Privacy Policy & DPA
Last updated: September 11, 2026
1. Who we are & roles
TwBase ("we") provides a business platform. For your account data we act as controller; for the business data you store (your clients, conversations, invoices, finances) we act as processor on your behalf and on your instructions — this section serves as our Data Processing Addendum (DPA). You are the controller of your clients' personal data and responsible for collecting it lawfully.
2. Data we process
Account data: name, email, password (hashed), subscription and payment status (card details for YOUR subscription live in Stripe, never on our servers).
Your business data: the clients and leads you manage (contact details, conversations, notes), messages across the channels you connect (email, WhatsApp, SMS, web chat, social), calendar events and bookings, invoices, payments and financial records, catalog items and photos, files and media, and the content of pages you publish.
Integration credentials: tokens and API keys for the accounts YOU connect, stored encrypted and used only to operate the features you enabled.
Technical data: security logs (IP, login attempts), audit trails, aggregated usage.
3. Why (legal bases)
To provide the Service (contract), billing and security (legitimate interest / legal obligation), and product emails you can control in Notification preferences (consent where required).
4. Third parties & subprocessors
Two different situations apply:
(a) Accounts YOU connect (your own providers). When you connect your own accounts, data flows to those providers under YOUR direct agreement with them — they are your providers, not our subprocessors: your email mailbox (IMAP/SMTP, Google, Microsoft), your Stripe account (payments from your clients, including methods you enable such as Klarna or Afterpay), your Meta assets (WhatsApp Business messages and media, Facebook/Instagram pages, posts and ads), your Twilio account (SMS), your own AI provider keys (Anthropic, OpenAI, Google), your domains, and site integrations you configure (e.g., a WordPress/Amelia site). We transmit to each provider only what the feature needs, and store your credentials encrypted. Disconnecting an integration stops the flow and deletes the stored tokens.
(b) Our subprocessors (to run the platform).
- Stripe — your subscription payments to us
- AI providers (Anthropic / OpenAI / Google) — when you use platform-provided AI, only the message/content context needed for the feature; not used by us to train models
- Hosting/infrastructure — the servers where the Service and its backups run
Google user data. If you connect a Google account, we access it only to provide the mailbox and calendar features you enabled: reading and sending email from YOUR connected mailbox inside your workspace, and syncing YOUR calendar events. We never use Google user data for advertising, never sell it, and never transfer it to third parties except as needed to provide these features, for security, or to comply with law. Humans do not read your Google data unless you ask for support, it is required for security/abuse investigation, or the law requires it. Disconnecting the account (Settings → Email / Calendar) revokes our access and deletes the stored tokens. TwBase's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Your clients' data (end clients)
Personal data of YOUR clients (names, contact details, messages, bookings, invoices, payment records) is processed only to operate your workspace: storing their records, sending the messages you or your automations initiate, generating their invoices and portal pages, and accounting. We do not sell it, use it for our own marketing, or share it across other TwBase's customers' workspaces — each business's data is isolated per account. Their card details are handled by your payment processor, never stored by us.
6. AI processing
AI features send the relevant context (e.g., a conversation, your catalog, your playbook) to the configured AI provider to generate the reply or content, and the result is stored in your workspace. With your own AI keys, that processing happens under your agreement with the provider. Automated replies are labeled as such where the law or the channel requires it.
7. Security
Encryption in transit (TLS) and at rest for secrets (passwords hashed; credentials, tokens and API keys encrypted), two-factor authentication, role-based access for delegates, audit logs, rate-limiting and anti-abuse protections, and automated backups.
8. Retention & deletion
Your data is kept while your account is active. You can export everything (Settings → Your data) and delete your account, which purges your business data. Backups roll off within 30 days. Billing records and signed acceptance evidence are kept as required by law.
9. Your rights
Access, rectification, export (portability), deletion and objection. Exercise them in-app or via support@twbase.com. We answer within 30 days. Your clients should exercise their rights with YOU (their controller); we assist you in fulfilling them.
10. Breach notification
If a breach affects your data we will notify you without undue delay with the facts, impact and measures taken.
11. Contact
Nota: versión en español disponible a solicitud; en caso de conflicto prevalece la versión en inglés. This is a solid working draft; have it reviewed by your attorney before relying on it in a dispute.
