Legal

Data Security

Last Updated: April 2025

We are committed to protecting the confidentiality, integrity, and availability of all data entrusted to us.
This Data Security Statement outlines the safeguards, controls, and best practices we implement to secure client information and maintain a safe digital environment.

1. Our Security Commitment

We take data security seriously and maintain strict internal standards to prevent unauthorized access, misuse, disclosure, alteration, or loss of data.
Our security framework is continually updated to meet evolving threats, technologies, and compliance requirements.

2. Secure Infrastructure

Our systems, tools, and hosting partners use industry-standard security protocols, including:

  • Encryption of data in transit (HTTPS/SSL)
  • Secure firewalls and access controls
  • Intrusion detection and prevention systems
  • Regular monitoring and threat assessment

We work only with trusted service providers who maintain strong security practices.

3. Data Access Controls

To protect sensitive information, we enforce strict access controls:

  • Role-based permissions
  • Need-to-know access for team members
  • Multi-factor authentication (where applicable)
  • Activity logs and user monitoring
  • Internal restrictions on data export and file sharing

Only authorized personnel are allowed access to confidential data.

4. Secure Data Handling

We follow disciplined procedures for data collection, storage, use, and disposal:

  • All client data is handled through verified systems
  • Sensitive information is protected during transfer and storage
  • Data is retained only as long as necessary
  • When no longer needed, data is securely deleted or anonymized

We do not sell or rent personal information.

5. Protection Against Threats

We employ several layers of defense to protect against threats such as:

  • Malware
  • Phishing
  • Unauthorized access attempts
  • System vulnerabilities

Security scans and updates are performed regularly to maintain system integrity.

6. Employee Training & Security Awareness

All team members undergo ongoing training focused on:

  • Recognizing security risks
  • Handling sensitive information
  • Reporting suspicious activity
  • Following internal security protocols

Every employee plays an active role in maintaining a secure environment.

7. Third-Party Security

Some services may involve third-party platforms (hosting, analytics, communication tools, etc.).
We ensure that all external providers follow strong data-security practices and meet our compliance expectations.

We do not partner with vendors who fail to meet minimum security requirements.

8. Incident Response

In the unlikely event of a security incident, we follow a structured process:

  • Immediate assessment and containment
  • Identification of root cause
  • Notification to affected parties (if applicable)
  • Restoration of secure operations
  • Preventive measures to avoid recurrence

We treat every incident with urgency and transparency.

9. Continuous Improvement

Security is an ongoing priority.
We routinely review and enhance our systems, protocols, and training based on:

  • Industry standards
  • New technologies
  • Emerging threats
  • Internal audits

This ensures our security posture stays strong and up to date.

10. Contact Us

If you have questions regarding our data security practices or need more information, please contact us:

Phone: (817) 900-8030
Email: info@touchstonebpo.com

Address: 9800 Hillwood Parkway, Suite 140

Fort Worth, Texas 76177

Let's talk

Ready to build your offshore team?