Data Privacy Framework
How we protect person data
Thesis SM processes some of the most sensitive data a university holds. This page summarises how we protect it: the commitments we make, the controls behind them, and the governance that keeps both honest. The full Data Privacy Framework, along with the Thesis SM Data Processing Agreement and supporting policies, remains the authoritative source and is available to customers and prospective customers.
Our privacy programme is built around UK GDPR, the Data Protection Act 2018, EU GDPR and Canada's PIPEDA. Where these regimes overlap, we apply the higher standard, so customers in any supported jurisdiction receive consistent treatment of their data.
For the Thesis SM service, your institution is the controller and Thesis is the processor. We process customer data only on documented instructions, and you retain ownership of your data at all times.
Accountability sits at the top: overall responsibility rests with our CEO, with operational responsibility delegated to the Senior Director of IT & Information Security. An independent, qualified Data Protection Officer monitors compliance, supports impact assessments, acts as the contact point for the ICO and other supervisory authorities, and has direct access to the Executive Leadership Team. Data protection is a standing item at our senior governance forum.
Customer data is hosted in the region you select at contract, on Microsoft Azure, and is not moved outside that region without your explicit consent. Where authorised remote access happens from outside your hosting region (support, for instance), it is treated as a restricted international data flow, governed by the UK International Data Transfer Agreement and Standard Contractual Clauses where applicable, with transfer impact assessments performed where the destination warrants it.
Thesis SM operates within an Information Security Management System certified to ISO/IEC 27001:2022 by NQA. Controls include role-based access, multi-factor authentication, TLS encryption in transit, AES encryption at rest with keys managed in Azure Key Vault, customer database segregation, centralised logging and monitoring, regular independent penetration testing, and tested business continuity and disaster recovery arrangements.
Privacy is designed in, not retrofitted. Default configurations minimise data exposure, privacy implications are assessed at the design stage, and Data Protection Impact Assessments are completed wherever processing is likely to present high risk to individuals, and proactively where the risk profile is uncertain.
We support the full set of data subject rights under GDPR, with equivalent rights honoured under PIPEDA. Where we act as processor, requests are routed to your institution as controller and we assist within the timescales in the Data Processing Agreement.
Personal data is retained only as long as necessary. At the end of retention, or on your request, data is deleted or returned in line with the DPA, with disposal evidenced and auditable. We use a limited set of sub-processors, each bound by written agreement to equivalent protections; a current list is available on request, and you are notified of material changes.
We maintain a documented breach procedure aligned to UK and EU GDPR and PIPEDA. Where we are the processor, customers are notified without undue delay, with enough information to meet your own regulatory reporting obligations. All incidents are recorded and subject to post-incident review.
Shared Responsibility
Thesis SM is delivered as a shared responsibility model. Your institution remains accountable for the lawfulness of the processing you instruct, the accuracy of the data you upload, role-based access within your tenant, and responding to data subject rights requests where we are the processor. Our customer success and support teams help you operate the service in line with your own obligations.
Contact
Privacy queries, data subject rights requests and breach notifications: privacy@thesiscloud.com,
or your nominated Thesis contact, who will route the matter to the DPO function.