Last updated: 27 July 2026
Service businesses trust us with employee, customer, job, and payment-related data across Europe and the Americas. We limit internal access to what is needed to run the product. We do not claim SOC 2 or other certifications we have not obtained. Practices below reflect how Jomioz is actually built and operated today.
Connections use Transport Layer Security (TLS). Data is encrypted at rest where supported by our cloud infrastructure and file storage.
Customer data is hosted on reputable cloud infrastructure. Production access is restricted to authorized personnel on a least-privilege basis. In the product, workspace owners control roles and permissions for their teams.
We support strong authentication practices, including optional two-factor authentication (TOTP / email OTP and backup codes) for user accounts where enabled in the product.
We use automated tooling to manage vulnerabilities and harden our environment, and we engage external security review periodically as the product matures. Report suspected issues to security@jomioz.com.
Subscription billing and customer charges (including Jomioz Payments and tap-to-pay where available) are processed by Stripe. We do not store full card numbers on Jomioz servers for independent reuse.
Use strong unique passwords, enable two-factor authentication, and remove access for people who leave your business. You decide what End User data you store and how you message customers. Comply with privacy and messaging laws in every country where you operate.
Security: security@jomioz.com. Privacy: privacy@jomioz.com. See also our Terms of Service and Privacy Policy.