Twynity Privacy Policy
How 4th-IR Group AG collects, uses and protects your personal data — April 2026
At a glance. This policy explains what personal data the Twynity platform processes, why, how long for, with whom it is shared, and what your rights are. It applies from the moment you visit our website or create an account. If you choose to create a Virtual Persona ("Twyn") from your own voice and likeness, additional terms apply — the Twynity Twyn Creation Terms and the Twynity Biometric Data Notice, which this policy cross-references but does not replace.
1. Who we are
The controller of your personal data is 4th-IR Group AG, a company incorporated in Switzerland, with its registered office at Alpenstrasse 16, 6300 Zug ("4th-IR", "we", "us", "our").
Contact us at: info@4th-IR.com
For data-protection queries: info@4th-IR.com. Our Data Protection Officer is reachable at the same address.
EU / GDPR Article 27 representative: Derek Smith. UK representative: [to be appointed before UK launch, if applicable].
2. Scope of this policy
This policy applies to all processing of personal data carried out by 4th-IR in connection with the Twynity website, application and platform. It covers three broad groups of people:
- Visitors — people who browse our website without an account.
- Account holders — people who have signed up for a Twynity account, whether on a free or paid plan.
- Twyn Subjects — account holders who have chosen to create a Virtual Persona from their own voice and likeness.
Where a section applies to only one of these groups, we say so. Where an enterprise customer deploys Twynity on behalf of its staff, additional terms are set out in the applicable Data Processing Agreement between that customer and 4th-IR; for those deployments 4th-IR acts as a processor on the customer's instructions for customer-directed processing.
3. What personal data we process, and why
We process the categories of personal data set out in the table below. The table also sets out, for each category, the purpose of the processing and the legal basis we rely on under the EU and UK GDPR. Equivalent bases apply under the Swiss FADP.
Category | What it includes | Purpose | Legal basis |
|---|---|---|---|
Account data | Name, email address, password (stored as a salted hash), country, language preference, and, for enterprise users, employer and role. | Creating and operating your account; authenticating you; communicating with you about the service. | Performance of contract (GDPR Art. 6(1)(b)). |
Billing data | Billing address, VAT number where applicable, last four digits and type of payment method. Full card numbers are handled by our payment processor and are never stored by 4th-IR. | Taking payment for paid plans; issuing invoices; tax and accounting compliance. | Performance of contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)). |
Usage and device data | IP address, browser type, device identifiers, pages viewed, features used, timestamps, error and diagnostic logs. | Keeping the platform secure and reliable; detecting and preventing abuse; improving the service. | Legitimate interests (Art. 6(1)(f)) — operating a secure and reliable service. Where required, consent (Art. 6(1)(a)). |
Content you upload | Documents, scripts, training text and other material you add to the platform to configure or drive your Twyn. | Hosting and processing your content strictly to deliver the service you have configured. | Performance of contract (Art. 6(1)(b)). |
Biometric data (Twyn Subjects only) | Voice recordings; facial imagery from photos and video; a live on-camera consent recording; derived voiceprint, facial geometry and embeddings; the Twyn model itself. | Creating and operating your Twyn; identity verification; preventing impersonation; delivering authorised interactions. | Explicit consent (Art. 9(2)(a); FADP Art. 6(7)(a)). Governed in detail by the Twynity Biometric Data Notice. |
Interaction data | Audio, video, transcripts and prompts captured during Twyn sessions with third parties ("Interlocutors"). | Operating the session and producing the Twyn's responses; quality and safety monitoring. | Performance of contract with the account holder (Art. 6(1)(b)); the deploying organisation is responsible for informing Interlocutors and obtaining any further consents required locally. |
Support and communications | Messages you send us; records of calls or chats with our support team; feedback and survey responses. | Answering your questions; investigating issues; improving the service. | Legitimate interests (Art. 6(1)(f)); consent where required (Art. 6(1)(a)). |
Marketing preferences | Your subscription status for newsletters, product updates and events. | Sending you communications you have asked for, and not sending those you have not. | Consent (Art. 6(1)(a)); legitimate interests for existing customers where permitted by local law. |
Cookies and similar technologies | Session cookies for authentication; functional cookies for preferences; analytics identifiers where you consent. | Keeping you signed in; remembering your preferences; understanding aggregate use of the platform. | Strictly necessary cookies: legitimate interests. Analytics and marketing cookies: consent. See our Cookie Notice. |
Biometric data is different. Biometric data — voice, face and the identifiers derived from them — is a special category of personal data under GDPR Article 9 and sensitive personal data under Swiss FADP Article 5(c). We only process biometric data if you create a Twyn, only after you have given us your separate explicit consent, and only as described in the Twynity Biometric Data Notice. Creating an account does not authorise us to process biometric data about you.
4. How we collect your personal data
We collect personal data in three ways:
- Directly from you — when you create an account, configure your profile, create a Twyn, contact support, or otherwise interact with the platform.
- Automatically — through your device and browser when you use the platform (usage and device data, cookies).
- From third parties — where you sign in through an identity provider (for example, a corporate single sign-on), or where your employer provides account details for enterprise onboarding, or from fraud-prevention and identity-verification services we use to confirm who you are.
5. Who we share your personal data with
We share personal data only where we need to, and only with parties who are bound to protect it to the same standard we do. These parties fall into a small number of categories:
- Subprocessors — carefully selected service providers who process personal data on our behalf under written data processing agreements. They include cloud infrastructure providers (such as AWS and Microsoft Azure), generative voice and video model providers (such as Tavus), identity-verification providers, authentication providers, and payment processors. A current list is maintained at [twynity.ai/legal/subprocessors — URL to be confirmed].
- Enterprise customers — where you use Twynity through your employer or another organisation, that organisation has administrative access to your account for the scope set out in its contract with 4th-IR.
- Professional advisers — such as auditors, lawyers and accountants, bound by professional confidentiality.
- Authorities — where we are legally required to disclose data, for example in response to a valid order of a court of competent jurisdiction. Where lawful, we will notify you first.
- A successor — in connection with a corporate transaction (for example, a merger or acquisition), subject to the same protections as this policy.
We do not sell your personal data. We do not share your personal data with advertisers or data brokers. We do not use your biometric data to train or fine-tune general-purpose AI models, and our subprocessors are contractually prohibited from doing so on our behalf.
6. Where your personal data is processed
Your personal data may be processed in Switzerland, in the European Economic Area, and in the United States. Where data leaves Switzerland or the EEA, we rely on one of the following recognised transfer mechanisms:
- EU Standard Contractual Clauses (Commission Decision 2021/914), with supplementary measures where required by a transfer impact assessment.
- Swiss Standard Contractual Clauses as recognised by the Swiss Federal Data Protection and Information Commissioner.
- EU–US and Swiss–US Data Privacy Frameworks , where the receiving organisation is certified.
- UK International Data Transfer Agreement or UK Addendum to the EU SCCs, for data originating in the United Kingdom.
You can request a copy of the relevant transfer mechanism from info@4th-IR.com.
7. How long we keep your personal data
We keep personal data only for as long as we need it for the purposes set out in section 3, and then we delete or anonymise it. The main retention periods are:
Category | Retention |
|---|---|
Account data | For as long as your account is active, plus up to 12 months after closure to handle any post-termination matters, unless a longer period is required by law. |
Billing data | For the period required by Swiss tax and accounting law (currently 10 years). |
Usage and device data (raw logs) | Up to 13 months; aggregated and anonymised analytics may be retained longer. |
Content you upload | For as long as your account is active; deleted within 30 days of account closure, with backup purge on a rolling cycle not exceeding 90 days. |
Biometric data (Twyn Subjects) | For as long as your Twyn is active; deleted within 30 days of Twyn deletion, account closure or consent withdrawal, with backup purge on a rolling cycle not exceeding 90 days. See the Biometric Data Notice for detail. |
Live consent recording | Life of the Twyn plus a compliance tail of 24 months, held in a separate access-restricted vault, then permanently destroyed. |
Interaction data (sessions) | As configured by the account holder or enterprise customer, subject to a platform default of 30 days unless a longer period is explicitly requested. |
Support communications | Up to 24 months after the matter is closed. |
Marketing preferences | Until you unsubscribe or close your account. |
Cookies | Per the durations set out in our Cookie Notice. |
8. Your rights
You have rights in relation to your personal data under the laws that apply to you. You can exercise most of them directly from your account, or by contacting info@4th-IR.com. We will respond within the period required by the law that applies to you — under the GDPR and the Swiss FADP, that is normally one month.
8.1. Access. You can ask us to confirm whether we process your personal data and to provide a copy.
8.2. Rectification. You can ask us to correct inaccurate personal data, or to complete incomplete data.
8.3. Erasure. You can ask us to delete your personal data. We will do so except where we are legally required to retain it — and in that case, only for the minimum period required.
8.4. Restriction and objection. You can ask us to restrict or stop certain processing, in particular where we rely on legitimate interests.
8.5. Portability. Where processing is based on your consent or on a contract, and is carried out by automated means, you can ask for a copy of your data in a structured, commonly used, machine-readable format. Note that your Twyn model is a proprietary representation and may not be exportable in a form usable outside the Twynity platform.
8.6. Withdraw consent. Where processing is based on your consent — including the processing of your biometric data — you can withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before it. On withdrawal of biometric consent we will delete your Twyn and underlying biometric data on the timelines in section 7.
8.7. Automated decision-making. We do not use your personal data to make decisions that produce legal or similarly significant effects on you without human involvement.
8.8. Lodge a complaint. You can lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland; or with your local EU/EEA data-protection authority; or, for UK residents, with the UK Information Commissioner's Office (ICO). Residents of US states with biometric or privacy statutes may have rights under those statutes and may contact the relevant state Attorney General.
9. How we protect your personal data
We apply technical and organisational measures proportionate to the sensitivity of the data, including:
- encryption in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent);
- role-based access controls on a need-to-know basis, with access logging and monitoring;
- segregated storage for biometric data, with the live-consent vault separated from the operational environment;
- regular vulnerability scanning and at least annual third-party penetration testing;
- security and confidentiality clauses in every subprocessor contract, with audit rights;
- an incident-response process with notification to you and to regulators where legally required (GDPR Art. 33–34).
A fuller description is available in the Twynity Security Overview at [twynity.ai/security — URL to be confirmed].
10. Cookies and tracking
The Twynity website and platform use a small number of cookies and similar technologies. Strictly necessary cookies (for example, authentication and security) are set without consent because the platform cannot function without them. All other cookies — including analytics and marketing cookies — are set only if you consent through our cookie banner. You can change your choices at any time from your account settings or by revisiting the cookie banner. See our Cookie Notice for the full list of cookies, their purposes and their durations.
11. Children
The Twynity platform is not intended for, nor available to, anyone under 18. We do not knowingly collect personal data from minors. If we learn that we have collected personal data from a minor, we will delete it and, where applicable, close the account.
12. Automated decision-making and profiling
We do not use your personal data to make decisions that produce legal or similarly significant effects on you through automated means alone. The Twynity platform performs automated checks during Twyn enrolment — liveness detection, face-match, voice-match and phrase-match — to verify your identity and protect you and others from impersonation. Where any of these checks fails, a human review is available on request before a final decision is made.
13. How enterprise deployments work
Where you use Twynity through an employer or another organisation that has contracted with 4th-IR, that organisation is the controller for personal data it provides to us and for the scope of use it configures. 4th-IR processes that data as a processor, on the organisation's instructions, under a written Data Processing Agreement.
For your own biometric data specifically, 4th-IR remains a joint controller with the organisation to the extent necessary to guarantee your personal rights — in particular your right to refuse to create a Twyn, to withdraw consent, and to have your biometric data deleted — regardless of what your employer has agreed. Those rights always sit with you.
If you have a question about how your employer configures Twynity, please contact your employer directly; if you have a question about how 4th-IR processes your data, contact us at info@4th-IR.com.
14. Links to other sites and services
The Twynity website and platform may contain links to third-party sites and services. We are not responsible for the privacy practices of those third parties. When you follow a link away from Twynity, please read the privacy notice of the destination site.
15. Changes to this policy
We may update this policy from time to time to reflect changes in the platform, in our practices, or in the law. Where a change is material we will notify you — by email, in-product, or on the Twynity website — at least 30 days before the change takes effect. Where a change requires renewed consent under applicable law (for example, under GDPR Art. 7(3) or FADP Art. 6(7)), we will ask for that consent before the change applies to you.
16. How to contact us
For any question about this policy or about how we process your personal data, contact:
- Data protection: info@4th-IR.com
- General enquiries: info@4th-IR.com
- Post: 4th-IR Group AG, Alpenstrasse 16, 6300 Zug, Switzerland.
Document control. Twynity Privacy Policy. Version 1.0 — April 2026. Issued by 4th-IR Group AG, Alpenstrasse 16, 6300 Zug, Switzerland. To be reviewed at least annually.
Related documents: Twynity Platform Terms of Use; Twynity Twyn Creation Terms; Twynity Biometric Data Notice; Twynity Live Consent Recording Script; Twynity Cookie Notice; Twynity Security Overview; Twynity Subprocessor List.