Privacy Policy
Learn how TTK Europe Ltd (SendXPS) collects, uses, and protects your personal information
1. Introduction
SendXPS is operated by TTK Europe Ltd (Company No. 09922672), registered at Unit 1 Clayton Court, 5 Welcomb Street, Manchester M11 2NB, United Kingdom.
We are committed to safeguarding the privacy, integrity, and security of all data, including Amazon Information, handled via our platform and integrations.
2. Data We Collect
2.1 Information you provide
- Account registration details (name, company name, email, phone, billing address)
- Shipment information (recipient name, address, contact number)
- Payment details (processed securely by third-party providers; SendXPS does not store card data)
- Communications (emails, chats, support requests)
2.2 Information collected automatically
- Log data: IP address, browser type, device, access times
- Platform usage data: order imports, label generation, balance updates
- Cookies and similar technologies (see our Cookie Policy)
2.3 Information from third parties
- Marketplace data (e.g., Amazon orders, item details, buyer shipping address)
- Carrier tracking and delivery confirmations
- Payment and transaction confirmations
3. How We Use Your Data
We process your data to:
- Provide and operate our shipping and fulfillment services
- Generate labels, manage orders, and update tracking
- Sync with Amazon and other marketplaces
- Maintain billing, invoices, and compliance records
- Detect and prevent fraud or misuse
- Ensure system integrity, security, and service improvements
- Fulfill legal and regulatory obligations
4. Legal Basis for Processing
We rely on the following legal bases under UK GDPR:
Contract performance – to deliver our services
Legal obligation – to meet tax and compliance requirements
Legitimate interests – for security and optimization
Consent – for optional communications
5. Data Sharing
We may share data with:
- Couriers (e.g., Royal Mail, DPD UK) to fulfill shipments
- Marketplaces (e.g., Amazon) to synchronize orders and delivery status
- Payment processors for transactions and refunds
- IT infrastructure providers (AWS) for hosting and maintenance
- Authorities when required by law
We do not sell or rent personal data.
6. International Data Transfers
When data is transferred outside the UK or EEA, we use Standard Contractual Clauses (SCCs) or equivalent safeguards to ensure lawful and secure processing.
7. Data Retention and Deletion
- Amazon PII is retained only as long as necessary to fulfill orders and up to 30 days after delivery, unless required by law.
- Shipment data may be retained up to 12 months for claims and compliance.
- Billing data is retained up to 6 years for legal obligations.
All data is securely deleted or anonymized using NIST 800-88-compliant methods.
Upon Amazon's request, related data is deleted within 30 days and verified in writing.
8. Security Measures
We apply strict administrative, physical, and technical controls:
- Hosted on AWS within private subnets; databases encrypted with AES-256 and protected in transit using TLS 1.2+.
- Access limited to authorized personnel on a least-privilege basis, with Multi-Factor Authentication (MFA).
- Regular vulnerability scans, penetration tests, and code reviews.
- Continuous logging, monitoring, and intrusion detection via AWS CloudWatch, GuardDuty, and CloudTrail.
- Secure coding, patching, and DLP controls prevent unauthorized data movement.
9. Incident Response
We maintain a formal Incident Response Plan:
- Immediate detection, containment, and investigation
- Notification to Amazon within 24 hours of any Security Incident involving their data
- Reporting to affected users or authorities where required
- Full documentation, remediation, and process review to prevent recurrence
10. Employee Confidentiality
All employees handling personal or Amazon Information are trained annually on data protection, bound by confidentiality agreements, and subject to access reviews and policy enforcement.
11. Your Rights
You may:
12. Updates
We may update this Privacy Policy periodically. Any significant updates will be communicated through our website or email notifications.
13. Contact
TTK Europe Ltd (SendXPS)
Address: SendXPS DPO, Unit 1 Clayton Court, 5 Welcomb Street, Manchester, M11 2NB, UK
Email: dpo@sendxps.com
Supervisory Authority: Information Commissioner's Office (ICO) – https://ico.org.uk