Where is my data hosted?
Your data is hosted and primarily processed in the United Arab Emirates, in the Amazon Web Services UAE region (me-central-1). Our database is hosted on MongoDB Atlas within the same framework. For business continuity, we maintain an encrypted cross-region disaster-recovery replica outside the UAE, subject to appropriate safeguards under UAE data protection law. Data centres are operated by these providers with state-of-the-art physical and information security controls, and access to production infrastructure is strictly controlled and monitored.
How does Ordenance keep my data secure?
We apply layered technical safeguards across the platform:
- Encryption: data is encrypted at rest using AES-256 and in transit using HTTPS/TLS. Passwords are stored as salted hashes and are never held in plain text.
- Access controls: multi-factor authentication (MFA) is available for user logins, and internal access follows role-based access control (RBAC) and least-privilege principles.
- Network security: firewalls and network segmentation protect internal services and APIs.
- Monitoring and testing: automated security and vulnerability scanning, coupled with periodic penetration testing.
- Abuse prevention: CAPTCHA challenges, rate limiting, and IP throttling protect against automated and unauthorized access attempts.
- Data minimization: application logs are retained for a limited period and then securely deleted.
Is my data used to train AI?
No. Ordenance uses AI to extract data from your documents, suggest HS classifications, and flag discrepancies — but we do not use your documents or data to train artificial-intelligence models, and we do not sell or share your data. Your documents are processed solely to provide the Service to you.
What laws govern my data?
Ordenance operates under UAE law. Our data protection practices are built around UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the PDPL), overseen by the UAE Data Office. Our Terms of Use include a Data Processing (DPA) section that sets out our obligations as your data processor, including breach notification within 72 hours and return or deletion of your data on termination. Customers subject to other regimes (such as the GDPR) should contact us to discuss their specific requirements.
How are payments secured?
Payments are processed by our payment gateway provider on secure, PCI DSS-compliant infrastructure. Card details entered at checkout go directly to the payment gateway. Credit/debit card details are not stored on Ordenance systems, and Ordenance will not pass any debit or credit card details to third parties.
What user information does Ordenance store?
We store account information (name, email, company details), billing records (transaction references and masked card information only — never full card numbers), the documents you upload (customs declarations, commercial invoices, packing lists, shipping documents), records generated on the platform (jobs, reconciliations, reports), and metadata such as file names and sizes. We also log certain user actions to help resolve issues and improve the Service. Stored data can be deleted upon request, subject to legal retention obligations. Full details are in our Privacy Policy.
Who else processes my data?
We use a small set of sub-processors, each bound by data-protection obligations no less protective than our own: our cloud hosting provider, our database hosting provider, and our payment processor. We notify customers of any new sub-processor and provide a reasonable opportunity to object on legitimate grounds.
What happens if something goes wrong?
We maintain regular encrypted backups and a cross-region disaster-recovery replica, targeting a recovery point objective and recovery time objective of 24 hours each following a major incident. If a personal-data breach affects your data, we will notify you without undue delay — and in any event within 72 hours of becoming aware — and will assist you in mitigating it and meeting any notification obligations to the UAE Data Office or affected individuals.
How does Ordenance prevent unauthorized account access?
You control who accesses your workspace. The platform supports multi-factor authentication and sign-in with Google, and Ordenance Flow workspaces keep each client’s data separated within your account structure. You are responsible for keeping your credentials confidential; if you suspect unauthorized access, contact us immediately at [email protected] and we will help secure the account.
How does Ordenance respond to government or law enforcement requests?
We comply with legal requests as required by UAE law. Every request is reviewed to confirm it is valid and lawful, and any data shared is limited to the specific requirements of the request. Where permitted by law, we will inform affected customers of such requests.
Does Ordenance conduct penetration testing?
Yes. We conduct periodic penetration testing to identify and address potential vulnerabilities, alongside continuous automated scanning. To request further details or our rules of engagement for security testing, contact our team at [email protected].
How can I report a security vulnerability?
If you discover a security vulnerability, please report it immediately to [email protected] with “Security” in the subject line. We respond to all security reports within 3 business days or less, and we ask that you give us a reasonable opportunity to remediate before any public disclosure.
How does Ordenance make money?
Ordenance generates revenue exclusively through software subscriptions to Ordenance Core and Ordenance Flow. We do not sell or share user data with third parties, and we never will — our business model does not depend on your data.