TELOS PACKAGING LTD · England and Wales
Privacy Policy
This policy explains what data TELOS PACKAGING LTD ("the Company", "we", "us") processes through the
e-commerce platform APIs our application is authorised to use, the legal basis on which we process it,
where it is stored, how we protect it, and how to have it removed.
- Last updated
- 16 September 2026
- Review cycle
- Reviewed at least every six months, and on any material change
- Governing law
- UK GDPR and the Data Protection Act 2018
- Contact
- sggtong@gmail.com
1. Who we are
TELOS PACKAGING LTD is a private limited company registered in England and Wales. We are an independent
software vendor: we develop and operate an ERP application for merchants who sell on e-commerce
marketplaces such as Temu. For each seller account that authorises it, the application connects to the
marketplace through that marketplace's official API and consolidates the seller's product, order,
inventory, fulfilment and settlement data into a single management console that the seller's own team
uses.
We do not collect data directly from consumers through this website. This website carries company and
compliance information only; it has no accounts, no tracking or advertising cookies and no analytics
that identify visitors.
- Registered name
- TELOS PACKAGING LTD
- Company number
- 16035958 (Companies House, England & Wales), incorporated 23 October 2024
- Company type
- Private limited company
- Nature of business
- SIC 47910 — Retail sale via mail order houses or via Internet
- Registered office
- 126 City Road, London, England, EC1V 2NX
- Data protection contact
- GUANGTONG SHANGGUAN, Director — sggtong@gmail.com
We have not appointed a statutory Data Protection Officer, as we are not required to under Article 37
of the UK GDPR. The Director named above is responsible for data protection and is the point of contact
for all matters covered by this policy.
2. What data we process, and where it comes from
The data we process is obtained from e-commerce platforms through their official APIs, for seller
accounts that have authorised our application. It falls into the following categories:
- Order data — order identifiers, order items, quantities, order status,
shipment status and tracking references.
- Product and listing data — product identifiers, listing attributes,
images, variation relationships and enhanced content, and available and inbound inventory
quantities.
- Pricing data — the seller's own item prices, declared and supply prices,
and competitive or reference pricing information the platform makes available for the seller's
listings.
- Fulfilment data — inbound shipment plans, shipment status and received
quantities.
- Financial data — settlement reports, fees, refunds, reimbursements and
related financial events.
- Shipping and logistics data — shipping service offers and rates, the
service selected, and package tracking information through to delivery.
- Account and performance data — seller account health and performance
metrics the platform reports for the authorising account.
- Market and analytics data — where the platform makes it available,
aggregated search, traffic and category performance data relating to the seller's own listings.
This data is aggregated by the platform and does not identify individual buyers.
- Account and authorisation data — the identifier of the authorising seller
account and the access tokens issued to our application.
Buyer personal data is handled platform by platform, according to what each platform's
fulfilment model requires and what our application is authorised for:
- Temu (semi-managed) — under the semi-managed model the seller arranges
delivery, so the platform provides, for each order, the recipient's name, the shipping address, and
a platform-issued relay telephone number and relay email address. For most orders the platform
delivers these contact values in masked form. They are used only to fulfil and ship that order, and
they are not used for marketing, profiling or automated decision-making.
- Other fulfilment models and other platforms — where the platform handles
delivery itself, no buyer name, address, telephone number or email address is provided to us and we
do not request any permission or role that would grant access to that data.
We also process limited personal data about the users of our application — the
seller's own staff: name or display name, work email address, account role and sign-in and action
audit records. This is needed to operate accounts, enforce permissions and keep an audit trail.
We do not obtain platform data from any source other than the platform's own APIs and the platform's
own merchant interfaces accessed under the seller's authorisation. We do not use data brokers, scraped
datasets or third-party data providers.
3. Why we process it
We process this data solely to provide the ERP service to the authorising seller. Specific purposes
are:
- Consolidating orders and inventory so the seller's operations team can process and monitor
fulfilment.
- Planning replenishment and reconciling shipments received against shipments sent.
- Calculating revenue, expenses and product-level profitability by combining platform financial data
with the seller's own cost data.
- Producing reports on sales trends, order volume, product performance and inventory turnover to
support the seller's purchasing and operational decisions.
- Monitoring for operational exceptions such as delayed shipments, low stock or price deviations.
- Creating and maintaining the seller's listings, and applying price changes according to target
prices and margin rules the seller has configured.
- Obtaining shipping rates, arranging the selected service for merchant-fulfilled orders, and
tracking packages through to delivery.
- Presenting aggregated market and search performance data alongside the seller's own sales data to
support product selection and listing optimisation.
- Operating, securing and supporting the application itself — authentication, access control,
audit logging, error diagnosis and backup.
We do not use this data for advertising, for profiling individuals, or for automated decision-making
producing legal or similarly significant effects on any individual.
4. Legal basis, and our role under the UK GDPR
Our role differs depending on whose data it is.
- Platform and buyer data belonging to an authorising seller — we act as a
processor. The seller decides what data is retrieved, for what purpose and for how long it
is kept; we process it only on the seller's documented instructions, expressed through the
authorisations the seller grants and the settings the seller configures in the application. The
seller, and in respect of buyer data also the platform, act as controller. We do not use this data
for our own purposes.
- Account data of the users of our application, and our own business records — we act
as a controller. This covers user accounts, sign-in and audit records, support
correspondence and billing records.
Where we act as a controller, we rely on the following lawful bases under Article 6(1) UK GDPR:
- Performance of a contract (Article 6(1)(b)) — to create and operate user
accounts, deliver the service the seller has contracted for, and handle support and billing.
- Legitimate interests (Article 6(1)(f)) — to keep the service secure and
available, maintain audit and access logs, prevent and investigate misuse, and diagnose faults. Our
legitimate interest is the secure and reliable operation of the service; we have assessed that this
does not override the rights and freedoms of the individuals concerned, because the data involved is
limited to business-context account and activity records and is retained only as long as needed.
- Legal obligation (Article 6(1)(c)) — where we must retain records or
respond to a lawful request.
Where we act as a processor, the lawful basis for the processing is the controller's, and our
processing is governed by the terms of our agreement with that controller. We do not process special
category data under Article 9 UK GDPR, and we do not knowingly process data relating to children.
5. Where data is stored
Data obtained through the Temu Open API is stored and processed in the United States, on
infrastructure operated by the Company for this purpose. Access to that environment is
restricted to named administrators and is subject to the controls described in Section 7.
Any change to the physical location of stored data is approved internally and disclosed to affected
platform partners before it takes effect. Where a transfer of personal data out of the United Kingdom
is involved, we rely on the UK International Data Transfer Agreement, or the UK Addendum to the
European Commission's Standard Contractual Clauses, together with the technical measures described in
Section 7.
6. Who we share it with
We do not sell platform data, and we do not share it with third parties for their own
purposes. It is accessible only to authorised personnel within our organisation, on a
least-privilege basis determined by job function.
Where an infrastructure, hosting or logistics provider necessarily processes data on our behalf in
order to deliver a service to us, that provider acts as a sub-processor. Each such provider is bound by
contract to equivalent confidentiality and security obligations, is permitted to process the data only
on our instructions and only for the purpose of delivering that service, and may not use it for any
other purpose. We disclose such arrangements to the relevant platform or seller where they require it,
and we remain responsible to the controller for the acts and omissions of our sub-processors.
We may also disclose data where we are required to do so by law, by a court, or by a competent
regulator.
7. How we protect it
- Encryption in transit — all traffic between our application, its users and
platform APIs is encrypted using TLS. Only TLS 1.2 and TLS 1.3 are enabled on our public endpoints;
TLS 1.1 and earlier are disabled.
- Encryption at rest — API credentials and tokens are encrypted using AES-256
before storage. The buyer contact data received with semi-managed marketplace orders —
recipient name, telephone number, email address and the two detailed street address lines — is
additionally encrypted at the column level using AES-256-GCM before storage.
Country, state or province, city and postal code are stored in clear text: they are not direct
identifiers, they are required for regional aggregation in reporting, and the platform does not mask
them either. Underlying storage volumes are encrypted at the disk level.
- Key management — encryption keys are held separately from the data they
protect, are not committed to source control, are not embedded in application code and are not
passed on command lines. Keys are rotated on a defined schedule and immediately on any suspected
exposure.
- Access control — role-based access with least privilege; administrative
access is protected by multi-factor authentication; access is revoked within 24 hours of a change of
role or departure.
- Isolation — each authorising seller account is held in a logically isolated
tenant; data from one account is not readable from another.
- Network — production services are published to the public internet only
through a reverse proxy; the origin servers are not directly exposed. Administrative interfaces and
databases are not published to the public internet and are reachable only over a private,
authenticated network.
- Governance — these controls are documented in our internal information
security policy, which is reviewed at least every six months. We hold no third-party security
certification; the controls above are self-assessed and are evidenced on request.
8. How long we keep it, and how it is deleted
- We retain platform data only for as long as it is needed for the purposes described in Section 3,
or for as long as the authorising seller instructs.
- An authorising seller may withdraw authorisation at any time. Our access ceases immediately, and
that account's data is deleted within 30 days, including from backups on their next
rotation.
- At the end of a contractual relationship with a platform or a seller, all collected data in our
possession is deleted within 30 days, including from backups on their next rotation, unless we are
required by law to retain a copy.
- User account and audit records are deleted within 30 days of the account being closed, except where
a longer period is required to meet a legal obligation.
- We assist platforms and sellers in responding to requests to delete, update or provide data, within
the timeframe the platform or applicable law specifies.
9. Security incidents
We maintain a written incident response plan with defined roles and reporting channels, reviewed at
least every six months. If we detect a security incident involving data belonging to a platform or a
seller, we notify the affected platform and seller within 24 hours of detection,
through the channel that platform specifies. Where we act as a processor we assist the controller in
meeting its own notification duties; where we act as a controller and the incident constitutes a
personal data breach likely to result in a risk to individuals, we report it to the Information
Commissioner's Office within 72 hours of becoming aware of it, as required by Article 33 UK GDPR.
As at the last update of this policy, we have not experienced any security breach leading to the
accidental or unlawful exposure of personal data, and we have received no complaint or notice from any
data protection or regulatory authority.
10. Your rights
If you are an individual whose personal data we hold, the UK GDPR gives you the following rights:
- Access — to be told whether we hold data about you and to receive a copy of
it.
- Rectification — to have inaccurate data corrected and incomplete data
completed.
- Erasure — to have your data deleted where one of the grounds in Article 17
applies.
- Restriction — to have our processing restricted while a dispute about
accuracy or lawfulness is resolved.
- Portability — to receive data you provided to us in a structured, commonly
used, machine-readable format, where the processing is based on consent or contract and is carried
out by automated means.
- Objection — to object to processing we carry out on the basis of legitimate
interests, and to object at any time to direct marketing (we do not carry out direct marketing using
this data).
- Withdrawal of consent — where we rely on consent, to withdraw it at any
time, without affecting processing already carried out.
To exercise any of these rights, or if you are a seller or platform seeking the deletion, correction or
provision of data we hold, contact us at
sggtong@gmail.com. We will acknowledge your request and respond
within 30 days, or sooner where a platform or applicable law requires it. We do not
charge a fee for a request unless it is manifestly unfounded or excessive.
Where we hold your data as a processor on behalf of a seller or a platform, we will forward your
request to that controller and assist them in responding, rather than acting on it ourselves.
You also have the right to lodge a complaint with the UK supervisory authority, the Information
Commissioner's Office, at
https://ico.org.uk/make-a-complaint/.
We would ask that you raise the matter with us first so that we have the opportunity to resolve it.
11. What we do not do
- We do not buy, sell, rent or otherwise trade personal data.
- We do not obtain data from data brokers, scraped datasets or third-party data aggregators.
- We do not build marketing profiles of buyers, and we do not carry out automated decision-making
that produces legal or similarly significant effects on individuals.
- We do not use buyer contact data for any purpose other than fulfilling and shipping the order it
relates to.
- We do not use platform data to train third-party machine learning models.
- We do not place advertising or cross-site tracking cookies on this website.
12. Changes to this policy
We review this policy at least every six months and update it whenever our practices, systems or
obligations change materially. The last-updated date at the top of this page always reflects the
current version. Where a change materially affects an authorising seller or platform partner, we
notify them directly.
13. Contact
- Data protection contact
- GUANGTONG SHANGGUAN, Director
- Email
- sggtong@gmail.com
- Postal address
- TELOS PACKAGING LTD, 126 City Road, London, England, EC1V 2NX, United Kingdom
- Supervisory authority
- Information Commissioner's Office —
ico.org.uk/make-a-complaint