Internal Personal Data Protection Policy
1. Purpose
This policy defines how Tecnodata / WinSAE protects personal information processed through the WinSAE ERP and TikTok Shop integration. The purpose is to ensure that personal information is collected, used, stored, accessed, shared, retained, and deleted in a secure and lawful manner.
2. Scope
This policy applies to:
- The WinSAE ERP and TikTok Shop integration.
- Personal information, seller data, authorization tokens, API credentials, logs, backups, and support records related to the integration.
- Employees, contractors, or service providers who may access systems or data related to the integration.
3. Data Protection Principles
Tecnodata / WinSAE follows these principles when processing personal information:
- Purpose limitation: personal information is processed only to provide, support, secure, and audit the authorized integration.
- Data minimization: only the data required for the integration and support is processed.
- Confidentiality: personal information is accessible only to authorized personnel with a legitimate business need.
- Security: appropriate technical and organizational controls are used to protect personal information.
- Retention limitation: personal information is retained only for as long as necessary or legally required.
- Accountability: policies, controls, incidents, and requests are reviewed and documented where appropriate.
4. Access Control
Access to personal information is restricted based on the principle of least privilege. Only authorized personnel may access seller data, personal information, API credentials, authorization tokens, databases, hosting, or administrative systems when required for legitimate business purposes.
5. Security Measures
Tecnodata / WinSAE applies reasonable security measures, including:
- Password-protected accounts and restricted administrative access.
- Multi-factor authentication where supported by the service or platform.
- HTTPS/TLS for data transmission where applicable.
- Secure server-side handling of API credentials and authorization tokens.
- Endpoint protection, software updates, and monitoring of relevant logs or alerts.
- Incident response and notification procedures for suspected or confirmed data breaches.
6. Data Subject and Seller Requests
Tecnodata / WinSAE will reasonably assist sellers and TikTok Shop with requests to access, update, provide, delete, or anonymize personal information processed through the integration, subject to authentication, legal requirements, contractual obligations, and technical feasibility.
7. Retention and Deletion
Personal information is retained only as long as needed to provide the integration, support sellers, maintain security, comply with legal obligations, or resolve disputes. At the end of the contractual relationship, Tecnodata / WinSAE will delete or anonymize personal information under its control unless retention is legally required.
8. Incident Reporting
Suspected or confirmed privacy or security incidents must be reported to suporte@tecnodataonline.com.br. Incidents are reviewed, contained, investigated, remediated, and notified to affected parties where required by law, contract, or platform rules.
9. Review and Updates
This policy is reviewed at least annually and whenever there is a material change to the application, infrastructure, data processing scope, applicable law, or TikTok Shop platform requirements. Updates are approved by the document owner and communicated to relevant personnel.
10. Approval
Approved by: Murilo Ribeiro Calaca
Title: Owner
Date: 2026-07-03