Who is responsible
Tweed Tyne Technologies Ltd (company number SC874131, Scotland) operates TTT CRM. We are registered with the ICO under number ZC184042. Registered office: 5 South Charlotte Street, Edinburgh, EH2 4AN, United Kingdom.
We are the controller for staff account and service data. For Customer Data in brand workspaces, your organisation is typically the controller and we process that data under our Data processing addendum. Full detail: Privacy policy.
What we hold
Depending on what you use: staff accounts, brand configuration, cases and notes, CRM records, knowledge articles, inbound and outbound mail, attachments, automation state, and security/audit logs.
Where the data lives
Production application data is hosted in the European Economic Area on Railway, a US-incorporated cloud provider. Application services, managed PostgreSQL, Redis, and related media storage run in Railway’s EU hosting region. Connections use HTTPS. Database connections use TLS in production where configured. Access to production systems is limited to people who need it to run and support the service.
Because Railway is US-incorporated, its platform control plane and support functions may involve the United States even while primary workloads stay in the EU. We address that through Railway’s customer DPA and transfer safeguards, described in the Privacy policy and DPA.
Processors we rely on
- Railway — hosting, database, Redis, and media storage for the live service.
- Cloudflare — DNS, CDN, and edge security; Turnstile bot protection on staff login and selected public forms; Email Routing/Workers for inbound brand support and sales mail where configured.
-
iDrive e2 — encrypted offsite backups stored in object storage in
the London region (
eu-west-3), separate from the live Railway stack. - S3-compatible storage — attachments and related files as configured for the platform.
- Transactional email (SMTP) — invites, password resets, magic links, and service notices.
The formal sub-processor list for Customer Personal Data is in the DPA.
Backups
Database and related backups run on a regular schedule. Live provider backups and offsite iDrive e2 copies are encrypted in transit and at rest with the providers’ standard controls. Offsite copies are kept for a limited rolling retention window.
Who can see brand data
TTT CRM is multi-tenant by brand. Brand records are scoped so other brands cannot read them. Within a brand, access follows staff roles and portal authentication. Passwords are stored hashed. Public forms that create or open sessions are protected with Cloudflare Turnstile where enabled.
Compliance posture
We design TTT CRM around UK GDPR expectations for a small SaaS product: least-privilege access, encryption in transit, brand isolation, processor contracts, and an ICO registration you can check. We are not claiming ISO certification or a public SOC 2 report. If you need a short questionnaire answered, email crm@tweedtynetechnologies.co.uk.
Your rights
Individuals whose data you store retain their rights under UK GDPR. You remain responsible for having a lawful basis to hold that data. Contact us at crm@tweedtynetechnologies.co.uk for requests that relate to TTT CRM’s own account or service processing.
Related policies
Terms of service · Privacy policy · Data processing addendum · Guides