Wholesail Information Security Addendum
Addendum to the Wholesail Terms of Service
This Wholesail Information Security Addendum (this “Addendum”) supplements the Wholesail Terms of Service (the “Wholesail Terms”) between Wholesail, Inc. (“Wholesail”) and Seller and applies to Wholesail’s handling of Seller Content in connection with the Wholesail Services. Capitalized terms used but not defined in this Addendum have the meanings set forth in the Wholesail Terms. In the event of a conflict between this Addendum and the Wholesail Terms, the Wholesail Terms will control except to the extent the conflict relates specifically and directly to the security of Seller Content, in which case this Addendum will control.
“Security Incident” means a confirmed unauthorized access to, or unauthorized acquisition, disclosure, or destruction of, unencrypted Seller Content in Wholesail’s possession or control that materially affects the confidentiality or security of such Seller Content. Security Incident does not include unsuccessful attempts or activity that does not compromise Seller Content, such as pings, port scans, denial-of-service attacks, or unsuccessful log-in attempts.
1. Information Security Program. Wholesail maintains a written information security program, including administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of Seller Content, appropriate to the nature of the data and aligned with generally recognized industry standards and frameworks (including the framework underlying Wholesail’s SOC 2 examination). Wholesail reviews and updates its program periodically to address evolving threats and legal requirements.
2. Personnel and Access Controls. Wholesail limits access to Seller Content to personnel and contractors who need such access to perform the Wholesail Services, under written confidentiality obligations, and applies least-privilege principles, role-based access controls, and multi-factor authentication for access to production systems. Wholesail provides periodic security awareness training to personnel with access to Seller Content and revokes access promptly upon role change or termination.
3. Encryption. Wholesail encrypts Seller Content in transit over public networks and at rest using industry-standard protocols and algorithms.
4. Vulnerability Management and Testing. Wholesail maintains a risk-based vulnerability management program, including periodic vulnerability scanning of production systems and penetration testing by a qualified independent third party at least annually, with remediation of identified issues prioritized according to risk.
5. Security Assurance. Upon Seller’s written request, no more than once per twelve (12) months and subject to confidentiality obligations, Wholesail will make available its then-current SOC 2 Type II report (or equivalent third-party audit report) and a summary of its most recent penetration test. Wholesail may satisfy security questionnaires and diligence requests by referencing such reports or the documentation available through Wholesail’s trust portal. This Section states Seller’s sole audit and assessment rights with respect to Wholesail’s security program; no onsite audits are permitted.
6. Hosting and Subprocessors. Wholesail uses reputable third-party cloud hosting providers and service providers to provide the Wholesail Services. Wholesail maintains a current list of its material subprocessors, available through its trust portal or upon written request, and will update that list to reflect material changes. Wholesail remains responsible for its subprocessors’ handling of Seller Content to the same extent as if performed by Wholesail directly.
7. Data Location. Wholesail stores Seller Content in data centers located in the United States. Authorized Wholesail personnel and contractors may access Seller Content from other locations in connection with providing and supporting the Wholesail Services, subject to the access controls described in this Addendum.
8. Business Continuity and Disaster Recovery. Wholesail maintains, and tests at least annually, a business continuity and disaster recovery plan designed to restore the material functions of the Wholesail Services promptly following a disaster or significant service interruption, including maintaining backups of Seller Content in a geographically separate location from primary production systems. A summary of the plan is available upon written request.
9. Incident Response. Wholesail maintains a written incident response plan. Wholesail will notify affected Sellers of a Security Incident without undue delay after confirmation, and in any event as required by applicable law, and will provide information regarding the nature of the incident, the categories of Seller Content involved, and the steps Wholesail is taking in response, together with a point of contact at Wholesail. Wholesail will take commercially reasonable steps to contain, investigate, and mitigate the Security Incident.
10. Seller Responsibilities. Security is a shared responsibility. Seller is responsible for maintaining the security of its own systems, devices, and networks used to access the Wholesail Services; for the secrecy and appropriate use of credentials issued to Seller and its Authorized Users (as further described in the Wholesail Terms); for promptly notifying Wholesail of any suspected unauthorized access to Seller’s account; and for the accuracy and lawfulness of the Seller Content it provides.
11. Relationship to Other Terms. If Wholesail and Seller have executed a Data Processing Addendum or negotiated security terms that impose stricter obligations on Wholesail with respect to particular data or services, those stricter obligations control for that data or those services. Wholesail may update the specific technical measures described in this Addendum from time to time, provided that no update will materially reduce the overall level of protection for Seller Content during the Term.
12. Machine Learning and AI. Wholesail may use machine learning and similar technologies to provide, secure, and improve the Wholesail Services, using Seller Content only as licensed under the Agreement and the Privacy Policy. Wholesail will not use Seller Content that identifies Seller or its Buyers to train third-party generative AI foundation models that retain such data for the provider’s own model improvement, without Seller’s consent. Wholesail’s use of aggregated and anonymized data is governed by the Wholesail Terms. Wholesail will describe material generative-AI features of the Wholesail Services in its product documentation.