DIGITAL PRIVACY CENTRE

Data Handling & Protection

PURPOSE

This page describes how Thesis SM hosts, transmits, processes and protects customer data. It is published as part of our Security & Compliance Hub and complements the Thesis Privacy Policy, which 
covers the collection, use and sharing of personal data, including transfers outside the EEA. Where this page refers to controls codified in the underlying policies of our Information Security Management System, those policies remain the 
authoritative source.

SCOPE

The scope also covers Thesis SM's supporting cloud infrastructure operated within Microsoft Azure, and the operational processes used to run the service. It addresses customer data, personal data within customer datasets, operational data and system telemetry. It does not restate the contents of the Privacy Policy, the Information Security Policy or the Data Processing Agreement, each of which remains available on request or as part of the contractual documentation set.

 

Data Hosting & Residency

Thesis SM is hosted exclusively within Microsoft Azure. Customer data is provisioned into the Azure region appropriate to the customer’s geopolitical zone. UK customers are hosted on Azure regions located within the United Kingdom, and Canadian customers are hosted on Azure regions located within Canada. Primary processing, storage and backup activity for a customer remains within the customer’s designated region and does not cross the geopolitical boundary except where Thesis acts on the customer’s documented instruction or where required for support purposes under controlled and logged access. Tenant data is logically segregated, with each customer assigned a separate database instance to remove the need for data partitioning within shared databases.

Encryption & Cryptographic Controls

Data in transit, between the customer and the service and across all public-network connections within the platform, is encrypted using TLS 1.2 or higher with current ciphers. Data at rest is encrypted using AES 256, applied at the database layer through Transparent Data Encryption (TDE) and at the storage layer through Azure platform-managed encryption. Cryptographic key material is held in Azure Key Vault, with access governed by least-privilege role assignments, segregation of duties and periodic review. Secrets and credentials supporting the platform are issued, rotated and audited through the same key management framework, and are never embedded in source code, configuration files or deployment pipelines.

Data Classification

Thesis SM operates a four-level data classification scheme that determines how data is handled across its lifecycle. Public information has no special handling requirements. Internal information is restricted to Thesis personnel and stored within approved repositories. Confidential information, which includes customer contracts and financial reports, is encrypted in transit and at rest and is shared only via secure channels. Restricted information, which covers personally identifiable information, student records and authentication data, is subject to additional controls including enforced multi-factor authentication, audit 
logging, and a prohibition on local storage unless encrypted. Classification decisions are owned by data owners, with the IT and Security teams acting as custodians for the underlying technical controls.

Access Control & Authentication

Access to Thesis SM and to the underlying infrastructure is governed by role-based access control, least privilege, and the separation of administrative accounts from day-to-day accounts. Authentication is performed through Thesis Identity Services, which integrates with Microsoft Entra ID. Multi-factor authentication is enforced for remote access and for all privileged accounts. Sessions are locked after five minutes of inactivity, accounts are locked after five consecutive failed authentication attempts, and inactive accounts are disabled after ninety days. Customer-facing application access is configured and managed by the customer. Back-end access by Thesis personnel is restricted to activities that are necessary for installation, maintenance, support or upgrade, is limited to Cloud Engineers and Support Consultants, and is centrally logged. Privileged activity logs are retained for a minimum of one year, and access logs held in the centralised monitoring solution are retained for 365 days

Data Handling in Operations

Production data is not used in development, QA or other non-production environments unless it has been anonymised or masked. Where support activities require access to live customer data, that access is controlled through documented authorisation and recorded against the relevant support case in our IT service management system. Application data flows are designed to keep customer data within the tenant boundary, and integrations with third-party systems are constrained by the customer’s documented instructions. Source code is held in controlled repositories, builds and deployments are executed only through approved CI/CD pipelines, and direct changes to production environments are limited and subject to documented emergency authorisation under our Change Management process.

Backup, Recovery & Resilience

Backups for Thesis SM are performed exclusively within Microsoft Azure, in the customer’s designated Azure region, using Azure native backup services. Customer databases are protected through point-in time backup capability, allowing restoration to a specific date and time within the contractual recovery window. Thesis SM operates internal recovery targets of 24 hours for restoration of Tier 1 platform services, and 4 hours of acceptable data loss where technically feasible. These are Thesis targets that  drive testing and operational design; the Recovery Time Objective and Recovery Point Objective that apply to a particular customer are those agreed in that customer’s contract, which take precedence over the internal targets where they differ. The disaster recovery process is exercised through a full application-level test at least annually, with results reviewed and signed off by the Senior Director of IT & Information Security and made available to customers on request.

Data Retention & Secure Disposal

Customer data is retained for the duration of the customer agreement. On termination, and at the customer’s first request, data is either returned in a migration-capable format or destroyed without retention of a copy. Data that has reached the end of its retention period is securely deleted using cryptographic erasure rather than logical deletion alone. Media that has held customer or sensitive data is decommissioned through guaranteed removal procedures, rather than reformatting or undirected deletion. Audit trails associated with platform activity are retained for the period needed to satisfy regulatory and contractual obligations, with privileged activity logs retained for at least one year.

Logging, Monitoring & Audit

Security-relevant events, including authentication, authorisation, privileged actions and data changes, are generated by the platform and routed to centralised logging and monitoring. Logs are protected against unauthorised access and modification, and are integrated with detection and alerting capability. Platform health and security signals feed into the incident response process; suspected events are triaged against documented severity criteria and escalated through defined paths. The integrity and effectiveness of monitoring is reviewed as part of internal assurance and external audit activity.

Personnel Security & Training

Personnel with access to customer data are subject to background screening, contractual confidentiality obligations and role-based access controls. All employees and contractors complete annual security awareness and data protection training, with additional targeted training for those who handle restricted data. The Incident Response Team participates in annual exercises, including at least one tabletop exercise, to validate decision-making and communication under stress. Departures and role changes trigger timely review and removal of access, coordinated between the HR team and the IT & Cloud team.

Sub-Processors

Thesis engages a defined set of sub-processors to support delivery of the service. Microsoft Azure provides cloud infrastructure for hosting, storage and backup, and Microsoft also provides corporate productivity tooling. Flywire Payments, located in the United States, provides international payment 
processing where the customer has purchased payment services. Twilio SendGrid, located in the United States, provides outbound email delivery. GlobalLogic, with personnel located in India, provides Tier 3 support and development services, with customer data remaining within the customer’s geopolitical zone. Focus Services, with personnel located in the Philippines, provides support consultant services, again with customer data remaining within the customer’s geopolitical zone. Sub-processors are subject to due diligence, contractual security obligations and ongoing oversight, and a complete and current sub-processor list is maintained within the Data Processing Agreement.

Incident Notification

Where a security incident is confirmed to affect customer data, Thesis will notify the affected customer without undue delay, and in any event within 48 hours of becoming aware of the incident. Thesis acts as Data Processor and the customer acts as Data Controller, so the decision on whether an incident meets the threshold for notification to the Information Commissioner’s Office, or to any other supervisory authority, rests with the customer. Thesis does not notify the ICO or any other regulator on behalf of customers. The information needed to support the customer’s assessment, including timeline, scope, root cause and likely impact, is shared as it becomes available, and a documented record of the incident is maintained. Where the customer determines that notification is required under UK GDPR Article 33 within 72 hours, or communication to affected individuals is required under Article 34, Thesis will provide reasonable support and evidence to assist with that process. The Data Protection Officer is available in an advisory capacity throughout.

All decisions taken by Thesis are documented regardless of the customer’s notification outcome.

Compliance & Assurance

Thesis SM operates an Information Security Management System certified to ISO 27001:2022. The control framework is aligned to ISO 27001 Annex A and is supported by documented policies, technical controls and assurance activities. Independent penetration testing is conducted at least annually, with additional testing performed following material architectural change or significant new functionality. Critical and high findings are remediated prior to release unless formally risk accepted under defined governance. Compliance with applicable data protection law, including UK GDPR and Canadian PIPEDA, is supported through documented data handling practices, contractual safeguards and the Privacy Policy.

NQA ISO 27001 Logo - UKAS

Document Governance 

This document is owned by the Senior Director of IT & Information Security. It is reviewed at least annually, and on any material change to the underlying control environment, hosting model or sub-processor list. It is published as part of the Thesis SM Security & Compliance Hub and may be cited as a reference document in customer due diligence and assurance exercises. Where this document and a customer contract conflict, the customer contract takes precedence; where this document and an underlying ISMS policy conflict, the underlying policy is authoritative.