Trust Center

At QC Analytics LP, trust, transparency, and security are at the heart of our operations. Whether we are supporting clients in the medical and pharmaceutical industries through consulting services or developing secure Confluence Cloud applications for organizations worldwide, we are committed to the highest standards of data protection, privacy, and operational integrity.

Our Commitment to Trust

  • Transparency: We are clear and open about how we collect, process, and protect data, both for our consulting services and our software products.
  • Security: We apply industry-leading security practices across all services, systems, and applications.
  • Privacy: We rigorously safeguard confidential information and personal data.
  • Compliance: We align with global standards and regulations, including ISO/IEC 27001:2022 and GDPR.

Third-Party & Supplier Security Guidelines

To ensure continuous ecosystem security, we hold our suppliers to the same high standards:

  • Supplier Assessment: All suppliers and cloud hosts handling internal or client data undergo annual security evaluations and compliance checks.
  • Access Control: Third-party integrations and access are restricted based on the principle of least privilege and protected via Multi-Factor Authentication (MFA).

Information Security Action Plan (2026)

To keep our Business Management System (BMS) aligned with the highest standards, we are currently executing the following updates:

  • Context & Stakeholders: Updating our SWOT Analysis with cybersecurity threats and refining our Interested Parties Matrix to separate mandatory Needs from elective Expectations.
  • Risk Management: Enhancing our Asset Register with full Confidentiality, Integrity, and Availability (CIA) classifications and embedding objective rules into our supplier approvals.

Information Security Management System

To demonstrate our commitment to information security, QC Analytics LP operates an Information Security Management System (ISMS) that has been independently certified to conform to the ISO/IEC 27001:2022 standard.

Our ISMS ensures that:

  • Client and internal data is protected from unauthorized access, loss, or misuse.
  • Information security risks are identified, assessed, and mitigated.
  • Staff receive regular training in data protection and cybersecurity responsibilities.
  • Security controls are regularly reviewed, updated, and improved.

Data Security

For both consulting services and our Confluence Cloud applications:

  • Encryption: All data, whether in transit or at rest, is encrypted using AES-256 and TLS 1.3 protocols.
  • Access Controls: Strict role-based access management ensures that only authorized personnel handle sensitive or client-provided data.
  • Secure Software Development: Our Confluence Cloud apps are designed and maintained following Atlassian's security requirements and secure development lifecycle (SDLC) practices.
  • Infrastructure Security: All systems are hosted on ISO 27001-certified, SOC 2-compliant cloud platforms.

Privacy & Data Protection

  • For Consulting Clients: Data from our medical and pharmaceutical partners is handled under strict confidentiality agreements, with dedicated safeguards to meet sector-specific data protection needs.
  • For App Users: Our Confluence Cloud applications are designed to operate with minimal required data access and never store customer content without explicit consent.
  • Data Retention: We retain data only as long as necessary to fulfill service or contractual obligations, or as legally required.
  • Your Rights: Clients and app users may access, correct, or request deletion of their personal data at any time by contacting us at [email protected].

Compliance & Certifications

QC Analytics LP complies with the following standards and best practices:

  • ISO/IEC 27001:2022 (Information Security Management System (ISMS))
  • GDPR (General Data Protection Regulation)
  • Atlassian Marketplace Cloud Security requirements for app development

Risk Management & Business Continuity

  • Risk Assessments: Periodic internal risk reviews and external audits ensure the security posture remains strong.
  • Incident Response: As per Incidents & Service Status | QC Analytics Support.
  • Business Continuity & Disaster Recovery: Strategies in place to minimize disruption and maintain reliable service across consulting projects and software products.

Third-Party Vendor Management

We carefully assess and monitor third-party providers, including hosting, analytics, and app distribution platforms, ensuring they meet our stringent security, privacy, and compliance standards.

Responsible App & Data Practices

For our Confluence Cloud applications:

  • Secure by Design: All apps are built following secure coding principles.
  • Minimal Permissions: We request only the access required for functionality and never collect unnecessary data.
  • Regular Updates: Security patches and feature improvements are deployed in a timely manner.
  • Transparency: Detailed privacy policies and app descriptions are provided via the Atlassian Marketplace.

For our consulting services:

  • Data Ethics: Data is used strictly to deliver agreed services, with a focus on accuracy, integrity, and confidentiality.
  • Client-Specific Protections: Custom data handling processes for healthcare and pharma sector clients.

Contact Us

For any questions, concerns, or requests regarding security, privacy, or data protection:

Updates to This Trust Center

This Trust Center may be updated periodically to reflect changes in regulations, technologies, or our services. Please check back for the latest information.

Updated date: 16 June 2026