Digital Club Operations, S.L. (trading as Digital Club Agency) CIF B70858964 · Calle Gran Vía 54, 3B · 28220 Majadahonda (Madrid), Spain
Document status. This is the controlled copy of the policy, published by Digital Club Operations, S.L. at the URL above. The version number and effective date in the table below identify the copy in force; superseded versions are retained internally. Published policies are adopted by resolution of the company's management and do not require a handwritten signature to be binding.
| Document owner | Noah Valderrama — Co-CEO |
| Version | 1.0 |
| Effective date | 2026-09-30 |
| Next scheduled review | 2027-03-30 (every 6 months) |
| Approved by | Noah Valderrama, Co-CEO, for Digital Club Operations, S.L. |
| Applies to | All employees, contractors and operators of Digital Club Operations, S.L. |
This plan satisfies the requirement of the Amazon Data Protection Policy, section 1.6 (Risk Management and Incident Response Plan) and is maintained as a condition of Digital Club Operations' participation in the Amazon Service Provider Network and its access to Amazon Information.
This plan defines how Digital Club Operations detects, responds to, escalates and records Security Incidents, with particular attention to incidents that affect Amazon Information.
Amazon Information means any data obtained from Amazon or from a selling partner's Amazon account in the course of providing services, including but not limited to: Selling Partner API and Advertising API data, order and customer data, seller account credentials and access tokens, business and performance reports, and any derived data stored in Digital Club Operations' systems.
The plan covers all systems that store, process or transmit Amazon Information, whether operated by Digital Club Operations or by a subprocessor.
A Security Incident is any actual or reasonably suspected event that compromises, or may compromise, the confidentiality, integrity or availability of Amazon Information or of the systems that hold it. This includes, without limitation:
A suspicion is enough to trigger this plan. Confirmation is not required before reporting internally or to Amazon.
| Role | Holder | Responsibilities |
|---|---|---|
| Incident Management Point of Contact (IMPOC) | Noah Valderrama, Co-CEO — noah@digitalclubagency.com · +34 661 559 667 | Single point of contact for Amazon. Declares incidents, leads response, sends the notification to Amazon, keeps the incident record. |
| Backup IMPOC | Carlos Imaz, COO — carlos@digitalclubagency.com | Assumes all IMPOC duties when the IMPOC is unreachable within 2 hours. |
| Incident Commander (technical) | Lucas Salvador Gómez, Co-CEO & CTO — reachable at contacto@digitalclubagency.com and through the internal contact annex | Coordinates containment and recovery; the only person who authorises changes to affected systems during an incident. |
| Operations lead | Carlos Imaz, COO | Client communication; coordination of account operators; assessment of impact on selling partners. |
| Legal / data protection | Noah Valderrama, Co-CEO, with the company's external legal counsel | GDPR assessment, notification to the Spanish supervisory authority (AEPD) and to data subjects where required, contractual notifications. |
| All personnel | Everyone | Report any suspected incident immediately to the IMPOC. Reporting in good faith never carries a penalty, including when the reporter caused the incident. |
Contact details for the IMPOC and Backup IMPOC are kept current and are re-verified at every scheduled review of this plan. Any change of IMPOC is notified to Amazon under the Organizational Change Notification Policy.
Internal reporting channel: contacto@digitalclubagency.com and noah@digitalclubagency.com — both monitored by the IMPOC and the Backup IMPOC — plus a direct phone call to the IMPOC on +34 661 559 667. Out of hours, the phone call takes precedence over email. Personal mobile numbers are held in the internal contact annex and re-verified at every scheduled review of this plan.
| Severity | Definition | Internal response target |
|---|---|---|
| SEV-1 — Critical | Confirmed or suspected unauthorised access to Amazon Information, to a selling partner's account, or to credentials granting such access. Ransomware or intrusion in any system holding Amazon Information. | Response begins immediately. Amazon notified within 24 hours of detection. |
| SEV-2 — High | Incident with potential but unconfirmed exposure of Amazon Information; compromise of an internal system with no evidence of data access; suspected phishing with credential entry. | Response begins within 4 hours. Treated as SEV-1 for Amazon notification purposes unless exposure of Amazon Information is ruled out within 24 hours. |
| SEV-3 — Moderate | Security event with no exposure of Amazon Information (for example blocked malware, phishing not acted on, policy violation without data access). | Response within 1 business day. Recorded; no Amazon notification unless reassessed upwards. |
When severity is uncertain, the higher severity applies until the assessment is complete.
Within 10 business days of closing a SEV-1 or SEV-2 incident, the IMPOC runs a blameless review producing: timeline, root cause, impact on Amazon Information and on selling partners, what worked, what failed, and corrective actions with an owner and a due date. Corrective actions are tracked to completion and their status is reported to the CEOs monthly until closed.
Digital Club Operations notifies Amazon by email to security@amazon.com within 24 hours of detecting a Security Incident or suspecting that one has occurred, as required by section 1.6 of the Amazon Data Protection Policy.
Note: the former address
3p-security@amazon.comhas not been monitored since 3 July 2024.security@amazon.comis the current channel.
The notification is sent by the IMPOC (or Backup IMPOC) and includes, to the extent known at the time — an incomplete notification within 24 hours always takes precedence over a complete notification later:
Updates are sent as the investigation progresses, and a final report is sent on closure. All incident documentation is made available to Amazon on request.
| Recipient | Trigger | Deadline |
|---|---|---|
| Affected selling partners / clients | Their account or data is affected | Without undue delay, and in any case within 48 hours of detection |
| Spanish Data Protection Agency (AEPD) | Personal data breach posing a risk to data subjects (GDPR art. 33) | 72 hours from becoming aware |
| Data subjects | Breach posing a high risk to their rights (GDPR art. 34) | Without undue delay |
| Insurer / external counsel | Per policy and contract | As applicable |
Amazon notification is never delayed while other notifications are prepared.
Systems holding Amazon Information log, at minimum: authentication successes and failures, access attempts, data changes, privilege changes and system errors, each with date, time and actor. Logs are protected against modification and retained for at least 12 months so that an incident can be reconstructed. During an incident, relevant logs are preserved immediately and excluded from routine rotation or deletion.
Every incident, whatever its severity, is recorded in the incident register held by the IMPOC (held internally, retained for at least 3 years and made available to Amazon on request). Each entry contains: identifier, detection date and time, reporter, severity, systems and data affected, selling partners affected, notifications sent (including the Amazon notification with its timestamp), timeline of actions, root cause, corrective actions and closure date. Records are retained for at least 3 years and are made available to Amazon on request.
| Version | Date | Author | Change |
|---|---|---|---|
| 1.0 | 2026-09-30 | Noah Valderrama (Co-CEO) | Initial version, issued in response to the Amazon Service Provider Network assessment. |