AMAZON SELLER SERVICES LISTINGS AGREEMENT
This Amazon Seller Services Listings Agreement (“
Agreement
”) is effective as of_________ and entered
into between:
Amazon Seller Services Private Limited, a private limited company having its registered office at Amazon
Seller Services Limited, 8
th
Floor, Brigade World Trade Center, 26/1 Dr. Raj Kumar Road, Malleswaram,
Bangalore 560055 (“
Amazon
” and the expressions “
we
”, “
us
” and "
our
" will be construed accordingly) or
any of its affiliate companies domiciled in India;
And
,
a
private/public
limited
company/ sole proprietorship/ partnership firm having its office at _______________________________
(“
Service Provider
” and the expressions "
you
" and "
your
" will be construed accordingly).
This Agreement contains the terms and conditions that govern your Listing on the Service Provider
Network (as defined below).
"
Amazon Site
" means Amazon.in (including its website, mobile application or mobile site thereof).
"
Listing(s)
" or "
Listing information
" or "
your Listing
" means information or details provided by you in
the format prescribed under Schedule A of this Agreement, which may be listed by us on the Service
Provider Network.
BY LISTING ON THE SERVICE PROVIDER NETWORK, YOU (ON BEHALF OF YOURSELF OR THE
BUSINESS YOU REPRESENT): (A) AGREE TO BE BOUND BY THIS AGREEMENT; (B)
ACKNOWLEDGE AND AGREE THAT YOU HAVE INDEPENDENTLY EVALUATED THE DESIRABILITY
OF LISTING ON THE SERVICE PROVIDER NETWORK AND ARE NOT RELYING ON ANY
REPRESENTATION, GUARANTEE, OR STATEMENT OTHER THAN AS EXPRESSLY SET FORTH IN
THIS AGREEMENT; AND (C) HEREBY REPRESENT AND WARRANT THAT YOU ARE LAWFULLY
ABLE TO ENTER INTO CONTRACTS (E.G., YOU ARE NOT A MINOR). IN ADDITION, IF THIS
AGREEMENT IS BEING AGREED TO BY A COMPANY OR OTHER LEGAL ENTITY, THEN THE
PERSON AGREEING TO THIS AGREEMENT ON BEHALF OF THAT COMPANY OR ENTITY HEREBY
REPRESENTS AND WARRANTS THAT HE OR SHE IS AUTHORIZED AND LAWFULLY ABLE TO BIND
THAT COMPANY OR ENTITY TO THIS AGREEMENT.
1.
Listing Process
To begin the Listing process, you must complete the application provided by us in any form or process
given by us via the Amazon Network Property, as identified by us in our sole discretion. You will at all
times comply with the policies, guidelines and terms pertaining to your Listing and/or the Service Provider
Network on the said Amazon Network Property (including the "Seller Central" pages of such Amazon
Network Property), including our Content Guidelines (collectively, "
Program Policies
"). We may at any
time remove you or reject or remove any of your Listings without notice and/or without assigning any
reason whatsoever.
2.
Service Provider Network
In consideration of the covenants contained herein, you permit us to display or publish your Listing on the
Service Provider Network in any medium including but not limited to any Amazon Network Property, as
we may determine in our discretion. For the purpose of this Agreement, the terms "
Service Provider
Network
" means a directory of service providers that offer Ecommerce Enablement Services to Sellers.
The terms "
Ecommerce Enablement Services
" or "
Services
" means services that assist Sellers to list
and sell their products on the Amazon Site. Some examples of the Services that may be offered by you
include: (a) product imaging; (b) cataloging; (c) shipping and logistics; (d) transportation of goods; (e)
1
product labeling and packing; (f) technical integration and order management services; and/or (g) tax
registration for place of business. The term "
Sellers
" under this Agreement means sellers registered with
Amazon for sale of their products on the Amazon Site.
You may provide one or more Services and each will be listed as a unique listing. We do not guarantee
that your Listing will be placed on or made available through any Amazon Network Property, nor do we
guarantee your Listing will appear in any particular position or rank. We do not guarantee any leads, sales
or adoption of your Services by Sellers. At any time during the Term of this Agreement, Amazon may in its
sole discretion offer certain marketing schemes or promotions to Sellers who may utilize your Services.
Under such marketing schemes or promotions, Amazon will compensate you with the fee payable for the
Services rendered to the Sellers upon receipt of an invoice for such amount as mutually agreed between
Amazon and you in writing.
Any Amazon Network Property may be redesigned or modified at any time. As between you and us, you
will be solely responsible for all obligations, risks and other aspects pertaining to the information or
Services referred to in your Listings. In addition, you are solely responsible for (including all obligations,
risks, liabilities and other aspects related to): all Listings content, URLs and any other information you
submit to us in connection with your Listing and the websites and/or other properties to which your
Listings relate to.
"Amazon Network Property"
means: (a) any website or other online point of presence operated by
Amazon or any of our affiliated companies; and/or (b) any other website, device, service, feature or online
point of presence through which any website of any of our affiliated companies and/or products or
services available thereon are syndicated, offered, merchandised, advertised or described.
3.
Listing Information
You will provide us (in any format (for instance, e-mail, excel or online form), as we may require in our
sole discretion or accept) accurate, current and complete information for each of your Listings and will
promptly update such information as necessary to ensure it at all times remains accurate, current and
complete. It is your responsibility to keep back-ups of your Listing information feeds, and we are not
responsible for loss of any Listing information for any reason. You grant us a royalty-free, non-exclusive,
worldwide, perpetual, irrevocable right and license to use, reproduce, perform, display, distribute, adapt,
transmit, modify, excerpt, analyze, re-format, create derivative works of and otherwise commercially or
non-commercially exploit in any manner, any and all of the Listing information you submit, and to
sublicense the foregoing rights.
4.
Listing Requirements
You agree that Amazon may at its discretion from time to time provide to Sellers education material
regarding the Services. You agree we may use automated software and other methods to cache, crawl,
spider, analyze and examine websites and other properties related to your Listing to improve our service
and Listings quality. Using the highest industry standards, you will treat Sellers who reach you or your
website via the Listings with courtesy and respect during all stages and resolve to our satisfaction in a
timely and professional manner any related customer service matters we or these Sellers bring to your
attention. You will not provide any information for, or otherwise seek to list on any Amazon Network
Property, any services that are prohibited by us. You will not, directly or indirectly, engage in any
fraudulent, impermissible, inappropriate or unlawful activities in connection with your Listing, including: (a)
sending multiple listings of identical services in the same feed; (b) generating fraudulent, repetitive,
impressions, queries or other interactions, whether through the use of automated applications or
otherwise; (c) collecting any information from any Amazon Network Property or retrieving, extracting,
indexing or caching any portion of any Amazon website or services or the websites or services of our
affiliates, whether through the use of automated applications or otherwise; (d) submitting information that
is incorrect, inappropriate, obscene, defamatory, infringing or violating any law for the time being in force;
(e) interfering with the proper working of any Amazon Network Property, the Listings or our systems; or
(g) attempting to bypass any mechanism we use to detect or prevent such activities.
2
5.
Term of the Agreement
The term of this Agreement will begin on the Effective Date of this Agreement or the date your Listing gets
listed on the Service Provider Network, whichever is earlier, and will continue for a period of 2 years
("
Term
"). This Agreement will get renewed upon completion of 2 years until either of the party terminates
this Agreement. Amazon may at any time without prior notice terminate this Agreement and/or de-list your
Listings, with or without cause. You may terminate this Agreement upon giving a 30 day written notice to
Amazon. To de-list your Listings, you shall give Amazon a 60 day written notice and also confirm that all
the Sellers availed of your Services have been intimated of such de-listing. Upon termination, all rights
and obligations of the parties under this Agreement will end, and Sections 3, 4, 6, 8 - 17 will survive
termination.
6.
Modification
We may modify any of the terms and conditions contained in this Agreement and/or change the form of
the Agreement (into an online format) at any time and by providing a written intimation to you or posting a
change notice or a new agreement on the relevant Amazon Network Property in our discretion. IF ANY
MODIFICATION OR CHANGE IN FORM IS UNACCEPTABLE TO YOU, YOUR ONLY RECOURSE IS TO
TERMINATE THIS AGREEMENT. YOUR CONTINUED LISTING FOLLOWING OUR WRITTEN
INTIMATION TO YOU OR POSTING OF A CHANGE NOTICE OR NEW AGREEMENT ON THE
RELEVANT AMAZON NETWORK PROPERTY WILL CONSTITUTE BINDING ACCEPTANCE OF THE
CHANGE. We reserve the right to modify or discontinue offering all or any part of the Listings at any time
without notice.
7.
Relationship of Parties
You and we are independent contractors, and nothing in this Agreement will create any partnership, joint
venture, agency, franchise, sales representative, or employment relationship between the parties. You will
have no authority to make or accept any offers or representations on our behalf. You will not make any
statement, whether on your website or otherwise, that reasonably would contradict anything in this
section.
8.
Obligations of the Service Provider
You hereby agree to do the following: (a) You will offer Services to Sellers for Listing and sale of their
products on Amazon Site; (b) You will provide weekly information and reports to Amazon on the adoption
of the Services by Sellers including ad-hoc requests for such documents from time to time; (c) You will
have a direct commercial relationship with the Sellers; (d) You will be solely responsible for the quality,
scope and pricing of your Services offered to the Sellers; (e) You will be responsible at all times to keep
the Listings information updated; (f) You will at all times comply with the Amazon Service Provider Code
of Conduct set forth in Schedule B of this Agreement, which may be modified by Amazon at any time.
9.
Release from Liabilities and Obligations
You release us from all obligations and/or liabilities arising from your contractual relationship with the
Sellers. You agree that we will not be responsible for any loss or damage suffered by you on account of
any actions or inactions attributable to the Sellers, including breach of any warranties and obligations
under your agreement with the Sellers. It is also hereby clarified that we will not warrant any work product
or Services provided by you and will not intervene to resolve any of your disputes or issues with the
Sellers.
10.
Representations
You represent and warrant to us that: (a) if you are a business, you are duly organized, validly existing
and in good standing under the laws of India; (b) your principal place of business (or, if you are registering
3
as an individual, your primary place of residence) is located within India and you will not conduct any
operations relating to this Agreement from outside India; (c) you have all requisite right, power and
authority to enter into this Agreement and perform your obligations and grant the rights, licenses and
authorizations you grant hereunder; (d) you and all of your subcontractors, agents and suppliers will
comply with all applicable laws in your performance of your obligations and exercise of your rights under
this Agreement; and (e) nothing in the information submitted to us hereunder, displayed on your website
or on any website to which your Listings link is infringing, false, misleading, defamatory, libelous,
slanderous, illegal, harassing or threatening;
11.
Indemnification
You agree to indemnify, defend and hold harmless us and our affiliates and each of our and their
respective officers, directors, employees, agents, successors, assigns and representatives, from and
against any and all costs, losses, damages, liabilities, judgments and expenses (including reasonable
fees of attorneys and other professionals), arising out of or in connection with any claim, action or
proceeding (any and all of which are
"Claims"
) which in any way may result from or arise in any manner
out of: (a) your Listing in the Service Provider Network; (b) your breach or alleged breach of any
representation, warranty or obligation in this Agreement; (c) the display of any of your Listings; or (d) any
website, images, descriptions or other content, materials and information to which your Listings link or
that are contained in your Services information you submit, including any Claim of actual or alleged
infringement or misappropriation of any third party’s intellectual property rights. Furthermore, if you are an
Agent (defined below), you will defend, indemnify and hold harmless us and our affiliates and each of our
and their respective officers, directors, employees, agents, successors, assigns and representatives, from
and against any and all costs, losses, damages, liabilities, judgments and expenses (including reasonable
fees of attorneys and other professionals), arising out of any Claim related to any alleged breach of your
representations and warranties set forth in this Agreement. At our option, you will assume control of the
defense and settlement of any Claim subject to indemnification by you (provided that, in such event, we
may at any time elect to take over control of the defense and settlement of any such Claim). In any event,
you may not settle any Claim without our prior written consent.
12.
Limitation of Liability
WE WILL NOT BE LIABLE FOR INDIRECT, SPECIAL, OR CONSEQUENTIAL DAMAGES OR ANY
LOSS OF REVENUE, PROFITS, OR DATA ARISING IN CONNECTION WITH THIS AGREEMENT,
EVEN IF WE HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
13.
Disclaimers
THE SERVICE PROVIDER NETWORK, INCLUDING ALL SOFTWARE, FUNCTIONS, MATERIALS AND
INFORMATION MADE AVAILABLE ON OR PROVIDED IN CONNECTION WITH THE SERVICE
PROVIDER NETWORK, IS PROVIDED "AS-IS." YOU AGREE TO LIST ON THE SERVICE PROVIDER
NETWORK AT YOUR OWN RISK. WE DO NOT WARRANT THAT THE RELEVANT AMAZON
NETWORK PROPERTY WILL MEET YOUR REQUIREMENTS, BE AVAILABLE, UNINTERRUPTED OR
ERROR FREE, AND WE WILL NOT BE LIABLE FOR THE CONSEQUENCES OF ANY
INTERRUPTIONS OR ERRORS. TO THE FULLEST EXTENT PERMISSIBLE BY LAW, WE AND OUR
AFFILIATES DISCLAIM AND YOU WAIVE ALL CLAIMS REGARDING: (A) ANY GUARANTEES ABOUT
TIMING, POSITIONING, ADJACENCY, PERFORMANCE, QUANTITY OR QUALITY OF (AS
APPLICABLE): PLACEMENTS, TARGETING, IMPRESSIONS, AUDIENCE SIZE, DEMOGRAPHICS; (B)
ANY REPRESENTATIONS OR WARRANTIES REGARDING THIS AGREEMENT, INCLUDING ANY
EXPRESS OR IMPLIED WARRANTIES OF MERCHANTABILITY, WARRANTIES OF FITNESS FOR A
PARTICULAR PURPOSE, AND WARRANTIES OF NON-INFRINGEMENT; (C) ANY IMPLIED
WARRANTIES ARISING OUT OF COURSE OF DEALING, COURSE OF PERFORMANCE OR USAGE
OF TRADE; AND (D) ANY OBLIGATION, LIABILITY, RIGHT, CLAIM OR REMEDY IN TORT, WHETHER
OR NOT ARISING FROM OUR NEGLIGENCE.
14.
Tax Matters
4
You will issue a valid tax invoice within the prescribed time limit. You may charge and Amazon will pay
applicable national, state or local sales or use taxes or value added taxes, service tax, goods and
services tax ("
Taxes
") that you are legally obligated to charge under the applicable legislation. You should
raise a valid tax invoice under applicable law(s) and regulations within the prescribed time limit. You may
charge and Amazon will pay any applicable Taxes provided that such Taxes are stated separately on the
valid tax invoice that you provide to Amazon. Under no circumstances, you would separately recover
Taxes from Amazon after issuance of invoice for the corresponding period. If at any time the credit for
Taxes is denied to Amazon or payment of Taxes is sought from Amazon due to, but not limited to,
issuance of a deficient invoice, or default in payment of Taxes or non-compliance of applicable laws and
regulations by you, you shall indemnify Amazon against any denied credits or Taxes recovered along with
any interest and penalties imposed on Amazon.
Any taxes, obligations, liabilities, payments, duties arising out of your relationship with the Sellers shall be
borne by you and to your account, and we will not be required to make any payments, or reimbursements,
whether in whole or in part, to you. Amazon is not responsible for collecting, remitting or reporting any
taxes arising from your transaction with sellers. If we are required by law or by administration thereof to
collect any value added, service, sales, use, goods and services or similar taxes from you, you will pay
such taxes to us. You agree to provide Amazon with all documentation as reasonably required by
Amazon to comply with its obligations, if any, under the relevant law.
Amazon may deduct or withhold any taxes that Amazon may be legally obligated to deduct or withhold
from any amounts payable to you under the SPN Terms, and payment to you as reduced by such
deductions or withholdings will constitute full payment and settlement to you of amounts payable under
these SPN Terms. During the validity of the Certificate and at any time thereafter, you will provide Amazon
with any forms, documents, or certifications, including Permanent Account Number as may be required
for Amazon to satisfy any information reporting or withholding tax obligations with respect to any
payments under these SPN Terms and you confirm that you shall duly pay any applicable taxes on your
income, as applicable on all amounts on which taxes are not or inadequately withheld and report and file
a return of income under the applicable laws and provide the necessary certifications in this respect.
15.
Confidentiality; Publicity and Information Security
15.1.
During the course of your Listing on the Service Provider Network, you may receive information
relating to us or to the Service Provider Network that is not known to the general public
(
"Confidential Information"
). You agree that: (a) all Confidential Information will remain our
exclusive property; (b) you will use Confidential Information only as is reasonably necessary for
your Listing on the Service Provider Network; and (c) you will not disclose Confidential
Information to any individual, company, or other third party.
15.2.
You may not issue any press release or make any public statement related to the Service
Provider Network, or use our name, trademarks or logo in any way (including in promotional
material) without our prior written consent, or misrepresent or embellish the relationship between
us in any way.
15.3.
Further, you agree to comply with Amazon's "Vendor Security Requirements" set forth in
Schedule C hereto while dealing with any information disclosed by Amazon pursuant to this
Agreement.
16.
Suggestions
You or any of your affiliates may elect to provide or make available suggestions, comments, ideas,
improvements, or other feedback or materials (“
Suggestions
”) to us in connection with or related to any
Amazon Network Property or your Listing on the Service Provider Network (including any related
technology or content). We will be free to use, disclose, reproduce, modify, sublicense, transfer, distribute
and exploit Suggestions in any manner.
5


17.
Miscellaneous
This Agreement is governed by the laws of India, excluding its conflicts of law rules. All disputes and
differences arising out of or in connection with this Agreement, if not resolved within 15 (fifteen) days
through discussion between the parties, shall be referred to the arbitration of a sole arbitrator jointly
appointed by the parties, failing which there shall be 3 (three) arbitrators, 1 (one) nominated by each
party, and the third other (the presiding arbitrator) chosen by the 2 (two) arbitrators so nominated. The
arbitration shall be conducted in accordance with the provisions of the Arbitration and Conciliation Act,
1996. The arbitration proceedings shall be conducted in English and the venue of the arbitration shall be
Bangalore. The arbitrator(s) shall pass a reasoned award in writing within 4 (four) months of the date of
the appointment of sole arbitrator or the presiding arbitrator, as the case may be.
You may not assign this Agreement, by operation of law or otherwise, without our prior written consent.
Subject to that restriction, this Agreement will be binding on, inure to the benefit of, and be enforceable
against the parties and their respective successors and assigns. We may perform any of our obligations
or exercise any of our rights under this Agreement through one or more of our affiliates. Our failure to
enforce your strict performance of any provision of this Agreement will not constitute a waiver of our right
to subsequently enforce such provision or any other provision of this Agreement.
You will ensure that the information in your Listings application and otherwise associated with your
Listing, including your email address and other contact information, is at all times complete, accurate, and
up-to-date. We will send all notices and other communication to you at the e-mail address you specify in
your Listing or, where applicable. You must send us all notices and other communication relating to
Amazon, your Listing or this Agreement by a nationally recognized overnight courier service, speed post
with acknowledgment receipt, facsimile with electronic confirmation or personal delivery to our address
mentioned below:
Amazon Seller Services Limited, 8th Floor, Brigade World Trade Center, 26/1 Dr. Raj Kumar Road,
Malleswaram, Bangalore 560055
In the event of any conflict between this Agreement and any other agreements or policies on the relevant
Amazon Network Property applicable to the subject matter hereof, this Agreement will prevail. This
Agreement represents the entire agreement between the parties with respect to the subject matter
described herein and supersedes any previous or contemporaneous oral or written agreements and
understandings.
This Agreement is signed by duly authorized representatives of the parties. For and on behalf of:
Amazon Seller Services Private Limited
Service Provider
(Authorized Signatory)
(Authorized Signatory)
Name:
Name:
Title:
Title:
Address:
Address:
6
SCHEDULE A
●
Mandatory Information
o
Company Name
o
Website URL
o
Service offered
o
Locations covered (where do they offer this service)
o
Contact Name:
o
Contact Email Address
o
Contact Phone Number
o
Company Profile (can be a PDF, Word, etc.file)
o
Commercials / Pricing (in excel, Word or PDF format)
o
Service Provider SLAs and Terms and Conditions
●
Additional information that we will ask for in the future:
o
Clients
o
Testimonials
7
SCHEDULE B
SERVICE PROVIDER CODE OF CONDUCT
Amazon Service Provider Code of Conduct ("
Code
") is established to maintain a transparent and
compliant directory of Service Providers who are active on the Service Provider Network ("
SPN
"). This
Code applies to the Service Providers who have agreed to the Agreement. At Amazon, we expect you to
adhere to the Code and the principles outlined in this document/help page when offering Services on
Amazon under the SPN. Failure to comply with the terms of the Code can result in removal of listings on
SPN or suspension from use of Amazon’s tools and the SPN.
1.
Community Rules
Like any community, the Amazon Site and the SPN have rules to help ensure a safe and enjoyable selling
experience for its Sellers who list their products on the Amazon Site and who obtain Services from
Service Providers.
●
Honour your commitment to offer your Services.
●
If we have removed your listing privileges, you cannot open a new service provider account as
per the terms of the Listing Agreement.
●
Do not use fake collaterals with Sellers or third party stakeholders in any of the communication.
●
Maintain accurate contact information in respect of your Service Provider account with Amazon.
●
Never mislead Sellers with incorrect information.
●
Never engage in any misleading, fraudulent, inappropriate or offensive activities/behavior with
Sellers. This applies to all your activities, including but not limited to:
o
Information provided on your account;
o
Information provided in listings, content or images;
o
Communication between you and Amazon, you and our Sellers.
●
Act fairly at all times. Unfair behaviour includes but is not limited to the following:
o
Behaviour that could be deemed as manipulation or "gaming" of any part of the buying or
selling experience;
o
Actions that could be perceived as manipulating customer or Seller reviews, including by
directly or indirectly contributing false, misleading or inauthentic content;
o
Activities that could be perceived as attempting to manipulate Amazon's search results or
sales rankings;
o
Actions that intentionally damage another Seller or service provider or their listings or
their ratings on the Amazon Network Property.
●
If a service provider is accessing Seller's Seller Central account as a part of the service (subject
to access rights granted by the Seller in its sole discretion), then all policies applicable to the
Seller in respect of access to Seller Central, will also be applicable to the Service Provider.
●
Always act in a manner that ensures a trustworthy experience for Sellers.
●
Never list services or engage in activities that may cause harm to Seller or endanger their selling
privileges on the Amazon Site.
●
Never misuse the access of Seller Central given by the Seller.
2.
Attempts to divert Sellers:
Specifically, any advertisements, marketing messages (special offers) or "calls to action" that lead, prompt
or encourage Sellers to leave the Amazon Site are prohibited.
3.
Unauthorized and improper business names:
8
Your business name (identifying your business entity on Amazon’s SPN) must be a name that: accurately
identifies you; is not misleading; and that you have the right to use (that is, the name cannot include the
trademark of, or otherwise infringe on, any trademark or other intellectual property right of any person).
Service Providers should refrain from using business names that are similar to the names of Amazon
internal teams for instance 'Seller Support'.
4.
Unauthorized and improper invoicing:
The tax invoice provided by you to the Sellers is independent of Amazon and should not reference
Amazon as either a selling partner or a customer or buyer. Please note that all Services listed on SPN are
offered by the respective Service Providers to Sellers and the transaction between the Seller and Service
Provider is independent of and to the exclusion of Amazon. Amazon is neither a service provider nor a
selling partner / Seller in such transactions.
5.
Inappropriate email communications:
All Service Provider email communications with Sellers must be courteous, relevant and appropriate.
Email communications other than as necessary for discussion on Services and emails containing
marketing communications are prohibited on the SPN.
6.
Appropriate treatment of Seller information such as email, phone numbers, sales report
etc:
Service Providers may have access to the e-mail, phone numbers or other details of those Sellers
interested in seeking a Service. Service Providers may also receive permission from Sellers to access
multiple information available on the Seller's Seller Central account. If you receive any information in
respect of Sellers, such information shall be construed as "Confidential Information" in terms of the Listing
Agreement and you are required to adhere to the Amazon Vendor Security Policy, which can be found in
our
Listing Agreement
.
Please review the policy there and the guidance below to make sure that you are using Seller's phone
numbers correctly.
●
Proper treatment of Seller
phone numbers:
o
Do not use Seller phone numbers for any purpose other than for communication with the
Seller regarding Services to be potentially provided to the Sellers.
o
Monitor who in your organisation has access to Seller phone numbers—protecting such
information is your responsibility.
o
Treat such information and any other confidential information in accordance with your
confidentiality obligations as provided in the Listing Agreement executed by you with
Amazon.
●
Improper treatment of Seller phone numbers:
o
Never share Seller phone information with any third party.
7.
Multiple service provider accounts:
Operating and maintaining multiple Service Provider accounts is prohibited. Any attempt to create multiple
Service Provider accounts may lead to termination of your listing privileges by Amazon.
8.
Misuse of ratings, feedback or reviews:
9
Service Providers cannot submit abusive or inappropriate feedback entries, coerce or threaten Sellers
into submitting feedback, submit transaction feedback regarding themselves or include personal
information about a transaction partner within a feedback entry. Furthermore, any attempt to manipulate
ratings of any Seller or Service Provider is prohibited. Any attempt to manipulate ratings, feedback or
Service Provider reviews is prohibited.
The rating and feedback features allow Sellers to evaluate the overall performance of a Service Provider,
helping Service Providers to develop a reputation within the SPN. You may not post abusive or
inappropriate feedback or include personal information about a Seller. Please note that this also includes
posting ratings or feedback to your own account. You may request feedback from the Seller. However,
you may not pay or offer any incentive to the Seller for either providing or removing the feedback.
9.
Misuse of popularity for Services:
The popularity feature allows Sellers to evaluate Service Provider’s performance. Any attempt to
manipulate this popularity feature is prohibited Eg. uploading incorrect jobs in SP Central for the Services
not given to the Seller, trying to solicit feedback from Seller in exchange of cash or kind etc.
10.
Accurate descriptions of Service information:
The Service being offered must be listed on Service detail page that accurately describes the Services in
all respects, including with respect to the following attributes: about the Service, specialties & value added
services (if any).
11.
Seller Feedback
The Feedback score is a key measure of your ability to provide a good Seller experience. You are
expected to maintain consistency in the feedback provided by Seller. Inconsistency in the feedback may
lead to removal of listings on SPN, suspension from use of Amazon’s tools and the SPN.
10
SCHEDULE C
VENDOR SECURITY REQUIREMENTS
1.
SCOPE; DEFINITIONS
1.1Security Policy. Service Provider will comply in all respects with Amazon’s information security
requirements set forth in this Schedule C (the “
Security Policy
”). The Security Policy applies to
Service Provider’s performance under the Agreement and all access, collection, use, storage,
transmission, disclosure, destruction or deletion of, and security incidents regarding, Amazon
Information. This Security Policy does not limit other obligations of Service Provider, including under
the Agreement or laws that apply to Service Provider, Service Provider’s performance under the
Agreement, the Amazon Information or the Permitted Purpose. To the extent this Security Policy
directly conflicts with the Agreement, Service Provider will promptly notify Amazon of the conflict and
will comply with the requirement that is more restrictive and more protective of Amazon Information
(which may be designated by Amazon). Amazon may change this Security Policy from time to time at
its sole discretion upon providing written notice to Service Provider, provided that if such changes are
not commercially reasonable, the parties will meet and agree on appropriate additional fees.
1.2Permitted Purpose. Service Provider may access, collect, use, store, and transmit only the Amazon
Information expressly authorized under the Agreement and solely for the purpose of providing the
services under the Agreement, consistent with the licenses (if any) granted under the Agreement (the
“
Permitted Purpose
”). Except as expressly authorized under the Agreement, Service Provider will
not access, collect, use, store or transmit any Amazon Information and will not Aggregate Amazon
Information, even if Anonymized. [Except with Amazon’s prior express written consent, Service
Provider will not (1) transfer, rent, barter, trade, sell, rent, loan, lease or otherwise distribute or make
available to any third party any Amazon Information or (2) Aggregate Amazon Information with any
other information or data, even if Anonymized.
1.3Definitions.
1.3.1
“
Aggregate
” means to combine or store Amazon Information with any data or information of
Service Provider or any third party.
1.3.2
“
Anonymize
” means to use, collect, store, transmit or transform any data or information
(including Amazon Information) in a manner or form that does not identify, permit identification
of, and is not otherwise attributable to any user, device identifier, source, product, service,
context, brand, or Amazon or its affiliates.
1.3.3
“
Amazon Information
” means, individually and collectively: (a) all Amazon Confidential
Information (as defined in the Agreement or in the non-disclosure agreement between the
parties); (b) all other data, records, files, content or information, in any form or format, acquired,
accessed, collected, received, stored or maintained by Service Provider or its affiliates from or
on behalf of Amazon or its affiliates, or otherwise in connection with the Agreement, the
services, or the parties’ performance of or exercise of rights under or in connection with the
Agreement (including [Amazon Data]); and (c) derived from (a) or (b), even if Anonymized.
2
AMAZON SECURITY POLICY
2.1Basic Security Requirements. Service Provider will, consistent with current best industry standards
and such other requirements specified by Amazon based on the classification and sensitivity of
Amazon Information, maintain physical, administrative and technical safeguards and other security
measures (i) to maintain the security and confidentiality of Amazon Information accessed, collected,
used, stored or transmitted by Service Provider, (ii) to protect that information from known or
reasonably anticipated threats or hazards to its security and integrity, accidental loss, alteration,
disclosure and all other unlawful forms of processing, and (iii) that do not constitute unfair, deceptive
or abusive acts or practices with respect to Amazon Information. Without limitation, Service Provider
will comply with the following requirements:
11
2.1.1
Firewall. Service Provider will install and maintain a working network firewall to protect data
accessible via the Internet and will keep all Amazon Information protected by the firewall at all
times. The firewall must provide both ingress and egress filtering, and have a default policy of
blocking network traffic.
2.1.2
Updates. Service Provider will keep its systems and software up-to-date with the latest
upgrades, updates, bug fixes, new versions and other modifications necessary to ensure
security of the Amazon Information.
2.1.3
Anti-virus. Service Provider will at all times use best of breed anti-virus software and scanning
technologies, and regularly updated signature files, to ensure that all operating systems,
software and other systems hosting, storing, processing, or that have access to Amazon
Information and are known to be susceptible or vulnerable to being infected by or further
propagating viruses, spyware and malicious code, are and remain free from such viruses,
spyware and malicious code. Service Provider will mitigate threats from all viruses, spyware,
and other malicious code that are or should reasonably have been detected.
2.1.4
Supplier Policy. Service Provider will maintain and enforce an information and network security
policy for employees, subcontractors, agents, and suppliers that meets the standards set out in
this policy, including methods to detect and log policy violations. Upon request by Amazon,
Service Provider will provide Amazon with information on violations of Service Provider’s
information and network security policy, even if it does not constitute a Security Incident.
2.1.5
Subcontract. Service Provider will not subcontract or delegate any of its obligations under this
Agreement to any subcontractors, affiliates, or delegates (“Subcontractors”) without Amazon’s
prior written consent. Notwithstanding the existence or terms of any subcontract or delegation,
Service Provider will remain responsible for the full performance of its obligations under this
Agreement. The terms and conditions of this Agreement will be binding upon Service Provider’s
Subcontractors and Personnel. Service Provider (a) will ensure that its Subcontractors and
Personnel comply with this Agreement, and (b) will be responsible for all acts, omissions,
negligence and misconduct of its Subcontractors and Personnel
2.1.6
Testing. Service Provider will regularly test its security systems and processes to ensure they
meet the requirements of this Security Policy.
2.1.7
Access Controls. Service Provider will secure Amazon Information, including by complying with
the following requirements:
i.
Service Provider will assign a unique ID to each person with computer access to Amazon
Information.
ii.
Service Provider will restrict access to Amazon Information to only those people with a
“need-to-know” for a Permitted Purpose.
iii.
Service Provider will regularly review the list of people and services with access to
Amazon Information, and remove accounts that no longer require access. This review
must be performed at least once every 180 days.
iv.
Service Provider will not use manufacturer-supplied defaults for system passwords and
other security parameters on any operating systems, software or other systems. Service
Provider will mandate and ensure the use of system-enforced “strong passwords” in
accordance with the best practices (described below) on all systems hosting, storing,
processing, or that have or control access to, Amazon Information (e.g., internal
system-level account passwords) and will require that all passwords and access
credentials are kept confidential (e.g., not shared amongst personnel).
o
Password best practices. Passwords must EITHER:
●
Possess more than 52 bits of entropy, where bits are calculated as (number of
symbols in password) * ( Log (number of possible symbols)/ Log(2) ), OR
●
Meet the following criteria:
o
contain at least 8 characters;
o
contain at least three (3) of the following symbol sets: uppercase letters;
lowercase letters; numbers; and symbols, such as: ` ! " ? $ ? % ^ & * ( ) _
- + = { [ } ] : ; @ ' ~ # | \ ? / .
o
do not match previous passwords, the user’s login, a dictionary word or
common name; and
12
o
are regularly replaced after no more than 180 days.
v.
Service Provider will maintain and enforce “account lockout” by disabling accounts with
access to Amazon Information when an account exceeds more than ten (10) consecutive
incorrect password attempts.
vi.
Service Provider will track all access to Amazon Information by unique ID and will
maintain a secure record of that access for at least the trailing 90 days, or such longer
period specified by Amazon based on the classification and sensitivity of the Amazon
Information.
vii.
Except where expressly authorized by Amazon in writing, Service Provider will isolate
Amazon Information at all times (including in storage, processing or transmission), from
Service Provider’s and any third party information.
viii.
If additional physical access controls are specified in an Order based on the
classification and sensitivity of Amazon Information, Service Provider will implement and
use those secure physical access control measures.
ix.
Service Provider will provide to Amazon, on an annual basis or more frequently upon
Amazon’s request, (1) log data about all use (both authorized and unauthorized) of
Amazon’s accounts or credentials provided to Service Provider for use on behalf of
Amazon (e.g., social medial account credentials), and (2) detailed log data about any
impersonation of, or attempt to impersonate, Amazon personnel or Service Provider
personnel with access to Amazon Information.
x.
Service Provider will regularly review access logs for signs of malicious behavior or
unauthorized access.
2.1.8
Remote Access. Service Provider will ensure that any remote access to servers holding
Amazon Information or Service Provider’s corporate or development workstation networks
requires two-factor authentication (e.g., requires at least two separate factors for identifying
users).
2.1.9
“In Bulk” Access. Amazon may provide the Service Provider with access to Amazon
Information “in bulk” whether the Amazon Information is in an Amazon or Service Provider
controlled database or stored in any other method, including storage in file-based archives
(e.g., flat files), etc. in accordance with the terms and conditions as may be communicated by
Amazon, in writing, from time to time. For purposes of this section, “in bulk” access means
accessing data by means of database query, report generation or any other mass transfer of
data (including downloading and re-uploading data, as the case may be). Specifically, this
section prohibits any access to Amazon Information except for access to individual records as
needed for the Permitted Purpose. Service Provider will preserve detailed log data on
attempted or successful “in bulk” access to Amazon Information, and provide reports from
these logs as part of its obligations under Section 2.6 (Security Review). In the event that an
Order provides Amazon’s written authorization for access to Amazon Information “in bulk”,
Service Provider will (1) limit such access to specified employees and specific roles with the
“need to know”, and (2) use tools that limit access and require explicit authorization and
logging of all access.
2.1.10Supplier Personnel. Amazon may condition access to Amazon Information by Service
Provider personnel on (i) Amazon’s pre-approval of the authorized Service Provider personnel
and (ii) Service Provider personnel’s execution and delivery to Amazon of individual
nondisclosure agreements, the form of which is specified by Amazon. If Amazon informs
Service Provider that these restrictions apply to particular Amazon Information, Service
Provider will (a) immediately restrict access to that Amazon Information and all related
information to only those Service Provider personnel that satisfy the conditions imposed by
Amazon, (b) if required by Amazon, obtain and deliver to Amazon signed individual
nondisclosure agreements from Service Provider personnel that will have access to the
Amazon Information (prior to granting access or providing information to the Service Provider
personnel), (c) maintain a list of all Service Provider personnel who have accessed or
received the Amazon Information and promptly provide that list to Amazon upon request, and
(d) notify Amazon no later than 24 hours after any specific individual Service Provider
personnel authorized to access Amazon Information in accordance with this Section: (y) no
13
longer needs access to Amazon Information or (z) no longer qualifies as Service Provider
personnel (e.g., the personnel leaves Service Provider’s employment).
2.2Access to Amazon Extranet and Service Provider Portals. Amazon may grant Service Provider
access to Amazon Information via web portals or other non-public websites or extranet services on
Amazon’s or a third party’s website or system (each, an “
Extranet
”) for the Permitted Purpose. If
Amazon permits Service Provider to access any Amazon Information using an Extranet, Service
Provider must comply with the following requirements:
2.2.1
Permitted Purpose. Service Provider and its personnel will access the Extranet and access,
collect, use, view, retrieve, download or store Amazon Information from the Extranet solely for
the Permitted Purpose.
2.2.2
Accounts. Service Provider will ensure that Service Provider personnel use only the Extranet
account(s) designated for each individual by Amazon and will require Service Provider
personnel to keep their access credentials confidential. .
2.2.3
Systems. Service Provider will access the Extranet only through computing or processing
systems or applications running operating systems managed by Service Provider and that
include: (i) system network firewalls in accordance with Section 2.1.1 (Firewall); (ii) centralized
patch management in compliance with Section 2.1.2 (Updates); (iii) operating system
appropriate anti-virus software in accordance with Section 2.1.4 (Supplier Policy); and (iv) for
portable devices, full disk encryption in accordance with Section 2.3 (Data Transmission).
2.2.4
Restrictions. Except if approved in advance in writing by Amazon, Service Provider will not
download, mirror or permanently store any Amazon Information from any Extranet on any
medium, including any machines, devices or servers,.
2.2.5
Account Termination. Service Provider will terminate the account of each of Service Provider’s
personnel and notify Amazon no later than 24 hours after any specific Service Provider
personnel who has been authorized to access any Extranet (a) no longer needs access to
Amazon Information or (b) no longer qualifies as Service Provider personnel (e.g., the
personnel leaves Service Provider’s employment).
2.3Data Transmission. Service Provider will comply with Amazon’s standards for protecting the
confidentiality and integrity of all transmissions of Amazon Information, including but not limited to the
requirements set forth below. Service Provider acknowledges and agrees that Amazon’s choice of
encryption mechanisms may depend on a number of factors such as technical capability, transaction
volume, latency requirements, and availability requirements.
2.3.1
Encryption. If Service Provider transmits and/or stores Amazon Information, it must transmit all
Amazon Information using an Amazon-approved mechanism for data transmission and storage,
which include the following (and may include other methods as specified by Amazon):
i.
Accepted Encryption Algorithms for stored data.
o
Public key encryption must use a 2048-bit (or larger) RSA public key
o
Symmetric encryption must use AES with a 128-bit (or larger) key, in CBC or GCM
mode. If required for compatibility reasons, TDEA/3DES may be used in CTR or CBC
mode, with an HMAC of the encrypted data
o
Hashing of encrypted data must use 128 bit HMAC keys or SHA-256 or larger digests
using the SHA-2 family of hashes. SHA1 may only be used for HMACs, key
derivation functions and random number generators.
ii.
Accepted Transport encryption methods for data transmission.
o
Common Internet protocols (
e.g.
, AS2, HTTP, XML/HTTP) over TLS 1.2 or greater,
with certificate-based authentication
o
Digitally signed and encrypted PGP (Pretty Good Privacy) or GPG (Gnu Privacy
Guard) or S/MIME (Secure MIME) or XML-ENC messages over any transport
o
IPSec connections, using suites “VPN-B”, “Suite-B-GCM-128” or “Suite-B-GCM-256"
o
SFTP or SSH connections, using 128-bit (or stronger) symmetric encryption and host
key verification.
14
2.3.2
Verification. For all message-based encryption schemes employing digital signatures
(including PGP and S/MIME), Service Provider will verify the digital signature of the message
and reject all messages with invalid signatures.
2.3.3
Confidentiality. For all encryption schemes employing public key cryptography, Service
Provider will ensure the confidentiality of the private component of the public-private key pair
and will promptly notify Amazon if the private key is compromised. Encryption keys must not
be shared with Third Party Providers or any other third parties.
2.3.4
Third Party Systems. Without limitation, Service Provider will only use the methods approved
in Section 2.3.1 (Encryption) to encrypt files or backups that include any Amazon Information
before storing such information in any third party systems, networks or other storage devices
(including “cloud” services or public utility file storage services) (“
Third Party System
”).
i.
Service Provider will give Amazon prior notice and obtain Amazon’s prior written approval
before it uses any Third Party System that stores or may otherwise have access to
Amazon Information, unless a) the data is encrypted in accordance with this Security
Policy, and b) the Third Party System will not have access to the decryption key or
unencrypted “plain text” versions of the data. Amazon reserves the right to require an
Amazon security review (in accordance with Section 2.6 (Security Review)) of the Third
Party System before giving approval.
ii.
If Service Provider uses any Third Party Systems that store or otherwise may access
unencrypted Amazon Information, Service Provider must perform a security review of the
Third Party Systems and their security controls and will provide Amazon periodic reporting
about the Third Party System’s security controls in the format requested by Amazon (e.g.,
SASE70 or its successor report), or other recognized industry-standard report approved
by Amazon).
2.4Data Retention and Destruction.
2.4.1
Retention. Service Provider will retain Amazon Information only for the purpose of, and as long
as is necessary for, the Permitted Purpose.
2.4.2
Return or Deletion. Service Provider will promptly (but within no more than 72 hours after
Amazon’s request) return to Amazon and permanently and securely delete all Amazon
Information upon and in accordance with Amazon’s notice requiring return and/or deletion.
Also, Service Provider will permanently and securely delete all live (online or network
accessible) instances of the Amazon Information within 90 days after the earlier of completion
of the Permitted Purpose or termination or expiration of the Agreement.
2.4.3
Archival Copies. If Service Provider is required by law to retain archival copies of Amazon
Information for tax or similar regulatory purposes, this archived Amazon Information must be
stored in one of the following ways:
i.
As a “cold” or offline (i.e., not available for immediate or interactive use) backup stored in
a physically secure facility; or
ii.
Encrypted in accordance with Section 2.3 (Data Transmission), where the system hosting
or storing the encrypted file(s) does not have access to a copy of the key(s) used for
encryption.
2.4.4
Recovery. If Service Provider performs a “recovery” (i.e., reverting to a backup) for the
purpose of disaster recovery, Service Provider will have and maintain a process that ensures
that all Amazon Information that is required to be deleted pursuant to the Agreement or this
Security Policy will be re-deleted or overwritten from the recovered data in accordance with
this Section 2.4 within 24 hours after recovery occurs. If Service Provider performs a recovery
for any purpose, no Amazon Information may be recovered to any third party system or
network without Amazon’s prior written approval. Amazon reserves the right to require an
Amazon security review (in accordance with Section 2.6 (Security Review)) of the third party
system or network before permitting recovery of any Amazon Information to any third party
system or network.
2.4.5
Deletion Standards. All Amazon Information deleted by Service Provider will be deleted in
accordance with the NIST Special Publication 800-88 Revision 1, Guidelines for Media
Sanitation
December
18,
2014
(available
at
http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r1.pdf
),
or
through
15
degaussing of magnetic media in an electromagnetic flux field of 5000+ GER, or by shredding
or mechanical disintegration, or such other standards Amazon may require based on the
classification and sensitivity of the Amazon Information. With respect to Amazon Information
encrypted in compliance with this Security Policy, this deletion may be done by permanently
and securely deleting all copies of the keys used for encryption.
2.5Forensic Destruction. Before disposing in any manner of any hardware, software, or any other media
that contains, or has at any time contained, Amazon Information, Service Provider will perform a
complete forensic destruction of the hardware, software or other media so that none of the Amazon
Information can be recovered or retrieved in any form. Service Provider will perform forensic
destruction in accordance with the standards Amazon may require based on the classification and
sensitivity of the Amazon Information.
2.5.1
Service Provider will not sell, resell, donate, refurbish, or otherwise transfer (including any sale
or transfer of any such hardware, software, or other media, any disposition in connection with
any liquidation of Service Provider’s business, or any other disposition) any hardware, software
or other media that contains, or has at any time contained, Amazon Information and all data
storing devices have not been Forensically Destroyed by Service Provider.
2.6Security Review.
2.6.1
Initial Review. If Amazon requests, Service Provider will undergo an initial security review (to be
conducted by, and in accordance with standards specified by, Amazon or its authorized
representatives), including the completion of a risk assessment questionnaire provided by
Amazon. Service Provider will cooperate and provide Amazon with all required information
within a reasonable time frame but no more than 20 calendar days from the date of Amazon’s
request.
2.6.2
Amazon reserves the right to periodically request Service Provider to complete a new Amazon
risk assessment questionnaire.
2.6.3
Certification. Upon Amazon’s written request, Service Provider will certify in writing to Amazon
that it is in compliance with this Agreement.
2.6.4
Other Reviews. Amazon reserves the right to periodically review the security of systems that
Service Provider uses to process Amazon Information. Service Provider will cooperate and
provide Amazon with all required information within a reasonable time frame but no more than
20 calendar days from the date of Amazon’s request.
2.6.5
Remediation. If any security review identifies any deficiencies, Service Provider will, at its sole
cost and expense, promptly take all actions necessary to remediate those deficiencies.
2.7Security Incidents. Service Provider will inform Amazon within 8 hours of detecting any actual or
suspected unauthorized access, collection, acquisition, use, transmission, disclosure, corruption or
loss of Amazon Information, or breach of any environment (i) containing Amazon Information, or (ii)
managed by Service Provider with controls substantially similar to those protecting Amazon
Information (each, a “
Security Incident
”). Service Provider will remedy each Security Incident in a
timely manner and provide Amazon written details regarding Service Provider’s internal investigation
regarding each Security Incident. Service Provider agrees not to notify any regulatory authority, nor
any customer, on behalf of Amazon unless Amazon specifically requests in writing that Service
Provider do so and Amazon reserves the right to review and approve the form and content of any
notification before it is provided to any party. Service Provider will cooperate and work together with
Amazon to formulate and execute a plan to rectify all confirmed Security Incidents.
2.8General. All choices (no matter how described) by Amazon under this Agreement will be made in its
sole discretion. Any list of examples following "including" or "e.g." is illustrative and not exhaustive,
unless qualified by terms like "only" or "solely." All references to standards for security requirements
under this Security Policy refer to the specified standards and their respective successor versions or
equivalent versions, as they may be updated, unless Amazon specifies otherwise. All notices under
this Security Policy will be given in accordance with the requirements for notices under the
Agreement.
16