Legal document 01 of 03
Privacy notice
This notice is an inventory, not a reassurance. It states what personal data THE TWENTY FINTECH LTD holds, where it came from, why, on what lawful basis with the article cited, for how long, and who else sees it. Where the company acts as processor rather than controller, the section says so. Where something has not happened yet, it says that too.
1. Scope and how to read this
This notice covers personal data processed by THE TWENTY FINTECH LTD ("the company", "we") through this website, correspondence to any address on it, the company's commercial and administrative activities, and any software it publishes in future. It is written under the UK GDPR as retained in the law of England and Wales, and the Data Protection Act 2018. Article numbers are UK GDPR articles. PECR means the Privacy and Electronic Communications Regulations 2003.
The notice is organised as inventories. Each covers one group of people and states, in a table, the data held, example fields, source, purpose, lawful basis with the article cited, retention and recipients. To learn only what happens to your own data, read the inventory that describes you with sections 14 to 19.
Each section is marked with the role we hold. Controller means we decide why and how data is processed. Processor means we act only on another organisation's documented instructions, and that organisation is the controller.
The company was incorporated on 1 March 2026, has delivered no client engagement and published no software. Sections describing processing that has not begun say so, and state a committed position rather than an existing practice.
2. Who we are Controller
- Controller
- THE TWENTY FINTECH LTD
- Company number
- 17061506
- Registered in
- England and Wales
- Registered office
- 66 Paul Street, London, England, EC2A 4NA
- Privacy contact
- privacy@thetwentyfintech.co.uk
- ICO fee registration
- [TO CONFIRM: whether the ICO data protection fee is payable and the registration reference]
Data protection officer
None appointed. Article 37 requires one for public authorities, for core activities requiring large scale regular and systematic monitoring, or for large scale processing of special category or criminal offence data. None applies here. The position will be reassessed if processing changes, and this notice reissued.
No individual is named as a contact on this site. Officer details are held on the public Companies House record for company number 17061506.
Representative
The company is established in the United Kingdom and does not offer goods or services to, or monitor, individuals in the European Economic Area in a way that engages Article 27 of the EU GDPR. No EU representative is appointed.
3. Controller or processor
The company expects to hold both roles at once, for different data. Confusing them is the commonest defect in a supplier privacy notice, so the split is stated here.
| Activity | Role | In practice |
|---|---|---|
| Running this website | Controller | We decide what the site collects, which is the request data our host records. Section 4. |
| Handling your email | Controller | We decide how enquiries are stored, read and deleted. Section 5. |
| Client administration | Controller | Contacts, contracts, invoices, accounting record. Section 6. |
| Suppliers, applicants, staff | Controller | Records we must or choose to keep. Section 7. |
| Building on a client's data | Processor | The client decides why and how; we act on documented instructions under an Article 28 agreement. Sections 8 to 11. |
| Support access to a client system | Processor | Anything seen belongs to the client and is not retained beyond the task. Section 9. |
| Any application we publish | Controller | Applies if and when we publish one. Sections 23 to 27. |
Where we are a processor, the client's privacy notice governs the relationship with the individuals concerned. Section 11 explains what that means for you.
4. Inventory: website visitors Controller
This site is static files served from Cloudflare Pages. It runs no analytics, tag manager, advertising pixel, session recorder, chat widget or embedded media, and sets no cookies of its own. The cookie notice gives the full position. What remains is the data inherent in making an HTTP request, which no website can avoid.
| Category | Example fields | Source | Purpose | Lawful basis | Retention | Recipients |
|---|---|---|---|---|---|---|
| Connection data | IP address, country derived from it, timestamp | Your browser, automatically | Delivering the page; blocking abusive traffic at the edge | Article 6(1)(f). Legitimate interest: keeping the site available and defending it against denial of service and automated abuse. | Held by the host on its own short rolling window, measured in days. We download no copy. | Cloudflare, Inc. |
| Request metadata | URL, HTTP status, user agent, referrer if sent | Your browser, automatically | Diagnosing broken links and server errors | Article 6(1)(f). Legitimate interest: operating and correcting a working website. | As above. Nothing is exported into a company system. | Cloudflare, Inc. |
| Font request data | IP address and user agent sent to Google's font servers | Your browser, when it loads the page | Rendering the site in its intended typefaces | Article 6(1)(f). Legitimate interest: a legible, consistent site. This is a choice we could reverse by self hosting, which is why it is disclosed. | Google's own retention. We receive nothing back. | Google LLC |
Legitimate interests assessment
The interests are availability, correctness and security of a public information site. The data arrives unavoidably with a request, is not combined with any other data set, builds no profile, is not used for advertising and is not sold. A visitor would reasonably expect a server to log a request. The balance therefore favours the processing and the impact is low. You may object under Article 21 using the route in section 19.
5. Inventory: enquirers Controller
There is no form on this site. Everything below arrives because someone chose to email an address on the contact page, or replied to us.
| Category | Example fields | Source | Purpose | Lawful basis | Retention | Recipients |
|---|---|---|---|---|---|---|
| Identity and contact | Name, email, organisation, job title, telephone if given | You, directly | Replying and knowing who we are speaking to | Article 6(1)(b) for steps prior to a contract; otherwise Article 6(1)(f), legitimate interest in answering correspondence addressed to the company | 24 months from the last message, unless it becomes a client or supplier record | Our email host |
| Message content | Your text, subject line, headers, any attachment | You, directly | Answering the enquiry; evidencing what was said if a dispute follows | Article 6(1)(f). Legitimate interest: evidencing the substance and timing of business correspondence. | 24 months from the last message | Our email host |
| Data protection requests | Your request, identity evidence, our response and reasoning | You, directly | Handling the request and showing it was handled correctly | Article 6(1)(c), legal obligation, read with Articles 12 to 22 | 3 years from closure, so handling can be evidenced to the ICO | Our email host; the ICO on a complaint |
| Security reports | Report, reproduction steps, reporter contact, remediation notes | You, directly | Investigating and fixing a reported vulnerability | Article 6(1)(f). Legitimate interest: the security of the company's systems. | 3 years from closure | Our email host |
Please do not send personal data, cardholder data, credentials or production extracts by email. Email is not a confidential channel. Material of that kind received unsolicited is deleted, a short note that it arrived and was deleted is kept, and the sender is told.
Mail for this domain is handled by a third party provider acting as processor. [TO CONFIRM: identity, corporate entity and hosting region of the email provider] It will be named in section 14 once confirmed.
6. Inventory: clients and their staff Controller
These are the records needed to have a client relationship at all. Personal data inside a client's own systems is covered by sections 8 to 11, where we are processor. No engagement has yet been delivered; the inventory states the record set that will be kept when one is.
| Category | Example fields | Source | Purpose | Lawful basis | Retention | Recipients |
|---|---|---|---|---|---|---|
| Client contacts | Name, work email and telephone, job title, employer, role | The client organisation or the individual | Performing and communicating about the engagement | Article 6(1)(b) where the individual contracts; Article 6(1)(f) where their employer does, the interest being administering a business relationship | Engagement plus 6 years, matching the Limitation Act 1980 period | Accounting provider; advisers on a dispute |
| Contract documents | Engagement letter, statement of work, DPA, signatory and date | Both parties | Recording what was agreed, by whom, when | Article 6(1)(b), and Article 6(1)(f) for the evidential record | 6 years after the engagement ends | Advisers on a dispute; auditors if applicable |
| Billing records | Invoice, purchase order reference, payment and remittance detail | The client and our bank | Getting paid; keeping the accounting records required by law | Article 6(1)(c), legal obligation under the Companies Act 2006 and HMRC requirements | 6 years from the end of the accounting period | Accounting provider; HMRC; our bank |
| Engagement correspondence | Emails, meeting notes, decisions, issues raised and closed | Both parties | Delivering the work; explaining a decision later | Article 6(1)(b) and 6(1)(f). The interest is reconstructing technical reasoning after the people involved have moved on. | 6 years after the engagement ends | Our email host; advisers on a dispute |
| Supplier onboarding | Security questionnaire answers, insurance evidence, company identifiers, named signatories | Both parties | Satisfying a client's third party risk process | Article 6(1)(b) and 6(1)(f), the interest being consistency between answers given to different clients | 6 years after the relationship ends | The client only |
7. Inventory: suppliers and applicants Controller
The company has no employees and has run no recruitment process. The rows state the position when it does.
| Category | Example fields | Source | Purpose | Lawful basis | Retention | Recipients |
|---|---|---|---|---|---|---|
| Supplier contacts | Name, work email, telephone, role | The supplier or the individual | Buying and administering services we use | Article 6(1)(f). Legitimate interest: administering our own supply chain. | Relationship plus 6 years | Accounting provider |
| Supplier due diligence | Security and privacy assessments, sub-processor terms, transfer mechanisms | The supplier and public sources | Meeting the Article 28(1) duty to use only processors giving sufficient guarantees | Article 6(1)(c), read with Article 28 | Relationship plus 3 years | Clients on request, where the supplier is a sub-processor on their engagement |
| Job applicants | Name, contact details, curriculum vitae, covering message, interview notes, right to work check at offer | The applicant or a recruiter acting for them | Assessing an application; running a fair selection process | Article 6(1)(b) for steps prior to an employment contract; Article 6(1)(f) for interview notes, the interest being a defensible decision | 12 months from the decision, then deletion. Longer only with consent under Article 6(1)(a). | A recruiter where one is involved in that process |
| Personnel records | Contract, payroll reference, statutory deductions, absence | The individual and payroll processing | Employing someone lawfully and paying them correctly | Articles 6(1)(b) and 6(1)(c), with Article 9(2)(b) for health data processed for employment law purposes | 6 years after employment ends | Payroll and accounting providers; HMRC; pension provider |
8. When we act as your processor Processor
Where the company builds, tests, reviews or operates software handling a client's records, the client is controller of any personal data in them and we are processor. That is governed by a written agreement meeting Article 28(3), signed before access is granted. There is no scenario in which we take such access on a handshake.
- We process only on the client's documented instructions, including on any transfer to a third country, unless required otherwise by law. If we are, we tell the client first unless the law prohibits it.
- We do not decide the purposes. We cannot agree a new use because it looks useful, and will not do so at a third party's request.
- We do not use client data to improve our products, train any model, produce benchmarks or build aggregated data sets. That would need a separate written instruction, and none exists.
- We tell the client without undue delay if an instruction appears to infringe data protection law.
If you are an individual whose data we hold as processor, we cannot act on your request ourselves. We notify the controller without undue delay, assist them, and tell you we have done so and who they are where we may.
9. Client data our work may reach Processor
Ledger and reconciliation work involves reading real records, because the defects that matter live in the records rather than the specification. Access is bounded by rules written into the engagement agreement rather than left as good intentions.
Minimisation before access
The default request is reduced, pseudonymised or synthetic data. A reconciliation defect can usually be reproduced from references, amounts, dates and status codes without names or account identifiers. Where identifying fields are genuinely needed, the request states which and why.
Named, time bound, logged
Where live access is unavoidable it is granted to a named individual for a stated period on client issued credentials, and revoked at the end of the task. We ask the client to log it on their side, because a supplier's log of its own access is worth much less than the controller's.
Nothing taken away
Extracts are not copied to personal devices, not retained after the task, and not moved outside the agreed arrangements. Working notes quoting a record are treated as client data and deleted with it. A screenshot in a ticket, a stack trace containing a record fragment and a log line quoting a payment reference are all client data, retained only for the life of the ticket plus the period the client specifies, and never moved into a general knowledge base.
10. Article 28 commitments Processor
| Requirement | Our position |
|---|---|
| 28(3)(a) Instructions | Processing only on documented instructions, defined in the agreement, changed only in writing. |
| 28(3)(b) Confidentiality | Anyone authorised is bound by a written confidentiality obligation surviving the engagement. |
| 28(3)(c) Security | Measures appropriate to the risk under Article 32, described in the agreement, with the limits stated in section 17. |
| 28(3)(d) Sub-processors | None engaged without prior written authorisation. Under general authorisation, at least 30 days notice of any addition or replacement, with a right to object. |
| 28(3)(e) Rights | Assistance with Articles 15 to 22 by appropriate technical and organisational measures. |
| 28(3)(f) Articles 32 to 36 | Assistance with security, breach notification, impact assessments and prior consultation. |
| 28(3)(g) Deletion or return | At the client's choice, deletion or return of all personal data at the end, with written confirmation, unless retention is required by law. |
| 28(3)(h) Audit | Information made available to demonstrate compliance, and audits by the client or their mandated auditor on reasonable notice. |
11. If your employer is our client Processor
You may be reading this because an organisation you deal with has engaged us and your data sits in a system we work on. In that case:
- That organisation is the controller. Its privacy notice, not this one, describes why your data is processed and on what basis.
- We hold your data only to carry out the task it instructed, with no independent purpose of our own.
- Requests under Articles 15 to 22 should go to that organisation. If you send one to us we pass it on without undue delay, assist, and tell you we have done so. We will not action it ourselves.
- If we become aware of a breach affecting your data we notify the controller without undue delay under Article 33(2). Notifying the ICO and you is then their decision and duty.
If you do not know which organisation instructed us, write to the privacy address describing the context, and we will tell you where we may.
12. Special category data
As controller, the company does not seek Article 9 special category data. The only foreseeable case is health information about an employee under Article 9(2)(b) for employment law purposes, and no such record exists. The company does not carry out criminal record checks and processes no Article 10 criminal offence data.
As processor, a client system may contain special category data. The lawful basis under Article 9(2) is the controller's determination, not ours. Where an engagement would put such data within reach we expect the client to say so before access is agreed, we restrict access further, and we prefer to work on data with those fields removed.
13. Children
This site and the company's services are directed at businesses and at adults acting professionally. We do not knowingly collect data from children, do not offer an information society service directly to a child and do not rely on the Article 8 conditions for a child's consent. If you believe a child has sent personal data to an address on this site, write to the privacy address and it will be deleted. The ICO's Age Appropriate Design Code is used as a design reference for any future service a person under eighteen could foreseeably reach, even where it does not strictly apply.
14. Recipients and sub-processors
Personal data is not sold, rented or shared for anyone else's marketing, and is disclosed to no advertising network, data broker or analytics company, because the company uses none. Everyone who receives personal data is listed below.
| Organisation | Function | Data reached | Location | Transfer basis |
|---|---|---|---|---|
| Cloudflare, Inc. | Website hosting, content delivery and edge security | Connection and request data in inventory 4.1 | Global edge network, including servers outside the United Kingdom | Standard contractual clauses with the UK Addendum, and the UK Extension to the EU to US Data Privacy Framework where applicable. Section 15. |
| Google LLC | Delivery of web font files your browser requests from fonts.googleapis.com and fonts.gstatic.com | Your IP address and user agent at the moment of the font request. Nothing returns to us. | United States and Google's global infrastructure | Google is a separate controller for that request. The UK Extension to the Data Privacy Framework and standard contractual clauses apply between Google and its customers. |
| Email provider | Mail hosting and delivery for this domain | All correspondence in inventory 5.1 | [TO CONFIRM: hosting region] | [TO CONFIRM: provider identity and the transfer mechanism in its processing terms] |
| Accounting provider | Bookkeeping, statutory accounts, tax filing | Billing records in inventory 6.1 and supplier records in 7.1 | [TO CONFIRM: identity and location of the accountant engaged] | Recorded here once appointed |
| HM Revenue and Customs | Statutory tax filings | Whatever a filing requires | United Kingdom | Not a transfer |
| Companies House | Statutory company filings | Officer and person with significant control details, which the registrar publishes | United Kingdom | Not a transfer |
| Professional advisers | Legal, accounting or insurance advice on a specific matter | Only what the matter requires, case by case | United Kingdom unless stated at the time | Not a transfer where the adviser is in the United Kingdom |
We also disclose data where required by law, court order or a regulator acting within its powers, and tell you where we are permitted to. A request appearing to exceed the requester's powers is challenged rather than met by default.
For processor engagements, any addition or replacement of a sub-processor is notified at least 30 days in advance with a right to object. If an objection cannot be resolved, the client may terminate the affected part of the engagement without penalty.
15. International transfers
Some processing happens outside the United Kingdom, because the hosting and font providers operate global infrastructure. Chapter V permits a restricted transfer only on one of the following grounds.
UK adequacy
The Secretary of State may make adequacy regulations under Article 45 finding that a country ensures an adequate level of protection. Such regulations cover the European Economic Area and the other countries and territories the United Kingdom has recognised. For the United States the equivalent is the UK Extension to the EU to US Data Privacy Framework, which permits transfers to organisations certified under it and listed on the framework list. Where an adequacy finding is current at the time of transfer, no further safeguard is required.
The IDTA
Where adequacy does not apply, we use the International Data Transfer Agreement issued by the Information Commissioner under section 119A of the Data Protection Act 2018 and laid before Parliament. The IDTA is a standalone UK contract and is our preferred instrument for a new direct arrangement with a supplier outside the United Kingdom.
The UK Addendum to the EU SCCs
Many international suppliers publish processing terms built on the European Commission's standard contractual clauses. We then rely on the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, the UK Addendum, which adapts those clauses to work under UK law. In practice this is the mechanism applying to the large providers in section 14, because it is the form in which their terms are offered.
Transfer risk assessment and supplementary measures
Before relying on the IDTA or the UK Addendum we consider whether the destination country's law and practice would undermine the protection in fact, taking account of the nature of the data and the likelihood of public authority access. The transfers here are limited to connection metadata and business correspondence, which is recorded as a low risk assessment rather than left implied. We prefer providers offering encryption in transit and at rest, region pinning where available, and published transparency reporting, and select a United Kingdom or European Economic Area region where one is offered without material disadvantage.
You may ask for details of the safeguard relied on for a particular transfer at the privacy address. We will describe it and provide a copy of the relevant clauses where permitted, with commercial terms redacted.
16. Retention
Periods are stated in each inventory and consolidated below with the reason for each, because a retention schedule without reasons is a list of numbers somebody invented.
| Record | Period | Reason |
|---|---|---|
| Website request logs | Host's short rolling window, days | Useful only for immediate security and diagnostics. We hold no copy. |
| General correspondence | 24 months from the last message | Long enough for a conversation to resume, short enough that stale contact data does not accumulate. |
| Data protection requests | 3 years from closure | Article 5(2) requires us to demonstrate compliance, and the ICO may consider a complaint well after the event. |
| Security reports | 3 years from closure | A recurrence of a reported issue must be recognisable as a recurrence. |
| Accounting records | 6 years from the end of the accounting period | Section 388 of the Companies Act 2006 requires a private company to preserve accounting records for three years, and HMRC requires records supporting a company tax return for six years. Six years is applied as the single controlling figure. |
| Contracts and engagement records | 6 years after the engagement ends | Section 5 of the Limitation Act 1980 gives six years for an action on a simple contract. |
| Client contact records | Engagement plus 6 years | Kept with the contract file they relate to, for the same reason. |
| Supplier due diligence | Relationship plus 3 years | Enough to evidence the Article 28(1) assessment made at appointment. |
| Unsuccessful applications | 12 months from the decision | Covers the time limits for a claim arising from a recruitment decision, with a margin, and no longer. |
| Personnel and payroll | 6 years after employment ends | Aligns with payroll, tax and accounting duties. |
| Client data held as processor | The period the client instructs | It is not our data. Deletion or return happens under the Article 28(3)(g) term with written confirmation. |
| Backups | Until the provider's cycle overwrites them | Deleted data can persist in a backup. Restoring a backup to remove one record risks more harm than it prevents, so the record is suppressed on restore. The residual window is disclosed rather than denied. |
At the end of a period records are deleted or anonymised. Anonymisation means the individual can no longer be identified by us or anyone else using means reasonably likely to be used. Where that cannot be achieved, the record is deleted rather than described as anonymised.
17. Security, and what we do not claim
Article 32 requires measures appropriate to the risk. In place: HTTPS only with HTTP Strict Transport Security, a restrictive Content Security Policy, and the X-Content-Type-Options, X-Frame-Options and Referrer-Policy headers set at the edge; a static site with no database, no server side application code, no login and no upload, which removes rather than defends against the commonest web vulnerabilities; multi-factor authentication on company accounts where the provider supports it; client data kept in the environment agreed with the client rather than moved into company systems for convenience; full disk encryption and screen lock on devices; and named, time bound, revoked access to client systems as described in section 9.
Deliberately not claimed
The company is not certified to ISO 27001, holds no SOC 2 Type I or Type II report, and is not Cyber Essentials or Cyber Essentials Plus certified. No certification body has assessed it against any standard. This appears here because a privacy notice is exactly where a reader looks for such a claim, and its absence should be explicit rather than inferred from silence. Where a client requires a certification, it would have to be obtained first with timing agreed in writing.
No measure is perfect and this notice does not suggest otherwise. Transmission over the internet carries inherent risk, and email in particular is not a confidential channel.
18. Personal data breaches
A personal data breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
As controller: the ICO, Article 33
A breach affecting data we control is assessed for risk to the rights and freedoms of the individuals concerned. Unless it is unlikely to result in such a risk, it is notified to the Information Commissioner without undue delay and, where feasible, within 72 hours of the company becoming aware of it. A notification later than 72 hours includes the reasons for the delay. Where the full picture is not available in that window, information is given in phases rather than held back until complete. The notification describes the nature of the breach, the categories and approximate numbers of individuals and records affected, the contact point, the likely consequences, and the measures taken or proposed.
As controller: individuals, Article 34
Where a breach is likely to result in a high risk to individuals, they are told without undue delay in clear and plain language, covering the nature of the breach, the contact point, the likely consequences and the measures taken. Communication is not required where the data was rendered unintelligible to unauthorised parties, for example by strong encryption; where later measures have removed the high risk; or where individual communication would involve disproportionate effort, in which case a public communication is made instead.
As processor: Article 33(2)
Where a breach affects client data we hold as processor, the client is notified without undue delay after we become aware, with the information available and the rest to follow. Whether to notify the ICO and the individuals is the controller's decision, not ours, and we neither make it for them nor delay it while our own investigation finishes.
Internal record
All breaches are recorded internally, including those assessed as not notifiable, with the facts, effects and remedial action, as Article 33(5) requires. That record is what allows the assessment to be reviewed later by the ICO or a client's auditor.
19. Your rights, one by one
These apply where we are controller. Where we are processor, see sections 8 and 11: the request goes to the controller and we assist.
How to exercise any right
Write to privacy@thetwentyfintech.co.uk, or by post to 66 Paul Street, London, England, EC2A 4NA. Name the right or simply describe what you want; we will work out which right applies rather than refusing a request for using the wrong word. No form, no fee.
Verifying who you are
Where we have reasonable doubts about identity, Article 12(6) permits us to ask for the information needed to confirm it, which usually means replying from the email address already associated with the data. Identity documents are requested only where the request concerns sensitive material and no lighter method will do, and are deleted once identity is confirmed. The one month period does not begin until identity is established.
Timing
We respond without undue delay and within one month of receipt. Where a request is complex, or several have come from the same person, that may be extended by up to two further months under Article 12(3). If we extend, we tell you within the first month and explain why.
19.1 To be informed, Articles 13 and 14
You are entitled to know what is done with your data; this notice is how that is met. If something is unclear or incomplete, say so and we will answer and, where the notice is at fault, amend it.
19.2 Access, Article 15
You may ask whether we process your data and receive a copy with the supplementary information in Article 15(1): purposes, categories, recipients, retention, your other rights and the source where it was not collected from you. The first copy is free; a reasonable fee based on administrative cost may apply to further copies or to a manifestly unfounded or excessive request. Where the data includes information about another person, we provide what we can while protecting their rights, which may mean redaction.
19.3 Rectification, Article 16
You may have inaccurate data corrected and incomplete data completed, including by a supplementary statement. Where the data is an opinion, such as an interview note, the record can be annotated to show you disagree even where the opinion stands. Where data has been disclosed to a recipient we tell them about the correction unless it proves impossible or involves disproportionate effort, under Article 19.
19.4 Erasure, Article 17
You may ask for deletion where the data is no longer necessary, where consent is withdrawn and no other basis applies, where you object under Article 21(1) with no overriding ground, where processing is unlawful, or where deletion is required by law. It does not apply where processing is necessary for a legal obligation or for the establishment, exercise or defence of legal claims. In practice, accounting records inside the six year statutory period will not be deleted on request, and we will say so and identify the record.
19.5 Restriction, Article 18
You may ask us to keep data but stop using it: while we verify accuracy you contest, where processing is unlawful but you prefer restriction to erasure, where we no longer need it but you need it for legal claims, or while we consider an objection. While restricted we store it and do nothing else except with your consent or for legal claims, and we tell you before restriction is lifted.
19.6 Portability, Article 20
Where processing rests on consent or contract and is automated, you may receive the data you provided in a structured, commonly used, machine readable format and ask us to transmit it to another controller where technically feasible. It does not apply to data processed on legitimate interests, which covers most of this notice, and we will tell you if that is why a request cannot be met in that form.
19.7 Objection, Article 21
You may object at any time to processing based on legitimate interests, on grounds relating to your particular situation. We then stop unless we can demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or the processing is for legal claims. For direct marketing there is no balancing exercise: we stop immediately and permanently.
19.8 Automated decisions, Article 22
You have the right not to be subject to a decision based solely on automated processing, including profiling, producing legal or similarly significant effects. As section 20 states, we make no such decisions.
19.9 Withdrawing consent, Article 7(3)
Where processing rests on consent you may withdraw it at any time, as easily as it was given. Withdrawal does not affect processing carried out before it. We rely on consent in very few places, and the withdrawal mechanism is stated wherever consent is sought.
19.10 Complaint, Article 77
You may complain to the Information Commissioner's Office, detailed in section 22. You need not raise it with us first, though we would rather have the chance to put something right.
When we may refuse
A request may be refused, or a reasonable fee charged, where it is manifestly unfounded or excessive, in particular by being repetitive, under Article 12(5). A refusal is never silent: within one month we tell you, explain the reason, and set out your right to complain to the ICO and to seek a judicial remedy. A request may also be met in part where full compliance would disclose another person's data, or where an exemption in Schedule 2 of the Data Protection Act 2018 applies, such as legal professional privilege or the prevention of crime. Where an exemption is applied, we identify which one.
20. Automated decisions
The company makes no decisions about individuals based solely on automated processing that produce legal or similarly significant effects within Article 22. There is no credit scoring, automated eligibility decision, automated hiring screen or behavioural profiling of visitors.
Software built for a client may contain automated logic, including matching and exception rules in a reconciliation system. Where that logic could produce a decision engaging Article 22, the client as controller is responsible for the assessment, the safeguards including human intervention, and the explanation given to those affected. Our contribution is to build the logic so that its reasoning can be explained at all, which is a design requirement rather than a favour.
21. Marketing
The company runs no marketing list, newsletter or advertising, and there is no subscription form on this site because there is nothing to subscribe to.
If that changes, marketing email will be sent only with consent under Regulation 22 of PECR, or under the limited soft opt in where details were obtained during a sale or negotiations for a similar product and an easy means of refusal was offered at collection and in every message. Every message will identify the sender and carry a working unsubscribe route. Corporate subscribers are treated with the same care even where PECR permits less, because the person reading the message is a person either way. The company does not buy contact lists or use broker data.
22. Complaints and the ICO
If you are unhappy with how your data has been handled, write to privacy@thetwentyfintech.co.uk. You will get an acknowledgement within three working days and a substantive answer within one month. You may complain to the supervisory authority at any time, whether or not you raise it with us first.
- Authority
- Information Commissioner's Office
- Address
- Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
- Helpline
- 0303 123 1113
- Website
- ico.org.uk/make-a-complaint
You also have the right to an effective judicial remedy under Article 79 and to compensation for material or non-material damage under Article 82.
23. Mobile applications Controller
The company publishes no mobile application on the App Store, on Google Play or anywhere else. There is nothing to download, no account to create and no application data being processed today.
Sections 24 to 27 are therefore not a description of an operating product. They are the published standard any application released by this company will be built and operated to, written now so that it constrains the build rather than being drafted afterwards to describe whatever was built. On release, this notice is reissued with a new version and date, and these sections change from a commitment into a statement of fact. They exist because these are the points where mobile applications most often go wrong: permissions requested speculatively, identifiers shared with advertising networks, deletion offered nowhere but by email, and a store declaration that does not match the privacy notice.
24. Application permissions
The rule committed to is that a permission is requested at the moment it is needed for a feature the user chose to use, never as a block at first launch, and never as a condition of unrelated functionality.
| Permission | Purpose | Required or optional | If you decline | How to revoke |
|---|---|---|---|---|
| Camera | Only to capture a document or code the user chose to scan. Never background capture. | Optional | The scanning feature is unavailable; manual entry is offered instead. Nothing else changes. | iOS: Settings, the app, Camera. Android: Settings, Apps, the app, Permissions, Camera. |
| Photo library | Only to attach a file the user selects, using the limited selection interface where the platform offers one. | Optional | Attachment from the library is unavailable. | iOS: Settings, the app, Photos. Android: Settings, Apps, the app, Permissions, Photos and videos. |
| Notifications | Operational alerts the user asked for, such as completion of a job they started. | Optional | No push notifications. The same information stays visible in the app. | iOS: Settings, Notifications, the app. Android: Settings, Notifications, App notifications, the app. |
| Location | Not requested. No anticipated feature needs device location. | Not requested | Not applicable. | Not applicable. |
| Contacts | Not requested. We will not ask for the address book or design a feature that needs it. | Not requested | Not applicable. | Not applicable. |
| Microphone | Not requested. | Not requested | Not applicable. | Not applicable. |
| Biometric unlock | Local unlock if the user turns it on. The biometric never leaves the device; the platform returns only success or failure. | Optional | The app unlocks with the ordinary sign in method. | Turn it off in the app's own settings, or remove the permission in system settings. |
| Background refresh | Keeping data current between sessions where enabled. | Optional | Data refreshes when the app is opened instead. | iOS: Settings, General, Background App Refresh. Android: Settings, Apps, the app, Mobile data, Background data. |
| App Tracking Transparency | Not requested, because we do not track across other companies' apps or sites. Section 25. | Not requested | Not applicable. No prompt is shown. | Not applicable. |
Revoking a permission never deletes an account or data already processed. To delete data, use section 27.
25. Identifiers and App Tracking Transparency
The ATT position
Apple's App Tracking Transparency framework requires permission before tracking a user across apps and websites owned by other companies, or accessing the device advertising identifier, the IDFA. The company does not carry out such tracking, does not access the IDFA, and will therefore not display the tracking prompt. Where no prompt appears in an application published by this company, the reason is that there is nothing to ask permission for, not that permission has been assumed.
Advertising, analytics and identifiers
No advertising software development kit will be embedded, no attribution or install measurement network integrated, and no data shared with a data broker. No user level data will be sold, in the broad sense that includes disclosure for any consideration, not only money. Where product analytics is genuinely needed to fix crashes, the commitment is aggregate event counts rather than individual behavioural profiles, no third party advertising identifier, retention in months rather than years, and disclosure here with the provider named in section 14 before it is switched on. Any analytics relying on consent would seek it in the application with a genuine option to decline and no loss of core functionality for declining. Any identifier keeping a user signed in will be generated by the application for that purpose, scoped to it, reset on reinstall or sign out, and not linked to any cross company identifier.
26. Google Play Data Safety
Google Play requires a Data Safety declaration describing what an application collects and shares, whether it is encrypted in transit, and whether users can request deletion. Apple requires equivalent privacy nutrition labels. The company commits that the declaration on either store will match this notice section by section, and that where they would disagree the release does not ship until they agree. Specifically:
- Every data type declared as collected on a store listing will appear in an inventory here, with a purpose and a lawful basis.
- No data type will be declared as not collected on a listing while appearing in an inventory here.
- The declaration that data is encrypted in transit will be true of every network call the application makes, with no exception for a diagnostic endpoint.
- The declaration that users can request deletion will point at the route in section 27, which will exist and work when the listing goes live.
- Where a store category has no clean answer, the more protective description is selected rather than the more flattering one.
A store declaration is a public statement about processing. Treating it as a marketing field is how applications end up contradicting their own privacy notice.
27. Account and data deletion
No application exists, so there is no account to delete today. The commitment below applies to any account created in an application or service published by this company.
In-app route
Deletion will be available inside the application, no more than three taps from the main settings screen, under a heading that says delete account rather than something softer. The screen states what is deleted, what is retained and why, and takes one confirmation. It will not require contacting support, completing a form, waiting for a call back or explaining why you are leaving.
Email route and timing
Deletion may also be requested from privacy@thetwentyfintech.co.uk using the address associated with the account, or by post to the registered office. Identity is verified as in section 19 first, because deleting the wrong person's data is itself a breach. Deletion completes within 30 days of a verified request. The account is disabled immediately so it cannot be used while deletion is processed, and written confirmation follows on completion.
Retained after deletion
| Item | Period | Reason |
|---|---|---|
| Transaction and billing records | 6 years from the end of the accounting period | Companies Act 2006 and HMRC record keeping duties. This cannot be waived on request. |
| A record that deletion occurred | 3 years | So the request can be evidenced if you or the ICO later ask whether it was honoured. It holds the fact and the date, not the deleted content. |
| Data in backups | Until the cycle overwrites it | Restoring a full backup to remove one record is disproportionate. The record is suppressed on any restore so it does not return to live use. |
| Data needed for a legal claim | Until the claim ends and the limitation period expires | Article 17(3)(e) permits retention for legal claims. If this applies, you are told which records are affected. |
Everything not listed is deleted. Deleting an account does not cancel a subscription billed by an app store; those mechanics are in the terms of use and must be completed separately.
28. Changes to this notice
This is version 1.0, effective 7 August 2026. When it changes, the version and date at the top change with it. Material changes, meaning a new purpose, lawful basis, category of recipient or a longer retention period, are notified directly to affected individuals where we hold a contact route, and always take effect prospectively. Superseded versions are retained so the position applying at a past date can be established; ask at the privacy address.
Items marked [TO CONFIRM] are genuine gaps, not drafting placeholders. They are visible so a reader can see which facts are unsettled, and they will be replaced with the answer rather than quietly removed.
29. Contact summary
- Data protection
- privacy@thetwentyfintech.co.uk
- General
- hello@thetwentyfintech.co.uk
- Security reports
- security@thetwentyfintech.co.uk
- Post
- THE TWENTY FINTECH LTD, 66 Paul Street, London, England, EC2A 4NA
- Supervisory authority
- Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, telephone 0303 123 1113