0 hits
Back
TIWORA.
Privacy · UK GDPR / DPA 2018

Privacy Policy

Effective as of February 1st, 2026Last revised 10 February 2026 (v1.1.0) England & Wales, United Kingdom Belkhiria LTD (trading as Tiwora) · Co. No. 16382308

This Policy explains the personal data we collect through Tiwora, the purpose and legal basis for each processing operation, how long we retain it, and the rights you may exercise at any time.

§01

Data Controller

The data controller responsible for personal data processed through Tiwora is Belkhiria LTD (trading as Tiwora), registered in England & Wales, United Kingdom. All requests concerning this Privacy Policy or your personal data can be addressed to contact@tiwora.com.

We process personal data in compliance with the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, and — where applicable to EU users — the EU General Data Protection Regulation (Regulation (EU) 2016/679).

§02

Data We Collect

We only collect what is strictly necessary to operate the Service. Categories of personal data include:

  • Account data — the email address you use to sign up, an optional first name, and a securely hashed representation of your password (we never store plaintext passwords).
  • Authentication metadata — timestamps of successful and failed login attempts, IP addresses used for signing in, and the origin of your active session cookies. This is used to detect and throttle brute-force attempts.
  • Billing data — a Stripe customer identifier, subscription identifier, plan tier, and renewal timestamps returned to us by Stripe. We do not receive or store your card number, CVC, or full IBAN — these are handled directly by Stripe under PCI-DSS Level 1 controls.
  • Search & usage data — the sector, city, and radius parameters you supply to the search engine, the timestamps of your queries, and the identifiers of Google Places results returned. Search parameters are kept in a temporary 90-day cache so that repeated queries do not re-hit the paid Google Places API.
  • AI interaction data — the prompts you send to the AI chatbot and the copywriter, together with our responses, are retained only for the length of the conversation session so the assistant can preserve short-term context.
  • Operational logs — high-level application logs (endpoint, HTTP status, error stack traces) used for diagnostics. These logs are not designed to identify individuals and are purged on a rolling schedule.

We do not collect special-category personal data (health, political opinions, ethnicity, etc.). If you accidentally submit such information through a free-text field, please contact us at contact@tiwora.com so we can remove it.

§03

Purpose & Legal Basis

Each category of personal data is processed for one or more of the following purposes, under a corresponding legal basis of the UK GDPR:

  • Delivering the Service (contractual necessity, Art. 6(1)(b)): providing lead extraction, AI audits, outreach tools, and Stripe-backed billing that you have subscribed to.
  • Keeping the platform secure (legitimate interest, Art. 6(1)(f)): detecting abuse, throttling brute-force login attempts, preventing scraping, and preserving evidence when required.
  • Complying with legal obligations (Art. 6(1)(c)): retaining invoicing records for the periods required by UK tax law, and responding to lawful requests from regulatory authorities.
  • Communicating essential service messages (contractual necessity): password reset emails, security-alert notifications after credential changes, and material updates to these documents.
§04

Payments & Stripe Integration

All payment processing is delegated to Stripe Payments Europe, Ltd. When you enter payment information, that data is transmitted directly from your browser to Stripe over an encrypted TLS channel. Tiwora receives back only non-sensitive descriptors — the Stripe customer id, subscription id, tier, currency, and current-period-end timestamp — which are stored to reconcile your account.

Stripe acts as an independent data controller for your payment credentials. You can review Stripe's own privacy notice at https://stripe.com/privacy. When you close your Tiwora subscription, we retain the Stripe descriptors above for the duration required by UK accounting and tax law (currently six years) before secure deletion.

§05

Google Places Queries

The B2B search engine invokes the Google Places API on your behalf. Your parameters (sector, city, radius) and the resulting place identifiers are cached in our infrastructure for up to ninety (90) days to reduce cost and latency for repeated searches. The cache never contains your personal contact details or any subjective judgement about the businesses returned — only public place data as exposed by Google.

Use of the Service that involves Google Places is additionally governed by the Google Maps Platform Terms of Service and Google's own privacy policy at https://policies.google.com/privacy.

§06

Recipients & Sub-processors

We do not sell your personal data. We share it only with the sub-processors strictly required to run the Service, each bound by a data-processing agreement compliant with UK GDPR Art. 28:

  • Stripe Payments Europe, Ltd. — payment processing and subscription management.
  • Google LLC / Google Ireland Ltd. — the Places API responds to the searches you initiate.
  • OpenAI, LLC — supplies the underlying model that powers the chatbot, lead audits, and copywriter, in accordance with OpenAI's zero-retention business terms.
  • Resend Inc. — dispatches transactional email (password reset, security notifications) when enabled.
  • Our hosting and database providers, operating from data centres located in the United Kingdom and the European Economic Area.

Where a sub-processor is located outside the UK or the EEA, the transfer is protected by the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, together with any supplementary technical safeguards required by the Schrems II ruling.

§07

Data Retention

Account data is retained for as long as your account remains open, plus the shortest period required by law after closure. Specifically:

  • Account and authentication data: deleted within thirty (30) days of account closure, except where retention is required to defend a legal claim.
  • Billing and invoicing records: retained for six (6) years after the end of the tax year in which the transaction occurred (UK statutory requirement).
  • Google Places search cache: automatically expired after ninety (90) days.
  • Password reset tokens: deleted after use, or auto-expired after thirty (30) minutes if unused (Mongo TTL index).
  • AI conversation context: purged at the end of the session or after seven (7) days of inactivity, whichever comes first.
§08

Your Rights (GDPR & UK DPA)

Under UK GDPR and the Data Protection Act 2018 you have the following rights concerning your personal data:

  • Right of access — obtain a copy of the personal data we hold about you.
  • Right to rectification — correct any inaccurate or incomplete information.
  • Right to erasure ("right to be forgotten") — request deletion of your data, subject to overriding legal-retention obligations.
  • Right to restrict processing — pause the use of your data while a dispute is investigated.
  • Right to data portability — receive your data in a structured, commonly used, machine-readable format.
  • Right to object — object to processing based on our legitimate interests.
  • Right to withdraw consent — where consent was the legal basis, without affecting the lawfulness of processing carried out before withdrawal.
  • Right to lodge a complaint with a supervisory authority — the UK Information Commissioner's Office (ICO) at https://ico.org.uk, or your local EU supervisory authority.

To exercise any of these rights, contact contact@tiwora.com. We will respond within one (1) calendar month, or advise you of any extension permitted under UK GDPR Art. 12(3). We may ask for information reasonably necessary to verify your identity before actioning a request, to protect against unauthorised disclosure.

§09

Security

We implement industry-standard technical and organisational measures to protect your data, including TLS 1.2+ for all data in transit, encryption at rest for the primary database, bcrypt hashing of user passwords, HTTP-only cookies with same-site protection for session tokens, and strict least-privilege access controls on internal tooling. Despite these safeguards, no online service can guarantee absolute security — you play a role by choosing a strong password and keeping your credentials confidential.

§10

Cookies & Local Storage

Tiwora uses a small number of strictly necessary cookies (authentication session, CSRF protection) and lightweight browser local storage to remember your language preference and cached user identifier. We do not use third-party advertising or cross-site tracking cookies. Because these cookies are strictly necessary or functional, they do not require prior consent under the UK PECR framework.

§11

Minors

The Service is a B2B product and is not directed at children. We do not knowingly collect personal data from anyone under the age of sixteen (16). If you believe a minor has provided us with personal data, contact contact@tiwora.com and we will remove it.

§12

Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will update the "Effective as of" date at the top of this page and, where the change is material, notify you by email at the address on file at least thirty (30) days before it takes effect.

§13

Contact

To exercise your rights or ask any question about this Privacy Policy, please contact us at contact@tiwora.com. Written correspondence may be addressed to Belkhiria LTD (trading as Tiwora), registered office in the United Kingdom.

§14

Version history

  1. v1.1.010 February 2026Current

    Added Companies House registration number and public version history.

  2. v1.0.01 February 2026

    Initial published Privacy Policy — UK GDPR compliance, sub-processors, retention timelines.

Contact us
Any request related to this document should be sent to contact@tiwora.com.
Belkhiria LTD (trading as Tiwora)
Registered in England & Wales, United Kingdom · Companies House number 16382308