Privacy notice
Last updated: 7 August 2026
Written to UK GDPR and the Data Protection Act 2018. It explains what we collect, why we use it, who receives it, how long it is kept, and the rights available to you.
1. Who is responsible for the information
TwinLoom is a trading name of TwinCoreTech Ltd.
- Company number
- 15997244
- Registered office
- Bromley Old Town Hall, 30 Tweedy Road, Bromley BR1 3FE
- VAT number
- 489 0108 74
- Privacy contact
- privacy@twincoretech.com
Still to confirm. The ICO registration number, or confirmation that TwinCoreTech Ltd is not registered. It belongs in the table above.
TwinCoreTech Ltd is the controller for the personal information described in this notice, except where we process information only on a client's instructions as part of providing a client website or a connected service. That situation is described in section 7.
This notice covers the twinloom.com website and the twincoretech.com website, and services provided under either name.
2. Information you give us
Enquiries and contact
When you call, email, book a meeting or submit a form, we may collect your name, your business or organisation, your job title, your contact details, the content of your message, meeting details including the time booked and what you told us on the booking form, the written notes we take during a meeting, and any follow-up correspondence.
We do not record introductory meetings. The notes we take are written up and sent to you afterwards as a summary for you to correct, and that summary is what we keep. Booking a meeting does not add you to a mailing list.
Scoping requests
The TwinLoom website lets you send us a description of the website you want. Where you do, we collect the contact details you give us, your description in your own words, your answers to any scoping questions you choose to answer, and any files, images, screenshots, links or notes you attach.
We also keep a reference for your request, a record of anything you add to it afterwards, and the date and time of each. Adding to a request amends the original rather than creating a second one.
Questions you leave unanswered are recorded as assumptions we have made, and shown to you as assumptions, rather than filled in on your behalf.
Please do not submit passwords, payment-card details, unnecessary customer records, health information or other sensitive personal information unless we have agreed a secure and appropriate method with you in advance.
Client projects
If you become a client, we may collect client contacts and decision-makers, proposal, contract and billing information, project communications, approvals and decisions, account and access records, support requests, meeting notes and recordings where agreed, and the information needed to deliver, secure and maintain the work.
Supplier and partner contacts
We may hold business contact, contract, payment, performance and due-diligence information for suppliers, contractors and specialist partners.
Marketing preferences
Where you ask to receive updates, we record your contact details, your consent or other applicable basis, the topics you asked for, and your unsubscribe status.
3. Information collected when you use the website
Depending on your choices, we may receive your IP address, browser and device information, the pages you requested, the date and time, referral information, an approximate location derived from network information, your consent preferences, error and security logs, your interactions with forms and website features, and analytics events.
The Cookies page lists the storage and access technologies actually used by this website.
4. Why we use personal information
| Purpose | Information | Lawful basis |
|---|---|---|
| Respond to an enquiry | Contact details and enquiry content | Legitimate interests in responding to business enquiries; steps requested before entering a contract |
| Receive and review a scoping request | Submitted content, attachments and business information | Steps requested before entering a contract |
| Let you add to a scoping request already sent | The request, its reference and the record of changes | Steps requested before entering a contract; legitimate interests in providing the requested feature |
| Prepare a written scope and a proposal | Submitted content and business information | Steps requested before entering a contract |
| Deliver a project or a care plan | Client, project, account and support information | Performance of a contract |
| Invoice and maintain financial records | Client and transaction information | Performance of a contract; legal obligations |
| Secure and operate the website | Network, device, log and security information | Legitimate interests in security, service operation and fraud prevention |
| Measure website use | Usage and analytics information | Consent |
| Send requested or permitted marketing | Contact details and preferences | Consent, or legitimate interests subject to direct-marketing rules |
| Manage suppliers and partners | Contact, contract and performance information | Performance of a contract; legitimate interests |
| Establish or defend legal rights | Relevant records | Legitimate interests; legal obligations |
| Meet regulatory requirements | Relevant business and personal information | Legal obligations |
5. What happens if you do not provide information
You do not have to answer any scoping question, and you do not have to send files. The scoping journey is designed so that you can give as little or as much as you want to each question, and send at any point.
We do need a name and a contact route we can reply to, and enough information to respond to your enquiry. If you become a client, some information is required to enter and perform the agreement, manage access and issue invoices.
Optional fields are labelled optional.
6. Who receives the information
We may share information with:
- Hosting and deployment providers
- File-storage providers
- Email and business-productivity providers
- Booking providers
- Analytics and consent providers
- Accounting and payment providers
- Customer-relationship or project tools
- Professional advisers and insurers
- Specialist partners working under our contract
- Regulators, courts or public authorities, where required
- A potential buyer or successor, in a properly managed business transaction
We do not sell personal information to advertisers.
The Sub-processors page names the suppliers that process personal information for us.
7. Client information we process on instructions
When we host or support a client website, we may process that client's customer, employee or user information solely to provide the agreed service.
In that situation:
- The client decides the purpose and means of the processing
- The client is the controller
- TwinCoreTech Ltd acts as processor under the agreement
- Sub-processors, security, assistance, deletion and return are governed by the data-processing terms in that agreement
This notice does not replace the client's own privacy notice to the people whose information it collects.
8. International transfers
Some suppliers may store or access information outside the UK.
Where UK data-protection law requires safeguards, we use an applicable lawful transfer mechanism and assess the transfer and the supplier as required. The Sub-processors page identifies the locations and safeguards for each supplier.
9. How long we keep it
| Record | Retention |
|---|---|
| A scoping request saved but not sent | 30 days from last activity |
| A submitted enquiry that does not become a client | 12 months after the last meaningful contact |
| A proposal that is not accepted | 24 months after expiry or final contact |
| Client project and contract records | The contract term plus 6 years |
| Invoices and tax records | The period required by tax and company law |
| Support and security logs | Between 30 and 180 days, depending on purpose |
| Analytics | The shortest useful setting the tool supports |
| Marketing records | Until unsubscribe, objection or an inactivity rule applies, plus a suppression record |
| Complaint and data-rights records | 6 years |
| Backup copies | A rotating schedule, then overwritten |
Still to confirm. The retention period for meeting notes and summaries. It belongs as a row in the table above.
We may keep information for longer where it is necessary for a legal claim, a regulatory requirement, fraud prevention, or an agreed client instruction.
10. Security
We use proportionate technical and organisational measures designed to protect personal information. These include access control, multi-factor authentication, encryption in transit, supplier review, logging, secure development practices, backups, obligations on staff and contractors, and incident procedures.
No internet service can promise absolute security. Please do not use ordinary website forms to send passwords or highly sensitive records.
11. Your rights
Depending on the circumstances, you may have the right to:
- Ask for access to your personal information
- Ask us to correct information that is inaccurate
- Ask for deletion
- Ask us to restrict how we use it
- Object to processing based on legitimate interests, or to direct marketing
- Receive certain information in a portable format
- Withdraw consent
- Complain to the Information Commissioner's Office
- Ask about the safeguards used for an international transfer
These rights are not absolute in every situation. We may need to confirm your identity and understand the request before acting on it.
To exercise any of them, write to privacy@twincoretech.com.
12. Marketing
You can unsubscribe using the link in the message, or by contacting us.
Stopping marketing does not prevent us sending service, contract, security or transaction messages that are still necessary.
We keep a minimal suppression record where that is needed to respect an unsubscribe request.
13. Children
This website and these services are directed to businesses and are not designed for children to submit briefs.
If you believe a child has sent us personal information, contact us so that we can assess it and remove it where appropriate.
14. Automated decisions
We use your answers to generate an outline of the website they describe, and to produce a written scope.
That output is a planning aid. It does not automatically accept or reject a client, create a contract, set a final price, or make any decision with a legal or similarly significant effect. A person reviews every submitted request.
15. Complaints
Contact us first at privacy@twincoretech.com, or use the Complaints page.
You also have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. You do not have to complete our process before doing so.
16. Changes to this notice
We update this notice when the website, our suppliers or our processing changes.
Material changes are dated and, where appropriate, brought directly to the attention of affected clients and subscribers.
