Security and Data Handling

Effective Date: 26 August 2026

TJ Tech takes the security, confidentiality and responsible handling of customer information seriously.

This page explains the general principles we follow when designing, operating and supporting software systems, integrations, adapters and digital transformation solutions.

It is intended to provide transparency about our approach to security and data handling. Specific security requirements, responsibilities and controls for an individual customer engagement may be defined separately in the applicable agreement, statement of work, architecture documentation or data-processing terms.

1. Our Security Approach

TJ Tech designs systems with security, reliability and maintainability considered throughout the engineering lifecycle.

Our approach is based on principles including:

  • Least-privilege access

  • Clear responsibility boundaries

  • Secure authentication and authorization

  • Controlled system integrations

  • Data minimization

  • Input validation

  • Secure configuration

  • Separation of environments

  • Logging and monitoring

  • Failure handling

  • Controlled deployment and change management

  • Regular maintenance and updates

Security requirements may vary depending on the system architecture, customer environment, hosting arrangement, data being processed and third-party services involved.

2. Data Minimization

We aim to process only the information reasonably necessary to provide the agreed service or functionality.

Where possible, systems are designed so that unnecessary personal, financial or confidential information is not duplicated or transferred between systems.

For integration projects, the information exchanged should be limited to the fields required by the relevant workflow, interface or business process.

3. Customer Data Ownership

Customer business data remains the property and responsibility of the customer or other applicable rights holder.

TJ Tech does not claim ownership of customer data merely because that information is processed by software, adapters or systems that we develop or support.

The respective rights and responsibilities relating to customer data may be further defined in the applicable commercial agreement.

4. Access Control

Access to customer systems and information should be limited to individuals who require access for legitimate technical or operational purposes.

Depending on the engagement, controls may include:

  • Individual user accounts

  • Role-based permissions

  • Least-privilege access

  • Multi-factor authentication

  • Restricted administrative privileges

  • Environment-specific access

  • Access revocation when no longer required

Customers are responsible for managing access within systems they directly administer unless otherwise agreed.

5. Authentication and Credentials

Passwords, API keys, access tokens, certificates, private keys and other credentials should be treated as confidential security information.

TJ Tech does not recommend sharing production credentials through ordinary email, website forms, instant messaging or unsecured documents.

Where credentials must be exchanged for an engagement, an appropriate secure method should be agreed between the parties.

Credentials should be limited in scope wherever technically possible and rotated or revoked when they are no longer required.

6. Encryption

Where appropriate and supported by the relevant systems, sensitive information should be protected using encryption during transmission.

Encryption at rest may also be used depending on the hosting platform, database technology, information classification and customer requirements.

The specific cryptographic controls applicable to a project depend on its technical architecture and may be documented separately.

7. Development and Production Environments

Where appropriate, development, testing and production environments should be logically separated.

Production information should not be copied into development or testing environments unless there is a legitimate requirement and appropriate safeguards are in place.

Where realistic test information is required, anonymized, synthetic or otherwise appropriately protected datasets should be considered where practical.

8. Secure Software Development

TJ Tech’s engineering approach considers security throughout software design and implementation.

Depending on the project, this may include:

  • Secure architecture and design review

  • Input validation

  • Output encoding

  • Authentication and authorization controls

  • Protection against common application vulnerabilities

  • Dependency management

  • Error and exception handling

  • Secure configuration

  • Code review

  • Testing

  • Logging and monitoring

  • Controlled release processes

Security measures are selected according to the risks and requirements of the relevant system.

9. Third-Party Components and Dependencies

Modern software systems commonly depend on open-source libraries, cloud services, frameworks, APIs and other third-party technologies.

TJ Tech may use third-party components where appropriate for the relevant solution.

Third-party dependencies may introduce their own security considerations and should be maintained, monitored and updated where necessary.

No software dependency or external service can be guaranteed to remain free from vulnerabilities indefinitely.

10. Cloud Infrastructure

Where TJ Tech designs or supports cloud-hosted systems, infrastructure may use security capabilities provided by the selected cloud or hosting provider.

Depending on the implementation, these may include:

  • Network access controls

  • Identity and access management

  • Encryption

  • Logging

  • Backups

  • Monitoring

  • Firewall controls

  • Secret-management services

  • Availability and redundancy features

The exact responsibilities of TJ Tech, the customer and the cloud provider depend on the hosting and operating model agreed for the project.

11. Logging and Monitoring

Systems may generate technical logs to support:

  • Security monitoring

  • Troubleshooting

  • Operational support

  • Performance analysis

  • Failure investigation

  • Transaction tracking

  • Auditability

Logs should be designed to avoid recording unnecessary confidential information or credentials.

Access to operational logs may also be restricted according to system responsibilities and customer requirements.

12. Backups and Recovery

Where backups form part of the agreed solution, backup and recovery arrangements may be configured based on the customer’s operational requirements.

Factors may include:

  • Backup frequency

  • Retention period

  • Storage location

  • Encryption

  • Recovery procedures

  • Recovery objectives

  • Availability requirements

Customers should ensure that backup and disaster-recovery expectations are explicitly included in the agreed project scope where they are business-critical.

13. Vulnerabilities and Updates

Software, operating systems, frameworks and third-party components may require security patches or upgrades over time.

TJ Tech may recommend or implement updates as part of an agreed support or maintenance arrangement.

Customers are responsible for systems outside TJ Tech’s agreed scope, including third-party products and infrastructure they independently administer.

The ability to apply updates may depend on compatibility, customer approval, operational constraints and third-party vendor support.

14. Incident Handling

Where TJ Tech becomes aware of a suspected security incident affecting systems or information within its responsibility, we will take reasonable steps appropriate to the circumstances.

These steps may include:

  • Investigating the issue

  • Limiting or containing the impact

  • Preserving relevant technical information

  • Correcting identified vulnerabilities

  • Coordinating with affected customers

  • Supporting recovery

  • Providing notifications where required by applicable law or contract

The exact incident-response responsibilities for customer-operated systems may be defined in the relevant agreement.

15. Data Retention

TJ Tech does not intend to retain customer information indefinitely.

Information should be retained only for as long as reasonably necessary to:

  • Deliver contracted services

  • Provide support

  • Maintain required records

  • Resolve disputes

  • Meet legal or regulatory obligations

  • Protect legitimate business or security interests

Retention requirements may vary depending on the nature of the project and applicable agreements.

Where appropriate, information may be securely deleted, anonymized or returned when it is no longer required.

16. Data Deletion and Project Completion

At the conclusion of an engagement, customer data held specifically for that project may be deleted, returned or otherwise handled according to the applicable agreement and technical environment.

Some information may need to be retained for legal, accounting, security, backup or contractual reasons.

Data contained in system backups may remain until the relevant backup expires or is securely overwritten according to the applicable retention process.

17. UAE E-Invoicing Data Handling

TJ Tech may provide adapters, integration software and implementation services relating to UAE e-invoicing.

An e-invoicing integration may process information originating from customer accounting systems, ERP platforms or other defined sources.

TJ Tech’s approach is designed around preserving clear responsibility for source data.

The originating business system remains responsible for the correctness of business information such as:

  • Invoice values

  • Customer and supplier information

  • Tax information

  • Transaction information

  • Product or service details

  • Accounting classifications

TJ Tech software may validate whether required information is present or technically valid, but it should not be assumed to independently determine or correct the underlying commercial, tax or accounting meaning of customer data.

Where invalid or missing information is identified, the intended approach is generally for that information to be corrected through the appropriate source system or business process.

18. Accredited Service Provider Integrations

Where an e-invoicing solution connects with a customer’s chosen UAE Accredited Service Provider, information may be transmitted to and processed by that provider.

The Accredited Service Provider operates its own systems, infrastructure, security practices and contractual terms.

TJ Tech is not responsible for security controls or processing activities entirely outside systems that TJ Tech operates or controls, except where responsibility is expressly accepted in writing.

Customers should review the security, privacy and contractual terms of their selected provider.

19. Integration Security

Systems integration can involve communication between accounting software, ERP platforms, cloud services, APIs, databases, file-based processes and external providers.

Where appropriate, integrations may use measures such as:

  • Authenticated API connections

  • Encrypted transport

  • Restricted credentials

  • Network controls

  • Input validation

  • Schema validation

  • Transaction identifiers

  • Error handling

  • Retry controls

  • Reconciliation

  • Audit logging

The controls available depend on the technical capabilities of the systems being integrated.

20. Responsibility Boundaries

Security is a shared responsibility.

Depending on the engagement, responsibility may be divided among:

  • TJ Tech

  • The customer

  • Cloud infrastructure providers

  • Software vendors

  • ERP or accounting providers

  • Accredited Service Providers

  • Other integration partners

TJ Tech aims to define these boundaries clearly during architecture and implementation.

Customers remain responsible for areas under their direct control unless responsibility has been expressly assigned to TJ Tech.

This may include:

  • User account administration

  • Employee access

  • Source-system security

  • Endpoint security

  • Internal policies

  • Business-data accuracy

  • Physical security

  • Third-party vendor selection

21. Employee and Contractor Access

Where TJ Tech personnel require access to customer information or systems, access should be limited to legitimate project, engineering, support or operational requirements.

Access should be removed when it is no longer required.

Confidentiality and security obligations may also be addressed through applicable employment, contractor and customer agreements.

22. Confidential Information

TJ Tech treats information that is clearly confidential, or that should reasonably be understood as confidential, with appropriate care.

Customers should identify particularly sensitive information and communicate any special handling requirements before providing it.

Highly sensitive information should not be submitted through general website forms.

23. Personal Information

Where personal information is processed, TJ Tech seeks to handle that information in accordance with applicable data-protection requirements and our Privacy Policy.

Depending on the engagement, TJ Tech may act as a service provider or processor of information on behalf of a customer.

Additional data-processing terms may be agreed where appropriate.

24. International Data Processing

Some cloud, hosting, communications or technology providers may operate infrastructure in multiple jurisdictions.

Where customer information is processed internationally, the applicable hosting architecture, service-provider terms and data-protection requirements should be considered.

Where required, appropriate safeguards should be implemented in accordance with applicable law.

25. Security Testing

Security testing may form part of a software project depending on its requirements and agreed scope.

Testing may include automated checks, code review, dependency analysis, application testing or other appropriate technical assessments.

Independent penetration testing, formal audits or specialized compliance assessments are not included unless expressly agreed.

26. Certifications and Compliance

TJ Tech does not claim a security certification, regulatory approval or formal compliance status unless that certification or status has been expressly obtained and communicated by TJ Tech.

A customer’s compliance obligations depend on its industry, jurisdiction, systems, data and business activities.

Customers remain responsible for determining which regulatory, security and compliance requirements apply to their organization.

27. No System Is Completely Secure

Security risk cannot be eliminated entirely.

Although appropriate technical and organizational controls can significantly reduce risk, no website, software application, network, cloud service or data-transmission method can be guaranteed to be completely secure.

Security therefore requires ongoing maintenance, monitoring, responsible use and cooperation between all parties involved.

28. Reporting a Security Concern

If you believe you have identified a security issue affecting a TJ Tech website, product or system, please contact us promptly.

TJ Tech
Dubai, United Arab Emirates
Email: hello@tjtech.com

Please include “Security Report” in the subject line and provide enough information for us to understand and investigate the issue.

Please do not attempt to access, modify, delete, download or expose data that does not belong to you while investigating a suspected vulnerability.

29. Changes to This Security Statement

We may update this Security and Data Handling statement periodically as our systems, services and operational practices evolve.

The latest version will be published on our website with the applicable effective date.