Information Security Policy
Last updated: July 2026
Timax International LLC, doing business as WorkplaceTechHub, is committed to protecting the confidentiality, integrity, and availability of the information we handle — including customer data, quote and order information, and vendor/partner data shared with us as part of our business relationships.
Scope
This policy applies to all systems used to operate WorkplaceTechHub, including our e-commerce platform, internal databases, and the tools we use to manage vendor and customer information.
Data We Handle
- Customer contact and business information submitted through quote requests and business account applications
- Order and transaction records
- Vendor pricing, promotional, and partner program data shared with us under distributor and manufacturer agreements
We do not sell customer data to third parties.
Access Control
Access to internal systems and databases is restricted on a need-to-know basis. Database access follows role-based permissions — separate roles are used for administrative/schema changes, day-to-day application access, and read-only reporting, so that no single access path has more privilege than it needs.
Network and Infrastructure Security
- Production databases are not directly exposed to the public internet; access requires an authenticated, encrypted connection
- External-facing services use current TLS encryption
- Firewall and intrusion-prevention protections are maintained on infrastructure hosting customer-facing systems
- Administrative access to servers is limited to authenticated users with dedicated, non-default credentials
Data Backup and Recovery
We maintain regular automated backups of critical business data, with a defined retention period, and periodically verify that backups can be restored successfully.
Credential Management
Sensitive credentials (API keys, database passwords, payment processing credentials) are not stored in plaintext in shared or public locations. Changes to production credentials are made directly by authorized personnel through secure configuration channels.
Third-Party and Vendor Data
Where we receive confidential pricing, promotional, or partner data from manufacturers and distributors under partner agreements, we handle that information according to the confidentiality terms of those agreements and do not publish confidential vendor pricing publicly.
Incident Response
In the event of a suspected data security incident, we will take prompt action to contain and assess the issue, and will notify affected parties as required by applicable law.
Continuous Improvement
As our business grows, we review and update our security practices to reflect current best practices appropriate to our size and the data we handle.
Reporting a Concern
If you believe you have identified a security vulnerability or concern related to WorkplaceTechHub, please contact us via our Contact page.