Who we are
TwinScroll is the controller of personal data collected for its own enquiries, client relationships, billing, website operation and business administration. You can contact us using the contact options on this website.
This policy explains what TwinScroll collects, why it is used, who receives it and the rights available to individuals.
Last updated: 18 August 2026
TwinScroll is the controller of personal data collected for its own enquiries, client relationships, billing, website operation and business administration. You can contact us using the contact options on this website.
This policy covers personal data handled through twinscroll.co, enquiry and plan forms, email, WhatsApp, calls, meetings, proposals, contracts, support, billing and normal business administration. It does not replace a client's own privacy notice for a website or campaign operated for that client.
Please do not send special-category data, criminal-offence data or unrelated personal data unless we have agreed that it is necessary and there is a lawful basis.
We collect data from you, your authorised colleagues or advisers, our website and forms, normal server and security logs, payment and communications providers, publicly available business sources, and service platforms you authorise us to access.
We use personal data to respond to requests and take steps before a contract; perform and administer contracts; deliver and support Services; manage accounts, invoices and records; protect systems and investigate misuse; improve operations and the website; establish or defend legal claims; comply with law; and send relevant business communications.
Depending on the activity, our lawful basis is performance of a contract or pre-contract steps, our legitimate interests in operating and protecting the business and developing relevant services, compliance with a legal obligation, or consent where the law requires it. Where we rely on legitimate interests, we consider necessity and the effect on individual rights.
We may send relevant service communications to business contacts where permitted by data protection and electronic marketing law. You can object or unsubscribe at any time by replying to the relevant message or using our contact page. Service and legal messages are not marketing.
The public site uses limited first-party code and may store campaign or session information needed to preserve an enquiry journey. If optional analytics, advertising cookies or similar technologies are enabled, we will provide information and request consent where required. Browser controls can also restrict storage, although doing so may affect functionality.
We may share data only as reasonably necessary with hosting and infrastructure providers, email and communications services, CRM and support systems, payment providers, analytics or advertising services where enabled, contractors working under duties of confidentiality, professional advisers, insurers, prospective purchasers of the business, and courts, regulators or authorities where required. We do not sell personal data.
Some providers may process data outside the United Kingdom. Where a restricted transfer occurs, we use an applicable UK adequacy regulation, the UK International Data Transfer Agreement or UK Addendum, or another lawful safeguard, together with any assessment required by law. Contact us for more information about safeguards relevant to your data.
We keep personal data only for as long as reasonably necessary for the purpose collected. We consider the life of an enquiry or client relationship, support and security needs, contractual limitation periods, tax and accounting duties, dispute or complaint requirements, and whether a record is needed to establish or defend legal claims. Data may remain in protected backups for a limited recovery cycle before deletion or overwrite.
When a business connects a WhatsApp Business account or number to TwinScroll Hub, the service may receive and process message content, sender and recipient identifiers, WhatsApp profile names, phone numbers, timestamps, media and media metadata, message status information, WhatsApp Business Account and phone-number identifiers, and technical webhook, connection and security records. This data is processed only to provide the connected messaging, routing, triage, support, reporting and business-management functions requested by the relevant client.
For customer conversations handled for a client, the client will normally be controller and TwinScroll processor. Meta Platforms and WhatsApp provide the underlying messaging platform and process data under their own applicable terms and privacy notices. TwinScroll does not sell WhatsApp message data or use it for unrelated advertising, profiling or retargeting.
Retention follows the relevant client instructions, service requirements, security needs and applicable legal obligations. Disconnecting an integration or removing platform permissions does not automatically delete data already lawfully stored in TwinScroll systems. Individuals can use the Data Deletion page linked below to request deletion or exercise another data right.
Where TwinScroll processes a client's customer or staff data solely to provide a website, hosting, campaign, booking, CRM or support service, the client will normally be controller and TwinScroll processor. That processing is governed by the applicable client agreement and any required Article 28 data processing terms, not by treating TwinScroll as controller of the client's business data.
We use access controls, managed hosting, authentication, backups, monitoring and organisational safeguards appropriate to the nature of the data. No internet transmission or storage system is completely secure. Please tell us promptly if you believe personal data or an account relevant to TwinScroll has been compromised.
Depending on the circumstances, you may have rights to be informed, access your data, correct inaccurate data, erase data, restrict processing, receive portable data, object to processing, and withdraw consent without affecting earlier lawful processing. Rights are subject to legal conditions and exemptions. We may need to verify identity before acting. To make a request, use the data deletion instructions or contact page.
You have an absolute right to object to direct marketing. Tell us at any time and we will stop using your data for that purpose.
If you are concerned about our use of personal data, use the contact page or data deletion instructions. We maintain a process for handling data protection complaints and will acknowledge, investigate and respond within applicable statutory periods. You may also complain to the Information Commissioner's Office at ico.org.uk or by calling 0303 123 1113. We would appreciate the opportunity to address the issue first.
We do not use personal data collected through this site to make solely automated decisions that have legal or similarly significant effects. The site and Services are intended for business users and are not directed at children. We may update this policy when our Services, providers or legal obligations change; the date at the top identifies the current version.