Research CompanyIndependent Treasury Research and Assessment
Data protection & security
TRC is built to handle client project information carefully, keep client workspaces separate and make access and document activity traceable.
Last updated 23 August 2026
How client data is separated
Each client is created as a separate organisation with its own project, user access and product entitlements. Persistent project content is linked to that organisation and project. Access to client functions is checked server-side before project data is returned.
TRC tests this separation explicitly during UAT, including attempts to access another client's Business Case, entitlements and controlled documents.
Access and authentication
- Client access is tied to a named user and business email address.
- Temporary client access codes are stored as one-way hashes rather than readable passwords.
- Authenticated sessions use signed, secure, HTTP-only cookies with a limited session lifetime.
- Product access is controlled by project entitlement rather than by hiding links in the browser.
- TRC administrative access is separate from client access.
Controlled documents and audit trail
Where a TRC product creates a controlled PDF, versions are tied to the relevant client project. Draft and approved versions are recorded separately and project activity is written to an audit trail so material actions can be traced.
Hosting and service providers
TRC remains responsible for selecting appropriate providers, maintaining the relevant agreements and reviewing the services we rely on.
Encryption and transport
TRC is served over HTTPS. We rely on our hosting and database providers' security controls for infrastructure encryption, resilience and operational security, alongside application controls that restrict access to the relevant organisation and project.
Data minimisation
TRC is intended for treasury technology and project information, not large collections of personal data. Clients should provide only the personal information genuinely needed for the project. Special category personal data, criminal-offence data and unnecessary employee information should not be uploaded unless expressly agreed for a legitimate need.
Our role when handling client project data
For client project information, the client will normally determine the purpose of the processing and act as controller. TRC will normally act as processor and use the information to provide the contracted service. We do not treat identifiable client project data as a free research dataset or sell it to third parties.
Where TRC uses personal data for its own account administration, service security, enquiries or research subscriptions, TRC acts as controller. See our Privacy Notice.
Subprocessors and international processing
Our core technology providers may themselves use subprocessors and may process information outside the United Kingdom. We review the contractual safeguards made available by our providers and use appropriate transfer mechanisms where required by UK data protection law.
Retention and deletion
Client project retention is agreed as part of the client relationship. At the end of the relevant service, project personal data will be returned or deleted as agreed, subject to lawful backup, security and record-retention requirements. We do not intend to keep completed client workspaces indefinitely simply because storage is available.
Security incidents
TRC will investigate suspected security incidents promptly. Where TRC is acting as a processor, we will notify the relevant client without undue delay where required so that the client can meet its own legal obligations. Where TRC is the controller, we will assess any notification obligations under UK data protection law.
Client responsibilities
Security is shared. Clients should use individual access credentials, keep access codes confidential, remove access when it is no longer needed and avoid uploading information that is not required for the project.
Questions
For privacy, security or supplier due-diligence questions, contact research@thetreasuryresearchcompany.com.