Privacy Policy
Last updated: 30 July 2026 · Governed by UK GDPR and the Data Protection Act 2018
1. Who we are
The service is operated by ProcessTwin AI Ltd(“ProcessTwin”, “we”), a company registered in England and Wales (company no. [Companies House no. — pending]) with registered office at [Registered office address — pending]. We are registered with the Information Commissioner’s Office ([ICO registration — pending]). Privacy contact: privacy@processtwin.ai.
Two roles. For workspace content processed on behalf of a customer organisation, that organisation is the controller and ProcessTwin is the processor, under our Data Processing Addendum. For account, website, support and billing data, ProcessTwin is the controller — this notice covers that processing.
2. What we process, why, and the lawful basis
- Account data — name, work email, authentication identifiers (managed by our identity provider, Clerk). Purpose: providing sign-in and workspace membership. Lawful basis: performance of a contract (UK GDPR Art. 6(1)(b)).
- Workspace content — metadata and content from tools your organisation connects (for example email subjects, senders, timestamps, document names), used solely to map processes and power the features your organisation enables. Scope controls and PII masking limit what is ingested. We process this as processor on your organisation’s documented instructions — your organisation determines the lawful basis.
- Usage & security data — product events, logs and security telemetry (with tenant and request identifiers). Purpose: operating, securing and improving the service; abuse prevention. Lawful basis: legitimate interests (Art. 6(1)(f)) — balanced against your rights; we collect the minimum needed.
- Billing data — processed by Stripe; we never see full card numbers. Purpose: charging for the service and keeping statutory accounting records. Lawful basis: contract and legal obligation (Art. 6(1)(c)).
- Enquiries & support — contact-form and support-ticket content. Purpose: responding to you. Lawful basis: legitimate interests, or steps prior to a contract.
- Marketing — we send marketing only in accordance with PECR: to corporate subscribers, or with consent, always identifying ourselves and always with a working opt-out. Lawful basis: legitimate interests or consent (Art. 6(1)(a)).
3. AI processing & automated decisions
Where AI features are enabled, relevant workspace content is sent to the AI provider configured for your workspace (Anthropic or OpenAI) to generate the requested output. Your content is never used to trainour models or our providers’ models under our agreements. Workspaces can enable PII redaction, which masks emails, phone numbers and similar identifiers before any AI provider call, and can configure retention for prompts and traces.
UK GDPR Article 22. ProcessTwin does not make solely automated decisions that produce legal or similarly significant effects about individuals. AI agents start in suggestion mode, external actions require human approval until an administrator explicitly raises autonomy, and every run is logged with a full trace, a kill switch and human override.
4. How long we keep data
- Discovered signals — 180 days by default (workspace-configurable, 30–730), then deleted by a nightly job.
- Agent run content (prompts, traces, inputs) — 90 days by default (configurable 7–365); run statistics are kept without content.
- Notifications — 90 days.
- Audit records — 2 years (security and accountability).
- Billing & accounting records — 6 years, as required by UK tax and company law.
- Workspace deletion— a 30-day grace period (cancellable in-app), then the workspace’s data, derived data and encryption keys are removed from production systems.
5. International transfers
Workspace content is stored and processed on servers we operate in Germany. Transfers from the UK to the EEA are permitted under the UK’s adequacy arrangements. Some subprocessors are in the United States; where they process personal data we rely on the UK Extension to the EU-US Data Privacy Framework (the “UK-US Data Bridge”) where the provider is certified, or on the ICO’s International Data Transfer Agreement / UK Addendum with supplementary measures. The current list and mechanisms are in our DPA & subprocessor list.
6. Your rights
Under UK GDPR you have the rights of access, rectification, erasure, restriction, portability, and objection, and rights in relation to automated decision-making. Workspace members can exercise export and deletion directly in Settings → Security; for anything else contact privacy@processtwin.ai. We respond within one month. We will never charge for a first request unless it is manifestly unfounded or excessive.
If you are unhappy with our response you can complain to the Information Commissioner’s Office: ico.org.uk· 0303 123 1113 · Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We’d appreciate the chance to resolve it first.
7. Cookies (PECR)
We use only strictly necessarycookies: session and security cookies set by our authentication provider when you sign in. Your theme preference is kept in your browser’s local storage at your request. We set no advertising, analytics or tracking cookies— which is why you don’t see a cookie banner. If that ever changes, we will ask for consent first.
8. Subprocessors & sharing
We use a short list of subprocessors — Clerk (authentication), Stripe (payments), Anthropic and/or OpenAI (AI processing, per workspace configuration) and our German hosting provider — under written contracts imposing UK GDPR Article 28 obligations. The maintained list, with locations and transfer mechanisms, is published in the DPA. We do not sell personal data. We disclose data to authorities only where legally required, and we tell the affected customer unless prohibited.
9. Security & breaches
Controls include per-tenant encryption keys, row-level tenant isolation, tamper-evident audit logging, rate limiting and continuous security scanning — details at /security. Where a personal data breach is likely to result in a risk to individuals, we notify the ICO within 72 hours of becoming aware, notify affected customer organisations without undue delay, and document every breach regardless of severity.
10. Children & changes
The service is for business use and not directed at children; you must be 18 or older to create an account. We’ll post any material change to this notice here and, for significant changes, notify workspace owners. Continued use after the effective date constitutes acceptance.
This notice is maintained as part of the product and reviewed with counsel before material releases.