Skip to main content

Legal document 01 of 03

Privacy notice

  • Effective 7 August 2026
  • Version 1.0
  • UK GDPR and Data Protection Act 2018
  • Company number 17061506

This notice is an inventory, not a reassurance. It states what personal data THE TWENTY FINTECH LTD holds, where it came from, why, on what lawful basis with the article cited, for how long, and who else sees it. Where the company acts as processor rather than controller, the section says so. Where something has not happened yet, it says that too.

1. Scope and how to read this

This notice covers personal data processed by THE TWENTY FINTECH LTD ("the company", "we") through this website, correspondence to any address on it, the company's commercial and administrative activities, and any software it publishes in future. It is written under the UK GDPR as retained in the law of England and Wales, and the Data Protection Act 2018. Article numbers are UK GDPR articles. PECR means the Privacy and Electronic Communications Regulations 2003.

The notice is organised as inventories. Each covers one group of people and states, in a table, the data held, example fields, source, purpose, lawful basis with the article cited, retention and recipients. To learn only what happens to your own data, read the inventory that describes you with sections 14 to 19.

Each section is marked with the role we hold. Controller means we decide why and how data is processed. Processor means we act only on another organisation's documented instructions, and that organisation is the controller.

The company was incorporated on 1 March 2026, has delivered no client engagement and published no software. Sections describing processing that has not begun say so, and state a committed position rather than an existing practice.

2. Who we are Controller

Controller
THE TWENTY FINTECH LTD
Company number
17061506
Registered in
England and Wales
Registered office
66 Paul Street, London, England, EC2A 4NA
Privacy contact
[email protected]
ICO fee registration
[TO CONFIRM: whether the ICO data protection fee is payable and the registration reference]

Data protection officer

None appointed. Article 37 requires one for public authorities, for core activities requiring large scale regular and systematic monitoring, or for large scale processing of special category or criminal offence data. None applies here. The position will be reassessed if processing changes, and this notice reissued.

No individual is named as a contact on this site. Officer details are held on the public Companies House record for company number 17061506.

Representative

The company is established in the United Kingdom and does not offer goods or services to, or monitor, individuals in the European Economic Area in a way that engages Article 27 of the EU GDPR. No EU representative is appointed.

3. Controller or processor

The company expects to hold both roles at once, for different data. Confusing them is the commonest defect in a supplier privacy notice, so the split is stated here.

Role held, by activity
ActivityRoleIn practice
Running this websiteControllerWe decide what the site collects, which is the request data our host records. Section 4.
Handling your emailControllerWe decide how enquiries are stored, read and deleted. Section 5.
Client administrationControllerContacts, contracts, invoices, accounting record. Section 6.
Suppliers, applicants, staffControllerRecords we must or choose to keep. Section 7.
Building on a client's dataProcessorThe client decides why and how; we act on documented instructions under an Article 28 agreement. Sections 8 to 11.
Support access to a client systemProcessorAnything seen belongs to the client and is not retained beyond the task. Section 9.
Any application we publishControllerApplies if and when we publish one. Sections 23 to 27.

Where we are a processor, the client's privacy notice governs the relationship with the individuals concerned. Section 11 explains what that means for you.

4. Inventory: website visitors Controller

This site is static files served from Cloudflare Pages. It runs no analytics, tag manager, advertising pixel, session recorder, chat widget or embedded media, and sets no cookies of its own. The cookie notice gives the full position. What remains is the data inherent in making an HTTP request, which no website can avoid.

Inventory 4.1, website request data, controller
CategoryExample fieldsSourcePurposeLawful basisRetentionRecipients
Connection data IP address, country derived from it, timestamp Your browser, automatically Delivering the page; blocking abusive traffic at the edge Article 6(1)(f). Legitimate interest: keeping the site available and defending it against denial of service and automated abuse. Held by the host on its own short rolling window, measured in days. We download no copy. Cloudflare, Inc.
Request metadata URL, HTTP status, user agent, referrer if sent Your browser, automatically Diagnosing broken links and server errors Article 6(1)(f). Legitimate interest: operating and correcting a working website. As above. Nothing is exported into a company system. Cloudflare, Inc.
Font request data IP address and user agent sent to Google's font servers Your browser, when it loads the page Rendering the site in its intended typefaces Article 6(1)(f). Legitimate interest: a legible, consistent site. This is a choice we could reverse by self hosting, which is why it is disclosed. Google's own retention. We receive nothing back. Google LLC

Legitimate interests assessment

The interests are availability, correctness and security of a public information site. The data arrives unavoidably with a request, is not combined with any other data set, builds no profile, is not used for advertising and is not sold. A visitor would reasonably expect a server to log a request. The balance therefore favours the processing and the impact is low. You may object under Article 21 using the route in section 19.

5. Inventory: enquirers Controller

There is no form on this site. Everything below arrives because someone chose to email an address on the contact page, or replied to us.

Inventory 5.1, correspondence, controller
CategoryExample fieldsSourcePurposeLawful basisRetentionRecipients
Identity and contact Name, email, organisation, job title, telephone if given You, directly Replying and knowing who we are speaking to Article 6(1)(b) for steps prior to a contract; otherwise Article 6(1)(f), legitimate interest in answering correspondence addressed to the company 24 months from the last message, unless it becomes a client or supplier record Our email host
Message content Your text, subject line, headers, any attachment You, directly Answering the enquiry; evidencing what was said if a dispute follows Article 6(1)(f). Legitimate interest: evidencing the substance and timing of business correspondence. 24 months from the last message Our email host
Data protection requests Your request, identity evidence, our response and reasoning You, directly Handling the request and showing it was handled correctly Article 6(1)(c), legal obligation, read with Articles 12 to 22 3 years from closure, so handling can be evidenced to the ICO Our email host; the ICO on a complaint
Security reports Report, reproduction steps, reporter contact, remediation notes You, directly Investigating and fixing a reported vulnerability Article 6(1)(f). Legitimate interest: the security of the company's systems. 3 years from closure Our email host

Please do not send personal data, cardholder data, credentials or production extracts by email. Email is not a confidential channel. Material of that kind received unsolicited is deleted, a short note that it arrived and was deleted is kept, and the sender is told.

Mail for this domain is handled by a third party provider acting as processor. [TO CONFIRM: identity, corporate entity and hosting region of the email provider] It will be named in section 14 once confirmed.

6. Inventory: clients and their staff Controller

These are the records needed to have a client relationship at all. Personal data inside a client's own systems is covered by sections 8 to 11, where we are processor. No engagement has yet been delivered; the inventory states the record set that will be kept when one is.

Inventory 6.1, client relationship records, controller
CategoryExample fieldsSourcePurposeLawful basisRetentionRecipients
Client contacts Name, work email and telephone, job title, employer, role The client organisation or the individual Performing and communicating about the engagement Article 6(1)(b) where the individual contracts; Article 6(1)(f) where their employer does, the interest being administering a business relationship Engagement plus 6 years, matching the Limitation Act 1980 period Accounting provider; advisers on a dispute
Contract documents Engagement letter, statement of work, DPA, signatory and date Both parties Recording what was agreed, by whom, when Article 6(1)(b), and Article 6(1)(f) for the evidential record 6 years after the engagement ends Advisers on a dispute; auditors if applicable
Billing records Invoice, purchase order reference, payment and remittance detail The client and our bank Getting paid; keeping the accounting records required by law Article 6(1)(c), legal obligation under the Companies Act 2006 and HMRC requirements 6 years from the end of the accounting period Accounting provider; HMRC; our bank
Engagement correspondence Emails, meeting notes, decisions, issues raised and closed Both parties Delivering the work; explaining a decision later Article 6(1)(b) and 6(1)(f). The interest is reconstructing technical reasoning after the people involved have moved on. 6 years after the engagement ends Our email host; advisers on a dispute
Supplier onboarding Security questionnaire answers, insurance evidence, company identifiers, named signatories Both parties Satisfying a client's third party risk process Article 6(1)(b) and 6(1)(f), the interest being consistency between answers given to different clients 6 years after the relationship ends The client only

7. Inventory: suppliers and applicants Controller

The company has no employees and has run no recruitment process. The rows state the position when it does.

Inventory 7.1, suppliers, applicants, personnel, controller
CategoryExample fieldsSourcePurposeLawful basisRetentionRecipients
Supplier contacts Name, work email, telephone, role The supplier or the individual Buying and administering services we use Article 6(1)(f). Legitimate interest: administering our own supply chain. Relationship plus 6 years Accounting provider
Supplier due diligence Security and privacy assessments, sub-processor terms, transfer mechanisms The supplier and public sources Meeting the Article 28(1) duty to use only processors giving sufficient guarantees Article 6(1)(c), read with Article 28 Relationship plus 3 years Clients on request, where the supplier is a sub-processor on their engagement
Job applicants Name, contact details, curriculum vitae, covering message, interview notes, right to work check at offer The applicant or a recruiter acting for them Assessing an application; running a fair selection process Article 6(1)(b) for steps prior to an employment contract; Article 6(1)(f) for interview notes, the interest being a defensible decision 12 months from the decision, then deletion. Longer only with consent under Article 6(1)(a). A recruiter where one is involved in that process
Personnel records Contract, payroll reference, statutory deductions, absence The individual and payroll processing Employing someone lawfully and paying them correctly Articles 6(1)(b) and 6(1)(c), with Article 9(2)(b) for health data processed for employment law purposes 6 years after employment ends Payroll and accounting providers; HMRC; pension provider

8. When we act as your processor Processor

Where the company builds, tests, reviews or operates software handling a client's records, the client is controller of any personal data in them and we are processor. That is governed by a written agreement meeting Article 28(3), signed before access is granted. There is no scenario in which we take such access on a handshake.

  • We process only on the client's documented instructions, including on any transfer to a third country, unless required otherwise by law. If we are, we tell the client first unless the law prohibits it.
  • We do not decide the purposes. We cannot agree a new use because it looks useful, and will not do so at a third party's request.
  • We do not use client data to improve our products, train any model, produce benchmarks or build aggregated data sets. That would need a separate written instruction, and none exists.
  • We tell the client without undue delay if an instruction appears to infringe data protection law.

If you are an individual whose data we hold as processor, we cannot act on your request ourselves. We notify the controller without undue delay, assist them, and tell you we have done so and who they are where we may.

9. Client data our work may reach Processor

Ledger and reconciliation work involves reading real records, because the defects that matter live in the records rather than the specification. Access is bounded by rules written into the engagement agreement rather than left as good intentions.

Minimisation before access

The default request is reduced, pseudonymised or synthetic data. A reconciliation defect can usually be reproduced from references, amounts, dates and status codes without names or account identifiers. Where identifying fields are genuinely needed, the request states which and why.

Named, time bound, logged

Where live access is unavoidable it is granted to a named individual for a stated period on client issued credentials, and revoked at the end of the task. We ask the client to log it on their side, because a supplier's log of its own access is worth much less than the controller's.

Nothing taken away

Extracts are not copied to personal devices, not retained after the task, and not moved outside the agreed arrangements. Working notes quoting a record are treated as client data and deleted with it. A screenshot in a ticket, a stack trace containing a record fragment and a log line quoting a payment reference are all client data, retained only for the life of the ticket plus the period the client specifies, and never moved into a general knowledge base.

10. Article 28 commitments Processor

Position against each Article 28(3) requirement
RequirementOur position
28(3)(a) InstructionsProcessing only on documented instructions, defined in the agreement, changed only in writing.
28(3)(b) ConfidentialityAnyone authorised is bound by a written confidentiality obligation surviving the engagement.
28(3)(c) SecurityMeasures appropriate to the risk under Article 32, described in the agreement, with the limits stated in section 17.
28(3)(d) Sub-processorsNone engaged without prior written authorisation. Under general authorisation, at least 30 days notice of any addition or replacement, with a right to object.
28(3)(e) RightsAssistance with Articles 15 to 22 by appropriate technical and organisational measures.
28(3)(f) Articles 32 to 36Assistance with security, breach notification, impact assessments and prior consultation.
28(3)(g) Deletion or returnAt the client's choice, deletion or return of all personal data at the end, with written confirmation, unless retention is required by law.
28(3)(h) AuditInformation made available to demonstrate compliance, and audits by the client or their mandated auditor on reasonable notice.

11. If your employer is our client Processor

You may be reading this because an organisation you deal with has engaged us and your data sits in a system we work on. In that case:

  • That organisation is the controller. Its privacy notice, not this one, describes why your data is processed and on what basis.
  • We hold your data only to carry out the task it instructed, with no independent purpose of our own.
  • Requests under Articles 15 to 22 should go to that organisation. If you send one to us we pass it on without undue delay, assist, and tell you we have done so. We will not action it ourselves.
  • If we become aware of a breach affecting your data we notify the controller without undue delay under Article 33(2). Notifying the ICO and you is then their decision and duty.

If you do not know which organisation instructed us, write to the privacy address describing the context, and we will tell you where we may.

12. Special category data

As controller, the company does not seek Article 9 special category data. The only foreseeable case is health information about an employee under Article 9(2)(b) for employment law purposes, and no such record exists. The company does not carry out criminal record checks and processes no Article 10 criminal offence data.

As processor, a client system may contain special category data. The lawful basis under Article 9(2) is the controller's determination, not ours. Where an engagement would put such data within reach we expect the client to say so before access is agreed, we restrict access further, and we prefer to work on data with those fields removed.

13. Children

This site and the company's services are directed at businesses and at adults acting professionally. We do not knowingly collect data from children, do not offer an information society service directly to a child and do not rely on the Article 8 conditions for a child's consent. If you believe a child has sent personal data to an address on this site, write to the privacy address and it will be deleted. The ICO's Age Appropriate Design Code is used as a design reference for any future service a person under eighteen could foreseeably reach, even where it does not strictly apply.

14. Recipients and sub-processors

Personal data is not sold, rented or shared for anyone else's marketing, and is disclosed to no advertising network, data broker or analytics company, because the company uses none. Everyone who receives personal data is listed below.

Recipients and sub-processors as at 7 August 2026
OrganisationFunctionData reachedLocationTransfer basis
Cloudflare, Inc. Website hosting, content delivery and edge security Connection and request data in inventory 4.1 Global edge network, including servers outside the United Kingdom Standard contractual clauses with the UK Addendum, and the UK Extension to the EU to US Data Privacy Framework where applicable. Section 15.
Google LLC Delivery of web font files your browser requests from fonts.googleapis.com and fonts.gstatic.com Your IP address and user agent at the moment of the font request. Nothing returns to us. United States and Google's global infrastructure Google is a separate controller for that request. The UK Extension to the Data Privacy Framework and standard contractual clauses apply between Google and its customers.
Email provider Mail hosting and delivery for this domain All correspondence in inventory 5.1 [TO CONFIRM: hosting region] [TO CONFIRM: provider identity and the transfer mechanism in its processing terms]
Accounting provider Bookkeeping, statutory accounts, tax filing Billing records in inventory 6.1 and supplier records in 7.1 [TO CONFIRM: identity and location of the accountant engaged] Recorded here once appointed
HM Revenue and Customs Statutory tax filings Whatever a filing requires United Kingdom Not a transfer
Companies House Statutory company filings Officer and person with significant control details, which the registrar publishes United Kingdom Not a transfer
Professional advisers Legal, accounting or insurance advice on a specific matter Only what the matter requires, case by case United Kingdom unless stated at the time Not a transfer where the adviser is in the United Kingdom

We also disclose data where required by law, court order or a regulator acting within its powers, and tell you where we are permitted to. A request appearing to exceed the requester's powers is challenged rather than met by default.

For processor engagements, any addition or replacement of a sub-processor is notified at least 30 days in advance with a right to object. If an objection cannot be resolved, the client may terminate the affected part of the engagement without penalty.

15. International transfers

Some processing happens outside the United Kingdom, because the hosting and font providers operate global infrastructure. Chapter V permits a restricted transfer only on one of the following grounds.

UK adequacy

The Secretary of State may make adequacy regulations under Article 45 finding that a country ensures an adequate level of protection. Such regulations cover the European Economic Area and the other countries and territories the United Kingdom has recognised. For the United States the equivalent is the UK Extension to the EU to US Data Privacy Framework, which permits transfers to organisations certified under it and listed on the framework list. Where an adequacy finding is current at the time of transfer, no further safeguard is required.

The IDTA

Where adequacy does not apply, we use the International Data Transfer Agreement issued by the Information Commissioner under section 119A of the Data Protection Act 2018 and laid before Parliament. The IDTA is a standalone UK contract and is our preferred instrument for a new direct arrangement with a supplier outside the United Kingdom.

The UK Addendum to the EU SCCs

Many international suppliers publish processing terms built on the European Commission's standard contractual clauses. We then rely on the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, the UK Addendum, which adapts those clauses to work under UK law. In practice this is the mechanism applying to the large providers in section 14, because it is the form in which their terms are offered.

Transfer risk assessment and supplementary measures

Before relying on the IDTA or the UK Addendum we consider whether the destination country's law and practice would undermine the protection in fact, taking account of the nature of the data and the likelihood of public authority access. The transfers here are limited to connection metadata and business correspondence, which is recorded as a low risk assessment rather than left implied. We prefer providers offering encryption in transit and at rest, region pinning where available, and published transparency reporting, and select a United Kingdom or European Economic Area region where one is offered without material disadvantage.

You may ask for details of the safeguard relied on for a particular transfer at the privacy address. We will describe it and provide a copy of the relevant clauses where permitted, with commercial terms redacted.

16. Retention

Periods are stated in each inventory and consolidated below with the reason for each, because a retention schedule without reasons is a list of numbers somebody invented.

Retention schedule with reasons
RecordPeriodReason
Website request logsHost's short rolling window, daysUseful only for immediate security and diagnostics. We hold no copy.
General correspondence24 months from the last messageLong enough for a conversation to resume, short enough that stale contact data does not accumulate.
Data protection requests3 years from closureArticle 5(2) requires us to demonstrate compliance, and the ICO may consider a complaint well after the event.
Security reports3 years from closureA recurrence of a reported issue must be recognisable as a recurrence.
Accounting records6 years from the end of the accounting periodSection 388 of the Companies Act 2006 requires a private company to preserve accounting records for three years, and HMRC requires records supporting a company tax return for six years. Six years is applied as the single controlling figure.
Contracts and engagement records6 years after the engagement endsSection 5 of the Limitation Act 1980 gives six years for an action on a simple contract.
Client contact recordsEngagement plus 6 yearsKept with the contract file they relate to, for the same reason.
Supplier due diligenceRelationship plus 3 yearsEnough to evidence the Article 28(1) assessment made at appointment.
Unsuccessful applications12 months from the decisionCovers the time limits for a claim arising from a recruitment decision, with a margin, and no longer.
Personnel and payroll6 years after employment endsAligns with payroll, tax and accounting duties.
Client data held as processorThe period the client instructsIt is not our data. Deletion or return happens under the Article 28(3)(g) term with written confirmation.
BackupsUntil the provider's cycle overwrites themDeleted data can persist in a backup. Restoring a backup to remove one record risks more harm than it prevents, so the record is suppressed on restore. The residual window is disclosed rather than denied.

At the end of a period records are deleted or anonymised. Anonymisation means the individual can no longer be identified by us or anyone else using means reasonably likely to be used. Where that cannot be achieved, the record is deleted rather than described as anonymised.

17. Security, and what we do not claim

Article 32 requires measures appropriate to the risk. In place: HTTPS only with HTTP Strict Transport Security, a restrictive Content Security Policy, and the X-Content-Type-Options, X-Frame-Options and Referrer-Policy headers set at the edge; a static site with no database, no server side application code, no login and no upload, which removes rather than defends against the commonest web vulnerabilities; multi-factor authentication on company accounts where the provider supports it; client data kept in the environment agreed with the client rather than moved into company systems for convenience; full disk encryption and screen lock on devices; and named, time bound, revoked access to client systems as described in section 9.

Deliberately not claimed

The company is not certified to ISO 27001, holds no SOC 2 Type I or Type II report, and is not Cyber Essentials or Cyber Essentials Plus certified. No certification body has assessed it against any standard. This appears here because a privacy notice is exactly where a reader looks for such a claim, and its absence should be explicit rather than inferred from silence. Where a client requires a certification, it would have to be obtained first with timing agreed in writing.

No measure is perfect and this notice does not suggest otherwise. Transmission over the internet carries inherent risk, and email in particular is not a confidential channel.

18. Personal data breaches

A personal data breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

As controller: the ICO, Article 33

A breach affecting data we control is assessed for risk to the rights and freedoms of the individuals concerned. Unless it is unlikely to result in such a risk, it is notified to the Information Commissioner without undue delay and, where feasible, within 72 hours of the company becoming aware of it. A notification later than 72 hours includes the reasons for the delay. Where the full picture is not available in that window, information is given in phases rather than held back until complete. The notification describes the nature of the breach, the categories and approximate numbers of individuals and records affected, the contact point, the likely consequences, and the measures taken or proposed.

As controller: individuals, Article 34

Where a breach is likely to result in a high risk to individuals, they are told without undue delay in clear and plain language, covering the nature of the breach, the contact point, the likely consequences and the measures taken. Communication is not required where the data was rendered unintelligible to unauthorised parties, for example by strong encryption; where later measures have removed the high risk; or where individual communication would involve disproportionate effort, in which case a public communication is made instead.

As processor: Article 33(2)

Where a breach affects client data we hold as processor, the client is notified without undue delay after we become aware, with the information available and the rest to follow. Whether to notify the ICO and the individuals is the controller's decision, not ours, and we neither make it for them nor delay it while our own investigation finishes.

Internal record

All breaches are recorded internally, including those assessed as not notifiable, with the facts, effects and remedial action, as Article 33(5) requires. That record is what allows the assessment to be reviewed later by the ICO or a client's auditor.

19. Your rights, one by one

These apply where we are controller. Where we are processor, see sections 8 and 11: the request goes to the controller and we assist.

How to exercise any right

Write to [email protected], or by post to 66 Paul Street, London, England, EC2A 4NA. Name the right or simply describe what you want; we will work out which right applies rather than refusing a request for using the wrong word. No form, no fee.

Verifying who you are

Where we have reasonable doubts about identity, Article 12(6) permits us to ask for the information needed to confirm it, which usually means replying from the email address already associated with the data. Identity documents are requested only where the request concerns sensitive material and no lighter method will do, and are deleted once identity is confirmed. The one month period does not begin until identity is established.

Timing

We respond without undue delay and within one month of receipt. Where a request is complex, or several have come from the same person, that may be extended by up to two further months under Article 12(3). If we extend, we tell you within the first month and explain why.

19.1 To be informed, Articles 13 and 14

You are entitled to know what is done with your data; this notice is how that is met. If something is unclear or incomplete, say so and we will answer and, where the notice is at fault, amend it.

19.2 Access, Article 15

You may ask whether we process your data and receive a copy with the supplementary information in Article 15(1): purposes, categories, recipients, retention, your other rights and the source where it was not collected from you. The first copy is free; a reasonable fee based on administrative cost may apply to further copies or to a manifestly unfounded or excessive request. Where the data includes information about another person, we provide what we can while protecting their rights, which may mean redaction.

19.3 Rectification, Article 16

You may have inaccurate data corrected and incomplete data completed, including by a supplementary statement. Where the data is an opinion, such as an interview note, the record can be annotated to show you disagree even where the opinion stands. Where data has been disclosed to a recipient we tell them about the correction unless it proves impossible or involves disproportionate effort, under Article 19.

19.4 Erasure, Article 17

You may ask for deletion where the data is no longer necessary, where consent is withdrawn and no other basis applies, where you object under Article 21(1) with no overriding ground, where processing is unlawful, or where deletion is required by law. It does not apply where processing is necessary for a legal obligation or for the establishment, exercise or defence of legal claims. In practice, accounting records inside the six year statutory period will not be deleted on request, and we will say so and identify the record.

19.5 Restriction, Article 18

You may ask us to keep data but stop using it: while we verify accuracy you contest, where processing is unlawful but you prefer restriction to erasure, where we no longer need it but you need it for legal claims, or while we consider an objection. While restricted we store it and do nothing else except with your consent or for legal claims, and we tell you before restriction is lifted.

19.6 Portability, Article 20

Where processing rests on consent or contract and is automated, you may receive the data you provided in a structured, commonly used, machine readable format and ask us to transmit it to another controller where technically feasible. It does not apply to data processed on legitimate interests, which covers most of this notice, and we will tell you if that is why a request cannot be met in that form.

19.7 Objection, Article 21

You may object at any time to processing based on legitimate interests, on grounds relating to your particular situation. We then stop unless we can demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or the processing is for legal claims. For direct marketing there is no balancing exercise: we stop immediately and permanently.

19.8 Automated decisions, Article 22

You have the right not to be subject to a decision based solely on automated processing, including profiling, producing legal or similarly significant effects. As section 20 states, we make no such decisions.

19.9 Withdrawing consent, Article 7(3)

Where processing rests on consent you may withdraw it at any time, as easily as it was given. Withdrawal does not affect processing carried out before it. We rely on consent in very few places, and the withdrawal mechanism is stated wherever consent is sought.

19.10 Complaint, Article 77

You may complain to the Information Commissioner's Office, detailed in section 22. You need not raise it with us first, though we would rather have the chance to put something right.

When we may refuse

A request may be refused, or a reasonable fee charged, where it is manifestly unfounded or excessive, in particular by being repetitive, under Article 12(5). A refusal is never silent: within one month we tell you, explain the reason, and set out your right to complain to the ICO and to seek a judicial remedy. A request may also be met in part where full compliance would disclose another person's data, or where an exemption in Schedule 2 of the Data Protection Act 2018 applies, such as legal professional privilege or the prevention of crime. Where an exemption is applied, we identify which one.

20. Automated decisions

The company makes no decisions about individuals based solely on automated processing that produce legal or similarly significant effects within Article 22. There is no credit scoring, automated eligibility decision, automated hiring screen or behavioural profiling of visitors.

Software built for a client may contain automated logic, including matching and exception rules in a reconciliation system. Where that logic could produce a decision engaging Article 22, the client as controller is responsible for the assessment, the safeguards including human intervention, and the explanation given to those affected. Our contribution is to build the logic so that its reasoning can be explained at all, which is a design requirement rather than a favour.

21. Marketing

The company runs no marketing list, newsletter or advertising, and there is no subscription form on this site because there is nothing to subscribe to.

If that changes, marketing email will be sent only with consent under Regulation 22 of PECR, or under the limited soft opt in where details were obtained during a sale or negotiations for a similar product and an easy means of refusal was offered at collection and in every message. Every message will identify the sender and carry a working unsubscribe route. Corporate subscribers are treated with the same care even where PECR permits less, because the person reading the message is a person either way. The company does not buy contact lists or use broker data.

22. Complaints and the ICO

If you are unhappy with how your data has been handled, write to [email protected]. You will get an acknowledgement within three working days and a substantive answer within one month. You may complain to the supervisory authority at any time, whether or not you raise it with us first.

Authority
Information Commissioner's Office
Address
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline
0303 123 1113

You also have the right to an effective judicial remedy under Article 79 and to compensation for material or non-material damage under Article 82.

23. Mobile applications Controller

The company publishes no mobile application on the App Store, on Google Play or anywhere else. There is nothing to download, no account to create and no application data being processed today.

Sections 24 to 27 are therefore not a description of an operating product. They are the published standard any application released by this company will be built and operated to, written now so that it constrains the build rather than being drafted afterwards to describe whatever was built. On release, this notice is reissued with a new version and date, and these sections change from a commitment into a statement of fact. They exist because these are the points where mobile applications most often go wrong: permissions requested speculatively, identifiers shared with advertising networks, deletion offered nowhere but by email, and a store declaration that does not match the privacy notice.

24. Application permissions

The rule committed to is that a permission is requested at the moment it is needed for a feature the user chose to use, never as a block at first launch, and never as a condition of unrelated functionality.

Permission position for any application published by the company
PermissionPurposeRequired or optionalIf you declineHow to revoke
Camera Only to capture a document or code the user chose to scan. Never background capture. Optional The scanning feature is unavailable; manual entry is offered instead. Nothing else changes. iOS: Settings, the app, Camera. Android: Settings, Apps, the app, Permissions, Camera.
Photo library Only to attach a file the user selects, using the limited selection interface where the platform offers one. Optional Attachment from the library is unavailable. iOS: Settings, the app, Photos. Android: Settings, Apps, the app, Permissions, Photos and videos.
Notifications Operational alerts the user asked for, such as completion of a job they started. Optional No push notifications. The same information stays visible in the app. iOS: Settings, Notifications, the app. Android: Settings, Notifications, App notifications, the app.
Location Not requested. No anticipated feature needs device location. Not requested Not applicable. Not applicable.
Contacts Not requested. We will not ask for the address book or design a feature that needs it. Not requested Not applicable. Not applicable.
Microphone Not requested. Not requested Not applicable. Not applicable.
Biometric unlock Local unlock if the user turns it on. The biometric never leaves the device; the platform returns only success or failure. Optional The app unlocks with the ordinary sign in method. Turn it off in the app's own settings, or remove the permission in system settings.
Background refresh Keeping data current between sessions where enabled. Optional Data refreshes when the app is opened instead. iOS: Settings, General, Background App Refresh. Android: Settings, Apps, the app, Mobile data, Background data.
App Tracking Transparency Not requested, because we do not track across other companies' apps or sites. Section 25. Not requested Not applicable. No prompt is shown. Not applicable.

Revoking a permission never deletes an account or data already processed. To delete data, use section 27.

25. Identifiers and App Tracking Transparency

The ATT position

Apple's App Tracking Transparency framework requires permission before tracking a user across apps and websites owned by other companies, or accessing the device advertising identifier, the IDFA. The company does not carry out such tracking, does not access the IDFA, and will therefore not display the tracking prompt. Where no prompt appears in an application published by this company, the reason is that there is nothing to ask permission for, not that permission has been assumed.

Advertising, analytics and identifiers

No advertising software development kit will be embedded, no attribution or install measurement network integrated, and no data shared with a data broker. No user level data will be sold, in the broad sense that includes disclosure for any consideration, not only money. Where product analytics is genuinely needed to fix crashes, the commitment is aggregate event counts rather than individual behavioural profiles, no third party advertising identifier, retention in months rather than years, and disclosure here with the provider named in section 14 before it is switched on. Any analytics relying on consent would seek it in the application with a genuine option to decline and no loss of core functionality for declining. Any identifier keeping a user signed in will be generated by the application for that purpose, scoped to it, reset on reinstall or sign out, and not linked to any cross company identifier.

26. Google Play Data Safety

Google Play requires a Data Safety declaration describing what an application collects and shares, whether it is encrypted in transit, and whether users can request deletion. Apple requires equivalent privacy nutrition labels. The company commits that the declaration on either store will match this notice section by section, and that where they would disagree the release does not ship until they agree. Specifically:

  • Every data type declared as collected on a store listing will appear in an inventory here, with a purpose and a lawful basis.
  • No data type will be declared as not collected on a listing while appearing in an inventory here.
  • The declaration that data is encrypted in transit will be true of every network call the application makes, with no exception for a diagnostic endpoint.
  • The declaration that users can request deletion will point at the route in section 27, which will exist and work when the listing goes live.
  • Where a store category has no clean answer, the more protective description is selected rather than the more flattering one.

A store declaration is a public statement about processing. Treating it as a marketing field is how applications end up contradicting their own privacy notice.

27. Account and data deletion

No application exists, so there is no account to delete today. The commitment below applies to any account created in an application or service published by this company.

In-app route

Deletion will be available inside the application, no more than three taps from the main settings screen, under a heading that says delete account rather than something softer. The screen states what is deleted, what is retained and why, and takes one confirmation. It will not require contacting support, completing a form, waiting for a call back or explaining why you are leaving.

Email route and timing

Deletion may also be requested from [email protected] using the address associated with the account, or by post to the registered office. Identity is verified as in section 19 first, because deleting the wrong person's data is itself a breach. Deletion completes within 30 days of a verified request. The account is disabled immediately so it cannot be used while deletion is processed, and written confirmation follows on completion.

Retained after deletion

Retained after account deletion
ItemPeriodReason
Transaction and billing records6 years from the end of the accounting periodCompanies Act 2006 and HMRC record keeping duties. This cannot be waived on request.
A record that deletion occurred3 yearsSo the request can be evidenced if you or the ICO later ask whether it was honoured. It holds the fact and the date, not the deleted content.
Data in backupsUntil the cycle overwrites itRestoring a full backup to remove one record is disproportionate. The record is suppressed on any restore so it does not return to live use.
Data needed for a legal claimUntil the claim ends and the limitation period expiresArticle 17(3)(e) permits retention for legal claims. If this applies, you are told which records are affected.

Everything not listed is deleted. Deleting an account does not cancel a subscription billed by an app store; those mechanics are in the terms of use and must be completed separately.

28. Changes to this notice

This is version 1.0, effective 7 August 2026. When it changes, the version and date at the top change with it. Material changes, meaning a new purpose, lawful basis, category of recipient or a longer retention period, are notified directly to affected individuals where we hold a contact route, and always take effect prospectively. Superseded versions are retained so the position applying at a past date can be established; ask at the privacy address.

Items marked [TO CONFIRM] are genuine gaps, not drafting placeholders. They are visible so a reader can see which facts are unsettled, and they will be replaced with the answer rather than quietly removed.

29. Contact summary

Data protection
[email protected]
Security reports
[email protected]
Post
THE TWENTY FINTECH LTD, 66 Paul Street, London, England, EC2A 4NA
Supervisory authority
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, telephone 0303 123 1113

Back to contents