Generating PDF…
WebloTTS ← All documents
← Documents

Vendor and Third Party Security Policy

Weblo TTS · TIME4IT Sp. z o.o.
Version 1.0 · last updated: 22 June 2026

1. Purpose and Scope

This policy sets security requirements for vendors and third parties supporting Weblo TTS.

2. Vendor Classification

Vendors are classified by risk level, data type handled, and service criticality.

3. Due Diligence Assessment

Before onboarding, we assess vendor security posture, legal compliance, and operational capability.

4. Contractual Requirements

  • Confidentiality and data protection obligations.
  • Incident reporting requirements.
  • Right to audit or receive compliance evidence.
  • DPA execution where personal data processing occurs.

5. TikTok as External Platform

TikTok Shop is treated as a key third-party platform; cooperation follows API terms, security requirements, and contractual reporting obligations.

6. Hosting and Infrastructure Providers

Infrastructure vendors must provide appropriate security controls, business continuity capabilities, and disaster recovery mechanisms.

7. Ongoing Monitoring and Reviews

Vendor relationships are periodically reviewed for risk, service quality, and continued security compliance.

8. Offboarding

Upon contract termination, secure data return or deletion and access revocation confirmation are required.

TikTok Shop API Addendum

Weblo TTS provides WooCommerce and TikTok Shop integration through the official TikTok Shop API.

  • Authentication and authorization are handled through OAuth2 with PKCE.
  • Access and refresh tokens are stored and processed under least-privilege controls.
  • TikTok webhooks are validated using HMAC signatures before any processing.
  • Confidential data is handled in line with TikTok Business Partner Code section 3.11.
  • Security incidents are reported to [email protected] within 24 hours and to TikTok as required by the agreement.

Document Approval

This document has been approved by the Management Board of TIME4IT Sp. z o.o.

Version: 1.0

Approval date: 22 June 2026

Contact

For questions regarding this document, security or privacy:

TIME4IT Sp. z o.o.
ul. Plonowa 24I/2, 05-500 Nowa Wola, Polska
KRS: 0001140137 · NIP: 1231569806 · REGON: 540441588
e-mail: [email protected]

© 2026 Weblo · TIME4IT Sp. z o.o.

Privacy Policy Terms of Service Documents
PL · EN