Data Protection and Privacy Policy
1. Document Purpose
This document defines personal data protection and privacy governance for Weblo TTS under GDPR.
2. Definitions and Roles
Depending on the process, TIME4IT acts either as controller or processor of end-customer personal data.
3. GDPR Principles
- Lawfulness, fairness, and transparency.
- Data minimization and purpose limitation.
- Accuracy, integrity, and confidentiality.
- Accountability.
4. Data Processing Agreements (DPA)
Relationships with processors are governed by DPAs defining purpose, scope, and data protection safeguards.
5. Subprocessing
Subprocessors are selected through security and compliance assessment, and their list is maintained and updated.
6. Data Subject Rights
We handle requests for access, rectification, erasure, restriction, portability, and objection within statutory deadlines.
7. DPIA and Privacy by Design
High-risk processing activities require DPIA and implementation of privacy by design and by default controls.
8. Data Transfers
Transfers outside the EEA rely on adequate legal mechanisms and supplemental technical safeguards.
9. Personal Data Breaches
Breaches are identified, classified, and reported to the relevant controller without undue delay, considering statutory timelines.
10. Accountability and Oversight
Process owners and management are responsible for compliance, internal audits, and continuous improvement of the privacy program.
TikTok Shop API Addendum
Weblo TTS provides WooCommerce and TikTok Shop integration through the official TikTok Shop API.
- Authentication and authorization are handled through OAuth2 with PKCE.
- Access and refresh tokens are stored and processed under least-privilege controls.
- TikTok webhooks are validated using HMAC signatures before any processing.
- Confidential data is handled in line with TikTok Business Partner Code section 3.11.
- Security incidents are reported to [email protected] within 24 hours and to TikTok as required by the agreement.
Document Approval
This document has been approved by the Management Board of TIME4IT Sp. z o.o.
Version: 1.0
Approval date: 22 June 2026
Contact
For questions regarding this document, security or privacy:
TIME4IT Sp. z o.o.ul. Plonowa 24I/2, 05-500 Nowa Wola, Polska
KRS: 0001140137 · NIP: 1231569806 · REGON: 540441588
e-mail: [email protected]