Data Processing Agreement
GDPR article 28 · Last updated: September 2026
1. Parties and roles
This agreement is entered into between the customer company using the Twikii platform (the "controller") and Twikii, a business registered in Denmark (the "processor"). It applies automatically to every company workspace created on the platform and forms part of our Terms & Conditions.
The controller decides why and how personal data about its own staff, customers and jobs is processed. Twikii processes that data only on the controller's documented instructions, which are given through normal use of the platform.
2. Subject matter, duration and purpose
Twikii processes personal data in order to deliver the platform: accounts and roles, customers and service addresses, requests, quotes, scheduling, job logs with check-in/out times and photo documentation, invoices and payment records. Processing lasts for as long as the controller's workspace is active, plus the retention periods in section 7.
3. Categories of data subjects and personal data
- Staff members — name, email, phone, role, assigned jobs, check-in/out times, job photos, position at check-in.
- Private and business customers — name, company name, email, phone, service address and location, notes, job history, quotes, invoices and payment status.
- Workspace administrators — account and contact details, billing contact information.
Twikii does not require special-category data (article 9). Controllers must not enter health, religious, biometric or similar sensitive data into free-text fields, notes or photos.
4. Processor obligations
- process personal data only on the controller's instructions and never for our own unrelated purposes;
- keep personnel with access bound by confidentiality;
- implement the technical and organisational measures in section 6;
- assist the controller with data subject requests, impact assessments and consultations with authorities;
- notify the controller without undue delay, and at the latest within 48 hours, after becoming aware of a personal data breach;
- make available the information needed to demonstrate compliance and allow audits as described in section 8.
5. Subprocessors
The controller gives general authorisation for the following subprocessors. We notify controllers before adding or replacing a subprocessor, and the controller may object on reasonable data-protection grounds.
| Subprocessor | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication and photo storage | EU |
| Cloudflare | Application hosting, delivery and protection | Global edge, EU primary |
| Paddle | Merchant of Record for subscriptions, invoicing and tax | UK/EU |
| Google Maps | Route navigation opened from a job (address only) | EU/US (SCCs) |
Where a subprocessor processes data outside the EEA, transfers rely on EU standard contractual clauses or an adequacy decision.
6. Technical and organisational measures
- Tenant isolation — every database row is tied to a company workspace and enforced by row-level security in the database itself, so one company can never read another company's data.
- Role-based access — roles (private customer, business customer, staff, company administrator) are stored separately from profiles and validated server-side; staff see only jobs assigned to them or open jobs.
- Field-level restrictions — staff cannot change prices, customers, addresses or dates on a job; database triggers reject such changes.
- Photo storage — job photos live in a private bucket; only the uploader and the company administrator can read or delete them, limited to 10 before and 10 after photos per job.
- Encryption — data is encrypted in transit (TLS) and at rest.
- Authentication — password and federated sign-in with session tokens validated server-side on every privileged action.
- Data minimisation — position is recorded only in connection with an active shift, never in the background.
7. Retention, return and deletion
On termination of the workspace, Twikii deletes or anonymises personal data within 90 days, except where law requires longer retention (for example bookkeeping records for invoices, kept 5 years under Danish law). The controller can export its data at any time before deletion.
8. Audits and documentation
On request, Twikii provides documentation of the measures in section 6 and answers security questionnaires. Audits are carried out no more than once a year, with 30 days' notice, during normal business hours and without disrupting the service.
9. Acceptance and contact
By creating a company workspace, the controller accepts this agreement. If your organisation requires a signed copy or a customised DPA, contact us at support@twikii.com and we will provide one.