Privacy Policy (archived 8 August 2026)
This document has not been reviewed by a lawyer. Questions? Email [email protected].
This is an archived version from 8 August 2026, kept for reference. It is not the version that applies now. Read the current version
It was in force from 7 September 2026 until 14 September 2026.
SwiftGuard provides an AI voice agent that answers phone calls for plumbing and heating businesses across Europe. This policy explains what personal data we handle, why, how long we keep it, and the rights you have. It also explains the two roles we play: we are the data controller for the account and billing data of the businesses that use SwiftGuard, and we are a data processor for the personal data of the people who call those businesses.
In this policy, you means the business (and its staff) that holds a SwiftGuard account. Callers means the people who telephone your business and speak with the agent.
In short
- We collect the account, security and billing data we need to give you the service - and, when the agent answers calls for you, we handle your callers' data on your behalf to run and record those calls.
- We do not sell personal data and we do not use it for advertising.
- We use only strictly necessary cookies, so there is no cookie-consent banner.
- You can access, correct, export or delete your data, and object to some uses - email [email protected].
- You can complain to your local data protection supervisory authority.
1. Who we are
SwiftGuard is provided by SwiftGuard AI, our registered name with the Netherlands Chamber of Commerce (KvK) under number 75538288 - a sole proprietorship (eenmanszaak) run by Daan van den Bergh, at Ensahlaan 25, 3723 HT Bilthoven, The Netherlands ("we", "us"). As a sole trader, he is the controller of the account, security and billing data described in section 2.
For any privacy question, or to exercise your rights, contact us at [email protected].
We have not appointed a Data Protection Officer, as our current processing does not require one under the GDPR. For any data protection question, you can contact us at [email protected].
2. Data we collect and control (about you, our business customer)
| Category | Examples | Where it comes from |
|---|---|---|
| Account and profile | Your name, email address, business name (and a short web identifier derived from it), and an optional profile image | You, at sign-up and in your dashboard |
| Team invitations | The email address of a colleague you invite to your account, and the role you assign them | You, when you invite them |
| Login and security | IP address, browser and device (user-agent), sign-in times, failed login counts, and a log of security events | Automatically, when you use the service |
| Billing | Your plan and subscription status, and - for display only - your card brand, last four digits and expiry date; payment provider identifiers | From you and from our payment provider, Stripe, when you subscribe |
| Connected calendar | If you connect a calendar: the Google account address you connect, which calendar it is, its timezone, the permissions you granted, and a refresh token - a long-lived key that lets us reach the calendar until you withdraw it, encrypted before we store it. We never see or store your Google password. | From Google, when you connect a calendar. The connection is deleted the moment you disconnect it; the appointments we booked keep a reference to the calendar event until you delete your account. |
Providing your name, email and business details is necessary to create an account and use SwiftGuard; if you do not provide them, we cannot give you the service. Your password is stored only as a secure one-way hash. We never store full card numbers or security codes - card payments are handled entirely by Stripe on its own hosted checkout.
3. Why we use your data, our legal basis, and how long we keep it
| Purpose | Legal basis | How long we keep it |
|---|---|---|
| Provide and administer your account and the service | Performance of our contract with you | For as long as your account is active; deleted when you close your account |
| Take subscription payments and keep billing records | Contract, and our legal accounting and tax obligations | For the life of your subscription. Invoices and tax records are held by Stripe, as merchant of record, under its own legal obligations |
| Send service and security emails (email verification, password reset, security notices) | Contract, and our legitimate interest in keeping accounts secure | The one-time links in these emails expire shortly after they are sent |
| Keep the service secure - logging sign-ins, limiting failed logins, rate-limiting, and recording security events | Our legitimate interest in protecting the service and its users against fraud and abuse | Sessions up to 7 days; failed-login counters about 1 day; the security event log for 180 days. The log itself is kept after you close your account, but the personal details in its entries - phone numbers, email addresses, IP addresses, and browser and device details - are removed at that point. What is left is the event and the date it happened, with nothing in it that identifies a person. |
| Book appointments into the calendar you connect, and check when you are free | Performance of our contract with you - you asked us to book into your calendar | The connection and its token: until you disconnect the calendar or close your account, whichever comes first. Appointments we booked keep a reference to the calendar event until you close your account; the events themselves stay in your own calendar. |
Where we rely on legitimate interest, our interest is running a secure and reliable service; you can object at any time (see section 9). We do not sell your personal data, we do not share it for advertising, and we do not send marketing emails from the service.
4. Data we process for you (about your callers)
When our agent answers calls for your business, we act as your data processor - you are the controller and we process caller data only to provide the service and on your documented instructions, under a data processing agreement (available on request). To be sure it is really your customer on the line, the agent asks them for the postcode and house number on their record, and texts a one-time code to their phone, before it looks up their record, creates a record for them, or changes one of their bookings. The caller data we handle for you includes:
- Caller and job details recorded by you or by the agent: phone number, name, optional email, service addresses, and free-text notes about the job.
- What we use to check a caller is who they say they are: the postcode and house number they give us - kept separately from their service address, purely so the agent can ask for them again before it changes one of their bookings over the phone; whether their phone number is a mobile that can receive a text message (we check this so we do not text a landline that would never receive the message); the one-time code we text them; and the date their number was confirmed.
- The call itself: the recording, a written transcript of what was said, and a short AI-written summary of the call. Three different providers are involved, and section 7 says which does what: our telephone provider records the audio, our voice platform listens and speaks and writes the transcript, and a separate provider writes the summary afterwards.
How long caller data is kept: caller records are kept until you delete them or close your account - you control how long they are kept. The recording of the call is held by our telephone provider, Twilio, on our behalf; we do not keep a copy of the audio ourselves. We do store the written transcript and the AI summary of each call in our own database. We delete the transcript and summary 90 days after the call, and we delete the recording on the same 90-day schedule - our telephone provider does not remove old recordings by itself, so we run a daily job that deletes each one as its 90 days run out. A one-time code is never stored in a readable form, expires within five minutes, and is deleted the moment it is used. Two counters outlive everything else: so that the same number cannot be texted over and over, and so that nobody can keep guessing at the postcode and house number, we count those attempts against the caller's phone number - and that count, which contains the number itself, is kept for up to two days after the last attempt even if the caller's record has been deleted in the meantime. Without it, deleting a record would simply hand whoever asked a fresh set of texts and a fresh set of guesses. A caller can also appear in our security event log - for instance when a code was texted to them, or when someone failed the postcode check on their record. If you close your account, everything in those entries that says who the caller was, their phone number included, is stripped out of them: the entry stays, but it no longer says who was on the line.
Because you are the controller of caller data, callers who wish to exercise their rights should contact your business; we will help you respond.
5. Call recording and transcription
Calls answered by the agent are recorded and/or transcribed so the agent can understand the request, book the job, and give you a record of the call. As the business, you decide whether calls are recorded, for what purposes and for how long, and you choose the legal basis as the controller - typically performing the service the caller asked for, or your legitimate interest in documenting and improving service, with a way for callers to object.
The agent tells every caller, in its opening line, that it is an automated assistant and that the call is recorded - before they say anything about their job. If a caller objects to being recorded, it tells them plainly that it cannot switch the recording off and that they can hang up and contact the business another way instead. That announcement is a notification, not a request for consent, so as the business you are still responsible for complying with call-recording and telecoms law in each country you take calls in (see our Terms of Service). It matters most in countries such as Germany, Austria and Belgium, where everyone on the call must clearly consent to being recorded - there, an announcement on its own is not enough.
The agent understands what callers say in order to handle the call. It does not analyse the sound of a caller's voice to recognise who they are: we do not perform voiceprint or biometric identification.
There is one thing we do with call data for our own purposes, and we would rather say it plainly than bury it: a small number of our staff may listen to recordings and read transcripts to see how well the agent handled a call and to make it better - for example when it mis-hears an address, or fails to book a job it should have booked. That access is limited to the few people who operate the service and hold its credentials, and they are bound to confidentiality; we are still building per-person access controls and a log of who opened which call. We do not use this data to train AI models (see section 10) - we listen to check and correct how the agent behaves, not to feed it into a model.
For this one purpose we are not acting on the business's instructions but on our own, so for it we are the controller and we are answerable for it. Our legal basis is our legitimate interest in making the agent accurate, safe and reliable - which is also what protects callers from a mis-booked emergency. Recordings and transcripts used this way are deleted after 90 days like every other call. If you are a caller and you do not want your call used to improve the agent, you can object - simply email us at [email protected] and we will stop using your call for this and delete it from our review, without you having to give a reason.
We also keep a small set of technical measurements about each call, so we can tell how well the service is working and make it better. These are figures about our own software, not about the person on the line: how quickly the agent replied, how long each of its actions took and whether they succeeded, how many times the caller and the agent each spoke, whether our providers reported an error, and which AI model answered the call. They contain no recording, no transcript, no name, number or address - nothing a caller said. They are stored alongside the record of the call and are deleted with it after 90 days.
We keep them for the same purpose and on the same basis as the review described above - our legitimate interest in making the agent accurate, safe and reliable. Because they identify nobody, there is nothing in them to give you access to or to erase; if you ask us to delete a call, they go with it.
6. Cookies
We use only strictly necessary cookies. Our sign-in system sets a secure, HTTP-only session cookie so you stay logged in (about 7 days). Inside the billing area, our payment provider Stripe sets its own cookies to run checkout and prevent fraud. We do not use analytics, advertising or tracking cookies, and there are no third-party trackers on our website - so no cookie-consent banner is required.
7. Who we share data with
The service providers in the table below help us run SwiftGuard. Each of them is bound by a data-processing contract with us and uses the data only on our instructions. A calendar you connect yourself works differently - see below the table.
| Provider | What they do | Data they handle | Where they process it |
|---|---|---|---|
| Deepgram | Voice platform - listens to the caller, writes the transcript, and speaks the agent's replies unless another speaking voice is set for that language | Caller audio, transcripts, and anything the caller says on the call | European Union - our software is pinned to Deepgram's EU service, so the audio and the transcription happen inside the EU. Deepgram is a US company, so its own staff and systems may be reachable from outside the EEA |
| ElevenLabs | Speaking voice - turns the agent's replies into speech for those languages where we have set an ElevenLabs voice instead of the platform's own. Nothing the caller says goes to it, and it is not used for listening or transcription | The words the agent itself says in that language (which can repeat back a detail the caller gave, such as an address) | United States - EU Standard Contractual Clauses. Its EU option is available only on ElevenLabs' Enterprise plan, so unless we hold that plan the agent's speech in a language set to it is produced outside the EU. No language is set to it today |
| Google, then OpenAI as a backup | The language model that works out what the caller means and what to say next. We do not contract these directly: our voice platform passes the words to them and holds the contract - see below the table | The words spoken on the call, as text | United States - reached through Deepgram, under Deepgram's own safeguards |
| Twilio | Telephony - provides the phone numbers, carries the call, records the audio and holds the recording, and checks whether a number can receive a text message | Caller phone numbers and the call audio, including the stored recording | United States - EU SCCs / EU-US Data Privacy Framework |
| Mistral | Writes the short summary of each call that you see in your dashboard | The written transcript of the call | European Union (Mistral AI, France) - inside the EU/EEA |
| GatewayAPI | Text messages - sends the one-time code that checks a caller really has the phone number they gave | The caller's phone number and the code we text to it - no name, address or anything else said on the call | European Union (GatewayAPI ApS, Denmark) - inside the EU/EEA, on its EU servers |
| HERE Technologies | Address lookup - turns a spoken or typed address into a precise street address and location | The address text itself (street, house number, postcode, city) - no name, phone number or other call content | European Union (HERE Global B.V., the Netherlands) - EU SCCs where it processes outside the EEA |
| Stripe | Payments - merchant of record for subscriptions | Your name, email, and subscription and payment data | United States and EU - EU-US Data Privacy Framework / EU SCCs |
| MongoDB Atlas | Database hosting - stores the data described above | All stored personal data | European Union (Frankfurt, eu-central-1) |
| Resend | Sends service and security emails | Recipient email address and email content | United States - EU SCCs / EU-US Data Privacy Framework |
| Railway | Application hosting | All data in transit and in use | European Union or United States - EU SCCs where outside the EEA |
| Cloudflare | Edge network, CDN and security (WAF) | Website traffic and visitor IP addresses | Global edge network - EU SCCs / EU-US Data Privacy Framework |
Google Calendar sits outside that table, because it is not a provider we engage on your behalf. If you choose to connect a calendar, you connect your own Google account, under your own agreement with Google, and you can disconnect it - or withdraw our access in your Google account - at any time. Google asks you to allow two permissions: to see your calendar, and to create and change events on it. That is broader than what we use: we read which calendar it is and its timezone when you connect, read your free/busy times, create the appointments the agent books, and delete an event again if that appointment is cancelled or if we created it in error.
What we put in the calendar event: the appointment time, the job address, and the free-text job description and notes from the call. There is no field for the caller's name, phone number or email and we send none - but the address itself identifies the caller, and the free text is written by the voice agent from what the caller said and is not filtered before it reaches Google, so it can contain identifying and sometimes sensitive detail about the caller and their home. The event is stored on Google's infrastructure, including in the United States, under your agreement with Google and Google's own safeguards rather than ours. Appointments already written stay in your calendar after you disconnect - they are yours.
A word about the language model, because it is the part of a call that always leaves Europe. Our voice platform hears the caller in Europe, and speaks to them from Europe unless we have set an ElevenLabs voice for that language (see the table above and section 8), but to work out what the caller means and what to say next it passes the words - as text, not audio - to a language model in the United States: Google's, and OpenAI's if Google's is unavailable. We do not hold an account with either of them for this; our voice platform reaches them, pays for them and is responsible for them under its own contracts, in the same way a builder brings their own subcontractor. We name them here anyway, because what your caller says does travel there and you should not have to take that on trust. The full, current list of everyone in that chain is set out in Annex III of our Data Processing Agreement, and is also available on request.
8. International transfers
We store our core database in the European Union (Frankfurt). Listening to the caller, transcribing what they say, and writing the summary afterwards all happen inside the European Union. Speaking the agent's replies happens inside the European Union too, unless we have set an ElevenLabs voice for the language being spoken - in that case the words the agent says are turned into speech in the United States, under the EU Standard Contractual Clauses. We will tell you on request which languages, if any, are set that way.
Some of our providers do process personal data outside the European Economic Area, mainly in the United States: Twilio (which carries the call and holds the recording), Stripe, Resend, Railway, and Cloudflare's global network. For those transfers we rely on the EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework, as applicable to each provider. You can request a copy of the safeguards at [email protected].
One further transfer is not made by us but by our voice platform: to understand the call it sends the spoken words, as text, to a language model in the United States (see section 7). That transfer is made by our voice platform under its own safeguards rather than ours, so it is the transfer in the call itself for which the contract is not in our hands - unlike the ElevenLabs speech step above, which is a direct relationship of ours and covered by safeguards we hold and can send you.
If you connect a Google Calendar, the appointments we book are written into your own Google account and travel to Google's global infrastructure, including the United States. That transfer happens under your own agreement with Google and Google's own safeguards - not under safeguards we hold - so it is the one transfer for which we cannot send you a copy. Google states that Google LLC is certified under the EU-US Data Privacy Framework and that it relies on the EU Standard Contractual Clauses where adequacy does not apply. Disconnecting the calendar stops any further data going to Google; it does not remove what is already in your calendar, which stays there under your control.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy;
- have inaccurate or incomplete data corrected;
- have your data erased, where the law allows;
- restrict how we use your data, in certain cases;
- receive your data in a portable, machine-readable format;
- object to processing based on our legitimate interests;
- withdraw consent at any time, where we rely on consent.
To exercise any right, contact [email protected]. We respond within one month (extendable by up to two months for complex requests). The first request is free, and we may ask you to verify your identity. If your data relates to a call you made to a business that uses SwiftGuard, that business is the controller - please contact them, and we will help them respond.
You can also lodge a complaint with your local data protection supervisory authority.
10. Automated interactions and AI
Calls are answered by an automated assistant (an AI system), not a person. The agent introduces itself as an automated assistant and tells the caller the call is recorded, at the very start of the call. It books appointments and records call details; it does not make decisions that produce legal effects, or similarly significant effects, about anyone, and we do not identify callers biometrically.
We do not use your data or your callers' data to train AI models. That is our own conduct, and we control it. Listening to a call to correct and improve how the agent behaves (section 5) is a different thing from training a model on it: we do the first, never the second.
We cannot make that promise on our providers' behalf, so rather than claim it we tell you what we have done and what they themselves say, and you can check both.
Our voice platform, Deepgram, offers customers a way to opt out of having their audio used to improve its models. We set that opt-out on every single call, automatically - it is written into the software, not a setting somebody has to remember, so there is no call it can be forgotten on (see Deepgram's privacy policy). That opt-out covers Deepgram. Where a language is set to an ElevenLabs voice, what reaches ElevenLabs is the text of the agent's own replies rather than the caller's audio, and ElevenLabs states that it does not train on the content its business customers send (see ElevenLabs' privacy policy).
The language model that works out what the caller means is the part we are furthest from, and we will not dress that up. Both Google and OpenAI publish a commitment that data sent to their paid interfaces is not used to train their models (see Google's Gemini API terms and OpenAI's API data policy). But that step is reached on our voice platform's account, not ours, so the agreement that actually binds it is between them and Deepgram - which means we can point you to what those companies say publicly, and we cannot give you our own promise on top of it. If that distinction matters to your business, ask us and we will get you Deepgram's own answer in writing.
11. Security
We use reasonable technical and organisational measures to protect personal data, including encryption in transit (TLS) and encryption at rest provided by our database and hosting providers, access on a least-privilege basis, hashed passwords, and logging of security-relevant actions. To run and secure the service we also keep operational logs, which can contain limited personal data such as email and IP addresses and the town an address resolved to; we remove credentials from these logs, and the operational logs on our hosting platform are short-lived. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a personal-data breach affects you, we will notify you and the relevant authorities as required by law.
12. Children
SwiftGuard is a service for businesses and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided data through a call, contact us and we will help arrange its deletion.
13. Changes to this policy
We may update this policy. We will change the "Last updated" date above and, for material changes, tell you by email or in your dashboard. We will not apply material changes retroactively without a lawful basis.
14. Contact us
Questions or requests: [email protected] · SwiftGuard AI, Ensahlaan 25, 3723 HT Bilthoven, The Netherlands.
This policy is provided for information and is a draft pending legal review; it is not legal advice. A qualified lawyer must review it before it is treated as final.