Skip to content
Security

Your customer data, treated as the asset it is

A CRM holds the record of every relationship your business has. These are the controls we run to keep it safe, and the commitments we make about what happens to it.

Encrypted in transit and at rest

Traffic runs over TLS 1.2 or better, and data is encrypted at rest. Keys are managed separately from the application, and backups are encrypted with the same standard.

Access on a need-to-know basis

Role-based access control decides what each person can see and change, down to individual records and fields. Administrators can review and revoke access at any time.

A complete audit trail

Record changes are logged with the user and timestamp, so you can answer who changed what, and when — for your own governance as much as for anyone else's.

Your data stays yours

You can export everything in your account to CSV whenever you want, without asking us. If you leave, you leave with your data and we delete our copy on request.

In practice

The controls, spelled out

Specific enough to check, and to put in front of whoever runs your security review.

Platform

  • TLS 1.2+ for all connections, with HTTP Strict Transport Security enforced
  • Encryption at rest for application data and backups
  • Tenant data logically separated, with access scoped per account
  • Automated encrypted backups with tested restores
  • Dependency and vulnerability scanning as part of every release

Access control

  • Role-based permissions, configurable per team
  • Record- and field-level permissions
  • Single sign-on via SAML or OIDC
  • API tokens scoped per integration and individually revocable
  • Least-privilege internal access, reviewed regularly

Accountability

  • Audit logging of record changes with user and timestamp
  • Configurable data-retention rules
  • Full CSV export available to account administrators at any time
  • Documented deletion process on account closure
  • Data processing agreement available for customers who need one

Operations

  • Change control and code review before deployment
  • Monitoring and alerting on availability and error rates
  • Documented incident response with customer notification
  • Staff access to production limited and logged
  • Sub-processors reviewed before use and listed on request
Data protection

Compliance and data protection

We are a Hong Kong company and a data user under the Personal Data (Privacy) Ordinance (Cap. 486). For the customer records you hold in TMC CRM we act on your instructions, and we will sign a data processing agreement setting that out. Our controls follow the PDPO's data protection principles — collect only what is needed, keep it no longer than necessary, secure it, and give you a documented route to access, export, or delete it. Where you are subject to the GDPR or another regime, tell us during procurement and we will confirm in writing what we can support. If your process needs a security questionnaire completed, send it over.

Found something that looks like a vulnerability? Email [email protected] and we will get back to you. We will not pursue anyone who reports a genuine issue to us in good faith.

Ready to start your review?

Send us the questionnaire, the data processing agreement, or just the questions you still need answered, and we'll come back with specifics rather than a brochure.