top of page

Sub-processor List & Notification Policy 

Overview 

To support delivery of our Services, Twinit Limited uses third-party service providers and system integrations (each a "Sub-processor") to process customer data, including personal data. Prior to engaging any Sub-processor, we conduct a privacy and security review to ensure the vendor meets appropriate technical and organizational standards, including data protection agreements (DPAs) incorporating standard contractual clauses or equivalent legal transfer mechanisms where required. 

Current Sub-processors 

Below is the list of third-party Sub-processors currently engaged to process Personal Data on behalf of our customers: 

Subprocessor Name
Purpose of Processing
Categories of Data Processed
Processing Location / Transfer Mechanism
Security Measures & Data Protection Link
Amazon Web Services, Inc. (AWS)
Cloud infrastructure hosting, application database management (PostgreSQL), caching, object storage, secrets management, DNS, and transactional email routing (SES).
All customer application data, system backups, secrets, and transactional email recipient data.
Regions: Ireland for EU customer data, US, India, Australia, Singapore
https://aws.amazon.com/security/
Oracle Cloud Infrastructure (OCI)
Infrastructure hosting, managed databases, key management, and transactional email delivery for regional platform deployments.
Application data, backups, user credentials, secrets, and email recipient details.
Primary: India and Singapore
https://www.oracle.com/security/
Microsoft Corporation (Azure)
Identity management (Entra ID staff authentication), key storage, and network routing hubs.
Directory identity data and transit network traffic payload.
Primary: India and global Entra ID tenant infrastructure.
https://azure.microsoft.com/en-us/explore/security
Cloudflare, Inc.
Reverse proxy, global Content Delivery Network (CDN), DDoS protection, TLS termination, edge security, and access control.
All web request traffic passing through the edge (IP addresses, request bodies, transit credentials, and uploaded files).
Global: Processed dynamically across Cloudflare's global edge network nearest to the end user.
https://www.cloudflare.com/en-gb/trust-hub/
MongoDB, Inc. (MongoDB Atlas)
Fully managed database services supporting core platform applications.
Customer application data at rest and database point-in-time recovery backups.
EU Region: Ireland for EU instances, India
https://www.mongodb.com/products/platform/trust
ScaleGrid (GridGears LLC)
Database management plane for database clusters running inside private cloud tenancies.
Control-plane access only; customer application data remains stored at rest in internal tenancies (e.g., India).
Control Plane: United States / India
https://scalegrid.io/privacy-policy/
OpenAI, LLC
Artificial intelligence services powering chat responses, query completion, and document embeddings.
User prompt inputs, chat conversation history, and uploaded knowledge base document content.
Location: United States
https://openai.com/security-and-privacy/
Anthropic, PBC
Supplemental artificial intelligence and natural language generation processing.
User prompts, query logs, and interaction history.
Location: United States
https://trust.anthropic.com/
Mapbox, Inc.
Map rendering, tile service, geocoding, and location search capabilities within GIS/3D interfaces.
End-user IP addresses, viewed map coordinate assets, and typed location search queries.
Location: United States / Global edge network
https://www.mapbox.com/legal/privacy
Thinkific Labs Inc.
Learning management system (LMS) hosting for customer education and developer portals.
End-user first name, last name, and registered email address.
Location: Canada and United States.
https://www.thinkific.com/security-overview/
Sisense, Inc.
Embedded analytics and business intelligence dashboard rendering via single sign-on (SSO).
User email address carried within signed SSO authentication tokens.
Location: Hosted platform infrastructure
https://trust.sisense.com/
Cursor
AI-powered code editor providing code completion, chat assistance, and agentic coding workflows for the development team.
Location: United States (Anysphere, Inc.); prompts may be routed to model sub-processors under Cursor's data processing agreements.
https://trust.cursor.com/
Freshworks (CRM)
CRM services used for managing customer and engagement.
Email address
Location: Data centers in India
https://trust.freshworks.com/
Freshworks (Helpdesk)
Customer support helpdesk for Managing customer support tickets
Support ticket content, and customer interaction/communication history.
Location: Data centers in United States
https://trust.freshworks.com/
Skyspark (Skyfoundry)
Building and energy analytics software used to monitor, analyze, and report on facility operational data.
email address, Building sensor, equipment, and IoT operational data; SkySpark is not typically
Location: United States
https://skyfoundry.com/privacy
Microsoft Corporation (365)
Productivity and collaboration suite (email, document storage, calendaring, and messaging) for internal business operations.
Emails, documents, calendar data, and user identity/authentication information.
Location: Microsoft data centers in India
https://www.microsoft.com/en-us/trust-center/product-overview
NetSuite
Cloud-based ERP/financial management system used for accounting, order management, and business operations.
Financial and accounting records, transactional business data, customer/vendor contact information, and user account data.
Location: Oracle-operated data centers across North America, Europe, and Asia-Pacific, with paired primary/secondary regions for redundancy.
https://www.oracle.com/trust/
RightSignature (Citrix / ShareFile)
Electronic signature service used for sending, signing, and archiving contracts and other documents requiring e-signature.
Signer names, email addresses, signature data, and the content of documents sent for signature.
Location: Amazon Web Services (AWS) S3 data centers, with documents replicated across multiple locations for redundancy.
https://docs.sharefile.com/en-us/sharefile/electronic-signature/security

Notification of Changes & Right to Object 

We periodically update our list of Sub-processors as our platform infrastructure and business needs evolve. 

​

  • Notifications: Customers who have executed a Data Processing Addendum (DPA) with us will receive advance written notice (via email or via our in-app portal) before any new Sub-processor is engaged to process Personal Data. 

 

  • Objections: Customers may reasonably object to the appointment of a new Sub-processor on data protection grounds within 30 days calendar days of receiving notice by emailing us at security@twinit.com. If an objection is raised, we will work in good faith to discuss a solution or alternative deployment options.

Sub-processor Due Diligence 

We require all Sub-processors to: 

 

  • Process Personal Data strictly in accordance with our documented instructions. 

 

  • Implement appropriate administrative, technical, and physical security measures. 

 

  • Notify us promptly in the event of a security incident affecting Personal Data. 

bottom of page