TJ·Aero

Security

How your account, your identity documents and your data are protected.

TJ-Aero is hosted in an ISO/IEC 27001:2022 certified environment.

Our hosting provider, Hostinger, holds ISO/IEC 27001:2022 certification for its information-security management, independently audited by TÜV Thüringen. See their certificate ↗

In transit

  • Every connection is encrypted with HTTPS (TLS 1.3, 256-bit AES-GCM). Plain HTTP is redirected, and browsers are told to use HTTPS only (HSTS). Older, weaker TLS versions are refused.

Your identity documents

  • Your passport is used only to verify you, is checked by hand by our verification staff (never by AI), and the copy is deleted as soon as it has been verified.
  • Passport numbers are stored encrypted. They are never shown to other members.
  • Only staff with the identity-verification permission can open a passport copy, and every opening is logged.

Your account

  • Passwords are stored as one-way hashes, must be at least 12 characters, and are checked against known leaked passwords.
  • Two-factor sign-in with an authenticator app is available in Account Settings, and can be required for all staff accounts.
  • Repeated failed sign-ins are slowed down, and every form is protected against cross-site request forgery.
  • Our support team can see your account only if you allow it (Account Settings → Support access, 24 hours). A support view is read-only, closes your private areas, ends after 30 minutes, and is recorded for you with its reason.

Payments

  • Card details are entered on PayPal’s or PayHere’s own systems. They never reach TJ-Aero’s servers.

Resilience

  • The database and uploaded files are backed up every day, and about three weeks of backups are kept.
  • The hosting platform provides a web application firewall, DDoS protection and malware scanning.

Your data

  • Deleting your account removes your files, messages, activity history and mailing-list entries, including at our email providers. What is kept and for how long is set out in the Privacy Notice.

We follow the EU GDPR and Sri Lanka’s Personal Data Protection Act

TJ-Aero is built to meet the EU General Data Protection Regulation (and the UK GDPR) and Sri Lanka’s Personal Data Protection Act, No. 9 of 2022. Here is what that means in practice. Points marked “Checked just now” are tested automatically against the live system when this page loads — if one ever fails, it says so here rather than claiming it.

Lawful and transparent GDPR Arts. 5, 6, 12–14 · PDPA Part I

The Privacy Notice says what we collect, why, on what legal basis, who receives it, where it is stored and for how long. See it

In place

Only what is needed GDPR Art. 5(1)(c) · PDPA Part I

Your passport copy is used only to verify you and is deleted as soon as you are verified. No verified member’s copy is on file.

✓ Checked just now

Security of your data GDPR Art. 32 · PDPA Part I

Passport numbers are stored encrypted. Every connection uses TLS 1.3. Two-factor sign-in is available to everyone, and access to identity documents is limited to verification staff and logged.

✓ Checked just now

Kept only as long as needed GDPR Art. 5(1)(e) · PDPA Part I

Retention periods run automatically every night: activity logs after 12 months, declined registrations after 12 months, deleted accounts’ agreement records after six years.

Being corrected

Activity logs deleted after 12 months GDPR Art. 5(1)(e) · PDPA Part I

No search or activity record older than 12 months is held.

✓ Checked just now

Health information protected GDPR Art. 9 · PDPA special categories

A medical certificate is held only with your explicit consent, and other members never see the document.

✓ Checked just now

Marketing only with consent GDPR Arts. 6–7 · PDPA Part IV

News emails are off unless you ask for them, your consent is recorded, and an unsubscribe is final.

✓ Checked just now

No tracking GDPR Art. 25 · ePrivacy

No analytics or advertising trackers. Pages load their scripts, maps software and fonts from our own server; only map tiles come from OpenStreetMap.

✓ Checked just now

Your rights, in your hands GDPR Arts. 15–22 · PDPA Part II

Download a copy of your data (machine-readable), correct your profile, switch off news emails, or delete your account — all yourself, in Account Settings. Anything else: write to us and we reply within one month. See it

In place

Breaches handled by the book GDPR Arts. 33–34 · PDPA

A written procedure: contain, assess, and notify the data protection authority within 72 hours and affected members where the risk is high.

In place

If you think we have not handled your data properly, tell us first at contact@tj-aero.com. You can also complain to the Data Protection Authority of Sri Lanka (www.dpa.gov.lk) or, in the EU or UK, to your local data protection authority.

Found a security problem?

Please tell us privately at contact@tj-aero.com before sharing it anywhere else. We read every report and will reply.

No system is perfectly secure, and we do not claim otherwise.

Privacy Notice · Terms & Conditions · AI Policy · Raffles Online Platforms