Security Policy
Jopex Investment Ltd
Last updated: 25 June 2026
Protecting the information entrusted to us is central to how we build and run our software. This policy describes the measures we apply across our products, in support of our obligations under the Personal Data Protection Act, 2022. No system can be made perfectly secure, but we work to reduce risk and to respond quickly when something goes wrong.
1. How we protect data
All traffic between our applications and our servers is encrypted using HTTPS/TLS. Passwords and one-time passwords are never stored in readable form; secrets are hashed, and access tokens are held in the device's secure storage. Access is controlled through short-lived tokens with sessions that can be revoked on sign-out or account deletion, and sign-in is verified by SMS one-time password. Some products add an optional PIN or biometric lock for further protection on the device itself.
Within each product, people see only the information appropriate to their role and their organisation. Data belonging to separate organisations and users is kept logically isolated, so that one organisation or account cannot reach another's records; the specific guarantee for a given product appears in its Privacy Policy. We harden our servers, keep dependencies current, and take regular backups that are protected to the same standard as live data.
2. How we work
Access to production systems is limited to the few authorised people who need it. Staff and contractors are bound by confidentiality obligations, and the service providers we rely on for functions such as messaging, payments, and hosting are bound by contract to protect personal data and to use it only as instructed. Significant changes to our systems are reviewed before they are made.
3. Payments
Where a product processes a payment through a third-party provider, Jopex does not store full card numbers; the sensitive details are handled by that provider under its own security standards. Where a product only records a payment or shows a business's payment details, no payment credentials pass through Jopex at all.
4. Your part
Security is shared. Keep your phone, your device, your one-time passwords, and any PIN to yourself; our staff will never ask you for a one-time password or PIN. Use a secure device with a lock screen, enable the in-app lock where it is offered, sign out on shared devices, and tell us at once if you think someone has gained access to your account.
5. If something goes wrong
If an incident affects personal data, we will contain and investigate it, assess the risk to the people affected, notify the Personal Data Protection Commission and those individuals where the law requires and within the applicable time, and take steps to prevent it happening again. Where an organisation controls the data concerned, we will support it in meeting its own obligations.
If you discover a vulnerability, please tell us at info@jopex.co.tz and give us a reasonable chance to address it before disclosing it publicly. Responsible disclosure is welcome.