DIGITAL PRIVACY CENTRE

Data Privacy Framework

How we protect person data

WHERE YOUR DATA LIVES

Customer data is hosted in the region you select at contract, on Microsoft Azure, and is not moved outside that region without your explicit consent. Where authorised remote access happens from outside your hosting region (support, for instance), it is treated as a restricted international data flow, governed by the UK International Data Transfer Agreement and Standard Contractual Clauses where applicable, with transfer impact assessments performed where the destination warrants it.

HOW IS PROTECTED

Thesis SM operates within an Information Security Management System certified to ISO/IEC 27001:2022 by NQA. Controls include role-based access, multi-factor authentication, TLS encryption in transit, AES encryption at rest with keys managed in Azure Key Vault, customer database segregation, centralised logging and monitoring, regular independent penetration testing, and tested business continuity and disaster recovery arrangements.

Privacy is designed in, not retrofitted. Default configurations minimise data exposure, privacy implications are assessed at the design stage, and Data Protection Impact Assessments are completed wherever processing is likely to present high risk to individuals, and proactively where the risk profile is uncertain.

RIGHTS & RETENTION

We support the full set of data subject rights under GDPR, with equivalent rights honoured under PIPEDA. Where we act as processor, requests are routed to your institution as controller and we assist within the timescales in the Data Processing Agreement.

Personal data is retained only as long as necessary. At the end of retention, or on your request, data is deleted or returned in line with the DPA, with disposal evidenced and auditable. We use a limited set of sub-processors, each bound by written agreement to equivalent protections; a current list is available on request, and you are notified of material changes.

IF SOMETHING GOES WRONG

We maintain a documented breach procedure aligned to UK and EU GDPR and PIPEDA. Where we are the processor, customers are notified without undue delay, with enough information to meet your own regulatory reporting obligations. All incidents are recorded and subject to post-incident review.

Shared Responsibility

Thesis SM is delivered as a shared responsibility model. Your institution remains accountable for the lawfulness of the processing you instruct, the accuracy of the data you upload, role-based access within your tenant, and responding to data subject rights requests where we are the processor. Our customer success and support teams help you operate the service in line with your own obligations.

Contact 

Privacy queries, data subject rights requests and breach notifications: privacy@thesiscloud.com,
or your nominated Thesis contact, who will route the matter to the DPO function.