Keeping sensitive information private
Some of what you ask people for is more private than a shirt size: a tax file number, bank details, a passport, a police check. Mark a request or a contact field Sensitive and 1pm treats those answers differently from everything else. They're stored encrypted, hidden from your team, visible in full only to admins, and every time someone views one it's recorded.
What Sensitive does
For a sensitive request or field:
- The answer is masked everywhere. On the event, the Requests page, the contact record and in reports, a sensitive answer shows as dots with the last three characters, for example
••••• 782. A date shows as••/••/••••. Anything four characters or shorter shows as dots only. - Only admins can see it in full. An admin clicks View beside the masked value to see it. That's you as the account owner, and any team member whose access is set to Admin. See "Who can view it" below.
- Every view is recorded. Each time someone views an answer or opens a sensitive file, 1pm records who, when, and from which IP address. See "The access log" below.
- Files open only for admins. A sensitive upload shows its file name to everyone, but only an admin can open it. An image, such as a photo of a passport, is never shown as a thumbnail.
- It's stored encrypted. The answer or file is encrypted before it's saved, with a key held separately from the database. See "How the encryption works" below.
- It stays out of emails, searches and totals. The "requests complete" email says a sensitive answer was provided but doesn't include it. The crew sheet's "answer contains" filter doesn't search sensitive answers, and a sensitive number field isn't added up in the event totals.
Everything else works as it always does. Sensitive requests can still be required, chased, reviewed, approved or rejected, carried in a request pack and filed onto a contact field.
Which requests can be sensitive
A Text, Date or Upload request can be marked Sensitive. So can a custom contact field of the type Text, Date, Number or Upload. A sensitive contact field can't be asked on a lead form, because lead answers are shown in your Leads inbox and in the new-lead email. Marking a field sensitive takes it off any lead form it was on.
Choice, Terms, Sign PDF and Task requests can't. A choice or a signature isn't private in the same way, and a task only records that something was done.
A request that saves its answer to a contact field takes its setting from that field, because the answer lives on the contact record and shows on every event that asks for it. To make it sensitive, mark the field itself sensitive on the Fields page. Every request that saves to that field becomes sensitive at once.
Marking a request sensitive
On a new request: tick Sensitive in the add form, beside Required.
On an existing request: tick Sensitive on the request's row in the event's Requests panel. Answers already collected are encrypted in the background within a minute or two.
On a contact field: go to Contacts > Fields, open the field and click Mark as sensitive.
In a request pack: open the ask in the pack and tick Sensitive. Every event or portal the pack is added to gets the request already marked.
The starter packs already mark the asks that need it: tax forms (TFN declaration, IR330, P45, W-4, W-9, I-9), bank account numbers, super member numbers, proof of the right to work, police and DBS checks, National Insurance numbers and UTRs.
Turning it off
Unticking Sensitive shows every answer to that request, or every value of that field, to your whole team again. It also decrypts what's stored. So only an admin can do it, and 1pm asks you to confirm first. The change is recorded in the access log. The same goes for unlinking a document request from a sensitive upload field, since its files would no longer be sensitive.
Who can view it
On the Team page, each person with access to your account is either an Admin or a Member:
- Admin can do everything, including viewing sensitive answers and opening sensitive files.
- Member can do everything else: build events, send and review requests, approve uploads, manage contacts. Sensitive answers stay masked for them, and sensitive files won't open.
Everyone you invite starts as an Admin. To change someone, pick Member from the list beside their name on the Team page. The change applies from their next click.
Our support team never sees sensitive answers, even when helping you from inside your account.
What the person sees
On their own link, the person sees their sensitive answer masked too, with a pencil to change it. To change it they type it again in full: the box doesn't fill in with the old value. They already know their own tax file number, and a link can be forwarded or left open on a shared computer.
The access log
Go to Reports > Sensitive information access to see every time someone:
- viewed a sensitive answer
- opened a sensitive file
- exported your account with sensitive information included
- marked a request or field sensitive, or turned it off
Each entry shows when, who, what they looked at, whose answer it was, the event or portal, and the IP address. You can filter by date, print it, or download it as a CSV. Only the account owner and admins can see this report.
Exporting your data
The account export writes each sensitive answer as (sensitive), and leaves out sensitive files you attached to contacts. To include them in full, tick Include sensitive information in full in the download box. That export is recorded in the access log. See Exporting your account data.
How the encryption works
When a sensitive answer is saved, 1pm encrypts it before it reaches the database. The encryption key is held in a separate storage account, never in the database. So a copy of the database, or a backup of it, only ever holds scrambled text for sensitive answers.
An uploaded file is first checked for viruses, which takes a few seconds. It's then encrypted in storage. Until the check finishes the file can't be opened, and you'll see "still being checked" if you try.
1pm decrypts a value only when someone allowed to see it asks to, which is why every view is recorded. This is field-level encryption, not end-to-end encryption: 1pm itself can read the value in order to show it to your admins.
Deleting sensitive information automatically
Sensitive information is kept until you delete it. To change that, go to Account, then Profile, and find the Sensitive information card. Choose to delete it 30 days, 90 days, 1 year, 5 years or 7 years after a portal closes or after an event's date.
When the time comes, 1pm deletes the sensitive answers and files on that portal or event. The rest of the record stays: who answered, when, and that the request is complete. Each answer reads "Removed on" and the date, and each file shows that it was deleted under your retention setting. Answers saved onto a contact from those requests are removed too, but a value you typed onto a contact yourself is kept, and so is a file you attached to a contact yourself. If another open portal or event was relying on a removed contact value, that request shows as not provided yet and the person is asked for it again there.
You get an email 7 days before anything is deleted, listing each portal or event. Information already older than the period you choose is deleted 7 days after that email, not straight away. An open portal is never deleted from, and reopening a closed portal stops the clock. Each deletion is recorded in the access log.
Copies held in our backups are encrypted and are gone within 35 days of the deletion.
Tax file numbers in Australia
If you collect tax file numbers, the Privacy (Tax File Number) Rule 2015 applies to you whatever the size of your business. It asks you to protect TFNs from misuse and unauthorised access, limit who can see them, and destroy them once no law requires you to keep them. Marking a TFN request sensitive covers the first two, and the retention setting above covers the third. Employers generally have to keep payroll records, including TFN declarations, for several years, so check what applies to you before choosing a setting.