SINGAPORE KINGKUNGMEDIA PTE. LTD.
KingKung · Seller Center (TikTok Shop OMS)  |  Document ID: PIPS-KK-2026-1.1  |  Classification: Internal — Data Protection

Personal Information Protection Standard

Version 1.1  ·  Effective June 2026  ·  Review cycle: Annual  ·  Primary data region: Singapore

1. Purpose and scope

This Personal Information Protection Standard (“PIPS”) defines how SINGAPORE KINGKUNGMEDIA PTE. LTD. (“KingKung”, “we”, “our”) protects personal data and TikTok Shop merchant data processed through the KingKung Seller Center OMS and related integrations.

This standard applies to:

Public privacy notice: https://apitt.douking.vip/privacy.php

2. Roles and responsibilities

RoleResponsibility
ManagementApproves this standard, security resources, incident escalation
Data Protection Officer (DPO)Compliance oversight; privacy inquiries; breach notifications
EngineeringHTTPS, access control, encryption, logging, secure SDLC
OperationsHost hardening, backups, monitoring, patches (Alibaba Cloud Singapore)

DPO contact: privacy@kingkungmedia.com

3. Information security policy

KingKung maintains this PIPS and related procedures covering acceptable use, authentication, remote access, change management, and vendor management. Reviewed at least annually and after material incidents.

4. Network security and monitoring

5. Endpoint and workplace security baselines

6. Access control (least privilege)

7. Data classification and encryption

ClassExamplesControls
ConfidentialOAuth tokens, API secrets, full buyer PII if syncedEncrypt at rest; no git; restricted access
InternalOrder IDs, SKUs, masked buyer fieldsHTTPS; server access control
PublicPrivacy policy, termsIntegrity monitoring

8. Vulnerability and threat management

9. Incident response

  1. Detection — alerts, staff report, TikTok/merchant notification
  2. Containment — isolate systems, revoke tokens, block IPs
  3. Assessment — scope, data categories, affected merchants
  4. Notification — TikTok Partner support and merchants within 72h if breach confirmed
  5. Remediation — patch, rotate credentials, root cause
  6. Post-incident review — update controls within 30 days

Incident reports retained ≥ 3 years.

10. Privacy, merchant rights, and data lifecycle

11. Training and awareness

Security orientation before production access; annual refresher; developer training on TikTok API credential handling.

12. Subprocessors

Primary: Alibaba Cloud (Singapore) — hosting and networking under provider confidentiality terms.

13. Compliance statements

14. Document control

VersionDateChanges
1.02024Initial personal data protection policy
1.1June 2026Expanded to TikTok Partner PIPS format

Approved by:

Management — SINGAPORE KINGKUNGMEDIA PTE. LTD.
Date: June 2026