Twenty Growth

Privacy Policy

Last updated: 9 August 2026

Twenty Growth Pte. Ltd. (UEN: 202621126H) ("Twenty Growth", "we", "us", or "our") respects your privacy and is committed to protecting personal data in accordance with the Singapore Personal Data Protection Act 2012 (PDPA) and other applicable data protection laws.

This Privacy Policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and how you can have it deleted. It applies to twentygrowth.co, the Twenty Growth application at app.twentygrowth.co, and the AI voice and WhatsApp agents we operate for our business customers (together, the "Services").

1. The two roles we play

Read this section first, because the rest of the Policy depends on it.

  • We are the controller of personal data about our business customers: the people who create an account, run a workspace, and pay for the Services. We decide why and how that data is used, and this Policy governs it.
  • We are a processor (a data intermediary under the PDPA) for personal data about our customers' own customers: the people who call a business or message it on WhatsApp and are answered by an agent. That business decides why that data is collected. We process it on their written instructions, under our customer agreement, and we do not use it for our own purposes.

If you contacted a business and its agent replied to you, that business is the controller of your data. Please direct access and deletion requests to that business first. If you cannot reach them, contact us using Section 19 and we will assist them in responding.

2. Personal data we collect about our customers

(a) Information provided directly:

  • Name, job title, business name, business registration details
  • Email address, phone number, WhatsApp number
  • Account credentials (passwords are stored only as salted hashes, never in readable form)
  • Billing and payment information (card details are handled by our payment providers and are never stored on our systems)
  • Content you send us: enquiries, support requests, and documents you upload

(b) Information collected automatically:

  • IP address, browser type, device identifiers
  • Pages visited, features used, time spent, referral source
  • Application logs, error reports, and audit records of actions taken in your workspace
  • Cookies and similar technologies (see Section 13 and our Cookie Policy)

(c) Information from third parties:

  • Google, if you choose to sign in with Google or connect Google Calendar: your name, email address, profile picture, and the calendar availability you authorise
  • Meta, if you connect a WhatsApp Business account (see Section 4)
  • Publicly available business information, where you have made it available or where we look it up on your instruction

(d) Identity verification for phone number registration:

Singapore telephone numbers are allocated through licensed operators, and the operator must record who is behind each number. If you ask for a number registered in your business's own name, we collect your business registration profile, a government-issued ID of a director or authorised representative, and a recent proof of your business address. The documents are transmitted to our telecommunications carrier, which holds them for the registration. What we retain is a record of the check: the document type, its reference, and the date it was verified. We do not keep copies of the documents. Where a document carries an NRIC number, we collect it only because the carrier registration requires it, in line with the PDPC's advisory guidelines on NRIC numbers.

We do not knowingly collect personal data from individuals under 18 years of age.

3. Data we process on behalf of our customers

When a business runs an agent on our platform, the following personal data about that business's own customers passes through our systems:

  • WhatsApp conversations: message content, the sender's phone number and WhatsApp profile name, images, documents and voice notes sent to the business, timestamps, and delivery and read status
  • Telephone calls: caller phone number, call audio, call recordings where the business has enabled recording, machine-generated transcripts and summaries, call duration and outcome
  • Contact and enquiry records: names, contact details, bookings, appointments, orders, and any other details a caller or messager provides during a conversation
  • Knowledge base content: documents, price lists, menus, and policies that the business uploads so its agent can answer from them

Businesses using our Services are responsible for having a lawful basis to collect this data and for telling their own customers how it is used, including that an automated agent may answer them and that calls may be recorded.

4. Data we receive from Meta and the WhatsApp Business Platform

If you connect a WhatsApp Business account, we receive the following through Meta's APIs, with your authorisation:

  • Your WhatsApp Business Account ID, phone number ID, verified display name, and business profile details
  • Inbound message content and metadata, including the sender's phone number and WhatsApp profile name
  • Message delivery, read, and failure statuses for messages your agent sends
  • Template approval status and quality ratings for your account

We use this data only to operate the agent for the account it came from. Specifically, we do not:

  • sell it, licence it, or transfer it to data brokers or information resellers;
  • use it for advertising, ad targeting, or building advertising profiles;
  • combine it with data from other customers to create cross-business profiles of individuals; or
  • use it for any purpose other than providing the Services to the customer who authorised the connection.

Our use of this data is governed by the Meta Platform Terms, the WhatsApp Business Messaging Policy, and the WhatsApp Business Terms of Service. You may disconnect your WhatsApp Business account at any time from within the application, which stops all further data flow immediately. You can also revoke our access from your Meta Business Settings.

5. Why we use personal data

  • to create and administer your account and workspace;
  • to operate your agent: answering calls and messages, booking appointments, and updating the tools you have connected;
  • to meter usage and bill you accurately;
  • to provide support and respond to your enquiries;
  • to send service messages about outages, security, billing, and changes to the Services;
  • to send marketing about our Services where you have consented or where permitted by law;
  • to maintain security, detect and prevent fraud and abuse, and investigate incidents;
  • to improve the reliability and quality of the Services, using aggregated or de-identified data wherever it is sufficient;
  • to comply with legal, regulatory, accounting, and tax obligations;
  • for any other purpose for which you have given consent.

6. Automated decision-making and AI processing

The Services are built on artificial intelligence. To generate a reply, the content of a conversation, together with the playbook and knowledge base documents you have provided, is sent to third-party AI model providers, described in Section 8(a). Voice calls are additionally converted to and from speech by those providers.

What this means in practice:

  • Conversation content leaves our infrastructure and is processed by the AI providers we use.
  • Each provider's own terms govern how long they retain what is submitted to them.
  • Agents are configured never to request card numbers, passwords, or one-time codes in a conversation, and to offer a secure payment link instead.
  • An agent's reply is generated automatically. You control the boundaries it works within, and it hands over to a human on request. No decision producing a legal or similarly significant effect on an individual is made solely by the agent.

If you require a contractual commitment that a specific provider will not retain or train on your content, contact us before enabling your agent and we will confirm what is available.

7. Google Workspace data and the Limited Use requirements

This section applies if you connect a Google account to Twenty Growth. It is written to the Google Workspace API User Data and Developer Policy.

What we ask for, and why it is the narrowest thing that works. Twenty Growth requests exactly two OAuth scopes:

  • https://www.googleapis.com/auth/calendar.events — to read the busy times on your primary calendar so your agent never books a customer into a slot you already have, and to create, update, and cancel the appointment events your agent takes.
  • https://www.googleapis.com/auth/userinfo.email — to show you which Google account is connected, so you can tell one from another and disconnect the right one.

We deliberately do not request calendar.readonly, calendar.freebusy, or full calendar access. Availability is derived from the events our existing scope already covers, rather than by asking for a broader one. We read no other Google product: not Gmail, not Drive, not Contacts, not Photos.

What happens to it. Appointment details your agent creates, and the busy windows it reads to avoid a clash, are stored in your workspace and used to run your bookings, reminders, and reschedules. Free times derived from your calendar may be included in the text sent to the AI providers in Section 6 — for example, when a requested slot is taken and the agent has to offer the alternatives instead.

We do not use it to train AI. Google user data, whether raw, aggregated, anonymised, or otherwise derived, is never used by Twenty Growth to create, train, improve, or fine-tune any foundational or generalised machine learning or artificial intelligence model, and is never sold or transferred to anyone who would. We use AI providers only to generate a reply in the moment. Where a provider offers a setting or request flag that excludes providers which retain or train on submitted content, we set it: requests routed through OpenRouter carry data_collection: "deny", and where that leaves nothing available the request fails rather than falling through to a provider that would train on it.

Limited Use statement. Twenty Growth's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

Disconnecting. You can disconnect Google Calendar at any time from Connections in the app. Disconnecting revokes our access token immediately. Appointments already in your workspace remain, because they are your business records; ask us under Section 19 if you want them deleted as well.

8. Who we share personal data with

We do not sell personal data. We share it with the following categories of recipient:

(a) Service providers who help us run the Services. We share only the data a provider needs in order to perform its function, and never more. They fall into the following categories:

  • Messaging platforms, to send and receive WhatsApp messages. This is Meta, as described in Section 4.
  • Telecommunications carriers, to provide telephone numbers, carry call audio, and register numbers in your name where you request it. The verification documents described in Section 2(d) are transmitted to the carrier for that purpose.
  • Artificial intelligence providers, to convert speech and generate your agent's replies, as described in Section 6.
  • Cloud infrastructure and storage providers, to host the application, the database, call recordings, and uploaded documents.
  • Email and notification providers, to send account, billing, and service messages.
  • Payment providers, to take payment and manage subscriptions. They receive your billing details directly. We never see or store full card numbers.
  • Calendar and productivity providers, where you choose to connect them to your agent.

We do not publish the identity of each individual provider. The providers we use change as we improve the Services, and how the Services are built is confidential to us. If you are a customer and need these details for your own compliance or due diligence, email us using Section 19 and we will provide what you reasonably require.

(b) Other recipients:

  • Professional advisers such as lawyers, accountants, and auditors, under a duty of confidence;
  • Government authorities, regulators, or law enforcement, where required by law or to establish, exercise, or defend legal claims;
  • An acquirer or successor in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy continuing to apply;
  • Any other party you direct us to, with your consent.

9. Legal basis under the PDPA

  • Consent, express or deemed, for the relevant purpose;
  • Contractual necessity, to provide the Services you have signed up for;
  • Legitimate interests, where permitted under the PDPA, including business management, security, fraud prevention, and service improvement;
  • Legal obligation, to comply with applicable law.

You may withdraw consent at any time by contacting us (Section 19). Withdrawal may prevent us from continuing to provide the Services.

We are established in Singapore and the PDPA governs our processing. Where the data protection law of another country you are located in also applies, we process on the equivalent basis available under that law.

10. International transfers

Several of the providers in Section 8 are located outside Singapore, principally in the United States and the European Union. Where we transfer personal data out of Singapore we take reasonable steps under the PDPA to satisfy ourselves that it will receive a comparable standard of protection.

11. How long we keep data

  • Account and billing records: for the life of the account, then up to seven (7) years to meet Singapore accounting and tax requirements.
  • Conversation transcripts, message history, and contact records: for the life of the workspace, unless you delete them sooner. You can delete individual conversations and contacts at any time from within the application.
  • Call recordings: retained only where the business has enabled recording, and deletable at any time from within the application.
  • Knowledge base documents: until you remove them.
  • Identity verification records: the record of the check described in Section 2(d), for as long as the number remains registered and afterwards while we need to show the registration was properly made. The documents themselves are held by our carrier under its own retention rules.
  • After a subscription ends: your workspace remains available in read-only form for ninety (90) days so you can export your data or renew. After that period we delete or irreversibly anonymise it, except where we are required to retain records by law.
  • Application and security logs: for a limited period, and no longer than we need them to run the Services securely and investigate problems.
  • Aggregated or anonymised data that can no longer identify anyone may be kept indefinitely.

12. Deleting your data

You can ask us to delete your personal data at any time, and we will do so unless the law requires us to keep it.

The fastest route is to do it yourself. Signed in to app.twentygrowth.co you can delete individual conversations, contacts, recordings, and uploaded documents, disconnect your WhatsApp Business account, and close your workspace entirely.

To ask us to do it, email contact@twentygrowth.co with the subject line "Data deletion request", telling us the email address or WhatsApp number the data relates to. We will acknowledge your request with a reference number within five (5) business days and complete it within thirty (30) days.

Full step-by-step instructions, including what is deleted, what we must keep, and how to check the status of your request, are on our Data Deletion page.

If your data reached us through WhatsApp, deleting it here does not delete the copy held in your own WhatsApp account or by Meta. See Meta's own tools for that.

13. Cookies and tracking

We use cookies and similar technologies to operate the website, remember your preferences, analyse traffic, and improve the Services. Analytics cookies collect aggregated, non-identifying usage data. You can control cookies through your browser settings or through our cookie consent banner; disabling some cookies may affect functionality. For full details, see our Cookie Policy.

14. Security

We protect personal data with administrative and technical safeguards appropriate to the risk. These include encryption of data in transit and at rest, isolation of each customer's workspace from every other, passwords stored only as salted hashes, access controls and audit logging, and limiting staff access to what a task actually requires. The physical security of the facilities where data is stored is the responsibility of our infrastructure providers. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a data breach affecting you occurs, we will notify you and the Personal Data Protection Commission as required by the PDPA.

15. Your rights under the PDPA

Subject to the conditions and exceptions in the PDPA, you have the right to:

  • Access the personal data we hold about you and information about how it has been used or disclosed in the past year;
  • Correct personal data that is inaccurate or incomplete;
  • Delete your personal data, as described in Section 12;
  • Withdraw consent to the collection, use, or disclosure of your personal data;
  • Port your data by exporting it from the application in a machine-readable format;
  • Request information about our data protection policies and practices;
  • Complain to the Personal Data Protection Commission (PDPC) of Singapore at pdpc.gov.sg if you are not satisfied with our response, or to your own data protection authority where another law applies to you.

We respond to verified requests within thirty (30) days, or sooner where the law applying to you requires it. We may charge a reasonable fee for access requests, as permitted under the PDPA. We may need to verify your identity before acting. Where another data protection law gives you a right this list does not mention, you can exercise it with us the same way, using the contact details in Section 19.

16. Marketing messages, the Do Not Call Registry, and opting out

Businesses using our Services must obtain opt-in before sending WhatsApp messages, as required by the WhatsApp Business Messaging Policy, and must make it clear who is messaging and what the messages will be about.

Before a marketing call or message is sent to a Singapore telephone number through our platform, we check that number against Singapore's Do Not Call Registry, as section 43A of the PDPA provides for. A result is relied on for up to 21 days from the date it is received, the period the law prescribes; after that, the number is checked again. The business sees the date each result was received and how long it remains valid.

If you want a business using Twenty Growth to stop contacting you, reply STOP to its WhatsApp conversation or say so on a call. We record the opt-out and suppress future marketing contact across both calls and messages, and it overrides any consent the business previously relied on. You can also block the number in WhatsApp. To have your data deleted as well, follow Section 12.

17. Marketing from Twenty Growth

Where you have consented or where permitted by law, we may send you marketing about our Services. You can opt out at any time by clicking "unsubscribe" in any marketing email, or by emailing contact@twentygrowth.co. Opting out of marketing does not stop transactional or service messages.

18. Third-party links and changes to this Policy

Our website and application may link to third-party sites. We are not responsible for their privacy practices; review their policies separately.

We may update this Policy. The current version is always at twentygrowth.co/privacy with a revised "Last updated" date. We will tell you about material changes by email or in the application before they take effect.

19. Contact us

For any question, request, or complaint about this Policy or how we handle personal data, including access and deletion requests, contact our data protection contact:

Twenty Growth Pte. Ltd. (UEN: 202621126H)
Email: contact@twentygrowth.co
Website: twentygrowth.co
Singapore

If we cannot resolve your complaint, you may refer it to the Personal Data Protection Commission of Singapore at pdpc.gov.sg.

© 2025 Twenty Growth Pte. Ltd. (UEN: 202621126H) · Singapore