Twin

Twin's data policy
SECURE ANDRESPONSIBLE

Grant professionals work with sensitive data: project plans, financial figures, strategic choices. Of clients, or of their own organisation. Applying AI to that data calls for infrastructure that matches the responsibility of the profession.

This page sets out how Twin handles that. No marketing promises, just concrete choices and certifications.

ISO 27001
certified
ISO 27001
AIC4NL
participant
AIC4NL
EU-hosted
Helsinki
Chapter 1

Where your data lives

All of Twin's core data runs on a Hetzner cluster in Helsinki, Finland. No US cloud, no transfer outside the EU unless you choose it yourself.

EU-hosted at Hetzner Helsinki

Application and API servers, databases, customer files and the locally hosted LLM (see chapter 2) run within one European cluster under European law.

ISO 27001 certified

Twin is ISO 27001 certified. Hetzner itself complies with ISO 27001, ISO 27018 and SOC 2. Together they provide an audit baseline that procurement accepts without fuss.

Encryption in transit and at rest

TLS on all external connections, encryption at rest on databases and file storage, key management under Twin's control, and strict role-based access.

Chapter 2

You decide where your language model runs

Model quality, data sovereignty and zero data retention cannot all three be maximised at once. The trade-off is spelled out below, configurable per organisation.

A

Strongest models, worldwide

Customers who need maximum output quality and reasoning capability.

  • Models from OpenAI, Anthropic and Google, usually within weeks of their release
  • Processing may take place outside the EU, under the DPF and standard contractual clauses
  • Training on your data is contractually excluded
B

Hosted in Europe

Customers who want to keep all data processing within the EU.

  • European providers such as Mistral, or EU deployments of the major models
  • The entire processing chain stays within the EU, with no transfer to third countries
  • A new model typically lands here a few months later than in option A
  • Training on your data is contractually excluded
  • DPA and sub-processor list cover every party in the chain
C

On Twin infrastructure in Finland

Customers with the highest data sovereignty requirements, e.g. healthcare or government.

  • Open-source model on the same Twin cluster in Helsinki
  • Prompts and responses stay within our own infrastructure
  • Zero data retention, technically enforced on our hardware
  • On long, complex sections the reasoning capability is noticeably weaker than in option A

You can combine them. Customers with strict data requirements often choose option C for sensitive phases (processing sensitive data, draft texts) and option A or B for general tasks (summarising public schemes, language correction).

Chapter 3

What we do not do with your data

A common misconception is that Twin "trains models" on user data. We do not. Here is what we do and do not do.

What we do not do

Twin does not fine-tune on your data. Model weights are not adjusted based on what an organisation enters in Twin, and application texts from organisation A are never used in any form to make generic model improvements that end up with other organisations.

Your data is also not used for marketing, product development, or refinement at other organisations.

What we do

For each application we give the model context: your writing guidelines, earlier examples and project documents. That content stays within your organisation, applies only to that one application and is not absorbed into model weights.

Product improvement is based on anonymised usage data and voluntarily shared feedback. Multi-tenant isolation is enforced in every layer of the application and tested periodically.

Chapter 4

How you stay audit-ready

Whether it is a spot check, an internal ISO audit or external reporting, you need to be able to produce the full trail. Twin delivers that as standard.

Audit trail as standard

Every change, every AI call and every export is recorded in ISO 27001-compliant logs. Who did what, when, with which prompt, based on which sources.

Phased retention policy

Automated clean-up policy in two phases. Soft delete after 90 days for workflow runs, hard delete 365 days after soft delete. GDPR requests are carried out within 30 days.

Ownership stays with you

Application texts, expert instructions, your own templates and examples in your knowledge base are and remain the property of your organisation. Exportable on termination.

Chapter 5

Access by Twin staff

Twin staff only access your data to answer support questions, and only when a question cannot be answered without that access.

All actions are recorded in user activity logs and can be retrieved per staff member on request. Access is role-based and limited to what the role requires, and every Twin employee is contractually bound to confidentiality.

For procurement and compliance

The procurement pack

For the POC or contract phase we send a consolidated set of documents on request. One email, everything at once.

Data processing agreement (DPA) with sub-processor annex
ISO 27001 certificate
Recent pentest summary
SSO and SAML (Entra ID, Okta)
SLA with uptime, response tiers and escalation
RBAC matrix and audit trail export formats
Incident response procedure
Data export and exit procedure

Sent within one working day. DPA, ISO 27001 certificate and sub-processor list immediately, pentest summary after a short NDA exchange.

Pack contents updated May 2026

Questions not answered here?

We are happy to discuss your specific compliance context in a short call.