Privacy Policy

We appreciate your interest in our Privacy Policy. At swiirl, we take the protection of your Personal Information very seriously, and in the below we explain what data we collect when you use our website www.swiirl.io (“our website”), and how it is used.

General Information

What law applies?

In principle, we will only use yourPersonal Information in accordance with applicable data protection laws, in particular the California Consumer Privacy Act (“CCPA”) and the subsequent amendments from the California Privacy Rights and Enforcement Act (“CPRA”). As well as the EU's General Data Protection Regulation (“GDPR”), and only as described herein.

What is Personal Information?

PersonalInformation is any information relating to personal or material circumstances that relates to an individual. This may include a name, date of birth, e-mail address, postal address, or telephone number but also online identifiers such as IP addresses or device ID's.

What is processing?

"Processing" means any operation or set of operations which is performed upon Personal Information, whether or not by automatic means. The term is broad and covers virtually any handling of data.

Who is responsible for data processing?

The responsible party for data processing is swiirl (“swiirl”, “we”, “us” or“our”). If you have any questions or if you wish to exercise your rights, please contact us using info@swiirl.io, use our Contact Form.

What are the grounds for processing Personal Information?

We only process your Personal Information, if at least one of the following reasons applies:

•    for the fulfillment of contractual obligations
•    within the framework of our legitimate interests
•    based on your consent

Is there an obligation to provide Personal Information?

Within the scope of our business relationship, you are only required to provide Personal Information that is necessary for the establishment, implementation, and termination of a business relationship or that we are legally obliged to collect. Without this data, we will usually have to refuse to conclude the contract or will no longer be able to perform an existing contract and may have to terminate it.

Data we collect automatically

Log data

Each time you visit our website, our system automatically records the following data from the visiting device and stores it in a so-called log file: i) Name of the retrieved file, ii) date and time of the visit, iii) amount of data transferred, iv) message about successful retrieval, type of browser and version used, v) IP address (identification of the user's device), vi)Operating system of the visiting device, vii) Internet service provider of the visiting device, viii) website from which you access our website, and ix) which of our website pages you are accessing. The basis for processing is our legitimate interest.

Hosting

To provide our website, we use the services of Webflow, Inc. who processes all data to be processed in connection with the operation of this website on our behalf. The legal basis is our legitimate interest.

Content Management System (CMS)

We also use the Content Management System (CMS) of Webflow, Inc. to publish and maintain the created and edited content and texts on our website. This means that all content and texts submitted to us is transferred to WordPress. This represents a legitimate interest.

Cookies

We use so-called cookies with our website. Cookies are used to process certain information about you on an individual basis, such as your browser or location data or your IP address. The basis for the use of cookies is our legitimate interest and your consent. If you wish to learn more about cookies in general and how they work, please visit www.allaboutcookies.org. If you want to learn more about the cookies we use, please read our Cookie Policy.

Third-party services and content

We use content or service offers of third-party providers on the basis of our legitimate interests in order to integrate their content and services.  This always requires that the third-party providers of this content are aware of the IP address of the user, as without the IP address they would not be able to send the content to their browser. The IP address is therefore necessary for the display of this content.  The following provides an overview of third-party providers and their content, together with links to their privacy policies, which contain further information on the processing of data and so-called opt-out measures, if any,

•     Tag Management: Google Tag Manager and Google Site Tag by GoogleLLC,
•     Fonts: Google Fonts by Google LLC and FontAwesome by Fonticons Inc,

Data we collect directly

Contacting us

In addition to your name, e-mail address, IP address or phone number, if provided, we usually collect the context of your message which may also include certain Personal Information. The Personal Information collected when contacting us is to handle your request and the bases are both your consent and contract.

When you get involved

We process the Personal Information you provided in your use of our services in order to be able to provide our contractual services. This includes in particular our support, correspondence with you, invoicing, fulfillment of our contractual, accounting and tax obligations. Accordingly, the data is processed on the basis of fulfilling our contractual obligations and our legal obligations.

Administration, financial accounting, office organization, contact management

We process data in the context of administrative tasks as well as organization of our business, and compliance with legal obligations, such as archiving. In this regard, we process the same data that we process in the course of providing our contractual services. The processing bases are our legal obligations and our legitimate interest.  

Newsletter

If you have consented to receive our newsletter, we will use your e-mail address to send you information about us, our services and general news. You can revoke your consent to receive the newsletter or to the creation of personalised user profiles at any time with effect for the future. You will find the unsubscribe link at the end of each newsletter.

 

General Principles

Who receives my data?

Within swiirl, those that need your data to fulfill our contractual and legal obligations will receive access to it. We ensure that access by our employees to your data is only available on a need-to-know basis, restricted to specific individuals, and is logged and audited. We communicate our privacy and security guidelines to our employees and enforce privacy and data protection safeguards strictly.

Outside of swiirl, only if this is i) necessary for the performance of our services, ii) you have consented to the disclosure, iii) or if we are legally obliged todo so e.g., by court order or if this is necessary to support criminal or legal investigations or other legal investigations or other legal proceedings; or proceedings at home or abroad or to fulfill our legitimate interests.

How long will my data be stored?

As far as necessary, we process and store your Personal Information for the duration of our business relationship, which also includes, for example, the initiation and execution of a contract.

In addition, we are subject to various storage and documentation obligations, which result from the minimum statutory retention periods and the California Department of Tax and Fee Administration. The retention and documentation periods specified there are up to 7 years.

How do we secure your data?

Our website uses SSL or TLS encryption to ensure the security of data processing and to protect the transmission of content or contact requests that you send to us. We have also implemented numerous security measures (“technical and organizational measures”) for example encryption or need to know access, to ensure the most complete protection of Personal Information processed through this website.

Nevertheless, internet-based data transmissions can always have security gaps, so that absolute protection cannot be guaranteed. And databases or data sets that include Personal Information may be breached inadvertently or through wrongful intrusion. Upon becoming aware of a data breach, we will notify all affected individuals whose Personal Information may have been compromised as expeditiously as possible after which the breach was discovered.

Is data transferred to a third country?

We may transfer your Personal Information to other companies and/or business partners as necessary for the purposes described in this Privacy Policy. In order to provide adequate protection for your Personal Information when it is transferred, we have contractual arrangements regarding such transfers. We take all reasonable technical and organizational measures to protect the Personal Information we transfer.

Sensitive Data

Unless specifically required when using our services and explicit consent is obtained for that service, we do not process sensitive data.

Automated decision-making

Automated decision-making is the process of making a decision by automated means without any human involvement. Automated decision-making including profiling does not take place.

COPPA (Children Online PrivacyProtection Act)

When it comes to the collection of Personal Information from children under the age of 13 years old, the Children’s Online Privacy Protection Act (COPPA) puts parents in control. The Federal Trade Commission, United States’ consumer protection agency, enforces the COPPA Rule, which spells out what operators of websites and online services must do to protect children’s privacy and safety online. We do not specifically market to children under the age of 13 years old. 

CAN SPAM Act

The CAN-SPAM Act is a law that sets the rules for commercial email, establishes requirements for commercial messages, gives recipients the right to have emails stopped from being sent to them, and spells out tough penalties for violations. To be in accordance with CAN SPAM, we agree to the following: If at any time you would like to unsubscribe from receiving future emails, you can email us, and we will promptly remove you from ALL correspondence.

Telephone Consumer Protection Act (TCPA)

If we process your Personal Information for the purpose of sending you SMS marketing communications, you may manage your receipt of marketing and non-transactional communications from us by replying or texting ‘STOP’ if you receive our SMS communications. In this respect, the data processing is carried out solely on the basis of our consent in personalized direct advertising perSMS.

Controls For Do-Not-Track Features

Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ('DNT') feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, our website does not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online.If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this policy.

DO NOT SELL

We do not sell your Personal Information.

 

Your Rights and Privileges

Privacy rights

Under the CCPA and the CPRA amendment, you can exercise the following rights:

•     Right to Know/Access
•     Right to Delete
•     Right to Opt-out of Sale
•     Right to Non-Discrimination
•     Right to Rectification
•     Right to Limit Use and Disclosure of Sensitive Personal Information

 Further, California’s “Shine the Light” law (Civil Code Section 1798.83) requires us to respond to requests from California asking about the business’s practices related to disclosing Personal Information to third parties for the third parties’ direct marketing purposes. You may make a request about our collection and disclosure of your Personal Information using the contact details provided.

Under the GDPR, you can exercise the following rights:

•     Right to information
•    
Right to rectification
•    
Right to deletion
•    
Right to data portability
•    
Right of objection
•    
Right to withdraw consent
•    
Right to complain to a supervisory authority
•    
Right not to be subject to a decision based solely on automated processing.

If you have any questions about the nature of the Personal Information we hold about you, or if you wish to exercise any of your rights, please contact us.

Updating your information

If you believe that the information we hold about you is inaccurate or that we are no longer entitled to use it and want to request its rectification, deletion, or object to its processing, please do so by contacting us.

Withdrawing your consent

You can revoke consents you have given at any time by contacting us. The legality of the data processing carried out until the revocation remains unaffected by the revocation.

Access Request

In the event that you wish to make a Data Subject Access Request, you may inform us in writing of the same. We will respond to requests regarding access and correction as soon as reasonably possible. Should we not be able to respond to your request within thirty (30) days, we will tell you why and when we will be able to respond to your request. If we are unable to provide you with anyPersonal Information or to make a correction requested by you, we will tell you why.

Complaint to a supervisory authority

You have the right to complain about our processing of Personal Information to a supervisory authority responsible for data protection. The competent data protection authority in California is: The California Privacy Protection Agency (CCPA), 2101 Arena Blvd, Sacramento, CA 95834, www.cppa.ca.gov

Changes and Updates

We may update our Privacy Policy from time to time. This might be for a number of reasons, such as to reflect a change in the law or to accommodate a change in our business practices and the way we use cookies. We recommend that you check here periodically for any changes to our Privacy Policy.

Validity and questions

This Privacy Policy was last updated on Friday, May 10, 2023, and is the current and valid version. If you have any data protection questions, please feel free to contact us.