TikTok
Resumo do Questionário de Segurança & Privacidade – TikTok
- Aplicação: Software Desktop On-Premises (Instalação Local)
- Escopo: Avaliação de Conformidade de Segurança e Privacidade
- Idioma do Preenchimento: Inglês
1. Segurança de Infraestrutura & Operações
- 1.1 Política de Segurança da Informação Publicada
- Status: ❌
NÃO - Justificativa:
We selected "No" because we do not maintain a publicly published information security policy, as our solution is a desktop application deployed directly on our clients' local servers. However, we enforce core security measures within the application, including user authentication (username and password) to control access. Furthermore, data security and network protection are maintained through the client's local server environment, secured by their own firewall and network protocols.
- Status: ❌
- 1.2 Segregação de Rede e Prevenção de Ameaças
- Status: ❌
NÃO - Justificativa:
We selected "No" because our software is an on-premises desktop application deployed within the client's local infrastructure. Network segregation, intrusion detection/prevention systems, and threat monitoring are managed directly by the client's internal IT and network security team.
- Status: ❌
- 1.3 Antivírus nos Terminais da Empresa
- Status: ❌
NÃO - Justificativa:
We selected "No" as we do not deploy a centralized antivirus policy across company endpoints; however, access to corporate devices is restricted and system updates are regularly applied to mitigate endpoint threats.
- Status: ❌
- 1.4 Linha de Base de Segurança Operacional (MFA, Bloqueio de Tela, etc.)
- Status: ❌
NÃO - Justificativa:
We selected "No" as we do not maintain a centralized operational security baseline policy; however, team members are instructed to follow core security hygiene, such as locking workstations when away and using secure credentials.
- Status: ❌
- 1.5 Gerenciamento de Vulnerabilidades e Ameaças
- Status: ❌
NÃO - Justificativa:
We selected "No" because we do not perform formal automated vulnerability scans or periodic penetration tests for our desktop software. However, we maintain active code review practices and release software updates and bug fixes whenever security vulnerabilities or technical issues are identified.
- Status: ❌
2. Controle de Acesso & Proteção de Dados
- 2.1 Política de Controle de Acesso e Privilégio Mínimo
- Status: ✅
SIM - Justificativa:
We selected "Yes" regarding our access restriction practices. We enforce role-based access control (RBAC) and the principle of least privilege across internal systems and within our desktop software, ensuring users and personnel only access data strictly necessary for their specific functions.
- Status: ✅
- 2.2 Classificação e Criptografia de Dados (Trânsito e Repouso)
- Status: ✅
SIM - Justificativa:
We selected "Yes" regarding our data protection standards. All external communication in transit is encrypted using TLS 1.2 or higher (e.g., HTTPS/SSL), and sensitive application data or credentials stored locally are protected using standard strong encryption algorithms.
- Status: ✅
- 2.3 Exclusão de Dados Coletados ao Fim do Contrato
- Status: ❌
NÃO - Justificativa:
We selected "No" because our solution is a local (on-premises) desktop application, where data is stored directly on the client's local infrastructure under their own control. We do not retain or host client operational databases on our systems.
- Status: ❌
3. Governança, Privacidade & LGPD
- 3.1 Países de Armazenamento/Processamento dos Dados
- Resposta: Brasil
- 3.2 Política Interna de Proteção de Dados Pessoais
- Status: ❌
NÃO - Justificativa:
We selected "No" because we do not maintain a formal, written internal data protection policy document. As a desktop application deployed on-premises within client environments, data collection, storage, and lifecycle management are governed directly by the client's internal privacy policies and local infrastructure.
- Status: ❌
- 3.3 Política de Privacidade Mantida e Atualizada
- Status: ❌
NÃO
- Status: ❌
- 3.4 Encarregado de Proteção de Dados (DPO)
- Status: ✅
SIM - E-mail de Contato:
dataplus@dataplussistemas.com.br
- Status: ✅
- 3.5 Atendimento a Direitos dos Titulares (Exclusão/Atualização)
- Status: ✅
SIM
- Status: ✅
- 3.6 Certificações de Segurança (ISO 27001, SOC 2, etc.)
- Status: ❌
NÃO
- Status: ❌
4. Gestão de Incidentes & Histórico
- 4.1 Política de Resposta a Incidentes e Canais de Comunicação
- Status: ✅
SIM - Justificativa:
We selected "Yes" regarding our operational response process. We maintain dedicated communication and support channels for clients to report system issues or critical failures, with defined internal responsibilities for investigating, patching, and restoring software functionality promptly.
- Status: ✅
- 4.2 Processo de Notificação de Violações de Dados
- Status: ✅
SIM
- Status: ✅
- 4.3 Histórico de Violações de Segurança (Últimos 3 Anos)
- Status: ❌
NÃO - Justificativa:
We selected "No" as we have not experienced any security breach, data leak, or unauthorized exposure of personal data in the past 3 years that required notification to regulatory authorities or clients.
- Status: ❌
- 4.4 Histórico de Reclamações ou Notificações Regulatórias (Últimos 3 Anos)
- Status: ❌
NÃO - Justificativa:
We selected "No" as we have not received any formal complaints, objections, regulatory notifications, or inquiries from data protection authorities, clients, or individuals regarding the processing of personal data in the past 3 years.
- Status: ❌
5. Contexto Adicional (Comentários Gerais)
- Texto Submetido:
Additional Context: Our primary solution operates as an on-premises desktop application installed directly within our clients' local IT infrastructure. Because of this deployment model, infrastructure-level security controls (such as network segregation, server firewalls, host intrusion systems, and server-side encryption) are managed directly by the client's internal IT teams. Our company focuses on application-level security, user authentication, access control mechanisms, and delivering timely software updates and technical support