Digital Club AgencyDigital Club Agency
ServicesCase studiesBlogContact
esen
Request an audit
Digital Club AgencyDigital Club Agency

The pan-European Amazon agency. Madrid · Spain · Italy · France · Germany.

contacto@digitalclubagency.com+34 661 559 667

Services

  • Amazon PPC
  • Amazon SEO
  • A+ Content
  • Vendor Central
  • Amazon DSP
  • EU expansion

Company

  • About
  • Case studies
  • Contact

Resources

  • Blog
  • European Amazon Index
  • ACOS Calculator
© 2026 Digital Club Operations, S.L. · VAT ESB70858964 · Madrid, Spain. All rights reserved.
Privacy policyTermsCookiesLegal noticeIncident responseOrganizational changes

Security Incident Response Plan

Digital Club Operations, S.L. (trading as Digital Club Agency) CIF B70858964 · Calle Gran Vía 54, 3B · 28220 Majadahonda (Madrid), Spain

Document status. This is the controlled copy of the policy, published by Digital Club Operations, S.L. at the URL above. The version number and effective date in the table below identify the copy in force; superseded versions are retained internally. Published policies are adopted by resolution of the company's management and do not require a handwritten signature to be binding.

Document ownerNoah Valderrama — Co-CEO
Version1.0
Effective date2026-09-30
Next scheduled review2027-03-30 (every 6 months)
Approved byNoah Valderrama, Co-CEO, for Digital Club Operations, S.L.
Applies toAll employees, contractors and operators of Digital Club Operations, S.L.

This plan satisfies the requirement of the Amazon Data Protection Policy, section 1.6 (Risk Management and Incident Response Plan) and is maintained as a condition of Digital Club Operations' participation in the Amazon Service Provider Network and its access to Amazon Information.


1. Purpose and scope

This plan defines how Digital Club Operations detects, responds to, escalates and records Security Incidents, with particular attention to incidents that affect Amazon Information.

Amazon Information means any data obtained from Amazon or from a selling partner's Amazon account in the course of providing services, including but not limited to: Selling Partner API and Advertising API data, order and customer data, seller account credentials and access tokens, business and performance reports, and any derived data stored in Digital Club Operations' systems.

The plan covers all systems that store, process or transmit Amazon Information, whether operated by Digital Club Operations or by a subprocessor.

2. Definition of a Security Incident

A Security Incident is any actual or reasonably suspected event that compromises, or may compromise, the confidentiality, integrity or availability of Amazon Information or of the systems that hold it. This includes, without limitation:

  • Unauthorised access to, or use of, a selling partner's Amazon account, Seller Central, Vendor Central or Advertising Console.
  • Compromise, theft, loss or unintended disclosure of credentials, API keys, refresh tokens or service-account files.
  • Unauthorised access to Digital Club Operations' internal systems that hold Amazon Information (ERP, databases, code repositories, cloud storage, shared drives).
  • Accidental or unauthorised disclosure of Amazon Information to a third party, including sending data to the wrong recipient or exposing it publicly.
  • Malware, ransomware or any intrusion affecting a workstation or server with access to Amazon Information.
  • Loss or theft of a device with access to Amazon Information.
  • A Security Incident at a subprocessor that affects Amazon Information.

A suspicion is enough to trigger this plan. Confirmation is not required before reporting internally or to Amazon.

3. Roles and responsibilities

RoleHolderResponsibilities
Incident Management Point of Contact (IMPOC)Noah Valderrama, Co-CEO — noah@digitalclubagency.com · +34 661 559 667Single point of contact for Amazon. Declares incidents, leads response, sends the notification to Amazon, keeps the incident record.
Backup IMPOCCarlos Imaz, COO — carlos@digitalclubagency.comAssumes all IMPOC duties when the IMPOC is unreachable within 2 hours.
Incident Commander (technical)Lucas Salvador Gómez, Co-CEO & CTO — reachable at contacto@digitalclubagency.com and through the internal contact annexCoordinates containment and recovery; the only person who authorises changes to affected systems during an incident.
Operations leadCarlos Imaz, COOClient communication; coordination of account operators; assessment of impact on selling partners.
Legal / data protectionNoah Valderrama, Co-CEO, with the company's external legal counselGDPR assessment, notification to the Spanish supervisory authority (AEPD) and to data subjects where required, contractual notifications.
All personnelEveryoneReport any suspected incident immediately to the IMPOC. Reporting in good faith never carries a penalty, including when the reporter caused the incident.

Contact details for the IMPOC and Backup IMPOC are kept current and are re-verified at every scheduled review of this plan. Any change of IMPOC is notified to Amazon under the Organizational Change Notification Policy.

Internal reporting channel: contacto@digitalclubagency.com and noah@digitalclubagency.com — both monitored by the IMPOC and the Backup IMPOC — plus a direct phone call to the IMPOC on +34 661 559 667. Out of hours, the phone call takes precedence over email. Personal mobile numbers are held in the internal contact annex and re-verified at every scheduled review of this plan.

4. Incident classification

SeverityDefinitionInternal response target
SEV-1 — CriticalConfirmed or suspected unauthorised access to Amazon Information, to a selling partner's account, or to credentials granting such access. Ransomware or intrusion in any system holding Amazon Information.Response begins immediately. Amazon notified within 24 hours of detection.
SEV-2 — HighIncident with potential but unconfirmed exposure of Amazon Information; compromise of an internal system with no evidence of data access; suspected phishing with credential entry.Response begins within 4 hours. Treated as SEV-1 for Amazon notification purposes unless exposure of Amazon Information is ruled out within 24 hours.
SEV-3 — ModerateSecurity event with no exposure of Amazon Information (for example blocked malware, phishing not acted on, policy violation without data access).Response within 1 business day. Recorded; no Amazon notification unless reassessed upwards.

When severity is uncertain, the higher severity applies until the assessment is complete.

5. Response procedure

5.1 Preparation (ongoing)

  • Access to Amazon Information is granted on a least-privilege basis and reviewed quarterly.
  • Credentials and API keys must be stored in the company password manager and secrets store, and must never be kept in code, spreadsheets, chat or email. A secret committed to a repository by mistake is treated as a Security Incident under section 2.
  • Multi-factor authentication is required on every system that holds, or grants access to, Amazon Information. Any exception must be documented, time-boxed and approved in writing by the CTO.
  • Logs are collected and retained for at least 12 months (see section 7).
  • All personnel with access to Amazon Information complete security awareness training at onboarding and annually.
  • This plan is tested through a tabletop exercise at least every 6 months (section 9).

5.2 Identification

  1. Whoever detects or suspects an incident reports it immediately through the internal reporting channel — no triage by the reporter, no delay to gather evidence.
  2. The IMPOC acknowledges, opens an incident record (section 8) and assigns a severity.
  3. The IMPOC starts the 24-hour clock for Amazon notification at the moment of detection or suspicion, not at the moment of confirmation.
  4. Evidence is preserved before remediation: logs, screenshots, affected files and access records are copied to the incident record.

5.3 Containment

  • Revoke or rotate the affected credentials, API keys, refresh tokens and service accounts.
  • Suspend the affected user accounts and sessions; remove third-party application authorisations where relevant.
  • Isolate affected devices and systems from the network.
  • Where a selling partner's account is affected, coordinate with that selling partner before making changes to their account.

5.4 Eradication

  • Identify and remove the root cause: malware, backdoor, misconfiguration, exposed secret, vulnerable dependency or compromised subprocessor.
  • Rebuild rather than clean any system that cannot be verified as trustworthy.
  • Verify that no persistence mechanism remains.

5.5 Recovery

  • Restore service from a verified clean state and confirm data integrity.
  • Reissue credentials and re-establish access under least privilege.
  • Monitor the affected systems closely for at least 14 days after recovery.

5.6 Post-incident review (lessons learned)

Within 10 business days of closing a SEV-1 or SEV-2 incident, the IMPOC runs a blameless review producing: timeline, root cause, impact on Amazon Information and on selling partners, what worked, what failed, and corrective actions with an owner and a due date. Corrective actions are tracked to completion and their status is reported to the CEOs monthly until closed.

6. Notification

6.1 Notification to Amazon — within 24 hours

Digital Club Operations notifies Amazon by email to security@amazon.com within 24 hours of detecting a Security Incident or suspecting that one has occurred, as required by section 1.6 of the Amazon Data Protection Policy.

Note: the former address 3p-security@amazon.com has not been monitored since 3 July 2024. security@amazon.com is the current channel.

The notification is sent by the IMPOC (or Backup IMPOC) and includes, to the extent known at the time — an incomplete notification within 24 hours always takes precedence over a complete notification later:

  • Date and time of detection, and of the incident itself if known.
  • Description of the incident and current status.
  • Categories and approximate volume of Amazon Information affected, and the selling partner accounts involved.
  • Root cause, if known.
  • Containment and remediation actions already taken and planned.
  • IMPOC name, email and phone for follow-up.

Updates are sent as the investigation progresses, and a final report is sent on closure. All incident documentation is made available to Amazon on request.

6.2 Other notifications

RecipientTriggerDeadline
Affected selling partners / clientsTheir account or data is affectedWithout undue delay, and in any case within 48 hours of detection
Spanish Data Protection Agency (AEPD)Personal data breach posing a risk to data subjects (GDPR art. 33)72 hours from becoming aware
Data subjectsBreach posing a high risk to their rights (GDPR art. 34)Without undue delay
Insurer / external counselPer policy and contractAs applicable

Amazon notification is never delayed while other notifications are prepared.

7. Logging and evidence

Systems holding Amazon Information log, at minimum: authentication successes and failures, access attempts, data changes, privilege changes and system errors, each with date, time and actor. Logs are protected against modification and retained for at least 12 months so that an incident can be reconstructed. During an incident, relevant logs are preserved immediately and excluded from routine rotation or deletion.

8. Records

Every incident, whatever its severity, is recorded in the incident register held by the IMPOC (held internally, retained for at least 3 years and made available to Amazon on request). Each entry contains: identifier, detection date and time, reporter, severity, systems and data affected, selling partners affected, notifications sent (including the Amazon notification with its timestamp), timeline of actions, root cause, corrective actions and closure date. Records are retained for at least 3 years and are made available to Amazon on request.

9. Testing, review and maintenance

  • Tabletop exercise at least every 6 months, using a realistic scenario (for example: compromise of a Seller Central credential, or exposure of an API key in a public repository). The exercise is documented, and gaps identified become corrective actions.
  • Plan review every 6 months and, additionally, after any major change to infrastructure, systems, controls, operational environment, risk level or supply chain, and after any SEV-1 incident.
  • Each review verifies that roles, contact details, systems inventory and notification channels are still accurate; the version table at the top of this document is updated on every change.

10. Version history

VersionDateAuthorChange
1.02026-09-30Noah Valderrama (Co-CEO)Initial version, issued in response to the Amazon Service Provider Network assessment.