Your paperwork is your business. We treat it that way.
logixflo holds commercially sensitive documents: client rates, consignment details, driver records. This page sets out how that data is isolated, encrypted, retained, and who can reach it.
Encrypted in transit and at rest
TLS 1.2+ and AES-256 storage
Tenant isolation
Every query scoped to your tenant
UAE PDPL aligned
GDPR-equivalent terms available
Full audit trail
Every access and change logged
How the platform is built and defended
Controls grouped the way an IT reviewer reads them. Every item here is implemented today, not on a roadmap.
Encryption
- TLS 1.2 or higher on every connection, HSTS enforced
- AES-256 at rest for databases, document images, and backups
- Managed key rotation, no keys in application code
Access control
- Role-based permissions: owner, dispatcher, accounts, read-only
- One account per user, shared logins blocked
- SSO and enforced MFA available on Enterprise
Tenant isolation
- Every query and file path scoped to a tenant identifier
- Document storage partitioned per customer
- Cross-tenant access tested as part of every release
Logging & monitoring
- Immutable audit log of document access, edits, and approvals
- Alerting on anomalous login and export activity
- Audit exports available to Enterprise administrators
Resilience & backups
- Encrypted daily backups, cycled within 35 days
- Restore tested on a regular schedule, not only on paper
- Documents queue and retry if a downstream service is unavailable
Secure development
- Peer review on every change, no direct pushes to production
- Dependency and secret scanning in the build pipeline
- Separate development, staging, and production environments
What we hold, where it lives, how long it stays
You own your data. We are the processor: we hold it to run the platform on your instructions, and you can take it out whenever you want.
Two commitments worth stating plainly. We do not sell data. And we do not train OCR models on your documents unless you agree to it in writing — accuracy improvements come from aggregated, de-identified statistics.
Data residency
Primary hosting in AWS eu-central-1 (Frankfurt, Germany). Where a provider processes data outside the UAE we rely on standard contractual clauses and equivalent safeguards.
| Data | Retention | Notes |
|---|---|---|
| Document images | 12–36 months, or as configured | 12–36 months, or as configured |
| Extracted fields & trips | Life of contract | Subject to statutory record-keeping |
| Invoices & payout records | Life of contract | Commercial and tax obligations apply |
| Security & audit logs | 12 months | Immutable, exportable on Enterprise |
| Backups | 35 days | Encrypted, cycled automatically |
| After termination | 30 days | Export window, then deleted or anonymised |
Where we stand today
We would rather be accurate than impressive. Below is what is in place, what is in progress, and what we can supply on request.
UAE PDPL
AlignedFederal Decree-Law No. 45 of 2021. Lawful bases, data subject rights, and breach notification are implemented in the product and in our terms.
GDPR / UK GDPR
DPA availableFor customers with EU or UK exposure we sign a data processing addendum with standard contractual clauses and a subprocessor schedule.
ISO 27001
In progressControls mapped and internal policies in place; formal certification is targeted for [ISO 27001 target date]. We will publish the certificate when issued.
Available on request
- Data processing addendum and subprocessor list
- Completed security questionnaire and architecture overview
- Penetration test summary and remediation status
- Business continuity and incident response summary
Incident response
If a personal data breach affects your tenant we notify you without undue delay, with what we know, what we are doing, and what you may need to tell your own clients or regulator. Regulators are notified where the law requires it.
Who else touches the data
Each is bound by written terms and processes data only for the purpose we specify. Customers are notified before we add a subprocessor that handles their content.
| Category | Purpose | Data reached |
|---|---|---|
| Cloud hosting & storage | Runs the application, database, and document store | All tenant data |
| WhatsApp Business (Meta) | Carries document photographs from drivers to the platform | Images, sender number |
| OCR & ML infrastructure | Runs extraction on submitted document images | Document images |
| Transactional email | Delivers invoices, statements, and account notifications | Contact details, PDFs |
| Payments & billing | Processes subscription payments | Billing contact only |
| Support desk & analytics | Handles tickets and measures product usage | Account and usage data |
Named vendors, their locations, and the transfer mechanism for each are listed in the subprocessor schedule supplied with the data processing addendum. Request it at privacy@logixflo.com.
Found something? Tell us first.
Report suspected vulnerabilities to security@logixflo.com with enough detail to reproduce. We acknowledge within two business days and keep you updated until it is closed. We will not pursue legal action against researchers who act in good faith and follow the rules below.
- Test only against your own tenant or a sandbox we provide.
- Give us reasonable time to fix before publishing.
- No denial of service, spam, social engineering of our staff, or access to other customers' data.