

Thoughtexchange
By Fulcrum Management Solutions Ltd
Implementing ThoughtExchange involves several key steps to ensure effective engagement and data collection:
Account Setup: Create an account at my.thoughtexchange.com using your email or through Single Sign-On (SSO) if available
Define Objectives: Clearly outline the goals of your engagement to guide the creation of your Exchange.
Create the Exchange:
Title and Objective: Provide a concise title and define the objective of the Exchange.
Introduction and Question: Craft an introduction and pose the main question to participants.
Attachments: Optionally, include relevant documents or media to provide context.
Add Survey Questions: If needed, incorporate various types of survey questions to gather specific data.
Schedule Participation: Set the opening and closing dates and times for the Exchange to manage participation.
Invite Participants: Distribute the Exchange link via email, Slack, Microsoft Teams, or other communication channels.
Monitor Engagement: During the active period, oversee participation and address any issues that arise.
ThoughtExchange offers a range of customizable features to align with specific business needs:
Engagement Methods: The platform provides multiple data collection methods, including Surveys, Exchanges, and Interviews, allowing organizations to choose the most suitable approach for their objectives.
Survey Customization: Users can design surveys with various question types such as Likert scales, dropdowns, comment boxes, and satisfaction scores, enabling tailored data collection.
Theming and Categorization: The Edit Results feature allows for the creation of up to 20 summary themes and 20 sub-themes within each, facilitating detailed organization of participant thoughts.
Advanced Analytics: The platform's AI-powered Advisor provides instant summaries, key themes, and talking points, enhancing the speed and depth of data analysis.
Multi-Language Support: ThoughtExchange offers instant translation for participants in over 100 languages, ensuring inclusivity in diverse organizational settings.
Custom Integrations: The platform supports importing participants directly from systems like Student Information Systems (SIS) or Human Resource Information Systems (HRIS), streamlining data management.
ThoughtExchange provides comprehensive training and support to ensure new users can effectively utilize their platform:
Dedicated Customer Success Managers (CSMs): From the outset, each organization is assigned a dedicated CSM who assists with training, planning, and executing engagements. This personalized support ensures that users receive guidance tailored to their specific needs.
Resource Library: The platform offers a rich collection of free guides, eBooks, reports, webinars, and toolkits covering various topics to help users maximize their engagement strategies.
ThoughtExchange implements set of security measures to protect user data and ensure privacy:
Data Encryption:
In Transit: Data transmitted over public networks is encrypted using Transport Layer Security (TLS) 1.2 or higher, safeguarding information during transmission.
At Rest: Stored data is encrypted with Advanced Encryption Standard (AES) 256-bit encryption, ensuring data remains secure when not in use.
Access Controls
Multi-Factor Authentication (MFA): MFA is employed for administrative access to production systems, third-party SaaS providers, and internal business systems, adding an extra layer of security.
Password Management: Employees are encouraged to use approved password managers to create complex, unique passwords for all systems and services.
Network Security:
Segregated Environments: Separate network environments are maintained for testing, development, marketing, customer result sites, and corporate networks, isolating sensitive data.
Limited Access: Administrative access to production systems is restricted to the development operations team, minimizing potential unauthorized access.
System Monitoring and Logging:
Active Monitoring: Servers, workstations, and mobile devices are actively monitored for vulnerabilities and attacks. User activity logs, server logs, and audit logs are maintained for all systems.
Alert Management: Alerts are examined and addressed based on priority to ensure timely responses to potential security incidents.
Regular Security Assessments:
Penetration Testing: Regular application and infrastructure penetration tests are conducted. The security and development teams review and prioritize any findings, resolving high and medium-priority issues before deployment.
Virus and Malware Protection:
File Scanning: Uploaded files are scanned using redundant ClamAV instances. Infected files are quarantined, and exchange leaders are notified to contact support. Virus definitions are updated hourly.
Endpoint Security: Workstations run monitoring tools to detect malware and unsafe configurations. They are required to encrypt data, have strong passwords, and lock when idle.
Mobile Device Management:
Centralized Management: Mobile devices used within ThoughtExchange are centrally managed and required to enroll in the mobile device management system, ensuring compliance with security policies.
Data Confidentiality and Privacy:
Compliance with Regulations: Internal controls are in place to safeguard data in accordance with applicable laws, including GDPR, PIPEDA, FERPA, CIPA, PPRA, and COPPA.
Participant Privacy: Participants' input can be made public as part of the process, but their identities (e.g., email addresses, names) are shared only between the customer and ThoughtExchange, maintaining confidentiality.
Certifications and Commitments:
ISO/IEC 27001 and 27701: ThoughtExchange has obtained these certifications, demonstrating adherence to international standards for information security and privacy management.
SOC 2 (Type II): Compliance with Trust Services Principles is maintained, with reports available upon request.
ThoughtExchange policies on data ownership and portability are outlined in their Data Processing Addendum (DPA) and Privacy Policy:
Data Ownership
Customer as Data Controller: In the context of data protection laws, ThoughtExchange identifies the customer (e.g., the organization using the platform) as the Data Controller. This means that the customer determines the purposes and means of processing personal data. ThoughtExchange acts as the Data Processor, handling data on behalf of the customer.
Participant Data: Participants' input (such as thoughts and ratings) can be made public as part of the engagement process. However, their identities (e.g., email addresses, names) are shared only between the customer and ThoughtExchange. The association of identity to input is kept private by ThoughtExchange, except as required by legal considerations.
Data Portability
Participant Rights: Participants have the right to request access to their personal data, as well as the correction, amendment, or deletion of such data where it is inaccurate. ThoughtExchange commits to assisting customers in responding to such requests in accordance with data protection laws.
ThoughtExchange policies regarding contract renewal and cancellation are outlined in their Subscription Agreement and Terms of Use. Key points include:
Automatic Renewal
Annual Renewal: Subscriptions are automatically renewed annually on the anniversary date of the initial subscription. Customers are notified of any price increases at least 120 days prior to the renewal date.
Cancellation Policy
Customer-Initiated Cancellation: Customers may cancel their subscription at any time during the subscription period by providing written notice. No refund is provided for subscription fees already invoiced or paid.
ThoughtExchange adheres to several industry-recognized compliance standards to ensure the security and privacy of user data:
ISO/IEC 27001: This standard specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). ThoughtExchange's adherence to ISO/IEC 27001 demonstrates its commitment to managing information security in line with international best practices.
ISO/IEC 27701: Serving as an extension to ISO/IEC 27001, this standard focuses on privacy information management. Compliance with ISO/IEC 27701 indicates that ThoughtExchange has implemented a comprehensive framework for managing personally identifiable information (PII) in accordance with global privacy requirements.
SOC 2 (Type II): This certification pertains to the Trust Services Criteria of security, availability, processing integrity, confidentiality, and privacy. ThoughtExchange's SOC 2 (Type II) compliance signifies that its systems are designed to keep sensitive data secure and are audited over an extended period to ensure consistent adherence.