Twist
Twist is a team communication app built by Doist.
Score
Notes
The policy does not explicitly or indirectly allow personally-targeted or behavioral marketing.
Even if there is a reasonable delay before the data is fully deleted (as is common), the data still counts as "permanently deleted" and satisfies the parameters for this question.
Score
Citation
"Upon deleting your account, all your personal data will be removed from our production systems. Only an encrypted copy of your data will remain on our backup archives for 90 days. After this period, all data associated with your account will be deleted permanently."
This may come in the form of outright data sharing or by using local third-party analytics software (such as Google Analytics, which collects a plethora of user information).
Note that whether the policy allows sharing aggregated user data does not affect this question.
If the personal data is encrypted when it passes through the third-party, it does not count as third-party access (as the data is inaccessible to that party).
If personal data has been made public by, for example, posting it to a blog, it does not count as private personal information (and is therefore not considered by this question).
Score
Citation
"Twist uses third party vendors and hosting partners to provide the necessary hardware, software, networking, storage, and related technology required to run Twist."
"When necessary, we use the following GDPR-compliant third party services:
- Amazon Web Services
- Google Analytics
- Zendesk
- SendGrid
- Mailgun
- Paypal
- Stripe
- Microsoft Azure
- Microsoft Visual Studio App Center
- Fabric (Crashlytics)
- Baremetrics
- MailChimp
"
"We do NOT partner with or have special relationships with any ad server companies."
Notes
(Source.)
Score
Citation
"We will not voluntarily disclose your data and information to any government organizations and entities. We will only disclose your data and information to government agencies when we are forced to fulfill legal or regulatory requirements. We will email or send Service notifications to our Customer if the Customer’s account is under investigation by government agencies."
Score
Citation
"At Twist, we maintain a security system that ... supports continuous monitoring for potential vulnerabilities."
"We regularly test, assess and evaluate the effectiveness of our processes and technology."
Notes
Twist has a comprehensive separate page dedicated to their security practices.
Score
Notes
There is no option to review the privacy policy's history, but a last effective date is shown.
Note that all companies operating in the EU are subject to Art. 33 of the GDPR, which requires companies to notify their data protection authority of a data breach within 72 hours of discovering it.
Score
Notes
The privacy policy does not specify a data breach protocol.
Score
Citation
"If our information practices change in the future we will post the policy changes to our website and notify you of these changes."
This includes the use of data brokers and independent verification authorities (such as background check providers).
Score
Notes
It is not inferred from the policy that Twist collects personal data from third parties.
Score
Citation
"We only collect personal data that is required to provide our service, and we only store it insofar that it is necessary to deliver these services."
"Twist also collects user activity data for analytical purposes. The user data we collect is used to improve Twist and the quality of our service."
"Your information is only used internally for the necessary operation of Twist and won't be shared with others."
Some services allow users to opt-out or opt-in to of non-critical collection or use of personal data, such as collecting data for personalized advertisements.
Score
Notes
Twist allows third-party apps integration who have their respective privacy practices.
Score
Citation
"When registering for Todoist and Twist you voluntarily give us information such as your name and email address. You can access and update this information at any time in your personal Account Settings.
In addition, when you use our services, you give us the consent to use the following data:
- IP address
- Device ID
- Name and surname (optional, not processed)
- Job (optional, not processed)
- Phone number (optional, not processed)
- VAT ID (optional)
- Invoice address (for Unlimited accounts)
"
Notes
(Source.)
Last Updated
May 26, 2021
Sources
Contributors