Processor terms

Data processing addendum

The terms on which Swarm processes the personal data in your lead lists and conversations: on your instruction, for your purposes, with the sub-processors named here.

Revision 1.0Updated 20 August 2026

01 Roles

For the data a Customer uploads and the conversations run from the Customer's instance, the Customer is the operator (the controller) and Swarm processes on instruction under Article 6(3) of Federal Law 152-FZ; where the GDPR applies, the Customer is the controller and the Operator the processor within the meaning of Article 28.

This addendum forms part of the public offer and is accepted with it. Where it conflicts with the offer on a data protection question, this addendum prevails.

02 Subject, duration, nature and categories

Subjectprocessing of personal data for outreach run by the Customer through the platform
Durationthe term of the contract, plus the return and deletion period below
Nature and purposecollection from the Customer's upload, recording, systematisation, storage, updating, extraction, use for composing and sending messages, translation, transfer to the connected channel, blocking, deletion, destruction
Categories of subjectsthe Customer's leads and the people who answer from their side
Categories of dataname, company, role, phone or messenger identifier, email, language, source of the contact, message history, campaign metadata

The Operator does not process special categories of personal data on the Customer's instruction and asks the Customer not to upload them.

03 Processing on instruction only

The Operator processes the Customer's data only on the Customer's documented instruction — the settings, policies and campaigns configured on the instance, and requests sent by the Customer's authorised people — and for no purpose of its own. The Operator does not use the Customer's lead data to train models, to build its own lists, or to sell to anyone.

If an instruction appears to the Operator to breach data protection law, the Operator will say so and may decline to carry it out until it is corrected.

04 Security and confidentiality

The Operator applies the measures listed in the privacy policy: role-based access, encryption of credentials and secrets at rest, TLS in transit, per-account isolation, rate limiting, audit logging, verified backups, closed management ports and a written incident procedure.

Everyone with access is bound by a confidentiality obligation that survives the end of their engagement. Access is granted on need and withdrawn when the need ends.

05 Sub-processors

The Operator engages the following sub-processors. Each is bound to process only on instruction and to a level of protection no lower than this addendum requires.

WhoWhat they doWhere
Hosting providerruns the servers holding the instance and its databaseEuropean Union
Language-model providerdrafts first messages and translates incoming replies; receives the fields needed for one messageoutside the EU and Russia
Support-assistant provideranswers support questions from product documentationUnited States
Channel platforms and mail providersdeliver the messages; connected by the Customer under the Customer's own relationship with themper platform

The named list — company names and current locations — is provided to the Customer on request and on signature of the contract, and is kept current. The Operator notifies the Customer at least 15 calendar days before adding or replacing a sub-processor; a Customer who objects on reasonable data protection grounds may terminate the affected part of the service without penalty.

06 Cross-border transfer

Providing the service transfers data outside the Russian Federation, as described in the privacy policy. The Operator files the notification required by Article 12 of 152-FZ before such transfer begins, and applies the additional grounds that article requires where a receiving country is not on the adequate-protection list.

A Customer bound by the localisation rule in Article 18(5) of 152-FZ must say so before uploading data, so that the instance is deployed on infrastructure located in Russia.

07 Help with subject requests

If a data subject writes to the Operator about data held on a Customer's instance, the Operator does not answer on the merits: it suppresses the contact, forwards the request to the Customer within 3 working days and gives the Customer what it needs to answer within the statutory period.

On the Customer's request the Operator provides access to, corrects, blocks, exports or deletes a specific record.

08 Incident notification

The Operator notifies the Customer within 24 hours of becoming aware of an incident affecting the Customer's data, with what is known at that point: what happened, which data is involved, what has been done. Notification to Roskomnadzor is made on the timetable in Article 21(3.1) of 152-FZ, and the parties coordinate on who notifies the subjects.

09 Evidence and audit

On a written request, once per contract year, the Operator provides a description of the technical and organisational measures in place, the current sub-processor list, and answers to a reasonable security questionnaire. An on-site or third-party audit is arranged by agreement, at the Customer's cost, without access to other customers' data.

10 Return and deletion

On termination, the Customer may export lead data and conversations in a machine-readable format for 30 calendar days. After that period the Operator deletes them from the live systems; copies in backups are overwritten within a further 30 days on the normal backup rotation.

Suppression records are the deliberate exception: the contact identifier is kept, without the rest of the record, so that a refusal continues to be honoured after everything else is gone.

11 Liability and precedence

Liability under this addendum is subject to the limits in the public offer, except where the law does not allow those limits to apply. If a term of the contract contradicts this addendum on a data protection question, this addendum governs.

Operator details

Legal entity— to be filled —
Tax ID (ИНН)— to be filled —
Registration (ОГРН)— to be filled —
Registered address— to be filled —
Roskomnadzor notice— to be filled —
Responsible for personal data— to be filled —
Governing law and venue— to be filled —
Privacy requestsprivacy@swarm.app
Abuse reportsabuse@swarm.app