Data Security & Incident Response
Dong Guan Shi Xing Shi Jie Ke Ji You Xian Gong Si operates advertising analytics and campaign-management technology under UNY Advertising Technology. We maintain administrative, technical, and operational safeguards designed to protect Amazon Ads information, advertising account data, credentials, and related application data from unauthorized access, disclosure, alteration, or misuse.
1. Access Control
Access to Amazon Ads information is limited to authorized personnel who require access for legitimate operational, technical, reporting, analytics, or campaign-management functions.
- Administrative systems require authenticated access.
- Access is restricted according to operational need and job function.
- Public website visitors do not receive access to advertiser data, API credentials, databases, or internal management systems.
- Internal advertising dashboards and management interfaces are protected from unrestricted public access.
2. Network and Application Security
We use network and application controls intended to reduce the risk of unauthorized access to systems that process Amazon Ads information.
- Public-facing services use HTTPS and TLS encryption.
- Administrative systems are separated from publicly accessible marketing pages.
- Database and application credentials are not published on public web pages.
- Application configuration and secret credentials are stored outside publicly accessible web directories where applicable.
- Access to hosting, database, and application administration functions is restricted to authorized personnel.
3. Encryption in Transit
Amazon Ads information transmitted between supported systems is protected using encrypted HTTPS/TLS connections where applicable.
OAuth authorization, API communication, administrative access, and internal web application access are designed to use secure encrypted transport rather than unencrypted public connections.
4. Credential Protection
API credentials, passwords, refresh tokens, client secrets, encryption keys, and other sensitive authentication material are treated as confidential security information.
- Credentials are not intentionally committed to public repositories.
- Credentials are not intentionally displayed in publicly accessible application code or web pages.
- Credentials are not shared with unrelated third parties.
- Application secrets are stored separately from public website content wherever technically possible.
- Credentials may be revoked or rotated when compromise is suspected or when operational circumstances require it.
5. Password Requirements
Personnel and administrative systems that can access protected information are expected to use strong passwords and secure authentication practices.
- Passwords should be sufficiently long and difficult to guess.
- Reuse of passwords across unrelated systems should be avoided.
- Administrative credentials must not be shared with unauthorized persons.
- Passwords or credentials suspected of compromise must be changed or revoked promptly.
6. Third-Party Infrastructure
We do not sell, license, or intentionally provide Amazon Ads information to unrelated third parties.
Contracted hosting and infrastructure providers may supply the server, networking, storage, database, backup, or related infrastructure required to operate the service. Such infrastructure is used only as necessary to host and operate authorized systems.
7. Security Monitoring and Incident Response
We maintain an incident response process for suspected or confirmed security events involving systems, credentials, advertiser information, or Amazon Ads information.
Incident response process
- Identify and assess. Review the reported event, affected systems, potentially affected data, credentials, and scope.
- Contain. Restrict unauthorized access, disable affected accounts, isolate impacted systems, or suspend affected integrations when appropriate.
- Protect credentials. Revoke, rotate, or replace passwords, access tokens, refresh tokens, client secrets, or other credentials when compromise is suspected.
- Investigate. Review available logs, system activity, affected resources, and relevant records to determine cause and impact.
- Remediate. Correct identified vulnerabilities, configuration issues, access-control failures, or application defects.
- Recover. Restore affected services only after reasonable corrective measures have been completed.
- Document and review. Record the incident, actions taken, outcome, and any preventive improvements identified during the review.
8. Incidents Involving Amazon Information
If we identify an actual or suspected security incident involving Amazon Ads information, Amazon credentials, or unauthorized access to Amazon-related systems or data, we will assess the incident promptly and take appropriate containment and remediation measures.
Security incidents involving Amazon information will be reported to Amazon through the applicable Amazon security reporting channel, including security@amazon.com when required by Amazon's policies or instructions.
We will cooperate with reasonable security investigation, remediation, credential rotation, access suspension, or related actions requested by Amazon in connection with an incident.
9. Reporting a Security or Privacy Concern
Security vulnerabilities, suspected unauthorized access, privacy concerns, or potential misuse involving our services may be reported to us through our public contact channel.
Please provide sufficient information for us to understand and investigate the issue, but do not include passwords, private keys, access tokens, or other sensitive credentials in the initial report.
10. Data Minimization and Retention
We aim to collect and retain only information reasonably needed to operate authorized advertising analytics, campaign-management, reporting, measurement, quality-control, and historical decision-support functions.
Data retention periods may vary depending on operational, technical, auditing, reporting, contractual, or security requirements. Data that is no longer required may be deleted, anonymized, archived, or otherwise restricted as appropriate.
11. Security Review and Updates
Security controls, credentials, access permissions, application architecture, and incident-response procedures may be reviewed and updated as the service changes or when new security risks are identified.
This page may be updated to reflect changes to our security practices, infrastructure, Amazon Ads integrations, or applicable contractual requirements.