Skip to main content

Data residency and international transfers

Twenty Cloud runs on AWS servers located in Frankfurt, Germany.
Hosting region can be selected starting 2027, alternatively you can reach out to our Partners to help you set up your instance.
A list of all sub-processors is available in our Trust center.
EU Standard Contractual Clauses with the UK Addendum and Swiss amendments apply to international data transfers within EU and all sub-processors.
Latest DPA is available in your workspace at https:///settings/legal/dpa (e.g. https://getting-started.twenty.com/settings/legal/dpa).
As per our Privacy Policy, Twenty acts as the data processor for merchant and contact information stored in the CRM, while your company remains the data controller.
CRM content is not used to train any AI model and Twenty does not have its own AI model, all AI models available on cloud are models provided by our sub-processors.
AI can be turned off by disabling all AI models we offer in Settings → AI → Models, moreover no data is sent to AI if there is no interaction with AI chat and AI node in workflows.

Security and access controls

All data are encrypted in transit and at rest, all tenant data are isolated thanks to schema-per-tenant setup and our keys are periodically rotated.
Twenty engineering and support team can access customer workspaces only upon customer’s issue report and when customer agrees to allow access to workspace in Settings → General → Security.
In the event of a confirmed personal data breach affecting your data, we will notify you without undue delay and in any event within 48 hours of becoming aware of it. Our notification will include, to the extent known at the time: the nature of the breach, the categories and approximate volume of data and individuals affected, likely consequences, and the remediation and mitigation measures taken or planned. We will provide updates as the investigation progresses.

Data retention and deletion

When a record is removed, first it’s soft-deleted and still possible to restore, once it’s permanently removed, it’s removed from active systems.
Removed record is in backup for 30 days, after that it’s permanently removed.
Removed workspace’s data are immediately removed from active systems and backups of said workspace are available for 7 days, after 7 days, all data are permanently removed.
Yes, during any backup-retention period, deleted data is isolated from operational use.
We acknowledge erasure requests and provide written confirmation once deletion is complete.

Backups and resilience

Backups are created daily and retention period is 30 days.
RTO and RPO are both 6 hours (as per our DPA).
To request a restoration, please reach out to team via support chat or mail to contact@twenty.com.
All backups are encrypted and stored in geographically separate locations within the same jurisdiction (e.g. within EU for EU data).

Compliance

Yes, Twenty is GDPR compliant.
Yes, Twenty is SOC 2 compliant.
No, Twenty is in the process of becoming HIPAA compliant.
If you have more questions, please check our Terms and Conditions, Privacy Policy and Trust Center, if your questions are still unanswered, send them to contact@twenty.com or via support chat.