01 Operator and scope
The Operator of personal data is the organisation named in the details at the end of this page, reachable at the addresses given there. This document is the policy regarding the processing of personal data that Article 18.1(2) of Federal Law No. 152-FZ of 27 July 2006 requires an operator to publish and keep freely accessible.
It covers the website, the sign-in gate, the hosted application and the support assistant. It covers two different situations, and the difference matters:
- The Operator's own processing — visitors, customers, their staff, billing and support. Here the Operator decides the purposes and is fully responsible.
- Processing on a customer's instruction — the lead lists a customer uploads and the conversations run from the customer's instance. There the customer is the operator and Swarm acts on instruction under Article 6(3) of 152-FZ; the terms are in the data processing addendum.
02 Legal grounds
Processing is carried out on the basis of the Constitution of the Russian Federation, Federal Law 152-FZ “On personal data”, Federal Law 149-FZ “On information, information technologies and the protection of information”, the Civil Code and the Consumer Rights Protection Act, and — for each specific purpose — on one of the following grounds: performance of a contract to which the subject is a party, the consent of the subject, a legal obligation of the Operator, or the legitimate interest of the Operator where it does not override the subject's rights.
Where a subject is covered by another country's data protection law, the Operator applies the equivalent lawful basis under that law.
Consent is used as a ground where consent is actually asked for, and to one rule throughout: separately from other terms, through a box that is not ticked in advance, with a link to this policy next to the button that submits. Today that is the browser-storage banner on a first visit (see the cookie notice); the same rule will bind any form that appears on the site later. Silence, continued use of the site and a pre-ticked box are not consent. Consent can be withdrawn at any time — the procedure is in the section on your rights.
03 Whose data is processed
- visitors of the website, including people who write to the addresses published on it;
- customers and the employees of customers who are given access to an instance;
- people whose business contact details a customer has uploaded as leads, and who receive or answer messages through the platform.
The Operator does not knowingly process the data of persons under 18, does not process special categories of personal data (health, beliefs, political views, biometrics) and does not use personal data for automated profiling that produces legal consequences.
04 What is processed
From the website: the content of a message you send to a published address; the technical data every web server records — IP address, user agent, request time and page requested; the language and theme you chose, which are stored in your own browser and not on the server (see the cookie notice).
From the application: the operator name, role, password hash, session identifier, sign-in time and address; the actions taken in the interface, recorded in the audit log.
From the customer's lead data: name, phone number or messenger identifier, email address, company, language, the source the contact came from, the text of the conversation, and the campaign metadata attached to it.
From support: the text of the question asked in the support widget and the answer given.
05 Why it is processed
- to conclude and perform the contract, open access and run the instance;
- to send and receive messages in the channels the customer has connected, and to keep one inbox for them;
- to keep a suppression list, so that a refusal is honoured everywhere and permanently;
- to answer support requests and to improve the product's documentation;
- to protect the service: rate limits, abuse detection, audit logs, incident investigation;
- to issue invoices and meet accounting and tax obligations;
- to answer requests from authorities where the law requires it.
06 How it is processed, and what is not automated
Processing is mixed: automated with the use of information systems, and non-automated where a person reads or writes. Data is collected, recorded, systematised, stored, updated, extracted, used, transferred to the recipients named below, blocked, deleted and destroyed.
The product drafts first messages and translations with a language model, but it is built so that no decision with legal or financial consequences is taken automatically. Prices, discounts, availability and commitments are blocked by policy; as soon as a conversation reaches real intent, the system stops writing and calls a human operator, who sees the whole thread. This is deliberate, and it is what Article 16 of 152-FZ requires.
07 Who else sees the data
Data is disclosed only to those who need it to deliver the service, each under a contract that binds them to confidentiality and to processing on instruction:
- the hosting provider on whose infrastructure the instance runs;
- the language-model provider that drafts and translates messages — it receives the fields required to compose one message, not the database;
- the provider of the support assistant, which receives the text of a support question;
- the messaging platforms and mail providers the customer has connected, under the customer's own relationship with them;
- state authorities, when a request is made in the form and on the grounds the law prescribes.
The current list, with names and locations, is published in the data processing addendum. Personal data is not sold, rented or given for someone else's advertising.
08 Cross-border transfer and data localisation
Delivering the service involves transferring data outside the Russian Federation. Before such transfer begins the Operator files the notification required by Article 12 of 152-FZ, and where a receiving country is not on the list of states providing adequate protection, transfer is carried out only on the additional grounds that article allows.
Where the data actually sits. The site, the sign-in gate and the app run on leased servers in the European Union; the hosting provider is a company registered in Germany. The other parties engaged, with their locations, are listed in the data processing addendum. A standard configuration uses no database located in the Russian Federation.
What follows from that under Article 18(5) of 152-FZ. The article requires that, when personal data of Russian citizens is collected, its recording, systematisation, accumulation, storage, updating and retrieval be carried out using databases located in Russia. A standard configuration does not meet that requirement, and the Operator says so plainly rather than in general terms. A customer to whom the article applies gets an instance deployed on infrastructure in Russia — tell the Operator before uploading such data. If having your data outside Russia is unacceptable to you, write to the privacy address before you send it to us.
09 How long it is kept
- website messages — until the question is closed and 1 year after, then deleted;
- account and audit data — for the term of the contract and 1 year after it ends;
- lead data and conversations — for the term of the contract; on termination, exported and deleted under the data processing addendum;
- suppression records — kept indefinitely on purpose: this is the only way a refusal can stay honoured after everything else is deleted;
- accounting documents — 5 years, as tax law requires.
Backups roll off on their own schedule and are overwritten within 30 days.
10 Security measures
The measures required by Articles 18.1 and 19 of 152-FZ that the Operator actually applies:
- a person responsible for organising the processing of personal data is appointed;
- access is granted by role and only to those whose work requires it; staff are bound to confidentiality;
- channel credentials, proxy passwords and session secrets are encrypted at rest and are never returned through the API;
- each sending account runs isolated — its own worker, its own proxy, its own identity;
- the service is served over TLS with strict transport security; management ports are closed at the firewall;
- sign-in is rate-limited; actions in the application are written to an audit log;
- backups are taken and their integrity is verified;
- incidents are investigated on a written procedure, and the measures are reviewed after each one.
11 Your rights, and how to use them
You may ask for confirmation that your data is processed, for access to it, for its correction, blocking or destruction if it is incomplete, out of date, unlawfully obtained or not needed for the stated purpose; you may withdraw consent; you may object to the processing; and you may complain to Roskomnadzor or go to court.
Send the request to the privacy address in the details below. Include enough to identify you — the name and the contact the data is held under — and say what you want done. The Operator answers within 10 working days of receiving the request, as Article 20 of 152-FZ requires; if the request needs more work, the period may be extended once by no more than 5 working days, and you will be told why.
If your data reached us because a customer uploaded you as a lead, the Operator will forward your request to that customer, who is the operator in that case, and will suppress you meanwhile.
12 Refusing messages
One refusal is enough, and it is permanent. Answer “stop” — in any wording, in any language — to a message from any account, or write to the abuse address below. The contact is added to the suppression list and no account, campaign or channel on the platform will write to it again. The check runs before every send, so a later re-import of the same contact does not revive it.
13 If data leaks
On becoming aware of an incident involving unlawful transfer of or access to personal data, the Operator notifies Roskomnadzor within 24 hours of the fact and of the measures taken, and within 72 hours of the result of the internal investigation, as required by Article 21(3.1) of 152-FZ. Affected customers are notified without undue delay, with what is known at the time and what is being done.
14 Changes and contacts
This policy may be updated. The current version is always the one published here, with its revision number and date at the top of the page; the previous version is provided on request.
Questions about personal data, and requests under the section above, go to the privacy address in the operator details below.