Trust
Data Processing Agreement
To request a signed copy once it is final, email privacy@swfte.com (copying security@swfte.com).
1. Parties
This agreement is between the customer named in the order form (the “Customer”) and <Swfte legal entity — founder to fill> (“Swfte”), registered address <registered address — founder to fill>.
<Founder: our privacy policy names "Swfte Limited" and the site footer names "Swfte Digital Solutions Limited". Pick the correct contracting entity and use it everywhere.>
2. Roles
For personal data the Customer submits to the Swfte services, the Customer is the controller and Swfte is the processor, within the meaning of Article 28 of the GDPR (and the UK GDPR where it applies). Swfte processes that data only on the Customer's documented instructions.
3. Subject matter and duration
Subject matter: provision of Cortex and related Swfte services under the Customer's agreement with Swfte. Duration: the term of that agreement, plus the period needed to delete or return data under section 9.
4. Nature and purpose of processing
Hosting and storage of Customer content; routing prompts to the model provider for the selected cloud intelligence level; authentication; billing. Prompts handled in on-device mode are processed on the Customer's Mac and are not received by Swfte.
5. Categories of data and data subjects
- Data subjects: the Customer's users, and people who appear in the Customer's files and meetings.
- Data: account details (name, email), prompts and responses sent to cloud intelligence levels, files and meeting content the Customer uploads, billing records.
- Special categories: <founder to fill — whether permitted, and on what conditions>
6. Sub-processors
The Customer authorises the sub-processors listed on the sub-processors page (currently a draft). Swfte will give notice of new sub-processors <notice period — founder to fill> in advance, and the Customer may object on reasonable data-protection grounds.
7. Security measures (Annex II)
Measures in place today:
- Customer data at rest is stored in AWS eu-west-1 (Ireland).
- Encryption at rest: RDS databases encrypted; DynamoDB on a KMS key; S3 with SSE-S3.
- Encryption in transit: API traffic uses TLS 1.2 or later (TLS 1.3 preferred).
- On-device mode processes prompts on the customer’s Mac without sending them to Swfte or model providers.
- Screen capture, microphone listening and wake word are off by default; product telemetry is off by default.
- Computer-use actions are recorded in a local audit log.
- Authentication via Google, Microsoft or GitHub through WorkOS.
Measures to be documented before this DPA is final:
- Access control and administrative access review: <founder to fill>
- Logging and monitoring: <founder to fill>
- Backup, business continuity and recovery objectives (RTO/RPO): <founder to fill>
- Vulnerability management and penetration testing: <founder to fill>
- Personnel security and confidentiality: <founder to fill>
- Incident response procedure: <founder to fill>
What we do not yet offer (SOC 2, SAML SSO, MFA enforcement and others) is listed on the trust centre.
8. International transfers
Where personal data is transferred outside the EEA or the UK to a country without an adequacy decision, the parties will rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. Both are <to be attached — founder to fill>. Some configured model providers are hosted outside the EEA, including in China; see the sub-processors page.
9. Breach notification, deletion and return
- Swfte will notify the Customer without undue delay, and within <hours — founder to fill>, after becoming aware of a personal data breach affecting Customer data.
- At the end of the agreement Swfte will delete or return Customer data at the Customer's choice, within <days — founder to fill>, unless law requires retention.
10. Assistance and audits
Swfte will assist the Customer with data-subject requests and data-protection impact assessments, and will make available the information needed to demonstrate compliance with Article 28. Audit terms: <audit frequency, notice and cost — founder to fill>. Swfte has no SOC 2 or ISO 27001 report to offer in place of an audit today.
11. Contact
Privacy: privacy@swfte.com. Security: security@swfte.com.
Related: Trust centre · Sub-processors · Model cards · Security