English disclosure
The integration is not presented as already approved. Live TikTok messaging access will be activated only after TikTok grants the required scopes and an eligible Business Account owner completes the official authorization flow.
1. Product and business use case
OmniDesk is a business customer-support workspace developed by META Z VN. It helps an authorized business team manage customer-initiated conversations from supported channels in one inbox. For TikTok, the intended use is to retrieve conversations for a connected Business Account, display them to employees assigned to that channel, and send replies on behalf of that business.
2. Eligible users
The integration is for businesses that own or are authorized to manage the connected TikTok Business Account. A business administrator chooses which employees can access each connected channel. Employees who are not assigned to a channel are not permitted to read or reply to its conversations.
3. Human oversight and automation boundaries
- Customer conversations are handled by authorized business employees through a human-operated inbox.
- Automatic or suggested messages are used only when supported by TikTok, enabled by the business administrator and permitted for the relevant account or conversation.
- OmniDesk does not use Business Messaging access for unsolicited bulk outreach, scraping, account impersonation or bypassing TikTok messaging limits.
- The business remains responsible for message content, employee assignment and compliance with TikTok policies and applicable law.
4. Data roles
The connected business determines why and how its customer conversations are handled and acts as the business data controller. META Z VN operates OmniDesk as a service provider or processor for the authorized business, subject to its documented instructions, platform requirements and applicable law. META Z VN does not sell messaging data or use it for unrelated advertising.
5. Authorization and revocation
OmniDesk does not request a TikTok password. The eligible account owner is redirected to the official TikTok authorization interface and chooses whether to grant access. The business can disconnect the channel in OmniDesk and can also revoke access through the relevant TikTok account or authorization controls. After revocation, OmniDesk must stop new API access for that authorization.
End-to-end data flow
01Business authorizationAn eligible TikTok Business Account owner completes TikTok's official authorization flow.
02Webhook eventTikTok sends an event to the configured HTTPS webhook. The event is accepted only after the required verification checks.
03Authorized retrievalOmniDesk uses the granted access token and permitted endpoints to retrieve the relevant conversation or message content.
04Scoped workspaceThe conversation is associated with the correct organization and channel, then shown only to employees assigned to that channel.
05Reply or permitted automationAn authorized employee sends a reply, or an administrator-configured message is used only where TikTok indicates the capability is available.
06Audit, revoke and deleteRelevant actions are logged. The business can revoke access, disconnect the channel and request deletion of associated service data.
Data categories may include Business Account identifiers, conversation and message identifiers, message text, supported media, timestamps, delivery or capability status, employee assignment and security/audit events. OmniDesk requests and processes only data needed for the authorized workflow.
Requested access and purpose
AccessPurpose in OmniDeskRestriction
Business Messaging ReadList authorized conversations and messages, retrieve supported media and check conversation capabilities.Used only for a connected Business Account and employees assigned to that channel.
Business Messaging SendSend a human reply, upload supported reply media and use supported direct-reply capabilities.Used only for an eligible conversation and within TikTok capability and messaging limits.
Auto Message SettingConfigure supported automatic messages for a Business Account when this feature is included in the approved use case.Administrator-controlled; no unsolicited bulk messaging and no use outside TikTok-supported message types.
Business Messaging WebhooksReceive message-related events and synchronize the authorized conversation workspace.HTTPS endpoint, verification checks, replay/idempotency controls and organization/channel routing are required before production activation.
Data minimization
OmniDesk does not request every available TikTok permission. Each requested Business Messaging permission must be tied to the functions described above. Features outside the approved use case remain disabled.
Security and access controls
- Organization data is separated and channel access is granted according to business role and assignment.
- Access tokens and secrets are not displayed to ordinary users and must be protected in server-side storage.
- Administrative actions, assignments and outbound replies are designed to be attributable through audit records.
- Production activation requires HTTPS, webhook verification, secret management, backup and incident-response controls.
Công bố bằng tiếng Việt
Tích hợp này chưa được trình bày như đã được TikTok phê duyệt. Quyền nhắn tin thật chỉ được kích hoạt sau khi TikTok cấp đúng phạm vi quyền và chủ Tài khoản Doanh nghiệp đủ điều kiện hoàn tất luồng ủy quyền chính thức.
1. Mục đích sử dụng
OmniDesk là không gian chăm sóc khách hàng do META Z VN phát triển. Với TikTok, mục đích dự kiến là nhận hội thoại của Tài khoản Doanh nghiệp đã kết nối, hiển thị hội thoại cho đúng nhân viên được gán vào kênh và gửi câu trả lời thay mặt doanh nghiệp đó.
2. Phân quyền nhân viên
Quản trị viên doanh nghiệp quyết định nhân viên nào được truy cập từng kênh. Nhân viên không được gán vào kênh TikTok sẽ không được đọc hoặc trả lời hội thoại của kênh đó. Dữ liệu của các tổ chức khác nhau không được trộn lẫn.
3. Giới hạn tự động hóa
- Nhân viên được ủy quyền là người trực tiếp xử lý phần lớn hội thoại.
- Tin nhắn tự động hoặc gợi ý chỉ được dùng khi TikTok hỗ trợ, quản trị viên chủ động bật và tài khoản/hội thoại có khả năng tương ứng.
- Không dùng quyền Business Messaging để gửi hàng loạt không mong muốn, thu thập dữ liệu trái phép, mạo danh hoặc vượt giới hạn TikTok.
- Doanh nghiệp chịu trách nhiệm về nội dung trả lời, phân công nhân viên và việc tuân thủ chính sách.
4. Vai trò xử lý dữ liệu
Doanh nghiệp kết nối quyết định mục đích và cách xử lý hội thoại khách hàng. META Z VN vận hành OmniDesk với vai trò nhà cung cấp hoặc bên xử lý dữ liệu theo hướng dẫn hợp lệ của doanh nghiệp, yêu cầu nền tảng và pháp luật. Dữ liệu tin nhắn không được bán hoặc dùng cho quảng cáo không liên quan.
5. Thu hồi quyền và xóa dữ liệu
OmniDesk không yêu cầu mật khẩu TikTok. Chủ tài khoản thực hiện ủy quyền trên giao diện chính thức của TikTok. Doanh nghiệp có thể ngắt kết nối kênh, thu hồi quyền tại TikTok và gửi yêu cầu xóa dữ liệu dịch vụ liên quan theo Hướng dẫn Xóa dữ liệu.
Luồng dữ liệu từ đầu đến cuối
01Doanh nghiệp ủy quyềnChủ Tài khoản Doanh nghiệp TikTok đủ điều kiện hoàn tất luồng ủy quyền chính thức của TikTok.
02Sự kiện webhookTikTok gửi sự kiện tới webhook HTTPS đã cấu hình. Sự kiện chỉ được nhận sau các bước xác minh bắt buộc.
03Truy xuất có ủy quyềnOmniDesk dùng access token đã được cấp và endpoint được phép để lấy hội thoại hoặc nội dung tin nhắn liên quan.
04Workspace đúng phạm viHội thoại được gắn đúng tổ chức và kênh, sau đó chỉ hiển thị cho nhân viên đã được phân công vào kênh.
05Trả lời hoặc tự động hóa được phépNhân viên được phép gửi câu trả lời; tin được quản trị viên cấu hình chỉ dùng khi TikTok xác nhận khả năng tương ứng.
06Nhật ký, thu hồi và xóaHoạt động liên quan được ghi nhận. Doanh nghiệp có thể thu hồi quyền, ngắt kết nối và yêu cầu xóa dữ liệu dịch vụ.
Nhóm dữ liệu có thể gồm mã Tài khoản Doanh nghiệp, mã hội thoại/tin nhắn, nội dung, media được hỗ trợ, thời gian, trạng thái gửi hoặc capability, phân công nhân viên và sự kiện bảo mật/kiểm toán. OmniDesk chỉ yêu cầu dữ liệu cần cho quy trình đã được ủy quyền.
Phạm vi quyền yêu cầu và mục đích
QuyềnMục đích trong OmniDeskGiới hạn
Business Messaging ReadLiệt kê hội thoại/tin nhắn đã được phép, lấy media được hỗ trợ và kiểm tra capability.Chỉ dùng cho Business Account đã kết nối và nhân viên được phân công đúng kênh.
Business Messaging SendGửi câu trả lời trực tiếp, upload media trả lời được hỗ trợ và dùng direct-reply khi khả dụng.Chỉ dùng cho hội thoại đủ điều kiện, trong capability và giới hạn nhắn tin của TikTok.
Auto Message SettingCấu hình tin nhắn tự động TikTok hỗ trợ khi chức năng này thuộc use case được duyệt.Do quản trị viên kiểm soát; không gửi hàng loạt không mong muốn hoặc dùng loại tin ngoài hỗ trợ.
Business Messaging WebhooksNhận sự kiện tin nhắn và đồng bộ workspace hội thoại đã được ủy quyền.Phải có HTTPS, xác minh, chống lặp/replay và route đúng tổ chức/kênh trước khi bật production.
Giảm thiểu dữ liệu
OmniDesk không yêu cầu tất cả quyền TikTok hiện có. Mỗi quyền Business Messaging phải gắn với chức năng được mô tả ở trên; chức năng ngoài use case được duyệt sẽ bị tắt.
Bảo mật và kiểm soát truy cập
- Dữ liệu tổ chức được tách biệt; quyền kênh được cấp theo vai trò và phân công của doanh nghiệp.
- Access token và secret không hiển thị cho người dùng thường và phải được bảo vệ ở phía máy chủ.
- Thao tác quản trị, phân công và trả lời ra ngoài được thiết kế để truy vết bằng audit log.
- Chỉ kích hoạt production sau khi kiểm tra HTTPS, webhook, quản lý secret, backup và xử lý sự cố.
Questions, review and contact
Questions about this integration, reviewer testing, privacy or security can be sent to [email protected]. Please do not send passwords, access tokens, private keys or real customer message content by email.
Câu hỏi, xét duyệt và liên hệ
Câu hỏi về tích hợp, tài khoản reviewer, quyền riêng tư hoặc bảo mật có thể gửi tới [email protected]. Không gửi mật khẩu, access token, private key hoặc nội dung tin nhắn khách hàng thật qua email.