TTT CRM

Privacy policy

How Tweed Tyne Technologies Ltd processes personal data when you use TTT CRM.

Operated by Tweed Tyne Technologies Ltd, registered in Scotland (SC874131). ICO ZC184042. Last updated: 12 August 2026.

1. Who is responsible

Tweed Tyne Technologies Ltd (company number SC874131, Scotland) operates TTT CRM. We are registered with the Information Commissioner’s Office under number ZC184042. Registered office: 5 South Charlotte Street, Edinburgh, EH2 4AN, United Kingdom. Contact: crm@tweedtynetechnologies.co.uk.

For account and service data (staff logins, platform administration, security logs, billing contacts for the platform itself), we are the controller.

For Customer Data you enter in a brand workspace (cases, contacts, knowledge articles, mail content, and similar records), your organisation is typically the controller. We act as your processor under our Data processing addendum.

2. What we collect

Account and organisation

Name, email, hashed password, role, brand memberships, and related workspace settings.

Customer Data you enter

Cases and notes, contacts and accounts, leads and opportunities, knowledge articles, inbound/outbound mail, attachments, campaign data, and automation configuration — depending on features you use.

Technical and security data

IP address, browser and device signals, timestamps, audit logs, and bot-protection tokens when Cloudflare Turnstile protects login or other public forms. Inbound email routed through Cloudflare Email Routing/Workers may include message content needed to deliver mail into the platform.

3. Why we process it

  • Contract: to provide TTT CRM, authenticate users, host brand workspaces, and send service emails.
  • Legitimate interests: to secure the service, prevent abuse, improve reliability, and keep audit trails.
  • Legal obligation: where tax, accounting, or data-protection law requires retention or disclosure.
  • Processor instructions: for Customer Data, only as needed to deliver the features you use, under the DPA.

4. Where data lives and who helps us

Production application data is hosted in the European Economic Area on infrastructure operated by Railway (Railway Corp, a US-incorporated provider). Deployed workloads and primary databases are placed in Railway’s EU region. Railway’s US corporate control plane may still be involved in operating the platform.

Key processors include:

  • Railway — application hosting, managed PostgreSQL, Redis, and related media/object storage.
  • Cloudflare, Inc. — DNS, CDN, edge security, Turnstile bot protection on selected forms, and Email Routing/Workers for inbound brand support/sales mail where configured.
  • iDrive e2 (IDrive Inc.) — encrypted offsite backup copies for disaster recovery. Backup object storage is configured in the London region (eu-west-3).
  • Object storage for attachments — case attachments may use S3-compatible storage configured for the platform (region as deployed).
  • Transactional email (SMTP) — service mail is sent via the SMTP provider configured for TTT CRM.

Transfers outside the UK/EEA (for example where a US provider’s support or control plane is involved) rely on appropriate safeguards such as UK/EU Standard Contractual Clauses, Data Privacy Framework participation where applicable, and our contracts with those providers. More detail: Security and compliance.

5. Cookies and similar technology

We use essential cookies and local storage for sign-in sessions, CSRF protection, security (including Turnstile), and basic product preferences. We do not run third-party advertising trackers on TTT CRM.

6. How long we keep data

Account and Customer Data stay while your organisation uses TTT CRM, plus any grace, archive, and backup retention period. Offsite backups are retained for a limited rolling window and then expire. You may ask us to delete sooner by emailing crm@tweedtynetechnologies.co.uk.

7. Sharing

We do not sell personal data. We share it with processors listed above, when required by law, or to protect the service. Within each brand workspace, access follows the roles you assign.

8. Your rights

Under UK GDPR you may have rights to access, rectify, erase, restrict, object, and data portability, and to complain to the ICO.

For Customer Data stored in a brand workspace, contact the organisation that controls that workspace first. For our own account or service processing, contact crm@tweedtynetechnologies.co.uk.

9. Changes

We may update this policy as the product or processors change. The “Last updated” date at the top will change when we do.

10. Related policies

Terms of service · Data processing addendum · Security and compliance · Guides