Internal Personal Data Protection Policy
KUKER LTD
Internal Personal Data Protection Policy
Effective date: 14 August 2026
Last reviewed: 14 August 2026
Policy owner: KUKER LTD Management
Review frequency: At least annually and whenever there is a material change to systems, processing activities, applicable law or service providers.
1. Purpose
KUKER LTD is committed to protecting personal data and complying with applicable UK data-protection law.
This policy establishes the internal rules and controls used by KUKER LTD when collecting, accessing, storing, transmitting, sharing, retaining and deleting personal information.
It applies to personal information processed through KUKER LTD websites, marketplaces, customer-service systems, cloud services, fulfilment operations, inventory systems and internal business tools.
2. Scope
This policy applies to all directors, employees, contractors and authorised users who may access personal data on behalf of KUKER LTD.
It also applies to systems and integrations used by KUKER LTD, including where relevant:
- Shopify;
- Amazon;
- eBay;
- Etsy;
- Temu;
- TikTok Shop;
- Google Workspace;
- Google Sheets;
- Google Apps Script;
- Google Cloud;
- payment providers;
- fulfilment and logistics providers;
- professional advisers and other authorised processors.
3. Data-protection principles
KUKER LTD will process personal information in accordance with the following principles:
- lawfully, fairly and transparently;
- only for specified and legitimate purposes;
- limited to information reasonably necessary for those purposes;
- accurate and kept up to date where appropriate;
- retained only for as long as necessary;
- protected using appropriate technical and organisational security measures.
The ICO states that personal data should be adequate, relevant and limited to what is necessary, and should not be retained longer than required.
4. Data minimisation
KUKER LTD will minimise the personal information processed through internal operational systems.
Where possible, stock-management, reporting and marketplace-integration systems will use non-identifying operational information such as:
- SKU;
- product identifier;
- order number;
- quantity;
- order status;
- fulfilment status;
- marketplace identifier;
- inventory level.
Customer names, addresses, telephone numbers, email addresses and other personal information should not be copied into inventory or analytical systems unless required for a specific operational or legal purpose.
5. Purpose limitation
Personal data obtained from customers, marketplaces or service providers may only be used for legitimate KUKER LTD business activities, including:
- processing and fulfilling orders;
- customer service;
- returns and refunds;
- delivery and logistics;
- stock and inventory reconciliation;
- accounting and legal compliance;
- fraud prevention;
- security;
- marketplace administration.
Personal information must not be sold, transferred for unrelated purposes or used for unauthorised profiling or marketing.
6. Access control
Access to personal information must be restricted to authorised persons who require it for their duties.
KUKER LTD applies the principles of least privilege and need-to-know.
Where technically available:
- accounts must be individually assigned;
- strong passwords must be used;
- multi-factor authentication should be enabled;
- shared credentials should be avoided;
- administrative permissions should be limited;
- service accounts should receive only the permissions required for their function.
The ICO identifies access controls and security monitoring as examples of appropriate organisational and technical security measures.
7. Employee and contractor access
When an employee or contractor changes responsibilities, their system permissions must be reviewed.
When a person leaves KUKER LTD or no longer requires access:
- access must be removed promptly;
- passwords and credentials must be changed where necessary;
- active sessions or tokens should be revoked where appropriate;
- access to shared folders, cloud platforms and marketplace accounts must be reviewed.
8. Authentication and credentials
API keys, passwords, client secrets, access tokens and similar credentials must not be stored in publicly accessible documents or ordinary spreadsheet cells where avoidable.
Credentials for integrations should be stored using appropriate secret-management mechanisms such as:
- secured application properties;
- cloud secret-management services;
- encrypted credential stores;
- platform-provided secure authentication mechanisms.
Credentials must not be shared outside authorised KUKER LTD personnel.
9. Encryption and secure communications
Personal information must be transmitted through secure encrypted connections wherever reasonably possible.
KUKER LTD systems and integrations should use HTTPS and modern TLS protocols.
Where personal information is stored using approved cloud providers, the storage and security protections offered by those providers will be used together with KUKER LTD access controls.
10. Cloud and third-party processors
KUKER LTD may use authorised third-party providers to process data, including cloud, marketplace, payment, logistics, fulfilment and professional service providers.
Before using a provider to process personal data, KUKER LTD should consider:
- the purpose for which the provider is used;
- the categories of information involved;
- the security measures available;
- the provider's contractual and privacy protections;
- applicable international-transfer requirements;
- whether access is proportionate to the service provided.
Relevant processor relationships and data flows should be reviewed periodically.
11. Marketplace integrations
Marketplace integrations must be configured to obtain only the API permissions and data necessary for the relevant operational purpose.
Where APIs permit narrower access scopes, KUKER LTD should prefer the least-privileged scope.
Personal marketplace customer information must not be retained in internal stock systems where a non-identifying order or SKU reference is sufficient.
12. Retention and deletion
Personal information must not be retained indefinitely.
Retention periods should reflect:
- the purpose for which the information was collected;
- contractual requirements;
- accounting or tax obligations;
- legal claims;
- marketplace requirements;
- regulatory requirements.
Operational personal data that is no longer required should be deleted or anonymised.
For marketplace API integrations, KUKER LTD aims not to retain customer identity information beyond the period necessary for order fulfilment, customer support or applicable legal obligations.
Where a platform agreement requires deletion within a particular timeframe, KUKER LTD will comply with that requirement.
The ICO recommends documenting retention schedules and being able to justify how long categories of information are retained.
13. Data-subject rights
KUKER LTD will cooperate with valid requests relating to personal information, including where applicable requests for:
- access;
- correction;
- deletion;
- restriction;
- objection;
- portability.
Requests should be referred to KUKER LTD management and handled within applicable legal deadlines.
Where information originates from a marketplace and the marketplace is responsible for responding to the individual, KUKER LTD will provide reasonable assistance as required.
14. Logging and monitoring
Systems accessing marketplace or customer data should maintain appropriate operational and security logs where technically feasible.
Logs may include:
- identity of the authorised account or service;
- date and time;
- system or API action;
- relevant merchant/shop identifier;
- endpoint or function accessed;
- success or error status.
Logs should avoid unnecessarily recording complete personal-data payloads.
Access to logs must be limited to authorised personnel.
15. Personal data breaches and security incidents
Any suspected loss, unauthorised access, disclosure, compromise or misuse of personal information must be escalated immediately to KUKER LTD management.
KUKER LTD will:
- contain the incident;
- protect affected systems and credentials;
- determine what information may be affected;
- assess the potential impact on individuals;
- document the incident and actions taken;
- notify affected service providers or marketplaces where required;
- notify the ICO or other competent authority where legally required;
- notify affected individuals where required by law;
- take reasonable corrective measures to reduce recurrence.
A breach and security-incident log will be maintained.
The ICO expects organisations to record personal data breaches, including relevant facts, effects and remedial actions.
16. Security incident notification process
Where a suspected or confirmed incident relates to a marketplace or external platform, KUKER LTD will review the relevant contractual notification requirements and notify the platform without undue delay where required.
Where UK data-protection law requires regulatory notification, KUKER LTD will follow the applicable ICO reporting requirements.
17. Files containing personal information
Documents such as shipping labels, invoices, screenshots or exported reports containing personal information should only be retained where required for an operational, contractual or legal purpose.
Such files should not be uploaded into general shared folders or stock-management systems unless required.
When no longer required, they should be securely deleted.
18. Privacy by design
New systems, marketplace integrations and automation projects should consider privacy and security during design rather than after implementation.
KUKER LTD should consider:
- whether personal information is genuinely required;
- whether identifiers can be replaced by order or SKU references;
- minimum API permissions;
- retention period;
- access restrictions;
- encryption;
- logging;
- processors;
- international transfers;
- incident response.
For higher-risk processing, KUKER LTD will consider whether a formal data-protection impact assessment is appropriate.
19. International transfers
Where personal information is transferred outside the UK, KUKER LTD will consider whether an appropriate transfer mechanism or legal safeguard is required.
Where possible, KUKER LTD will prefer service configurations that process operational marketplace data within the UK or Europe where appropriate to the service.
20. Training and awareness
People with access to personal information must understand that customer and marketplace data is confidential.
Relevant personnel should be made aware of:
- this policy;
- secure credential handling;
- data minimisation;
- incident reporting;
- phishing and unauthorised-access risks;
- appropriate use of customer information.
21. Policy review
This policy will be reviewed:
- at least annually;
- when KUKER LTD introduces a material new processing activity;
- when a significant marketplace/API integration is introduced;
- following a significant security incident;
- when legal or regulatory requirements materially change.
Changes must be approved by KUKER LTD management.
Approval
Approved by: KUKER LTD Management
Effective date: 14 August 2026
Next scheduled review: 14 August 2027
Wholesale & Trade Enquiries
Fill in the form below to request a tailored wholesale quote for KUKER herbal teas. We’ll review your details and get back to you as soon as possible.