Policy Document
Data Processing Addendum
Last Updated: 2026-02-27
1. Compliance Architecture
Twinise is designed to support GDPR obligations, and CCPA requests are honoured. Tenant isolation and data minimization are built into the platform: every resource is bound to an organization, and every query is filtered by it.
2. Processing Scope
Data processing is restricted to the ingestion, storage, and presentation of sensor telemetry. We act as a data processor for any personally identifiable information (PII) incidentally captured — in device and context names, or in readings a customer chooses to attribute to a person.
3. Sub-Processors
- Cloud Infrastructure: DigitalOcean (managed Kubernetes and managed Postgres).
- Payment Processing: Stripe (transactions only, isolated from telemetry).
- Transactional Email: Brevo (account and order mail).
This is the complete list as of the date above. It is updated here before a sub-processor is added.