Data Security
Last Updated: April 2025
We are committed to protecting the confidentiality, integrity, and availability of all data entrusted to us.
This Data Security Statement outlines the safeguards, controls, and best practices we implement to secure client information and maintain a safe digital environment.
1. Our Security Commitment
We take data security seriously and maintain strict internal standards to prevent unauthorized access, misuse, disclosure, alteration, or loss of data.
Our security framework is continually updated to meet evolving threats, technologies, and compliance requirements.
2. Secure Infrastructure
Our systems, tools, and hosting partners use industry-standard security protocols, including:
- Encryption of data in transit (HTTPS/SSL)
- Secure firewalls and access controls
- Intrusion detection and prevention systems
- Regular monitoring and threat assessment
We work only with trusted service providers who maintain strong security practices.
3. Data Access Controls
To protect sensitive information, we enforce strict access controls:
- Role-based permissions
- Need-to-know access for team members
- Multi-factor authentication (where applicable)
- Activity logs and user monitoring
- Internal restrictions on data export and file sharing
Only authorized personnel are allowed access to confidential data.
4. Secure Data Handling
We follow disciplined procedures for data collection, storage, use, and disposal:
- All client data is handled through verified systems
- Sensitive information is protected during transfer and storage
- Data is retained only as long as necessary
- When no longer needed, data is securely deleted or anonymized
We do not sell or rent personal information.
5. Protection Against Threats
We employ several layers of defense to protect against threats such as:
- Malware
- Phishing
- Unauthorized access attempts
- System vulnerabilities
Security scans and updates are performed regularly to maintain system integrity.
6. Employee Training & Security Awareness
All team members undergo ongoing training focused on:
- Recognizing security risks
- Handling sensitive information
- Reporting suspicious activity
- Following internal security protocols
Every employee plays an active role in maintaining a secure environment.
7. Third-Party Security
Some services may involve third-party platforms (hosting, analytics, communication tools, etc.).
We ensure that all external providers follow strong data-security practices and meet our compliance expectations.
We do not partner with vendors who fail to meet minimum security requirements.
8. Incident Response
In the unlikely event of a security incident, we follow a structured process:
- Immediate assessment and containment
- Identification of root cause
- Notification to affected parties (if applicable)
- Restoration of secure operations
- Preventive measures to avoid recurrence
We treat every incident with urgency and transparency.
9. Continuous Improvement
Security is an ongoing priority.
We routinely review and enhance our systems, protocols, and training based on:
- Industry standards
- New technologies
- Emerging threats
- Internal audits
This ensures our security posture stays strong and up to date.
10. Contact Us
If you have questions regarding our data security practices or need more information, please contact us:
Phone: (817) 900-8030
Email: info@touchstonebpo.com
Address: 9800 Hillwood Parkway, Suite 140
Fort Worth, Texas 76177
