Data residency and international transfers
In which country and region would our workspace data, attachments, logs, and backups be stored?
In which country and region would our workspace data, attachments, logs, and backups be stored?
Can the hosting region be contractually fixed for our workspace?
Can the hosting region be contractually fixed for our workspace?
Which sub-processors may process or access our CRM data, and in which countries are they located?
Which sub-processors may process or access our CRM data, and in which countries are they located?
What safeguards apply to international data transfers?
What safeguards apply to international data transfers?
Data Processing Agreement and legal roles
Please provide the current Data Processing Agreement.
Please provide the current Data Processing Agreement.
Does Twenty act as the data processor for merchant and contact information stored in the CRM, while our company remains the data controller?
Does Twenty act as the data processor for merchant and contact information stored in the CRM, while our company remains the data controller?
Is CRM content ever used to train Twenty or third-party AI models?
Is CRM content ever used to train Twenty or third-party AI models?
If optional AI processing exists, can it be fully disabled for our workspace?
If optional AI processing exists, can it be fully disabled for our workspace?
Security and access controls
Is encryption used in transit and at rest, what are your key-management practices, and how tenant data is isolated?
Is encryption used in transit and at rest, what are your key-management practices, and how tenant data is isolated?
Which Twenty personnel or sub-processors may access customer workspaces, for what purposes, and how is access approved and logged?
Which Twenty personnel or sub-processors may access customer workspaces, for what purposes, and how is access approved and logged?
What is your incident-notification process and target notification timeframe following a confirmed security incident affecting our data?
What is your incident-notification process and target notification timeframe following a confirmed security incident affecting our data?
Data retention and deletion
When an individual CRM record is deleted, when is it removed from active systems?
When an individual CRM record is deleted, when is it removed from active systems?
How long may that record remain in backups or technical logs?
How long may that record remain in backups or technical logs?
When a workspace is closed or full deletion is requested, what exact timeline applies to production data, attachments, logs, and backups?
When a workspace is closed or full deletion is requested, what exact timeline applies to production data, attachments, logs, and backups?
During any backup-retention period, is deleted data isolated from operational access and use?
During any backup-retention period, is deleted data isolated from operational access and use?
Are any categories of data retained longer for legal, billing, fraud-prevention, security, or audit purposes? If so, which categories and for how long?
Are any categories of data retained longer for legal, billing, fraud-prevention, security, or audit purposes? If so, which categories and for how long?
Can Twenty provide written confirmation when a full deletion request has been completed?
Can Twenty provide written confirmation when a full deletion request has been completed?
Backups and resilience
What are the backup frequency and retention period?
What are the backup frequency and retention period?
What are the recovery-point objective and recovery-time objective for Twenty Cloud?
What are the recovery-point objective and recovery-time objective for Twenty Cloud?
What is the process for requesting or performing a restoration?
What is the process for requesting or performing a restoration?
Are backups encrypted and stored in the same region as the primary workspace data?
Are backups encrypted and stored in the same region as the primary workspace data?
Compliance
Is Twenty GDPR compliant?
Is Twenty GDPR compliant?
Is Twenty SOC 2 compliant?
Is Twenty SOC 2 compliant?
Is Twenty HIPAA compliant?
Is Twenty HIPAA compliant?