Privacy Policy & DPA
Last updated: August 27, 2026
1. Who we are
TwBase ("we") provides a business platform. For your account data we act as controller; for the business data you store (your clients, emails, finances) we act as processor on your behalf — this section serves as our Data Processing Addendum (DPA).
2. Data we process
Account data: name, email, password (hashed), subscription and payment status (card details live in Stripe, never on our servers).
Your business data: the clients, emails, calendar events, files and financial records you or your integrations put into the Service.
Technical data: security logs (IP, login attempts), aggregated usage.
3. Why (legal bases)
To provide the Service (contract), billing and security (legitimate interest / legal obligation), and product emails you can control in Notification preferences (consent where required).
4. Subprocessors
We use vetted providers strictly to run the Service:
- Stripe — subscription payments
- Microsoft — when YOU connect a Microsoft 365 mailbox (OAuth; we store encrypted tokens, never your password)
- Google — when YOU connect a Gmail mailbox or Google Calendar (OAuth; we store encrypted tokens, never your password)
- AI providers (Anthropic / OpenAI / Google) — only the message content needed for the AI features you use
- Hosting/infrastructure — servers where the Service runs
Google user data. If you connect a Google account, we access it only to provide the mailbox and calendar features you enabled: reading and sending email from YOUR connected mailbox inside your workspace, and syncing YOUR calendar events. We never use Google user data for advertising, never sell it, and never transfer it to third parties except as needed to provide these features, for security, or to comply with law. Humans do not read your Google data unless you ask for support, it is required for security/abuse investigation, or the law requires it. Disconnecting the account (Settings → Email / Calendar) revokes our access and deletes the stored tokens. TwBase's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Security
Encryption in transit (TLS) and at rest for secrets (passwords hashed, credentials and tokens encrypted), two-factor authentication, role-based access (delegates), audit logs, anti-abuse protections and automated backups.
6. Retention & deletion
Your data is kept while your account is active. You can export everything (Settings → Your data) and delete your account, which purges your business data. Backups roll off within 30 days. Billing records are kept as required by tax law.
7. Your rights
Access, rectification, export (portability), deletion and objection. Exercise them in-app or via support@twbase.com. We answer within 30 days.
8. Breach notification
If a breach affects your data we will notify you without undue delay with the facts, impact and measures taken. Operational incidents are visible on the public status page.
9. Contact
Nota: versión en español disponible a solicitud; en caso de conflicto prevalece la versión en inglés.
