Legal
Privacy Policy
Last updated: 22 August 2026
1. Data Controller
The data controller responsible for processing your personal data is:
- Company: Swiftly Workspace
- Registration number: BE1012954172
- Address: Borsbeeksebrug 34, 2600 Antwerpen, Belgium
- Email: info@swiftly-workspace.com
Swiftly Workspace is established in Belgium and is subject to the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the Belgian Data Protection Act of 30 July 2018, and the ePrivacy Directive 2002/58/EC as transposed into Belgian law.
2. What Personal Data We Collect
We collect and process the following categories of personal data depending on your interaction with our services:
2.1 Website Visitors
- Technical data: IP address (anonymized where possible), browser type and version, operating system, device type, screen resolution, and referring URL
- Usage data: Pages visited, time and date of visit, time spent on pages, click patterns, and scroll depth (collected via Google Analytics only with your consent)
- Cookie data: Your cookie consent preferences (stored in your browser’s localStorage)
2.2 Newsletter Subscribers
- Contact data: Email address, and optionally your name
- Subscription data: Date and time of subscription, consent record
2.3 Clients and Business Contacts
- Identity data: Name, job title, company name
- Contact data: Email address, phone number, business address
- Financial data: Invoicing details, VAT number, payment information (processed through our payment service provider)
- Communication data: Records of correspondence via email, contact forms, or video calls
2.4 Recruitment Portal Users
- Account data: Email address, password (encrypted), user role
- Session data: Session identifiers stored via HTTP-only cookies (4-hour expiry)
3. Legal Bases for Processing
Under Article 6 of the GDPR, we process your personal data based on the following legal grounds:
3.1 Consent (Art. 6(1)(a) GDPR)
- Setting non-essential cookies (analytics, marketing) on your device
- Sending you our newsletter
- Processing data through third-party embedded content (GoHighLevel forms)
You have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
3.2 Contract Performance (Art. 6(1)(b) GDPR)
- Processing client data necessary to deliver our services
- Managing project communications and deliverables
- Processing payments and invoicing
3.3 Legitimate Interests (Art. 6(1)(f) GDPR)
- Operating and maintaining our website (essential cookies and technical infrastructure)
- Improving our services based on aggregated, anonymized analytics data
- Ensuring network and information security
- Internal administration and record-keeping
3.4 Legal Obligation (Art. 6(1)(c) GDPR)
- Retaining invoicing and financial records as required by Belgian tax and accounting law (minimum 7 years)
- Responding to lawful requests from regulatory authorities
4. How We Use Your Data
We use your personal data for the following purposes:
- To provide and maintain our website and services
- To respond to your enquiries and communications
- To send you our newsletter (only with your explicit consent)
- To analyze website usage and improve our content and services (only with your consent)
- To manage client relationships, projects, and invoicing
- To comply with our legal and regulatory obligations
- To protect our legitimate business interests and enforce our terms
5. Data Sharing and Third-Party Processors
We share your personal data with the following categories of third parties, acting as data processors on our behalf or as independent controllers:
5.1 Data Processors
- Google LLC (United States) — Google Analytics for website analytics. Data processing is governed by Google’s Data Processing Amendment. Google Privacy Policy
- HighLevel Inc. (GoHighLevel) (United States) — Newsletter form hosting and email delivery. GoHighLevel Privacy Policy
- Salesforce, Inc. (Heroku) (United States) — Cloud hosting of this website and its database. The application and its database run in a United States region. Salesforce Privacy Statement
5.2 When We May Disclose Data
We may disclose your data:
- When required by law, court order, or regulatory authority
- To protect our rights, privacy, safety, or property
- In connection with a merger, acquisition, or sale of business assets (with prior notice where required)
We do not sell your personal data to any third party.
6. International Data Transfers
Our hosting infrastructure is located in the United States. The application and its database run on Heroku (Salesforce, Inc.) in a United States region, so the personal data we hold is stored there rather than in the European Economic Area. A number of our other third-party processors are also located outside the EEA, primarily in the United States. When transferring personal data to countries outside the EEA, we ensure adequate protection through:
- EU-U.S. Data Privacy Framework: Where the recipient is certified under the EU-U.S. Data Privacy Framework
- Standard Contractual Clauses (SCCs): As adopted by the European Commission, ensuring contractual safeguards for data transfers
- Adequacy decisions: Where the European Commission has determined that a country provides an adequate level of data protection
You may request a copy of the relevant safeguards by contacting us at info@swiftly-workspace.com.
7. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:
- Website analytics data: Retained for 14 months (Google Analytics default), then automatically deleted
- Newsletter subscription data: Retained until you unsubscribe or withdraw consent
- Client and invoicing data: Retained for a minimum of 7 years after the end of the business relationship, as required by Belgian accounting and tax law (Wetboek van Economisch Recht, Art. III.86)
- Communication records: Retained for the duration of the business relationship plus 3 years
- Cookie consent preferences: Stored in your browser until you clear your data or change your preferences
- Session cookies: Expire automatically after 4 hours
When personal data is no longer required, we securely delete or anonymize it.
8. Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15): You have the right to obtain confirmation of whether your personal data is being processed and to receive a copy of that data.
- Right to rectification (Art. 16): You have the right to request correction of inaccurate personal data or completion of incomplete data.
- Right to erasure (Art. 17): You have the right to request deletion of your personal data where there is no compelling reason for its continued processing (“right to be forgotten”).
- Right to restriction of processing (Art. 18): You have the right to request restriction of processing in certain circumstances.
- Right to data portability (Art. 20): You have the right to receive your data in a structured, commonly used, machine-readable format and to transmit it to another controller.
- Right to object (Art. 21): You have the right to object to processing based on legitimate interests. We will cease processing unless we have compelling legitimate grounds.
- Right to withdraw consent (Art. 7): Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.
- Right not to be subject to automated decision-making (Art. 22): You have the right not to be subject to decisions based solely on automated processing, including profiling. We do not engage in automated decision-making.
To exercise any of these rights, please contact us at info@swiftly-workspace.com. We will respond to your request within 30 days, as required by Article 12(3) GDPR.
9. Right to Lodge a Complaint
If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données):
- Name: Gegevensbeschermingsautoriteit (GBA)
- Address: Drukpersstraat 35, 1000 Brussels, Belgium
- Phone: +32 (0)2 274 48 00
- Email: contact@apd-gba.be
- Website: www.gegevensbeschermingsautoriteit.be
You may also lodge a complaint with the supervisory authority in the EU Member State of your habitual residence or place of work.
10. Cookies
For detailed information about the cookies we use, the purposes they serve, and how to manage your preferences, please refer to our Cookie Policy.
11. Security Measures
We implement appropriate technical and organisational measures to protect your personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures include:
- Encryption of data in transit (TLS/HTTPS)
- HTTP-only and Secure flags on session cookies
- SameSite cookie attributes to prevent cross-site request forgery
- Regular security reviews of our infrastructure and codebase
- Access controls limiting data access to authorised personnel
12. Children’s Privacy
Our services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at info@swiftly-workspace.com and we will take steps to delete such information.
13. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to know: You can request information about the categories and specific pieces of personal data we have collected about you.
- Right to delete: You can request deletion of your personal data, subject to certain exceptions.
- Right to opt-out of sale/sharing: You can opt out of the sale or sharing of your personal information. We do not sell personal data. You can exercise this right via the “Do Not Sell or Share My Personal Information” toggle in our cookie preferences.
- Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.
To exercise these rights, contact us at info@swiftly-workspace.com or use the cookie preferences available on our website.
14. The Swiftly Workspace App: Data We Process
This section applies to the Swiftly Workspace application distributed by Swiftly Workspace through the Apple App Store for iPhone, iPad and Mac (App Store ID 6755155607). It applies in addition to the sections above; where this section conflicts with a general provision, this section governs for your use of the app.
14.1 Account and Identity Data
- Account data: Email address, display name, and organisation or workspace name
- Authentication data: Credentials or third-party sign-in identifiers, and session tokens issued to your device
This data is linked to your identity and is required to operate your account.
14.2 User Content
- Content you create or upload: Documents, notes, messages, files, and other material you store in the app
- Prompts and AI inputs: Text, files, and context you submit when you invoke an AI feature, together with the responses returned to you
- Calendar data from your device: Where you grant calendar access, the App reads events from the calendars on your device and sends them to our servers, both on request and when your device calendar changes. This data is stored by us and is not processed only on your device.
- Feedback: The feedback and comments you submit, the votes you cast, your email address, a pseudonymous per-device identifier, and interaction events from the feedback screens. This is handled by a third-party processor on our behalf, identified in section 15.3.
User content is processed to deliver the functionality you request. When you invoke an AI feature, the relevant content is transmitted to the AI provider you have selected, as described in section 15.
14.3 Diagnostics and Usage Data
- Diagnostics: Crash logs, error reports, and performance data
- Product usage: Which features are used and how often, used to maintain and improve the app
14.4 Purchases
Subscriptions and other in-app purchases are processed by Apple Inc. through the App Store. We never receive or store your payment card number. Apple provides us with a transaction identifier and your subscription status so that we can enable the features you have paid for. See section 15.
14.5 What the App Does Not Collect
- The App contains no advertising and no third-party analytics or tracking SDKs. We do not collect advertising identifiers, and we do not track you across apps or websites owned by other companies
- We do not collect precise location data
- We do not access your contacts, photo library, health data, or financial account data
- We do not sell your personal data or your user content
On iOS, iPadOS and macOS the App requests a system permission only at the point where a feature you have invoked requires it, and you may decline. The categories above match the App Privacy information published on our App Store product page.
This section describes the App. It does not describe this website, which does use the analytics and marketing services listed in section 5, subject to your cookie consent.
15. The Swiftly Workspace App: Third-Party Processors
In addition to the processors listed in section 5, the following third parties process data on our behalf in connection with the app:
15.1 Apple
- Apple Inc. (United States) — App Store distribution, in-app purchase and subscription processing, and delivery of push notifications through the Apple Push Notification service. Push delivery transmits your device token together with the rendered notification title and body, which may contain business-record text. Apple also provides aggregated App Analytics and, where you choose to share them, crash diagnostics. Apple Privacy Policy
- RevenueCat, Inc. (United States) — Subscription status management. RevenueCat receives App Store transaction and receipt data, an anonymous RevenueCat user identifier, and device and app metadata. It does not receive your workspace data. RevenueCat Privacy Policy
15.2 AI Providers
AI features are available only where your organisation has configured a provider. Content is not sent to any AI provider when you are not using an AI feature.
- OpenAI (United States) — Privacy Policy
- Anthropic (United States) — Privacy Policy
- Google (United States) — Privacy Policy
- xAI (United States) — Privacy Policy
- Perplexity (United States) — Privacy Policy
- Cohere (Canada) — Privacy Policy
- Mistral AI (France) — Privacy Policy
- DeepSeek (China) — Privacy Policy
Content is transmitted only to the AI provider your organisation has configured with its own API key, and only when you invoke an AI feature. That provider processes the content under your organisation’s own agreement with it, and that agreement governs how the provider may use it. Swiftly Workspace does not supply an AI provider key on your behalf, and no content is sent to any provider your organisation has not configured.
Transfers outside the European Economic Area are covered by the safeguards described in section 6.
15.3 Infrastructure and Service Providers
- Salesforce, Inc. (Heroku and Heroku Postgres) (United States) — Hosting of the application server and its database. All workspace data resides there, in a United States region. Salesforce Privacy Statement
- Resend, Inc. (United States) — Delivery of transactional email sent by the service, such as invitations and notifications. Resend receives the recipient address and the subject and full body of the message. Resend Privacy Policy
- Swiftly Business Consulting BV, Borsbeeksebrug 34, 2600 Antwerpen, Belgium — Product feedback collection and management. This is operated by that third party as a processor on our behalf; Swiftly Workspace remains the controller of the data. It receives a pseudonymous per-device identifier, your email address, the content of your feedback and comments, your votes, and interaction events from the feedback screens. The service is hosted in the United States.
15.4 Address Lookup and Mapping
- OpenStreetMap Foundation (Nominatim) (United Kingdom) — Converting postal addresses into map coordinates. When a customer or vendor address is created or updated, and when a list is loaded containing addresses that have not yet been converted, the full address (street, city, region, postal code and country) is sent to this service as a search query. This happens automatically as part of managing address records; there is no separate setting for it. OSMF Privacy Policy
- Google LLC (United States and Ireland) — Distance and route calculation, only where your organisation has selected Google Maps as its distance method and supplied its own Google Maps API key. Delivery coordinates and route geometry are sent. Otherwise distances are calculated by us without contacting Google. Google Privacy Policy
15.5 Compliance and Business Services
- European Commission, DG TAXUD (VIES) (European Union) — VAT number validation, only when validation is explicitly requested. The country code and VAT number are sent; the response, which includes the registered name and address, is stored.
- Storecove B.V. (Netherlands) — Electronic invoicing over the Peppol network, only where your organisation enables it and supplies its own credentials. Storecove receives complete invoices, including buyer and seller names and addresses, VAT identifiers, line items and amounts, together with participant identifiers used for network directory lookups. Storecove Privacy Policy
- Pagero AB, Tradeshift and Babelway — Where your organisation uses one of these networks, they may deliver inbound message responses to us. We do not dispatch invoices through them.
15.6 Connections You or Your Organisation Choose to Enable
These services receive data only if a connection is set up. Nothing is sent to them otherwise.
- Google LLC (United States and Ireland) — Gmail and Google Calendar, where you connect a Google account. Authorisation tokens, message headers, message bodies, attachments and calendar events are exchanged under the permissions you grant in Google’s sign-in flow.
- Microsoft Corporation (United States and Ireland) — Outlook mail and calendar through Microsoft Graph, on the same basis.
- Apple Inc. (United States and Ireland) — iCloud Mail and iCloud Calendar, where you connect an iCloud account. Credentials, message content and calendar event content are exchanged.
- Any other mail server you configure — Where you connect a mail account directly, your credentials and message content are exchanged with the mail provider you have chosen, in whatever country that provider operates. You choose that provider, not us.
- Single sign-on providers — Where your organisation configures Google Workspace, Microsoft Entra ID or Sign in with Apple, sign-in codes and identity tokens are exchanged, including your email address, name and account identifier, and for Microsoft your group membership.
15.7 Processing That Stays on Your Device
The following are handled on your device and the content is not sent to us or to a cloud service:
- Apple Intelligence: where selected, prompts are processed by the on-device model and are never routed to a cloud AI provider.
- Speech to text and text to speech: performed on-device.
- Web search: if you enable it and supply your own key for Tavily, Brave Search, Microsoft Bing or Google Programmable Search, the key is stored in your device keychain and your search query is sent from your device directly to that provider. The query does not pass through our servers, but it does leave your device to a third party.
15.8 Services That Receive No Personal Data
For completeness: currency exchange rate providers receive only currency codes, and a public repository is checked periodically for a list of disposable email domains, which sends nothing about you.
16. The Swiftly Workspace App: Retention and Deletion
16.1 How Long We Keep App Data
- Account and identity data: Retained for as long as your account is active
- User content: Retained until you delete it, or until it is erased following a request under section 16.2, subject to the exceptions described there
- Diagnostics and usage data: Typically retained for up to 14 months, then deleted or aggregated so that it no longer identifies you
- Purchase and subscription records: Retained for a minimum of 7 years where required by Belgian accounting and tax law, as described in section 7
16.2 Account Lifecycle, Deactivation and Erasure
Swiftly Workspace accounts are provisioned and administered by the company or workspace that issues them. They are not self-managed accounts, and the App does not provide a control for deleting your own account. Where we process workspace data on behalf of your organisation, your organisation is the controller for that data and Swiftly Workspace acts as its processor.
An account can be deactivated. Deactivation marks the account inactive and ends its link to the current company, which ends access to the workspace. Deactivation is not erasure: the underlying records are retained.
To exercise any of the rights in section 8 for data processed through the App — including access and erasure — contact your workspace administrator, or email info@swiftly-workspace.com from the email address associated with your account. Where a request concerns data we process on behalf of your organisation, we will refer it to your organisation as the controller and assist it in responding. Requests are actioned typically within 30 days, and residual copies in encrypted backups are overwritten on our normal backup rotation, typically within 90 days.
The right to erasure is not absolute. Under Article 17(3) GDPR we retain certain records notwithstanding an erasure request. These include audit logs, which the App is required to keep intact and which we retain to comply with a legal obligation and for the establishment, exercise or defence of legal claims, and the invoicing and accounting records described in section 16.1 and section 7, retained for a minimum of 7 years under Belgian law. Records retained on these bases are kept in isolation and are not used for any other purpose.
Deactivation or erasure does not cancel your subscription. Subscriptions purchased through the App Store are managed by Apple: cancel in the Settings app on iOS or iPadOS, or in the App Store app on macOS. Refunds for in-app purchases are handled by Apple and are subject to Apple’s refund policy.
16.3 Data Held by AI Providers
Content transmitted to an AI provider under section 15.2 may be retained briefly by that provider for abuse monitoring, typically for up to 30 days, before deletion. We do not control those retention periods. They are governed by that provider’s own policy, linked above, and by whichever agreement applies to your workspace under section 15.2.
16.4 Your Rights
The GDPR and CCPA/CPRA rights described in sections 8 and 13 apply in full to data processed through the app, including your right of access, rectification, erasure, and data portability.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the “Last updated” date at the top of this page.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.
18. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
- Email: info@swiftly-workspace.com
- Company: Swiftly Workspace
- Registration number: BE1012954172
- Address: Borsbeeksebrug 34, 2600 Antwerpen, Belgium