Version: 1.0
Effective Date: May 7, 2024
Last Reviewed: May 7, 2024
The purpose of this Information Security Policy is to protect the confidentiality, integrity, and availability of information assets that support our platform which helps TikTok users manage their product orders. This policy establishes our commitment to safeguard customer data, operational systems, and business continuity.
This policy applies to all employees, contractors, partners, and third parties who access or manage systems, data, or services related to TikTok order management. It includes all hardware, software, network resources, and cloud services used in the business.
All users must:
Data is classified as:
Appropriate encryption and secure storage practices must be used for confidential data.
All security incidents must be reported immediately to the designated security contact. Incidents include:
An incident response plan will be followed for containment, investigation, and recovery.
The platform must be regularly backed up, with tested recovery procedures. Downtime in TikTok integration or order management tools must be addressed within agreed service levels.
Company devices should be kept secure. When accessing business tools remotely:
All third-party vendors (e.g., TikTok API, cloud storage, payment processors) must comply with our security and privacy requirements. Security reviews should be conducted before onboarding new vendors.
All staff must complete annual information security training, including:
This policy is reviewed annually or when significant changes occur in business processes or technology.
Violations of this policy may result in disciplinary action, up to and including termination or legal action.
For questions or to report a security concern, contact:
Security Contact: Bich An
Email: nguyenthibichan04@gmail.com