Data Processing Agreement

Customer agreement template — 11 October 2026

Request your agreement

Email info@twidget.io with your organisation's legal name, authorised contact and service requirements. Do not send customer records or credentials. TWIDGET LIMITED, company number 14995704, 128 City Road, London, United Kingdom, EC1V 2NX, is the service provider; Idris Kadri is our privacy contact.

This is a published template, not an executed agreement. It applies only when validly incorporated into or executed with your service agreement. The customer-specific processing details, authorised supplier version and applicable transfer arrangements must be recorded before execution. Visiting this page does not sign the DPA or establish that outstanding supplier checks are complete.

1. Roles and scope

For personal data processed on your behalf in configured applications, tables, files, APIs, functions and events, you are the controller (or an authorised processor acting for your controller) and Twidget is the processor (or subprocessor). Our separate account, billing, support and legal processing is described in the Privacy Policy. Applicable data protection law means the UK GDPR, Data Protection Act 2018 and EU GDPR where applicable.

2. Documented instructions

Twidget will process customer personal data only on documented instructions, including authorised service configuration and written requests, unless law requires otherwise. We will notify you of a legal requirement unless prohibited and inform you if we consider an instruction unlawful. You determine processing purposes, lawful grounds, permitted recipients and authorised users and provide appropriate notices. This does not remove Twidget's own obligations.

3. Confidentiality and security

Authorised personnel will be subject to confidentiality duties and limited access. Twidget will maintain risk-appropriate technical and organisational measures to protect confidentiality, integrity, availability and resilience, support recovery and assess those measures regularly. The agreed security annex must describe the actual deployed controls and relevant limitations, not an absolute security guarantee.

4. Subprocessors

The agreed supplier annex identifies the Twidget-appointed subprocessors you generally authorise. We will provide advance written notice of additions or replacements, allowing a reasoned data-protection objection before affected processing begins. We will seek a lawful resolution before starting disputed processing or ending the affected service under the service agreement. We will impose equivalent applicable obligations on subprocessors and remain responsible for their performance. See the current supplier and subprocessor information; customer-selected destinations are distinguished there.

5. International transfers

Existing hosting is DigitalOcean SFO3 in the United States; this agreement does not promise EU-only or UK-only hosting. Transfers must follow documented instructions and applicable transfer requirements. The parties must record the appropriate adequacy or contractual mechanism and necessary assessment for actual recipients and access locations. This template is not a replacement for required transfer clauses, the UK Addendum or IDTA. Contact info@twidget.io for account-specific transfer information.

6. Rights and regulatory assistance

Taking account of the processing and available information, Twidget will assist with applicable individual rights, security obligations, breach assessments, impact assessments and prior consultation. We will route requests about your customer-controlled content to you and follow lawful verified instructions without disclosing another tenant's information. An acknowledgement is not confirmation that a request is fulfilled.

7. Personal data breaches

Twidget will notify you without undue delay after becoming aware of a personal data breach affecting your customer personal data. Available information will describe the nature, affected categories and approximate numbers where known, contact, likely consequences and containment/remediation. We will supplement incomplete information without undue further delay and cooperate with your lawful response. You determine your own notifications unless Twidget has a separate obligation.

8. Return and deletion

At your choice on termination, Twidget will return or delete customer personal data and delete existing copies unless law requires retention. Authority, shared ownership and legal holds must be checked. Approved erasure is not subject to an ordinary recovery window. Where immediate backup deletion is not practicable, affected data must remain beyond use until the destruction cycle, and deletion decisions must be applied before restored data becomes accessible. Completion must distinguish deleted, retained and pending records.

Approved defaults are 30 days for customer logs/event history and ordinary deleted-workspace recovery archives, 90 days for minimal technical audit evidence and seven days for rotating MongoDB backups. These periods do not cover every supplier copy: applicable Namecheap Private Email backups may last up to four weeks. Necessary exceptions must be documented and limited to their continuing purpose. See the Privacy Policy for case-record and suppression retention.

9. Information and audits

Twidget will provide information necessary to demonstrate applicable processor obligations and allow and contribute to customer or appointed-auditor audits, including inspections. Reasonable confidentiality, scope and security arrangements must not prevent mandatory audit or regulator rights. Both parties will cooperate with competent authorities where required.

10. Customer-specific annex and acceptance

The executed agreement must identify the customer and authorised contact, service/order reference, accepted DPA version and effective date; the processing subject matter, nature, purpose and duration; categories of individuals and personal data; any sensitive, children's or high-risk processing; customer rights and instructions; actual security measures; and authorised suppliers, locations and transfer references. Service configuration or an agreed order may supply the particulars, but unknown categories must not be invented.

Mandatory data-protection requirements take priority over conflicting service terms. This template does not limit statutory rights or liability that cannot lawfully be limited. No new hosting arrangement or guarantee of compliance follows from publishing it.

Questions or requests: info@twidget.io. Related information: Subprocessors and Cookie Policy.

Have any questions? Get in Touch

Starting with Twidget is easy, fast and free

It only takes a few clicks to get started

Get started - it's free

No credit card required.


© Copyright 2026 - Twidget.io