Hero background
Legal

Information Security Policy

Last Updated: July 27, 2026

This Information Security Policy describes the security principles, controls, and practices implemented by ALLE TECH LLC FZ (“ALLE TECH”, “we”, “our”, or “us”) to protect customer information, business data, software platforms, and technology services.

This Policy applies to all ALLE TECH products, software solutions, ERP implementations, cloud services, consulting engagements, custom software development, support services, infrastructure, employees, contractors, and authorized third-party providers involved in delivering our Services.

1. Our Security Commitment

At ALLE TECH, information security is fundamental to our business. We are committed to maintaining the:

  • Confidentiality of customer information
  • Integrity of business and system data
  • Availability of our services and infrastructure

We implement commercially reasonable administrative, technical, physical, and organizational safeguards designed to protect information from unauthorized access, disclosure, alteration, destruction, misuse, or loss.

2. Scope

This Policy applies to:

  • Corporate Website & Customer Portals
  • Odoo & SAP Business One Solutions
  • Cloud & Mobile Applications
  • APIs and Integrations
  • AI-powered Solutions
  • Custom Software Development
  • Technical Support & Managed Services
  • Internal Corporate Systems

It also applies to all employees, contractors, consultants, partners, and authorized service providers handling ALLE TECH or Customer information.

3. Cloud Infrastructure

ALLE TECH utilizes reputable cloud infrastructure providers to deliver secure and reliable services. Depending on the solution deployed, infrastructure may include providers such as:

  • Amazon Web Services (AWS)
  • Microsoft Azure
  • Google Cloud Platform (GCP)
  • Odoo Cloud
  • SAP-approved hosting providers
  • Other enterprise cloud providers

These platforms provide enterprise-grade capabilities including:

  • Physical security & environmental controls
  • Infrastructure redundancy & continuous availability features
  • Network security & disaster recovery capabilities

ALLE TECH leverages these services to support secure delivery of customer solutions.

4. Data Encryption

Data in Transit

All communications between users and ALLE TECH systems are protected using industry-standard encryption protocols, including HTTPS and TLS. Where applicable, secure APIs and encrypted communication channels are used between integrated systems.

Data at Rest

Customer information stored within supported environments is protected using commercially reasonable security measures. Where technically appropriate and supported by the underlying platform, sensitive information may be encrypted at rest.

5. Identity and Access Management

Access to customer systems, software environments, and internal resources is granted strictly on the basis of business necessity and the principle of least privilege. Security controls include:

  • User authentication
  • Role-based access control (RBAC)
  • Administrative privilege management
  • Segregation of duties
  • Multi-factor authentication (where supported)
  • Access logging and monitoring
  • Periodic access reviews

Customers remain responsible for protecting their own user credentials and administrator accounts.

6. Password Security

ALLE TECH encourages strong authentication practices. Customers and users should:

  • Use strong and unique passwords.
  • Avoid password sharing.
  • Change compromised credentials immediately.
  • Enable Multi-Factor Authentication (MFA) whenever available.
  • Follow their organization's password policies.

7. Secure Software Development

ALLE TECH follows secure software development practices throughout the application lifecycle. Security measures may include:

  • Secure coding standards
  • Code reviews
  • Controlled deployment processes
  • Environment segregation
  • Vulnerability remediation
  • Dependency management
  • Application logging
  • Security testing
  • Version control
  • Change management procedures

Security practices are reviewed and improved on an ongoing basis.

8. Network Security

ALLE TECH maintains commercially reasonable network protection measures, including:

  • Firewall protection & secure network segmentation
  • Traffic filtering & access restrictions
  • Intrusion monitoring & threat detection
  • Security event monitoring & continuous infrastructure monitoring

9. Backup and Disaster Recovery

To support business continuity, ALLE TECH maintains backup and recovery procedures appropriate to the Services being delivered. Backup activities may include:

  • Database & Configuration backups
  • Application backups & Virtual server snapshots
  • Document backups & Disaster recovery planning

Backup frequency and retention periods vary according to the applicable customer agreement, platform capabilities, and operational requirements.

10. Security Monitoring and Incident Response

ALLE TECH maintains procedures for identifying, investigating, responding to, and recovering from information security incidents.

Where a confirmed security incident occurs, ALLE TECH will:

  • Assess the incident & Contain potential risks.
  • Investigate the root cause.
  • Implement corrective actions.
  • Restore affected services where appropriate.
  • Notify affected customers where required by applicable law or contractual obligations.

11. Employee Security Responsibilities

Employees, consultants, and contractors who access customer information are required to:

  • Protect confidential information.
  • Follow company security procedures.
  • Report suspected security incidents promptly.
  • Comply with internal information security policies.
  • Access customer information only where required for authorized responsibilities.

Access is granted only to personnel with a legitimate business need.

12. Third-Party Providers

ALLE TECH may engage carefully selected third-party providers to support the delivery of our Services. Examples include:

  • Cloud hosting & infrastructure providers
  • ERP software vendors
  • Security providers
  • Monitoring & communication platforms
  • AI technology providers
  • Integration partners

Reasonable efforts are made to select providers that maintain appropriate security standards and contractual confidentiality obligations.

13. Business Continuity

ALLE TECH maintains operational practices designed to support the continuity of our business operations and customer services. Business continuity measures may include:

  • Infrastructure redundancy
  • Backup procedures
  • Disaster recovery planning
  • Incident response processes
  • Cloud failover capabilities & recovery testing where appropriate

While every reasonable effort is made to ensure continuity, no technology service can guarantee uninterrupted availability.

14. Customer Security Responsibilities

Security is a shared responsibility. Customers remain responsible for:

  • Managing user accounts.
  • Protecting endpoint devices.
  • Maintaining internal IT security.
  • Applying vendor updates where applicable.
  • User awareness and training.
  • Compliance with applicable laws & regulations.
  • Appropriate data backup where contractually required.

ALLE TECH cannot be held responsible for security incidents arising from customer negligence, compromised credentials, unsupported customizations, or third-party systems outside our control.

15. Compliance

ALLE TECH designs its products, services, and implementation methodologies to support customer compliance initiatives.

However, each Customer remains solely responsible for ensuring compliance with all laws, regulations, industry standards, and internal governance requirements applicable to its business and jurisdiction.

16. Continuous Improvement

Information security is an ongoing process. ALLE TECH periodically reviews and enhances its:

  • Security controls & infrastructure
  • Internal procedures & risk management practices
  • Incident response capabilities & security awareness programs

to address evolving cybersecurity threats and industry best practices.

17. Policy Updates

ALLE TECH may update this Information Security Policy from time to time to reflect operational, technological, legal, or regulatory changes. Updated versions will be published on:

https://www.alle-tech.com

Continued use of our Services following publication of an updated Policy constitutes acceptance of the revised version.

18. Contact Information

For information security inquiries or to report a suspected security issue, please contact:

Security Team

ALLE TECH LLC FZ

Dubai, United Arab Emirates

whatsapp