Information Security Policy
How DXI Logistics LLC protects its systems, data, and customer information.
Working draft — pending review by UAE-licensed legal counsel before being relied on for external audits or procurement due diligence. Last updated: September 13, 2026.
1. Purpose
This policy sets out how DXI Logistics LLC (“DXI”) protects the confidentiality, integrity, and availability of its information systems and the data they hold, consistent with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and UAE Federal Decree-Law No. 34 of 2021 on Combating Rumours and Cybercrimes.
2. Scope
This policy applies to all DXI information systems, including the company website, admin systems, email, and any third-party services used to process business or customer data.
3. Access Control
- Access to systems and data is granted on a need-to-know basis.
- Administrative access is protected by strong, unique credentials and session controls.
- Access is revoked promptly when an employee’s role changes or they leave DXI.
4. Data Protection in Systems
Customer and employee data held in DXI systems is protected using industry-standard technical measures, including encrypted connections (HTTPS/TLS) for data in transit and access-controlled storage for data at rest.
5. Third-Party Service Providers
Where DXI uses third-party service providers to process data on its behalf, those providers are expected to maintain appropriate security controls.
6. Incident Response
Suspected security incidents must be reported immediately to [IT_SECURITY_CONTACT_EMAIL]. DXI will assess, contain, and, where required by law, report incidents involving personal data as set out in our Data Protection Policy.
7. Employee Responsibilities
All staff are responsible for safeguarding their credentials, reporting suspicious activity, and following DXI’s acceptable-use guidance for company systems and devices.
8. Policy Review
This policy is reviewed at least annually. Approved by: [APPROVER_NAME_AND_TITLE].
