Sub-processor List & Notification Policy
Overview
To support delivery of our Services, Twinit Limited uses third-party service providers and system integrations (each a "Sub-processor") to process customer data, including personal data. Prior to engaging any Sub-processor, we conduct a privacy and security review to ensure the vendor meets appropriate technical and organizational standards, including data protection agreements (DPAs) incorporating standard contractual clauses or equivalent legal transfer mechanisms where required.
Current Sub-processors
Below is the list of third-party Sub-processors currently engaged to process Personal Data on behalf of our customers:
Notification of Changes & Right to Object
We periodically update our list of Sub-processors as our platform infrastructure and business needs evolve.
-
Notifications: Customers who have executed a Data Processing Addendum (DPA) with us will receive advance written notice (via email or via our in-app portal) before any new Sub-processor is engaged to process Personal Data.
-
Objections: Customers may reasonably object to the appointment of a new Sub-processor on data protection grounds within 30 days calendar days of receiving notice by emailing us at security@twinit.com. If an objection is raised, we will work in good faith to discuss a solution or alternative deployment options.
Sub-processor Due Diligence
We require all Sub-processors to:
-
Process Personal Data strictly in accordance with our documented instructions.
-
Implement appropriate administrative, technical, and physical security measures.
-
Notify us promptly in the event of a security incident affecting Personal Data.