Effective Date: 26 August 2026
TJ Tech takes the security, confidentiality and responsible handling of customer information seriously.
This page explains the general principles we follow when designing, operating and supporting software systems, integrations, adapters and digital transformation solutions.
It is intended to provide transparency about our approach to security and data handling. Specific security requirements, responsibilities and controls for an individual customer engagement may be defined separately in the applicable agreement, statement of work, architecture documentation or data-processing terms.
TJ Tech designs systems with security, reliability and maintainability considered throughout the engineering lifecycle.
Our approach is based on principles including:
Least-privilege access
Clear responsibility boundaries
Secure authentication and authorization
Controlled system integrations
Data minimization
Input validation
Secure configuration
Separation of environments
Logging and monitoring
Failure handling
Controlled deployment and change management
Regular maintenance and updates
Security requirements may vary depending on the system architecture, customer environment, hosting arrangement, data being processed and third-party services involved.
We aim to process only the information reasonably necessary to provide the agreed service or functionality.
Where possible, systems are designed so that unnecessary personal, financial or confidential information is not duplicated or transferred between systems.
For integration projects, the information exchanged should be limited to the fields required by the relevant workflow, interface or business process.
Customer business data remains the property and responsibility of the customer or other applicable rights holder.
TJ Tech does not claim ownership of customer data merely because that information is processed by software, adapters or systems that we develop or support.
The respective rights and responsibilities relating to customer data may be further defined in the applicable commercial agreement.
Access to customer systems and information should be limited to individuals who require access for legitimate technical or operational purposes.
Depending on the engagement, controls may include:
Individual user accounts
Role-based permissions
Least-privilege access
Multi-factor authentication
Restricted administrative privileges
Environment-specific access
Access revocation when no longer required
Customers are responsible for managing access within systems they directly administer unless otherwise agreed.
Passwords, API keys, access tokens, certificates, private keys and other credentials should be treated as confidential security information.
TJ Tech does not recommend sharing production credentials through ordinary email, website forms, instant messaging or unsecured documents.
Where credentials must be exchanged for an engagement, an appropriate secure method should be agreed between the parties.
Credentials should be limited in scope wherever technically possible and rotated or revoked when they are no longer required.
Where appropriate and supported by the relevant systems, sensitive information should be protected using encryption during transmission.
Encryption at rest may also be used depending on the hosting platform, database technology, information classification and customer requirements.
The specific cryptographic controls applicable to a project depend on its technical architecture and may be documented separately.
Where appropriate, development, testing and production environments should be logically separated.
Production information should not be copied into development or testing environments unless there is a legitimate requirement and appropriate safeguards are in place.
Where realistic test information is required, anonymized, synthetic or otherwise appropriately protected datasets should be considered where practical.
TJ Tech’s engineering approach considers security throughout software design and implementation.
Depending on the project, this may include:
Secure architecture and design review
Input validation
Output encoding
Authentication and authorization controls
Protection against common application vulnerabilities
Dependency management
Error and exception handling
Secure configuration
Code review
Testing
Logging and monitoring
Controlled release processes
Security measures are selected according to the risks and requirements of the relevant system.
Modern software systems commonly depend on open-source libraries, cloud services, frameworks, APIs and other third-party technologies.
TJ Tech may use third-party components where appropriate for the relevant solution.
Third-party dependencies may introduce their own security considerations and should be maintained, monitored and updated where necessary.
No software dependency or external service can be guaranteed to remain free from vulnerabilities indefinitely.
Where TJ Tech designs or supports cloud-hosted systems, infrastructure may use security capabilities provided by the selected cloud or hosting provider.
Depending on the implementation, these may include:
Network access controls
Identity and access management
Encryption
Logging
Backups
Monitoring
Firewall controls
Secret-management services
Availability and redundancy features
The exact responsibilities of TJ Tech, the customer and the cloud provider depend on the hosting and operating model agreed for the project.
Systems may generate technical logs to support:
Security monitoring
Troubleshooting
Operational support
Performance analysis
Failure investigation
Transaction tracking
Auditability
Logs should be designed to avoid recording unnecessary confidential information or credentials.
Access to operational logs may also be restricted according to system responsibilities and customer requirements.
Where backups form part of the agreed solution, backup and recovery arrangements may be configured based on the customer’s operational requirements.
Factors may include:
Backup frequency
Retention period
Storage location
Encryption
Recovery procedures
Recovery objectives
Availability requirements
Customers should ensure that backup and disaster-recovery expectations are explicitly included in the agreed project scope where they are business-critical.
Software, operating systems, frameworks and third-party components may require security patches or upgrades over time.
TJ Tech may recommend or implement updates as part of an agreed support or maintenance arrangement.
Customers are responsible for systems outside TJ Tech’s agreed scope, including third-party products and infrastructure they independently administer.
The ability to apply updates may depend on compatibility, customer approval, operational constraints and third-party vendor support.
Where TJ Tech becomes aware of a suspected security incident affecting systems or information within its responsibility, we will take reasonable steps appropriate to the circumstances.
These steps may include:
Investigating the issue
Limiting or containing the impact
Preserving relevant technical information
Correcting identified vulnerabilities
Coordinating with affected customers
Supporting recovery
Providing notifications where required by applicable law or contract
The exact incident-response responsibilities for customer-operated systems may be defined in the relevant agreement.
TJ Tech does not intend to retain customer information indefinitely.
Information should be retained only for as long as reasonably necessary to:
Deliver contracted services
Provide support
Maintain required records
Resolve disputes
Meet legal or regulatory obligations
Protect legitimate business or security interests
Retention requirements may vary depending on the nature of the project and applicable agreements.
Where appropriate, information may be securely deleted, anonymized or returned when it is no longer required.
At the conclusion of an engagement, customer data held specifically for that project may be deleted, returned or otherwise handled according to the applicable agreement and technical environment.
Some information may need to be retained for legal, accounting, security, backup or contractual reasons.
Data contained in system backups may remain until the relevant backup expires or is securely overwritten according to the applicable retention process.
TJ Tech may provide adapters, integration software and implementation services relating to UAE e-invoicing.
An e-invoicing integration may process information originating from customer accounting systems, ERP platforms or other defined sources.
TJ Tech’s approach is designed around preserving clear responsibility for source data.
The originating business system remains responsible for the correctness of business information such as:
Invoice values
Customer and supplier information
Tax information
Transaction information
Product or service details
Accounting classifications
TJ Tech software may validate whether required information is present or technically valid, but it should not be assumed to independently determine or correct the underlying commercial, tax or accounting meaning of customer data.
Where invalid or missing information is identified, the intended approach is generally for that information to be corrected through the appropriate source system or business process.
Where an e-invoicing solution connects with a customer’s chosen UAE Accredited Service Provider, information may be transmitted to and processed by that provider.
The Accredited Service Provider operates its own systems, infrastructure, security practices and contractual terms.
TJ Tech is not responsible for security controls or processing activities entirely outside systems that TJ Tech operates or controls, except where responsibility is expressly accepted in writing.
Customers should review the security, privacy and contractual terms of their selected provider.
Systems integration can involve communication between accounting software, ERP platforms, cloud services, APIs, databases, file-based processes and external providers.
Where appropriate, integrations may use measures such as:
Authenticated API connections
Encrypted transport
Restricted credentials
Network controls
Input validation
Schema validation
Transaction identifiers
Error handling
Retry controls
Reconciliation
Audit logging
The controls available depend on the technical capabilities of the systems being integrated.
Security is a shared responsibility.
Depending on the engagement, responsibility may be divided among:
TJ Tech
The customer
Cloud infrastructure providers
Software vendors
ERP or accounting providers
Accredited Service Providers
Other integration partners
TJ Tech aims to define these boundaries clearly during architecture and implementation.
Customers remain responsible for areas under their direct control unless responsibility has been expressly assigned to TJ Tech.
This may include:
User account administration
Employee access
Source-system security
Endpoint security
Internal policies
Business-data accuracy
Physical security
Third-party vendor selection
Where TJ Tech personnel require access to customer information or systems, access should be limited to legitimate project, engineering, support or operational requirements.
Access should be removed when it is no longer required.
Confidentiality and security obligations may also be addressed through applicable employment, contractor and customer agreements.
TJ Tech treats information that is clearly confidential, or that should reasonably be understood as confidential, with appropriate care.
Customers should identify particularly sensitive information and communicate any special handling requirements before providing it.
Highly sensitive information should not be submitted through general website forms.
Where personal information is processed, TJ Tech seeks to handle that information in accordance with applicable data-protection requirements and our Privacy Policy.
Depending on the engagement, TJ Tech may act as a service provider or processor of information on behalf of a customer.
Additional data-processing terms may be agreed where appropriate.
Some cloud, hosting, communications or technology providers may operate infrastructure in multiple jurisdictions.
Where customer information is processed internationally, the applicable hosting architecture, service-provider terms and data-protection requirements should be considered.
Where required, appropriate safeguards should be implemented in accordance with applicable law.
Security testing may form part of a software project depending on its requirements and agreed scope.
Testing may include automated checks, code review, dependency analysis, application testing or other appropriate technical assessments.
Independent penetration testing, formal audits or specialized compliance assessments are not included unless expressly agreed.
TJ Tech does not claim a security certification, regulatory approval or formal compliance status unless that certification or status has been expressly obtained and communicated by TJ Tech.
A customer’s compliance obligations depend on its industry, jurisdiction, systems, data and business activities.
Customers remain responsible for determining which regulatory, security and compliance requirements apply to their organization.
Security risk cannot be eliminated entirely.
Although appropriate technical and organizational controls can significantly reduce risk, no website, software application, network, cloud service or data-transmission method can be guaranteed to be completely secure.
Security therefore requires ongoing maintenance, monitoring, responsible use and cooperation between all parties involved.
If you believe you have identified a security issue affecting a TJ Tech website, product or system, please contact us promptly.
TJ Tech
Dubai, United Arab Emirates
Email: hello@tjtech.com
Please include “Security Report” in the subject line and provide enough information for us to understand and investigate the issue.
Please do not attempt to access, modify, delete, download or expose data that does not belong to you while investigating a suspected vulnerability.
We may update this Security and Data Handling statement periodically as our systems, services and operational practices evolve.
The latest version will be published on our website with the applicable effective date.