Privacy Policy
Last updated: July 2026
1. Data controller
Twilbox ("Twilbox", "we") is the controller responsible for processing the personal data described in this policy and operates the platform available at twilbox.com and its subdomains. This Privacy Policy explains what data we collect, for what purposes, on what legal bases, with whom we share it, and what rights you have. For any privacy-related matter or to exercise your rights, you may write to us at admin@twilbox.com, stating your request and the information needed to identify you. We handle requests within the time limits required by applicable law.
2. Scope and acceptance
This policy applies to individuals who visit our website, register, or use the platform, as well as to the data we process on behalf of our clients when they connect third-party services. By using Twilbox you accept the practices described in this document; if you do not agree, we ask that you not use the platform. When we act as a data processor on behalf of a client—for example, when processing the data of the client's own contacts—that client is the data controller, and this policy applies in addition to the agreements entered into with them.
3. Data we collect
We collect: (a) identification and contact data that you provide when you register or communicate with us, such as name, email, phone, and company; (b) account and configuration data necessary to provide the service; (c) the content and records you manage within the platform, such as messages, contacts, notes, calendar events, forms, and files; (d) data obtained from the third-party platforms you choose to connect, described in the following sections; (e) technical browsing data, such as IP address, device type, browser, and pages visited, obtained through cookies and similar technologies; and (f) billing data when you subscribe to a paid plan. We collect only the data necessary for the purposes described in this policy.
4. Data obtained through connected platforms (Meta, Google, and others)
When you connect an external account—such as Meta (Facebook, Instagram, WhatsApp Business), Google, Microsoft, Clientify, or others—we access only the information necessary to provide the features you expressly enable through each provider's authorization process (OAuth). Depending on the integration, this may include your list of pages, messages and comments, form leads, WhatsApp Business numbers, advertising account metrics, calendar events and availability, and basic profile information. When you sign in with Google or Microsoft, we receive only your name, email address, and profile picture, and we use them solely to identify you and create or retrieve your account; we do not access your mail, files, or calendar unless you expressly enable that integration. We never request permissions beyond the functionality you activate, and you may revoke access at any time from the Integrations section. The processing of this data is governed by this policy and by each provider's terms.
5. Use of Google API services and the Limited Use policy
When you connect a Google account—for example, Google Calendar—Twilbox requests only the permissions strictly necessary for the enabled feature, such as reading your availability and creating, updating, or deleting the events corresponding to your bookings. The use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including its Limited Use requirements. Accordingly: (a) we use Google data exclusively to provide and improve the features you connected; (b) we do not sell Google data or use it for advertising purposes; (c) we do not transfer it to third parties except as necessary to provide the service, comply with the law, or in connection with a duly notified corporate transaction; (d) no human reads your Google data except with your explicit consent, for security purposes, to comply with applicable law, or where the data is aggregated and anonymized; and (e) we do not use Google data to train general-purpose artificial intelligence models. Access tokens are stored encrypted, and you may disconnect Google at any time, which revokes permissions and deletes the synchronized calendar data. When you connect Gmail, Twilbox uses that data solely to display, organise, reply to and send your email within the application. We do not transfer Gmail data, or data from any Google Workspace API, to artificial intelligence models or services, whether our own or third-party, and we do not use it to create, train or improve any machine learning model, whether raw, aggregated, anonymised or derived. Twilbox’s use of information received from Google Workspace APIs adheres to the Google User Data Policy, including the Limited Use requirements.
6. How we use your data
We use the data to: provide and maintain the service (unified inbox, CRM, scheduling, marketing, automation, and analytics); authenticate your access and protect accounts; handle your requests and provide support; send operational or service communications; comply with legal obligations; and improve the platform through usage metrics. Data obtained from connected platforms is used exclusively to provide the corresponding functionality. We never sell your personal data or use it to train general-purpose artificial intelligence models.
7. Legal bases for processing
Where the General Data Protection Regulation (GDPR) or other equivalent legislation applies, we process your data on the following bases: performance of the contract to provide the service you request; your consent—which you may withdraw at any time—to connect third-party platforms or receive optional communications; our legitimate interest in operating, securing, and improving the platform in a proportionate manner; and compliance with legal obligations. Where processing is based on consent, its withdrawal will not affect the lawfulness of processing carried out beforehand.
8. Sharing and third-party providers
We do not sell your personal data. We share it only with providers (data processors) strictly necessary to operate the service—such as cloud infrastructure and hosting, transactional email delivery, payment processing, and analytics tools—always under contract and obligations of confidentiality and security, and only for the purposes described in this policy. Data obtained through Meta is processed in accordance with the Meta Platform Terms, and data obtained through Google in accordance with the Google API Services User Data Policy. We may also disclose data where required by law or by a competent authority. When we receive a request for information from a public authority, we review whether it is legally valid and properly grounded before responding, and we object to and challenge, through the legal channels available to us, any request we consider unlawful, excessive or without legal basis. Where a response is appropriate, we disclose only the minimum information strictly necessary, and we document every request received, our response, the legal reasoning applied and the parties involved.
9. International transfers
Our providers may process data in countries other than yours. When we transfer data outside the European Economic Area or your jurisdiction, we adopt the appropriate safeguards required by applicable law, such as the Standard Contractual Clauses approved by the European Commission or other recognized mechanisms, to ensure an equivalent level of protection.
10. Data retention
We retain your data for as long as your account is active or as necessary to provide the service and comply with our legal, accounting, and security obligations. When you disconnect a platform or request deletion, we delete the associated data within a reasonable period, unless we are required to retain it by law or for the establishment or defense of legal claims. Technical and security logs may be retained for shorter periods in accordance with our internal policies.
11. Security
We apply technical and organizational measures to protect your data, including encryption in transit (TLS) and at rest, encryption of integration access tokens, role-based access control, activity logging, and automated backups. Our services run on private, isolated instances. Although no system is completely infallible, we work continuously to reduce risks and respond diligently to any security incident.
12. Your rights
You may request at any time access to, rectification, portability, restriction, objection to, or erasure of your personal data, as well as withdraw your consent, by writing to admin@twilbox.com. We will verify your identity before handling the request. If you are located in the European Union, you also have the rights granted by the GDPR and the right to lodge a complaint with the supervisory authority in your country. We will handle your request without undue delay and within the statutory time limits.
13. Deleting your data
You may delete the data obtained through a connected platform at any time by going to Integrations and disconnecting that platform, which revokes permissions and deletes the associated synchronized data. In the case of Google, disconnecting revokes the tokens and deletes the synchronized calendar information. You may also request the complete deletion of your account and data by following the instructions on our data-deletion page: https://www.twilbox.com/en/data-deletion.
14. Minors
Twilbox is a professional tool intended for businesses and is not directed at minors. We do not knowingly collect data from individuals who have not reached the age legally required to enter into a contract in their jurisdiction. If we discover that we have processed a minor's data without an appropriate basis, we will delete it as promptly as possible.
15. Cookies, changes, and contact
We use cookies necessary for the site to function and, where applicable, analytics cookies to understand its use; you can manage them from your browser settings. We may update this policy to reflect legal or service changes, and we will publish the current version on this page indicating the date of last update. For any privacy inquiry, write to us at admin@twilbox.com.