API Data retrieval via official API endpoints (Advertising, Reports, Brands) API requests with seller token, retrieval of campaign data EU (Amazon EU S.à r.l.) Contract with Amazon as SP-API Developer
No further recipients. In particular, no disclosure to marketing tools, analytics platforms or third-party services.

Important: No disclosure to the following categories

  • Advertising partners or affiliate networks
  • Data brokers or market research companies
  • Other Amazon Sellers or competitors
  • Business intelligence or analytics platforms (except AWS, which we operate ourselves)
  • CRM systems containing customer data

3. Data Protection & Security Measures

Encryption

  • In Transit: TLS 1.3
  • At Rest: AES-256
  • Database: Encrypted RDS instances
  • S3 Buckets: Server-Side Encryption (SSE-KMS)

Access Control

  • IAM least-privilege principle
  • Multi-Factor Authentication (MFA)
  • Role-Based Access Control (RBAC)
  • Four-eyes principle for critical operations

Monitoring & Logging

  • AWS CloudTrail (all API calls)
  • GuardDuty (threat detection)
  • CloudWatch alarms & dashboards
  • Immutable logs (12-month retention)

Data Separation

  • Separate S3 prefixes per seller
  • Partitioned database tables
  • Account-specific IAM policies
  • No cross-account queries possible

Backup & Recovery

  • Daily automatic backups
  • 30-day retention period
  • Multi-AZ deployment (high availability)
  • Disaster recovery plan (RPO: 1h, RTO: 4h)

Employee Training

  • Annual GDPR training
  • Amazon AUP awareness training
  • Commitment to data confidentiality
  • Security best practices (OWASP)

4. Amazon SP-API Website Guidelines Compliance

Our website meets all requirements of the Amazon SP-API Website Guidelines:

Company identity: Fully identical with the Amazon Developer Profile (hof digital, Sebastian Hof, Düsseldorf)
Service description: Detailed description of all Brand Analytics and PPC services (see Features section)
Contact information: Phone, email, address and support SLAs are publicly available (see Contact section)
Working links: All internal and external links have been checked and work
Legal pages: Legal notice, Privacy, Terms complete and GDPR-compliant
Pricing & transparency: All prices are transparent on the Pricing page, no hidden costs
Launch readiness: Support processes, onboarding plan and technical documentation in place

5. Governance & Auditability

Standard Operating Procedures (SOPs)

  • Code deployment (CI/CD pipeline with automated tests)
  • Change management (four-eyes principle, review process)
  • Access management (onboarding/offboarding, quarterly access reviews)
  • Data lifecycle (retention policies, automatic deletion after 90 days)
  • Penetration testing (annually by external service providers)

Documentation & Traceability

  • Audit Logs: Immutable CloudTrail logs for all AWS API calls (12 months)
  • Change History: Git-based version control with code reviews
  • Incident Reports: Documented incidents with root cause analysis
  • Compliance Reviews: Quarterly internal audits

Business Continuity & Disaster Recovery

  • RPO (Recovery Point Objective): 1 hour
  • RTO (Recovery Time Objective): 4 hours
  • Backup strategy: Daily automatic backups (30-day retention)
  • Failover: Multi-AZ deployment with automatic failover
  • DR tests: Semi-annual disaster recovery drills

6. Incident Response & Escalation

We maintain a documented incident response plan with a 24/7 escalation chain:

Incident Classification

Priority Description Response time
P1 (Critical) Data breach, service completely offline 15 minutes
P2 (High) Partial outage, significant performance issues 1 hour
P3 (Normal) Non-critical errors, feature issues 4 hours

Escalation Chain

  1. Level 1: Support team (support@Sellantica.ai)
  2. Level 2: Lead Consultant / Technical Lead
  3. Level 3: Managing Director Sebastian Hof

24/7 Emergency Hotline (for P1 incidents only):
+49 211 5420 2330

For the Amazon Solution Provider Team

This compliance page serves as evidence of our full compliance with the Amazon Policies. For any questions regarding the Public Solution Provider application, please contact:

Solution Provider Portal Case #18788952571 info@hof-consulting.de

Further Legal Information

Legal notice Privacy Policy Terms Contact
Back to Home

© 2026 Sellantica by hof digital. All rights reserved.

Legal notice Privacy Terms Compliance