Privacy Policy
Last updated: 14 August 2026
This Privacy Policy explains how Mykey Digital ("Mykey Digital", "we", "us", or "our"), the company behind the Twindem products, collects, uses, discloses, and protects personal data when you use the Twindem Team product (the desktop application, control plane, and delivery board), the Twindem Suite applications (such as Twindem Pulse), and the twindem.ai website (together, the "Services"). Mykey Digital operates from Romania, European Union, and processes personal data in accordance with the EU General Data Protection Regulation (GDPR).
Data controller: SC MYKEY DIGITAL SRL, Str. C-tin Radulescu Motru nr. 12, Bl. 27B-28, sector 4, Bucharest, Romania. Registered with the Trade Register under no. J40/14943/2021, sole registration code (CUI) RO44820207.
1. Information we collect
We collect only the data needed to operate the Services:
- Account & identity data — name, work email, and sign-in identifier (including Microsoft Entra ID identifiers when you sign in with your organization).
- Organization & seat data — your organization, projects, team members, seat assignments, roles, and subscription/billing metadata received from Microsoft Azure Marketplace (we do not receive or store your payment card details).
- Product usage & telemetry — records of agent runs, token usage, work-item activity, review findings, and related operational metrics used for coordination, usage visibility, and metered billing.
- Content you provide — work items, comments, project documents (Docs), knowledge-base notes, and Project Library artifacts you create in the Services.
- Support communications — messages, attachments, and contact details you send us for support or sales.
- Website data — standard log data and analytics from twindem.ai (see Cookies).
AI coding agents run locally on the operator's machine, where your source code resides. We do not receive your source code repositories; only the plans, status, evidence, and usage telemetry you push to the board are stored in the Services.
2. How we use information
- Provide, operate, secure, and improve the Services.
- Authenticate users and enforce organization, project, and seat access.
- Coordinate delivery work and provide usage, cost, and audit visibility.
- Calculate and report metered usage for Azure Marketplace billing.
- Provide support and respond to your requests.
- Comply with legal obligations and protect against fraud and abuse.
3. Legal bases (GDPR)
We process personal data to perform our contract with you (providing the Services), for our legitimate interests (securing and improving the Services, preventing abuse), to comply with legal obligations, and with your consent where required (for example, non-essential website analytics).
4. Hosting & sub-processors
The Services run entirely on Microsoft Azure. We use a limited set of sub-processors:
| Sub-processor | Purpose | Region |
|---|---|---|
| Microsoft Azure | Application hosting, database, secrets, identity | EU — Poland Central |
| Cloudflare | CDN/edge and object storage (R2) for uploaded artifacts | Global edge |
| Google Analytics | Aggregate website usage analytics (twindem.ai only) | Global |
5. How we share information
We do not sell personal data. We share it only with the sub-processors above, with Microsoft as the marketplace and billing provider for subscription and metered-usage reporting, when required by law, or to protect our rights and users.
6. International transfers
Personal data is primarily processed within the EU. Where a sub-processor processes data outside the EU, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
7. Data retention
We retain personal data for as long as your account or organization is active and as needed to provide the Services, then delete or anonymize it within a reasonable period, unless a longer period is required by law (for example, billing records).
8. Security
We apply strong technical and organizational measures, including multi-tenant isolation enforced by PostgreSQL Row-Level Security, encryption in transit and at rest, secret management in Azure Key Vault, a network-private database, and least-privilege access controls.
9. Your rights
Subject to applicable law, you have the right to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability. You may also withdraw consent and lodge a complaint with your supervisory authority (in Romania, the ANSPDCP). To exercise your rights, contact us at hello@twindem.ai. If you use Twindem Team through an organization, that organization is the controller of its content and you should also contact them.
10. Cookies & analytics
twindem.ai uses essential cookies required for the site to function and Google Analytics to understand aggregate usage. You can control cookies through your browser settings. The Twindem Team application uses only cookies and tokens necessary for authentication and session management.
11. Children
The Services are intended for business use and are not directed to children under 16.
12. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by additional notice.
13. Contact
Questions or requests regarding this policy or your personal data: hello@twindem.ai.