1. Roles
Customer is the controller of personal data entered into TTT CRM brand workspaces about contacts, customers, leads, and related individuals (“Customer Personal Data”). Tweed Tyne Technologies Ltd processes that data as processor to provide TTT CRM.
Tweed Tyne Technologies Ltd remains controller of its own account, billing, security, and support data, as described in the Privacy policy.
2. Details of processing
- Subject matter: hosting and processing Customer Personal Data in TTT CRM (cases, CRM records, knowledge base, mail, attachments, reports, and exports).
- Duration: for the term of Customer’s use of the platform, plus any grace, archive, and backup retention period, or earlier deletion on written request.
- Nature and purpose: storage, retrieval, transmission, backup, display, and deletion as needed to operate the features Customer enables.
- Types of data: names, contact details, organisation identifiers, case and correspondence content, attachments, and technical logs linked to user actions, as determined by Customer’s use of the platform.
- Data subjects: Customer’s personnel, end customers, leads, and other individuals whose data Customer chooses to store.
3. Processor obligations
Tweed Tyne Technologies Ltd shall:
- process Customer Personal Data only on documented instructions from Customer (including configuration and use of TTT CRM), unless UK law requires otherwise;
- ensure persons authorised to process the data are bound by confidentiality;
- implement appropriate technical and organisational measures as summarised in Security and compliance;
- not engage a sub-processor without the safeguards in section 4;
- assist Customer, taking into account the nature of processing, with data subject requests, security incidents, and DPIAs where reasonably required;
- delete or return Customer Personal Data after the end of providing services, subject to backup expiry and legal retention, when Customer so instructs;
- make available information necessary to demonstrate compliance with this DPA and allow reasonable audits (remote questionnaire or equivalent) on fair notice, no more than once per year unless a suspected breach requires earlier review.
4. Sub-processors
Customer authorises the Processor to use the following sub-processors for Customer Personal Data. We will post material changes on this page and, where practicable, give prior notice so Customer may object on reasonable data-protection grounds.
| Sub-processor | Role | Location notes |
|---|---|---|
| Railway Corp (“Railway”) | Application hosting, managed PostgreSQL, Redis, media/object storage | US-incorporated provider; Customer workloads hosted in Railway’s EU region |
| Cloudflare, Inc. | Edge DNS/CDN/security, Turnstile bot protection, Email Routing/Workers for inbound mail where configured | US-incorporated; global edge; limited technical and routed message data as needed |
| IDrive Inc. (iDrive e2) | Encrypted offsite backup object storage | US-incorporated; backup storage in London region (eu-west-3) |
| S3-compatible attachment storage (as configured) | Case and related file attachments | Region as deployed for the platform |
| Transactional email (SMTP provider) | Delivery of service emails where Customer Personal Data appears | As configured for TTT CRM; used only to send those messages |
The Processor remains responsible for sub-processor performance. International transfers rely on appropriate transfer tools (such as UK/EU Standard Contractual Clauses or a valid Data Privacy Framework certification) as offered by each provider.
5. Security
Measures include HTTPS for connections, TLS for production database connections where configured, hashed passwords, role-based multi-tenant brand isolation, audit logging, restricted production access, encryption in transit and at rest for backups with provider controls, and bot protection on public entry points. Further detail: Security and compliance.
6. Personal data breaches
After becoming aware of a personal data breach affecting Customer Personal Data, the Processor will notify Customer without undue delay and provide information reasonably available to help Customer meet UK GDPR notification duties. Customer remains responsible for notifying the ICO or data subjects where required.
7. Customer obligations
Customer warrants it has a lawful basis and any required notices/consents for Customer Personal Data, will not instruct unlawful processing, and will use roles and exports responsibly.
8. Liability and order of precedence
Liability under this DPA is subject to the limitations in the Terms of service, except where UK data protection law prohibits limitation. If there is a conflict between this DPA and the Terms on data-protection subject matter, this DPA prevails.
9. Governing law
This DPA is governed by the law of Scotland. Operator details: company number SC874131; ICO registration ZC184042.
10. Related policies
Privacy policy · Terms of service · Security and compliance · Guides