GDPR Compliance Statement
Last updated: August 11, 2026
This statement describes how TwoEngines complies with the EU General Data Protection Regulation (Regulation 2016/679, "GDPR") and the UK Data Protection Act 2018. It supplements our Privacy Policy and applies to all personal data of EU/UK residents that we process.
1. Role Under GDPR
Depending on the context, we act as either a Data Controller (for website visitors, newsletter subscribers, and prospects) or a Data Processor (for customer data processed through our SaaS products). When we act as a Processor, we process data only on documented instructions from the Controller (our customer).
2. Lawful Basis for Processing
We rely on the following lawful bases under Article 6 of the GDPR: (a) consent (Art. 6(1)(a)) for marketing communications and non-essential cookies; (b) performance of a contract (Art. 6(1)(b)) for providing subscribed services; (c) legitimate interests (Art. 6(1)(f)) for security monitoring and service improvement; and (d) legal obligation (Art. 6(1)(c)) for regulatory compliance.
3. Data Subject Rights
EU/UK data subjects have the following rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21), and rights related to automated decision-making (Art. 22).
To exercise these rights, contact us at the email provided below. We will respond within one month, as required by Article 12.
4. International Data Transfers
When transferring personal data outside the EU/UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions, or other appropriate safeguards as required by Chapter V of the GDPR.
Our primary data processing occurs in data centers located within the EU and/or regions with adequacy decisions where feasible.
5. Data Processing Agreement (DPA)
We offer a Data Processing Agreement to all customers subject to GDPR. The DPA outlines our obligations as a Processor, including processing only on documented instructions, confidentiality commitments, and assistance with data subject requests.
Customers can request a copy of our DPA by contacting us at the email below.
6. Data Breach Notification
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by Article 33. Where the breach is likely to result in a high risk to data subjects, we will also notify affected individuals without undue delay (Article 34).
7. Data Protection by Design and Default
We implement appropriate technical and organizational measures to ensure data protection by design and by default (Article 25), including data minimization, pseudonymization where applicable, and access controls based on the principle of least privilege.
8. Records of Processing Activities
We maintain records of our processing activities as required by Article 30, including the purposes of processing, categories of data subjects and personal data, recipient categories, and data retention periods.
9. Data Protection Officer
We have appointed a Data Protection Officer (DPO) who can be contacted at the email below. The DPO is responsible for overseeing our GDPR compliance and serving as a point of contact for supervisory authorities and data subjects.
10. Right to Lodge a Complaint
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with your local supervisory authority. We encourage you to contact us first so we can address your concerns.
Questions about this policy? Contact us at hello@twoengines.tech.