Privacy Policy
Last updated: 2026-04-22
This Privacy Policy explains how Neonworks Consulting Limited ("Twendie," "we," "us," or "our ") collects, uses, discloses, and protects personal data when you visit https://twendie.com, use our applications, or otherwise interact with us.
Twendie is a software-as-a-service platform used by travel agencies and travel professionals. This Policy applies to (a) the travel professionals and agencies who subscribe to our service ("Customers") and their authorised users, and (b) the travellers and prospects who interact with our Customers through our platform ("End Users"). Our respective roles for each category are explained in section 3.
1. Who we are
The data controller for personal data covered by this Policy is Neonworks Consulting Limited, a company incorporated in Kenya (registration number PVT-A71MK8ZJ), with its registered office at Ruaka, Banana Road, Nairobi, 00400, Kenya.
For privacy questions, contact us at privacy@twendie.com. For data protection matters escalated to our Data Protection Officer, use dpo@twendie.com.
EU and UK representatives
Where Article 27 of the EU GDPR or UK GDPR applies, we are in the process of appointing representatives in the European Economic Area and the United Kingdom. In the interim, data subjects in the EU/UK may raise any data protection matter directly with our Data Protection Officer at dpo@twendie.com, and we will respond within the timeframes required by applicable law.
2. Scope
This Policy applies to personal data we process in connection with our websites, applications, and services (collectively, the "Service"). It does not apply to third-party websites, applications, or services that we do not own or control, including sites linked from our Service.
If you are a traveller or prospect interacting with a travel agency that uses Twendie, that agency is primarily responsible for your personal data. Please also read our End-User Notice.
3. Our roles (controller vs processor)
Under data protection laws such as the EU and UK GDPR and the Kenya Data Protection Act, 2019, our role depends on the data in question.
When we act as a controller
We are the controller of personal data relating to:
- visitors to https://twendie.com and our marketing pages (including cookie and analytics data);
- Customer account holders and their authorised users (account administration, billing, support, security);
- prospects, sales leads, and individuals who contact us directly;
- individuals whose data we process to comply with legal obligations or to defend legal claims.
When we act as a processor
When a Customer uses the Service to manage their own clients, itineraries, communications, and bookings, the Customer is the controller of the End User personal data in that Customer's workspace. Twendie is a processor that handles that data on the Customer's documented instructions under our Data Processing Addendum. Requests from End Users to exercise data rights over data in a Customer workspace should be directed to the relevant Customer; we will assist Customers in responding.
4. Personal data we collect
Data you provide directly
- Account data: name, email, password hash, profile photo, phone, role and organisation name.
- Billing data: plan, billing address, tax ID, invoices, last four digits and brand of payment card. Full card numbers are collected and held by our payment processors and are never stored by Twendie.
- Content you upload: traveller contact details, itineraries, documents, messages, pricing, branding assets, and any other data you or your authorised users enter into the Service.
- Support data: messages, attachments, and diagnostic information you send when you contact us.
Data we collect automatically
- Device and log data: IP address, browser, OS, device identifiers, referrer, pages viewed, timestamps, and error diagnostics.
- Cookies and similar technologies: see our Cookie Policy.
- Usage data: feature usage, session length, and clickstream data we use to improve the Service.
Data from integrations you connect
- Google Workspace and Gmail: when a Customer connects a Gmail mailbox, we request OAuth scopes only for the purpose of reading and sending the messages necessary to operate the email channel. We do not use Google Workspace APIs data to develop, improve, or train generalised or non-personalised AI or machine learning models. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Other email and messaging providers: we integrate with Unipile to connect mailboxes and messaging channels on behalf of Customers. Message content transits and is stored consistent with this Policy.
- Google Maps and Places: we use these APIs to look up addresses and render maps. We store only the place identifier and the address string you select; we do not permanently store coordinates or other Google place details. Your use is also subject to Google's privacy policy.
5. How we use personal data
We use personal data to provide, maintain, secure, and improve the Service. In particular, we use data to:
- create and manage accounts, authenticate users, and support you;
- deliver Service features, including AI-assisted itineraries;
- process payments, issue invoices, and collect amounts due;
- send service and security notices, and (with your consent where required) marketing communications;
- detect, prevent, and investigate fraud, abuse, security incidents, and violations of our Acceptable Use Policy;
- monitor and improve performance, reliability, and product quality, including by running aggregated and de-identified analytics;
- comply with legal obligations and enforce our agreements and rights.
6. AI processing and automated decisions
The Service includes AI-assisted features (currently powered by Google Gemini) that help draft responses, build itineraries, and generate pricing suggestions. These features process data you or your authorised users submit to produce suggested outputs.
- We instruct our AI sub-processors not to use your content to train their general foundation models.
- AI outputs are drafts intended for human review. They may be inaccurate, incomplete, or out of date. Customers are responsible for reviewing outputs before relying on them or sending them to travellers.
- We do not use AI to make decisions that produce legal or similarly significant effects on individuals without human review.
7. Legal bases (EEA, UK, and similar regimes)
Where EU or UK GDPR applies, we rely on the following legal bases:
- Contract: to provide the Service you or your organisation has subscribed to.
- Legitimate interests: to secure, improve, and market the Service, and to handle enquiries, where those interests are not overridden by your rights.
- Consent: for non-essential cookies, optional marketing communications, and (where required) certain integrations. You can withdraw consent at any time.
- Legal obligation: to meet accounting, tax, and other statutory requirements.
9. International data transfers
Twendie operates from Kenya and uses sub-processors based in various jurisdictions, including the United States and the European Union. When personal data is transferred outside your country, we rely on appropriate safeguards, including:
- the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum where data originates from the EEA or UK;
- adequacy decisions where available;
- contractual and technical safeguards required by the Kenya Data Protection Act, 2019.
You can request a copy of the relevant safeguards by emailing privacy@twendie.com.
10. Data retention
We retain personal data as follows:
- Customer account and content: for the term of the subscription and up to 90 days after termination, unless the Customer instructs earlier deletion or a longer period is required by law.
- Billing and tax records: up to 7 years after the relevant transaction, as required by applicable tax and accounting laws.
- Security, audit, and diagnostic logs: typically up to 12 months.
- Marketing contacts: until you withdraw consent or opt out, and for a reasonable period thereafter for suppression-list purposes.
- Support communications: up to 3 years after the interaction.
After the retention period, we delete or irreversibly anonymise personal data.
11. Your rights
Subject to local law, you have rights over your personal data, including the right to:
- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- delete your personal data;
- restrict or object to certain processing;
- receive your data in a portable format and, where feasible, transmit it to another controller;
- withdraw consent at any time where processing is based on consent;
- lodge a complaint with a supervisory authority, such as the Office of the Data Protection Commissioner (Kenya), your local EU Data Protection Authority, or the UK Information Commissioner's Office.
California and other US state rights
If you are a California resident, you have rights under the California Consumer Privacy Act (as amended by the CPRA), including the right to know, delete, correct, and limit the use of sensitive personal information, and the right not to be discriminated against for exercising your rights. Similar rights apply under the laws of Colorado, Connecticut, Virginia, Utah, and other US states.
We do not sell personal information and we do not share personal information for cross-context behavioural advertising as those terms are defined by the CCPA.
How to exercise your rights
Email privacy@twendie.com from the email address associated with your account. We will verify your identity and respond within the timeframe required by applicable law (typically 30 days, extendable where permitted). If your data is held in a Customer workspace, we will forward your request to the relevant Customer and assist them in responding.
12. Security
We maintain administrative, technical, and physical safeguards designed to protect personal data, including:
- encryption in transit (TLS) and at rest for primary data stores;
- least-privilege access controls and multi-factor authentication for staff;
- logging, monitoring, and automated alerting on production systems;
- secure software development practices, dependency scanning, and periodic third-party testing;
- vendor due diligence and contractually-binding security requirements on sub-processors.
No system is perfectly secure. You are responsible for keeping your credentials confidential and notifying us of any suspected unauthorised access at support@twendie.com.
13. Children
The Service is not directed to children under 16 and we do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact privacy@twendie.com and we will take steps to delete it.
14. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date at the top of this page shows when changes were made. Material changes will be notified via the Service or by email. Continued use of the Service after an update constitutes acceptance of the updated Policy to the extent permitted by law.
15. Contact
For any privacy question or request, write to us at:
- Email (privacy): privacy@twendie.com
- Email (DPO): dpo@twendie.com
- Post: Neonworks Consulting Limited, Ruaka, Banana Road, Nairobi, 00400, Kenya