Amazon Data Protection Policy
This Data Protection Policy governs the treatment (receipt, storage, usage, transfer, and disposition) of all data vended and retrieved through Amazon Marketplace APIs.
Definitions
"Application" means the Duo Wen Inc software application as it interfaces with the Amazon Marketplace APIs or the API Materials.
"Amazon Information" means any information that is exposed by Amazon through the Marketplace APIs, Seller Central, or Amazon's public-facing websites. This data includes both public, non-public, and Personally Identifiable Information about Amazon customers.
"Customer" means any person or entity who has purchased items or services from Amazon's public-facing websites.
"Personally Identifiable Information" ("PII") means information that can be used on its own or with other information to identify, contact, identify in context, or locate a Customer. This includes, but is not limited to, a Customer's name, address, e-mail address, phone number, gift message content, survey responses, payment details, purchases, cookies, digital fingerprint (e.g., browser, user device), IP Address, geo-location, nine-digit postal code, or Internet-connected device product identifier.
"Security Incident" means any actual or suspected unauthorized access, collection, acquisition, use, transmission, disclosure, corruption, or loss of Amazon Information, or breach of any environment containing Amazon Information.
General Security Requirements
Consistent with industry-leading security standards and other requirements specified by Amazon based on the classification and sensitivity of Amazon Information, Duo Wen Inc will maintain physical, administrative, and technical safeguards, and other security measures (i) to maintain the security and confidentiality of Amazon Information accessed, collected, used, stored, or transmitted by Duo Wen Inc, and (ii) to protect that information from known or reasonably anticipated threats or hazards to its security and integrity, accidental loss, alteration, disclosure, and all other unlawful forms of processing. Without limitation, Duo Wen Inc will comply with the following requirements:
Network Protection
Duo Wen Inc servers and systems employ Google VPC, network firewall network protection and access control lists for the purpose of denying access to unauthorized IP addresses. Duo Wen Inc uses network segmentation, an intruder detection system and other cloud network security tools to prevent network-based threats, DDoS and WAF.
Systems access is restricted to approved internal employees only. Duo Wen Inc implements anti-virus and anti-malware software on end-user devices.
Access Management
Duo Wen Inc establishes a formal user access registration process and uses a unique ID assigned to each individual with computer access to Amazon Information. Under no circumstances do we create or use generic, shared, or default login credentials or user accounts. Baselining mechanisms are implemented to ensure that at all times only the required user accounts have access to Amazon Information. Access can be revoked at any time if required and access is reviewed regularly (every 90 days). Upon leaving the company access and user permissions are revoked within 24hours.
No Amazon data is allowed to be stored on removable or personal devices. Systems maintain and enforce "account lockout" by detecting suspicious activity such as multiple failed logins or large number of requests, and disable accounts with access to Amazon Information as needed.
Least Privilege Principle
Duo Wen Inc implements fine-grained access control mechanisms to allow granting rights to any party using the Application and the Application's authorized operators following the principle of least privilege. Access to Amazon Information is granted on a "need-to-know" basis.
Credential Management
Duo Wen Inc establishes minimum password requirements for personnel and systems with access to Amazon Information. Password requirements are a minimum of twelve (12) characters, not include any part of the user’s name (first, last name, username, email address), mix of upper-case letters, lower-case letters, numbers, and special characters, including minimum requirements for each. Minimum password age is 1-day and a maximum 365-day password expiration for all users. Duo Wen Inc ensures that Multi-Factor Authentication (MFA) is required for all user accounts and prevents the reuse of the last 10 passwords. Duo Wen Inc ensures that API keys provided by Amazon are encrypted and only required employees have access to them. API keys and associated credentials are rotated at minimum once every 12 months.
Encryption in Transit
All data in transit is encrypted using HTTP over TLS 1.2 (HTTPS) or SSH-2 on Duo Wen Inc systems. Any end points only accept HTTPS connections, there are no instances of data in transit not being encrypted.
Incident Response Plan
Duo Wen Inc establishes a risk assessment and management process that is reviewed by the senior management annually, which includes, but is not limited to, assessment of potential threats and vulnerabilities as well as likelihood and impact in order to track known risks. Duo Wen Inc maintains a plan to detect and handle Security Incidents. The plan identifies the incident response roles and responsibilities, defines incident types that may affect Amazon, defines incident response procedures for defined incident types, and defines an escalation path and procedures to escalate Security Incidents to Amazon. Duo Wen Inc reviews and verifies the plan every six (6) months and after any major infrastructure or system change, including changes to the system, controls, operational environments, risk levels, and supply chain.
Duo Wen Inc will notify Amazon (via email to security@amazon.com) within 24 hours of detecting a Security Incident. Duo Wen Inc investigates each Security Incident, and documents the incident description, remediation actions, and associated corrective process/system controls implemented to prevent future recurrence. Duo Wen Inc maintains the chain of custody for all evidences or records collected, and such documentation must be made available to Amazon upon request (if applicable). If a Security Incident has occurred, Duo Wen Inc cannot represent or speak on behalf of Amazon to any regulatory authority or customers unless Amazon specifically requests in writing that Duo Wen Inc do so.
Duo Wen Inc designates an Incident Management Point of Contact (IMPOC) who can be reached out to in the event of any incident, such as a data leakage or security breach.
Request for Deletion or Return
Duo Wen Inc will permanently and securely delete Amazon Information upon and in accordance with Amazon's notice requiring deletion within 30 days of Amazon’s requests unless the data is necessary to meet legal requirements, including tax or regulatory requirements. Duo Wen Inc will delete non-PII data within 18 months unless required for longer retention by applicable laws or regulations. Secure deletion occurs in accordance with industry-standard sanitization processes such as NIST 800-88. If requested by Amazon, Duo Wen Inc will certify in writing that all Amazon Information has been securely destroyed.
Data Attribution
Duo Wen Inc stores Amazon Information in a separate database or implements a mechanism to tag and identify the origin of all data in any database that contains Amazon Information.
Additional Security Requirements Specific to Personally Identifiable Information
The following additional Security Requirements will be met for Personally Identifiable Information ("PII"). PII is granted to Duo Wen Inc for select tax and merchant fulfilled shipping purposes, on a will-have basis. If an Amazon Services API contains PII, or PII is combined with non-PII, then the entire data store will comply with the following requirements:
Data Retention and Recovery
Duo Wen Inc will retain PII for no longer than 30 days after order delivery and only for the purpose of, and as long as is necessary to (i) fulfill orders, (ii) calculate and remit taxes, (iii) produce tax invoices, or (iv) meet legal requirements, including tax or regulatory requirements.
Data Governance
Duo Wen Inc has a publicly available privacy policy stating our compliance to all applicable data privacy regulations. The policy governs the appropriate conduct and technical controls to be applied in managing and protecting information assets. A record of data processing activities such as specific data fields and how they are collected, processed, stored, used, shared, and disposed for all PII is maintained to establish accountability and compliance with regulations.
Asset Management
Duo Wen Inc maintains baseline standard configuration for information systems and installs patches, updates, defect fixes, and upgrades on a regular basis. Duo Wen Inc also maintains, and updates quarterly, an accurate inventory of software and physical assets (e.g. computers, mobile devices) with access to PII. A change management process is established for all information systems, such that software and hardware with access to PII are tested, verified, and approved.
PII is never stored in removable media, personal devices, or unsecured public cloud applications unless it is encrypted using at least AES-128 or RSA-2048 bit keys or higher. Duo Wen Inc securely disposes of any printed documents containing PII. Duo Wen Inc implements data loss prevention (DLP) controls in place to monitor and detect unauthorized movement of data.
Encryption at Rest
Duo Wen Inc encrypts all PII at rest using at least AES-128 or RSA with 2048-bit key size or higher. The cryptographic materials (e.g., encryption/decryption keys) and cryptographic capabilities used for encryption of PII at rest are only accessible to Duo Wen Inc's processes and services in Google Cloud. Duo Wen Inc uses Google Key Management Service (KMS) that covers the complete key lifecycle management including key generation, exchange, secure storage, and processes for key revocation and rotation in accordance with industry best practices.
Secure Coding Practices
Sensitive credentials are never hardcoded in the code, including encryption keys, secret access keys, or passwords. Sensitive credentials are not exposed in public code repositories. Separate test and production environments are maintained.
Logging and Monitoring
Duo Wen Inc systems logging includes access logs, authorisation attempts, configuration changes, user events, administrative activities. Duo Wen Inc uses Google Cloud Logging as a centralised system to holistically capture logs from cloud components including all detailed security events that are stored for 400 days. Other cloud security tools are used for manual investigation, instant context on risky activity, real-time alert notifications and malicious activities detection. Security logs are reviewed every 14 days.
All logs have access controls to prevent unauthorised access and tempering. No PII Is stored in any logs. Changes to source code are logged and recorded to specific individual developers. Unauthorised access or unexpected request rates are flagged and suspicious activity is monitored and investigated as required. Investigations are documented in the incident response plan.
Vulnerability Management
Duo Wen Inc maintains a plan to detect and remediate vulnerabilities. Physical hardware containing PII is protected from technical vulnerabilities by performing vulnerability scans and remediating appropriately. Duo Wen Inc conducts vulnerability scanning at least every 30 days and scans code for vulnerabilities prior to each release. Critical risk impact vulnerabilities are remediated within 7 days, and high-risk impact vulnerabilities are remediated within 30 days of discovery.
Appropriate procedures and plans are in place to restore availability and access to PII in a timely manner in the event of a physical or technical incident. Geographically separated secondary/backup sites are maintained to ensure timely restoration (RTO/RPO) of PII access and availability in the event of a physical or technical incident.
Audit
Duo Wen inc maintains all appropriate books and records reasonably required to verify compliance with Amazon's Acceptable Use Policy, Data Protection Policy, and Amazon Services API Developer Agreement during the period of this agreement and for 12 months thereafter. Upon Amazon's written request, Duo Wen Inc will certify in writing to Amazon that we are in compliance with these policies.