1Who we are
ECOMR LTD trading as TwinScroll is the controller of personal data collected for its own enquiries, client relationships, billing, website operation and business administration. ECOMR LTD is registered in England and Wales under company number 13851965. Its registered office is 7 Pemberley Drive, Pemberley Drive, Tamworth, England, B78 3EX. Contact us at [email protected].
2What this policy covers
This policy covers personal data handled through twinscroll.co, enquiry and plan forms, email, WhatsApp, calls, meetings, proposals, contracts, support, billing and normal business administration. It does not replace a client's own privacy notice for a website or campaign operated for that client.
3Personal data we collect
- identity and contact details, including name, role, business, email, phone number and messaging details;
- enquiry, project and support information, including websites, social profiles, service interests, budgets, timing, instructions, approvals and communications;
- contract, billing and transaction information, including invoices, payment status and limited payment references supplied by payment providers;
- technical and usage data, including IP address, browser, device, source page, referral and campaign parameters, form events and security logs; and
- information you choose to provide in files, messages, calls or project systems.
Please do not send special-category data, criminal-offence data or unrelated personal data unless we have agreed that it is necessary and there is a lawful basis.
4Where data comes from
We collect data from you, your authorised colleagues or advisers, our website and forms, normal server and security logs, payment and communications providers, publicly available business sources, and service platforms you authorise us to access.
5Purposes and lawful bases
We use personal data to respond to requests and take steps before a contract; perform and administer contracts; deliver and support Services; manage accounts, invoices and records; protect systems and investigate misuse; improve operations and the website; establish or defend legal claims; comply with law; and send relevant business communications.
Depending on the activity, our lawful basis is performance of a contract or pre-contract steps, our legitimate interests in operating and protecting the business and developing relevant services, compliance with a legal obligation, or consent where the law requires it. Where we rely on legitimate interests, we consider necessity and the effect on individual rights.
6Marketing, cookies and similar storage
We may send relevant service communications to business contacts where permitted by data protection and electronic marketing law. You can object or unsubscribe at any time by replying or emailing [email protected]. Service and legal messages are not marketing.
The public site uses limited first-party code and may store campaign or session information needed to preserve an enquiry journey. If optional analytics, advertising cookies or similar technologies are enabled, we will provide information and request consent where required. Browser controls can also restrict storage, although doing so may affect functionality.
7Who receives personal data
We may share data only as reasonably necessary with hosting and infrastructure providers, email and communications services, CRM and support systems, payment providers, analytics or advertising services where enabled, contractors working under duties of confidentiality, professional advisers, insurers, prospective purchasers of the business, and courts, regulators or authorities where required. We do not sell personal data.
8International transfers
Some providers may process data outside the United Kingdom. Where a restricted transfer occurs, we use an applicable UK adequacy regulation, the UK International Data Transfer Agreement or UK Addendum, or another lawful safeguard, together with any assessment required by law. Contact us for more information about safeguards relevant to your data.
9How long we keep data
We keep personal data only for as long as reasonably necessary for the purpose collected. We consider the life of an enquiry or client relationship, support and security needs, contractual limitation periods, tax and accounting duties, dispute or complaint requirements, and whether a record is needed to establish or defend legal claims. Data may remain in protected backups for a limited recovery cycle before deletion or overwrite.
10WhatsApp and Meta platform data
When a business connects a WhatsApp Business account or number to TwinScroll Hub, the service may receive and process message content, sender and recipient identifiers, WhatsApp profile names, phone numbers, timestamps, media and media metadata, message status information, WhatsApp Business Account and phone-number identifiers, and technical webhook, connection and security records. This data is processed only to provide the connected messaging, routing, triage, support, reporting and business-management functions requested by the relevant client.
For customer conversations handled for a client, the client will normally be controller and TwinScroll processor. Meta Platforms and WhatsApp provide the underlying messaging platform and process data under their own applicable terms and privacy notices. TwinScroll does not sell WhatsApp message data or use it for unrelated advertising, profiling or retargeting.
Retention follows the relevant client instructions, service requirements, security needs and applicable legal obligations. Disconnecting an integration or removing platform permissions does not automatically delete data already lawfully stored in TwinScroll systems. Individuals can use the Data Deletion page linked below to request deletion or exercise another data right.
Read the TwinScroll data deletion instructions.
11Client services and processor data
Where TwinScroll processes a client's customer or staff data solely to provide a website, hosting, campaign, booking, CRM or support service, the client will normally be controller and TwinScroll processor. That processing is governed by the applicable client agreement and any required Article 28 data processing terms, not by treating TwinScroll as controller of the client's business data.
12Security
We use access controls, managed hosting, authentication, backups, monitoring and organisational safeguards appropriate to the nature of the data. No internet transmission or storage system is completely secure. Please tell us promptly if you believe personal data or an account relevant to TwinScroll has been compromised.
13Your rights
Depending on the circumstances, you may have rights to be informed, access your data, correct inaccurate data, erase data, restrict processing, receive portable data, object to processing, and withdraw consent without affecting earlier lawful processing. Rights are subject to legal conditions and exemptions. We may need to verify identity before acting. To make a request, email [email protected].
You have an absolute right to object to direct marketing. Tell us at any time and we will stop using your data for that purpose.
14Complaints
If you are concerned about our use of personal data, email [email protected]. We maintain a process for handling data protection complaints and will acknowledge, investigate and respond within applicable statutory periods. You may also complain to the Information Commissioner's Office at ico.org.uk or by calling 0303 123 1113. We would appreciate the opportunity to address the issue first.
15Automated decisions, children and updates
We do not use personal data collected through this site to make solely automated decisions that have legal or similarly significant effects. The site and Services are intended for business users and are not directed at children. We may update this policy when our Services, providers or legal obligations change; the date at the top identifies the current version.