logixflologixfloLog In
SECURITY & COMPLIANCE

Your paperwork is your business. We treat it that way.

logixflo holds commercially sensitive documents: client rates, consignment details, driver records. This page sets out how that data is isolated, encrypted, retained, and who can reach it.

Encrypted in transit and at rest

TLS 1.2+ and AES-256 storage

Tenant isolation

Every query scoped to your tenant

UAE PDPL aligned

GDPR-equivalent terms available

Full audit trail

Every access and change logged

01 · SECURITY POSTURE

How the platform is built and defended

Controls grouped the way an IT reviewer reads them. Every item here is implemented today, not on a roadmap.

Encryption

  • TLS 1.2 or higher on every connection, HSTS enforced
  • AES-256 at rest for databases, document images, and backups
  • Managed key rotation, no keys in application code

Access control

  • Role-based permissions: owner, dispatcher, accounts, read-only
  • One account per user, shared logins blocked
  • SSO and enforced MFA available on Enterprise

Tenant isolation

  • Every query and file path scoped to a tenant identifier
  • Document storage partitioned per customer
  • Cross-tenant access tested as part of every release

Logging & monitoring

  • Immutable audit log of document access, edits, and approvals
  • Alerting on anomalous login and export activity
  • Audit exports available to Enterprise administrators

Resilience & backups

  • Encrypted daily backups, cycled within 35 days
  • Restore tested on a regular schedule, not only on paper
  • Documents queue and retry if a downstream service is unavailable

Secure development

  • Peer review on every change, no direct pushes to production
  • Dependency and secret scanning in the build pipeline
  • Separate development, staging, and production environments
02 · DATA HANDLING

What we hold, where it lives, how long it stays

You own your data. We are the processor: we hold it to run the platform on your instructions, and you can take it out whenever you want.

Two commitments worth stating plainly. We do not sell data. And we do not train OCR models on your documents unless you agree to it in writing — accuracy improvements come from aggregated, de-identified statistics.

Data residency

Primary hosting in AWS eu-central-1 (Frankfurt, Germany). Where a provider processes data outside the UAE we rely on standard contractual clauses and equivalent safeguards.

DataRetentionNotes
Document images12–36 months, or as configured12–36 months, or as configured
Extracted fields & tripsLife of contractSubject to statutory record-keeping
Invoices & payout recordsLife of contractCommercial and tax obligations apply
Security & audit logs12 monthsImmutable, exportable on Enterprise
Backups35 daysEncrypted, cycled automatically
After termination30 daysExport window, then deleted or anonymised
03 · COMPLIANCE

Where we stand today

We would rather be accurate than impressive. Below is what is in place, what is in progress, and what we can supply on request.

UAE PDPL

Aligned

Federal Decree-Law No. 45 of 2021. Lawful bases, data subject rights, and breach notification are implemented in the product and in our terms.

GDPR / UK GDPR

DPA available

For customers with EU or UK exposure we sign a data processing addendum with standard contractual clauses and a subprocessor schedule.

ISO 27001

In progress

Controls mapped and internal policies in place; formal certification is targeted for [ISO 27001 target date]. We will publish the certificate when issued.

Available on request

  • Data processing addendum and subprocessor list
  • Completed security questionnaire and architecture overview
  • Penetration test summary and remediation status
  • Business continuity and incident response summary
Request the security pack

Incident response

If a personal data breach affects your tenant we notify you without undue delay, with what we know, what we are doing, and what you may need to tell your own clients or regulator. Regulators are notified where the law requires it.

Initial notification targetWithin 72 hours
Named contactsecurity@logixflo.com
Post-incident reportWithin 10 business days
04 · SUBPROCESSORS

Who else touches the data

Each is bound by written terms and processes data only for the purpose we specify. Customers are notified before we add a subprocessor that handles their content.

CategoryPurposeData reached
Cloud hosting & storageRuns the application, database, and document storeAll tenant data
WhatsApp Business (Meta)Carries document photographs from drivers to the platformImages, sender number
OCR & ML infrastructureRuns extraction on submitted document imagesDocument images
Transactional emailDelivers invoices, statements, and account notificationsContact details, PDFs
Payments & billingProcesses subscription paymentsBilling contact only
Support desk & analyticsHandles tickets and measures product usageAccount and usage data

Named vendors, their locations, and the transfer mechanism for each are listed in the subprocessor schedule supplied with the data processing addendum. Request it at privacy@logixflo.com.

05 · RESPONSIBLE DISCLOSURE

Found something? Tell us first.

Report suspected vulnerabilities to security@logixflo.com with enough detail to reproduce. We acknowledge within two business days and keep you updated until it is closed. We will not pursue legal action against researchers who act in good faith and follow the rules below.

  • Test only against your own tenant or a sandbox we provide.
  • Give us reasonable time to fix before publishing.
  • No denial of service, spam, social engineering of our staff, or access to other customers' data.

Security contacts