Telos Packaging
← Back to home
TELOS PACKAGING LTD · England and Wales

Privacy Policy

This policy explains what data TELOS PACKAGING LTD ("the Company", "we", "us") processes through the e-commerce platform APIs our application is authorised to use, the legal basis on which we process it, where it is stored, how we protect it, and how to have it removed.

Last updated
16 September 2026
Review cycle
Reviewed at least every six months, and on any material change
Governing law
UK GDPR and the Data Protection Act 2018
Contact
sggtong@gmail.com

1. Who we are

TELOS PACKAGING LTD is a private limited company registered in England and Wales. We are an independent software vendor: we develop and operate an ERP application for merchants who sell on e-commerce marketplaces such as Temu. For each seller account that authorises it, the application connects to the marketplace through that marketplace's official API and consolidates the seller's product, order, inventory, fulfilment and settlement data into a single management console that the seller's own team uses.

We do not collect data directly from consumers through this website. This website carries company and compliance information only; it has no accounts, no tracking or advertising cookies and no analytics that identify visitors.

Registered name
TELOS PACKAGING LTD
Company number
16035958 (Companies House, England & Wales), incorporated 23 October 2024
Company type
Private limited company
Nature of business
SIC 47910 — Retail sale via mail order houses or via Internet
Registered office
126 City Road, London, England, EC1V 2NX
Data protection contact
GUANGTONG SHANGGUAN, Director — sggtong@gmail.com

We have not appointed a statutory Data Protection Officer, as we are not required to under Article 37 of the UK GDPR. The Director named above is responsible for data protection and is the point of contact for all matters covered by this policy.

2. What data we process, and where it comes from

The data we process is obtained from e-commerce platforms through their official APIs, for seller accounts that have authorised our application. It falls into the following categories:

Buyer personal data is handled platform by platform, according to what each platform's fulfilment model requires and what our application is authorised for:

We also process limited personal data about the users of our application — the seller's own staff: name or display name, work email address, account role and sign-in and action audit records. This is needed to operate accounts, enforce permissions and keep an audit trail.

We do not obtain platform data from any source other than the platform's own APIs and the platform's own merchant interfaces accessed under the seller's authorisation. We do not use data brokers, scraped datasets or third-party data providers.

3. Why we process it

We process this data solely to provide the ERP service to the authorising seller. Specific purposes are:

We do not use this data for advertising, for profiling individuals, or for automated decision-making producing legal or similarly significant effects on any individual.

4. Legal basis, and our role under the UK GDPR

Our role differs depending on whose data it is.

Where we act as a controller, we rely on the following lawful bases under Article 6(1) UK GDPR:

Where we act as a processor, the lawful basis for the processing is the controller's, and our processing is governed by the terms of our agreement with that controller. We do not process special category data under Article 9 UK GDPR, and we do not knowingly process data relating to children.

5. Where data is stored

Data obtained through the Temu Open API is stored and processed in the United States, on infrastructure operated by the Company for this purpose. Access to that environment is restricted to named administrators and is subject to the controls described in Section 7.

Any change to the physical location of stored data is approved internally and disclosed to affected platform partners before it takes effect. Where a transfer of personal data out of the United Kingdom is involved, we rely on the UK International Data Transfer Agreement, or the UK Addendum to the European Commission's Standard Contractual Clauses, together with the technical measures described in Section 7.

6. Who we share it with

We do not sell platform data, and we do not share it with third parties for their own purposes. It is accessible only to authorised personnel within our organisation, on a least-privilege basis determined by job function.

Where an infrastructure, hosting or logistics provider necessarily processes data on our behalf in order to deliver a service to us, that provider acts as a sub-processor. Each such provider is bound by contract to equivalent confidentiality and security obligations, is permitted to process the data only on our instructions and only for the purpose of delivering that service, and may not use it for any other purpose. We disclose such arrangements to the relevant platform or seller where they require it, and we remain responsible to the controller for the acts and omissions of our sub-processors.

We may also disclose data where we are required to do so by law, by a court, or by a competent regulator.

7. How we protect it

8. How long we keep it, and how it is deleted

9. Security incidents

We maintain a written incident response plan with defined roles and reporting channels, reviewed at least every six months. If we detect a security incident involving data belonging to a platform or a seller, we notify the affected platform and seller within 24 hours of detection, through the channel that platform specifies. Where we act as a processor we assist the controller in meeting its own notification duties; where we act as a controller and the incident constitutes a personal data breach likely to result in a risk to individuals, we report it to the Information Commissioner's Office within 72 hours of becoming aware of it, as required by Article 33 UK GDPR.

As at the last update of this policy, we have not experienced any security breach leading to the accidental or unlawful exposure of personal data, and we have received no complaint or notice from any data protection or regulatory authority.

10. Your rights

If you are an individual whose personal data we hold, the UK GDPR gives you the following rights:

To exercise any of these rights, or if you are a seller or platform seeking the deletion, correction or provision of data we hold, contact us at sggtong@gmail.com. We will acknowledge your request and respond within 30 days, or sooner where a platform or applicable law requires it. We do not charge a fee for a request unless it is manifestly unfounded or excessive.

Where we hold your data as a processor on behalf of a seller or a platform, we will forward your request to that controller and assist them in responding, rather than acting on it ourselves.

You also have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner's Office, at https://ico.org.uk/make-a-complaint/. We would ask that you raise the matter with us first so that we have the opportunity to resolve it.

11. What we do not do

12. Changes to this policy

We review this policy at least every six months and update it whenever our practices, systems or obligations change materially. The last-updated date at the top of this page always reflects the current version. Where a change materially affects an authorising seller or platform partner, we notify them directly.

13. Contact

Data protection contact
GUANGTONG SHANGGUAN, Director
Email
sggtong@gmail.com
Postal address
TELOS PACKAGING LTD, 126 City Road, London, England, EC1V 2NX, United Kingdom
Supervisory authority
Information Commissioner's Office — ico.org.uk/make-a-complaint