Twenty Growth Pte. Ltd. (UEN: 202621126H) ("Twenty Growth", "we", "us", or "our") respects your privacy and is committed to protecting personal data in accordance with the Singapore Personal Data Protection Act 2012 (PDPA) and other applicable data protection laws.
This Privacy Policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and how you can have it deleted. It applies to twentygrowth.co, the Twenty Growth application at app.twentygrowth.co, and the AI voice and WhatsApp agents we operate for our business customers (together, the "Services").
Read this section first, because the rest of the Policy depends on it.
If you contacted a business and its agent replied to you, that business is the controller of your data. Please direct access and deletion requests to that business first. If you cannot reach them, contact us using Section 19 and we will assist them in responding.
(a) Information provided directly:
(b) Information collected automatically:
(c) Information from third parties:
(d) Identity verification for phone number registration:
Singapore telephone numbers are allocated through licensed operators, and the operator must record who is behind each number. If you ask for a number registered in your business's own name, we collect your business registration profile, a government-issued ID of a director or authorised representative, and a recent proof of your business address. The documents are transmitted to our telecommunications carrier, which holds them for the registration. What we retain is a record of the check: the document type, its reference, and the date it was verified. We do not keep copies of the documents. Where a document carries an NRIC number, we collect it only because the carrier registration requires it, in line with the PDPC's advisory guidelines on NRIC numbers.
We do not knowingly collect personal data from individuals under 18 years of age.
When a business runs an agent on our platform, the following personal data about that business's own customers passes through our systems:
Businesses using our Services are responsible for having a lawful basis to collect this data and for telling their own customers how it is used, including that an automated agent may answer them and that calls may be recorded.
If you connect a WhatsApp Business account, we receive the following through Meta's APIs, with your authorisation:
We use this data only to operate the agent for the account it came from. Specifically, we do not:
Our use of this data is governed by the Meta Platform Terms, the WhatsApp Business Messaging Policy, and the WhatsApp Business Terms of Service. You may disconnect your WhatsApp Business account at any time from within the application, which stops all further data flow immediately. You can also revoke our access from your Meta Business Settings.
The Services are built on artificial intelligence. To generate a reply, the content of a conversation, together with the playbook and knowledge base documents you have provided, is sent to third-party AI model providers, described in Section 8(a). Voice calls are additionally converted to and from speech by those providers.
What this means in practice:
If you require a contractual commitment that a specific provider will not retain or train on your content, contact us before enabling your agent and we will confirm what is available.
This section applies if you connect a Google account to Twenty Growth. It is written to the Google Workspace API User Data and Developer Policy.
What we ask for, and why it is the narrowest thing that works. Twenty Growth requests exactly two OAuth scopes:
https://www.googleapis.com/auth/calendar.events — to read the busy times on your primary calendar so your agent never books a customer into a slot you already have, and to create, update, and cancel the appointment events your agent takes.https://www.googleapis.com/auth/userinfo.email — to show you which Google account is connected, so you can tell one from another and disconnect the right one.We deliberately do not request calendar.readonly, calendar.freebusy, or full calendar access. Availability is derived from the events our existing scope already covers, rather than by asking for a broader one. We read no other Google product: not Gmail, not Drive, not Contacts, not Photos.
What happens to it. Appointment details your agent creates, and the busy windows it reads to avoid a clash, are stored in your workspace and used to run your bookings, reminders, and reschedules. Free times derived from your calendar may be included in the text sent to the AI providers in Section 6 — for example, when a requested slot is taken and the agent has to offer the alternatives instead.
We do not use it to train AI. Google user data, whether raw, aggregated, anonymised, or otherwise derived, is never used by Twenty Growth to create, train, improve, or fine-tune any foundational or generalised machine learning or artificial intelligence model, and is never sold or transferred to anyone who would. We use AI providers only to generate a reply in the moment. Where a provider offers a setting or request flag that excludes providers which retain or train on submitted content, we set it: requests routed through OpenRouter carry data_collection: "deny", and where that leaves nothing available the request fails rather than falling through to a provider that would train on it.
Limited Use statement. Twenty Growth's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Disconnecting. You can disconnect Google Calendar at any time from Connections in the app. Disconnecting revokes our access token immediately. Appointments already in your workspace remain, because they are your business records; ask us under Section 19 if you want them deleted as well.
We do not sell personal data. We share it with the following categories of recipient:
(a) Service providers who help us run the Services. We share only the data a provider needs in order to perform its function, and never more. They fall into the following categories:
We do not publish the identity of each individual provider. The providers we use change as we improve the Services, and how the Services are built is confidential to us. If you are a customer and need these details for your own compliance or due diligence, email us using Section 19 and we will provide what you reasonably require.
(b) Other recipients:
You may withdraw consent at any time by contacting us (Section 19). Withdrawal may prevent us from continuing to provide the Services.
We are established in Singapore and the PDPA governs our processing. Where the data protection law of another country you are located in also applies, we process on the equivalent basis available under that law.
Several of the providers in Section 8 are located outside Singapore, principally in the United States and the European Union. Where we transfer personal data out of Singapore we take reasonable steps under the PDPA to satisfy ourselves that it will receive a comparable standard of protection.
You can ask us to delete your personal data at any time, and we will do so unless the law requires us to keep it.
The fastest route is to do it yourself. Signed in to app.twentygrowth.co you can delete individual conversations, contacts, recordings, and uploaded documents, disconnect your WhatsApp Business account, and close your workspace entirely.
To ask us to do it, email contact@twentygrowth.co with the subject line "Data deletion request", telling us the email address or WhatsApp number the data relates to. We will acknowledge your request with a reference number within five (5) business days and complete it within thirty (30) days.
Full step-by-step instructions, including what is deleted, what we must keep, and how to check the status of your request, are on our Data Deletion page.
If your data reached us through WhatsApp, deleting it here does not delete the copy held in your own WhatsApp account or by Meta. See Meta's own tools for that.
We use cookies and similar technologies to operate the website, remember your preferences, analyse traffic, and improve the Services. Analytics cookies collect aggregated, non-identifying usage data. You can control cookies through your browser settings or through our cookie consent banner; disabling some cookies may affect functionality. For full details, see our Cookie Policy.
We protect personal data with administrative and technical safeguards appropriate to the risk. These include encryption of data in transit and at rest, isolation of each customer's workspace from every other, passwords stored only as salted hashes, access controls and audit logging, and limiting staff access to what a task actually requires. The physical security of the facilities where data is stored is the responsibility of our infrastructure providers. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a data breach affecting you occurs, we will notify you and the Personal Data Protection Commission as required by the PDPA.
Subject to the conditions and exceptions in the PDPA, you have the right to:
We respond to verified requests within thirty (30) days, or sooner where the law applying to you requires it. We may charge a reasonable fee for access requests, as permitted under the PDPA. We may need to verify your identity before acting. Where another data protection law gives you a right this list does not mention, you can exercise it with us the same way, using the contact details in Section 19.
Businesses using our Services must obtain opt-in before sending WhatsApp messages, as required by the WhatsApp Business Messaging Policy, and must make it clear who is messaging and what the messages will be about.
Before a marketing call or message is sent to a Singapore telephone number through our platform, we check that number against Singapore's Do Not Call Registry, as section 43A of the PDPA provides for. A result is relied on for up to 21 days from the date it is received, the period the law prescribes; after that, the number is checked again. The business sees the date each result was received and how long it remains valid.
If you want a business using Twenty Growth to stop contacting you, reply STOP to its WhatsApp conversation or say so on a call. We record the opt-out and suppress future marketing contact across both calls and messages, and it overrides any consent the business previously relied on. You can also block the number in WhatsApp. To have your data deleted as well, follow Section 12.
Where you have consented or where permitted by law, we may send you marketing about our Services. You can opt out at any time by clicking "unsubscribe" in any marketing email, or by emailing contact@twentygrowth.co. Opting out of marketing does not stop transactional or service messages.
Our website and application may link to third-party sites. We are not responsible for their privacy practices; review their policies separately.
We may update this Policy. The current version is always at twentygrowth.co/privacy with a revised "Last updated" date. We will tell you about material changes by email or in the application before they take effect.
For any question, request, or complaint about this Policy or how we handle personal data, including access and deletion requests, contact our data protection contact:
Twenty Growth Pte. Ltd. (UEN: 202621126H)
Email: contact@twentygrowth.co
Website: twentygrowth.co
Singapore
If we cannot resolve your complaint, you may refer it to the Personal Data Protection Commission of Singapore at pdpc.gov.sg.
© 2025 Twenty Growth Pte. Ltd. (UEN: 202621126H) · Singapore