Skip to main content

Data residency and international transfers

Twenty Cloud runs on AWS servers located in Frankfurt, Germany.
Hosting region selection will be available starting in 2027, initially for new workspaces. Users will be able to request a region change for an existing workspace at a later date. Alternatively, you can reach out to our Partners to help you set up your instance.
A list of all sub-processors is available in our Trust Center.
EU Standard Contractual Clauses, together with the UK Addendum and Swiss amendments, apply to international transfers of data outside the EU, including transfers to all sub-processors.
You can generate your signed DPA at https:///settings/legal/dpa (e.g. https://getting-started.twenty.com/settings/legal/dpa).
As per our Privacy Policy, Twenty acts as the data processor for merchant and contact information stored in the CRM, while your company remains the data controller.
CRM content can be used to train AI models depending on sub-processors’ Terms and Conditions. Twenty does not have its own AI model — all AI models available on Twenty Cloud are provided by our sub-processors.
AI can be fully disabled by turning off all AI models in Settings → AI → Models. Additionally, no data is sent to AI unless you actively interact with the AI chat or an AI node in a workflow.

Security and access controls

All data is encrypted in transit and at rest. Tenant data is isolated through a schema-per-tenant setup, and encryption keys are periodically rotated.
Twenty’s engineering and support teams may access customer workspaces to investigate and resolve issues. Workspace owners control this: support access can be disabled at any time in Settings → General → Security, and it stays off until you turn it back on.
In the event of a confirmed personal data breach affecting your data, we will notify you without undue delay and in any event within 48 hours of becoming aware of it. Our notification will include, to the extent known at the time: the nature of the breach, the categories and approximate volume of data and individuals affected, likely consequences, and the remediation and mitigation measures taken or planned. We will provide updates as the investigation progresses.

Data retention and deletion

When a record is deleted, it is first soft-deleted and can still be restored. It is permanently deleted and removed from active systems once the retention period elapses or a user manually destroys it.
By default, soft-deleted records are kept for 14 days, after which they are permanently removed from the system. The retention period for soft-deleted records can be changed in Settings → General → Security.
A removed record remains in backups for 30 days, after which it is permanently deleted.
When a workspace is deleted, its data is removed from live systems within approximately 90 days of service termination, and usually much sooner. Back-up and archival copies are then overwritten or purged within a further 90 days, after which all data is permanently deleted. Throughout both periods the data is isolated from any operational use. On request, we can provide written certification once the purge is complete. See clause 4.9 of your Data Processing Agreement for the full terms.
Yes, during any backup-retention period, deleted data is isolated from operational use.
We acknowledge erasure requests and provide written confirmation once deletion is complete.

Backups and resilience

Backups are created continuously with snapshots taken daily, and the retention period is 30 days.
RTO and RPO are both 6 hours (as per our DPA).
To request a restoration, please reach out to our team via support chat or mail to contact@twenty.com.
All backups are encrypted and stored in geographically separate locations within the same jurisdiction (e.g. within EU for EU data).

Compliance

Yes, Twenty is GDPR compliant.
Yes, Twenty is SOC 2 compliant.
No, Twenty is in the process of becoming HIPAA compliant.

Licensing

No. Running a modified version for your own team is not distribution, so no publication obligation arises. The AGPL’s network clause applies when people outside your organization interact with your modified instance over the network.
No. Your front end is your own, separate work, and talking to Twenty through its APIs does not change that. Since Twenty itself is unmodified, there is nothing to publish.
Yes, since you’re modifying code to distribute it to others, you’re required to publish those changes. If you don’t want to publish your changes, you can obtain Organization license.
If you have more questions, please check our Terms and Conditions, Privacy Policy and Trust Center. If your questions are still unanswered, send them to contact@twenty.com or via support chat.