● Legal
Data Processing Addendum
How Swelv processes personal data on behalf of its customers in the swelv platform. It forms part of the Master Services Agreement and sets out the controller and processor terms under Article 28 of the GDPR and the UK GDPR.
Last updated 10 Sept 2026
1. Parties and roles
This Data Processing Addendum (DPA) is between the Customer and the Swelv entity named in its Order Form under the Master Services Agreement (the Agreement). Terms defined in the Agreement have the same meaning here.
Contracting entity
The processor is the entity the Customer contracts with, listed for where the Customer is established. Swelv Group Limited is not a party to this DPA.
| Contracts with | Entity | Registered office | Governing law |
|---|---|---|---|
| UK customers | Swelv LtdUnited KingdomCompany number 17372800VAT {{VAT_NUMBERS}}ICO registration {{ICO_REG_NUMBER}} | 82A James Carter RoadMildenhall, IP28 7DEUnited Kingdom | England and Wales |
| EEA customers | {{SWELV_IE_LEGAL_NAME}}IrelandCompany number {{SWELV_IE_COMPANY_NUMBER}}VAT {{VAT_NUMBERS}} | {{SWELV_IE_REGISTERED_OFFICE}}Ireland | Ireland |
| US customers | Hammerstone Enterprises, Inc.Delaware, United StatesDelaware file number 10668153 | Registered agent: Harvard Business Services16192 Coastal HighwayLewes, DE 19958United States | Delaware |
| Customers elsewhere | {{ROW_CONTRACTING_ENTITY}} | ||
| Not a contracting party | Swelv Group LimitedIsle of ManCompany number 139338COwns the swelv intellectual property and licenses it to the entities above. | Cayman National House, 4-8 Hope StreetDouglas, IM1 1AQIsle of Man | Not applicable |
For Customer Personal Data, the Customer is the controller and Swelv is its processor. Where the Customer itself acts as a processor for someone else, such as a fund administrator acting for a fund manager, Swelv is its subprocessor, and the Customer is responsible for passing instructions and notices between Swelv and that controller.
2. Definitions
“Controller”, “processor”, “personal data”, and “processing” have the meanings given in Data Protection Law. In addition:
- Data Protection Law: the GDPR (Regulation (EU) 2016/679), the UK GDPR and the UK Data Protection Act 2018, and any other data protection law that applies to the processing.
- Customer Personal Data: personal data in Customer Data that Swelv processes on the Customer’s behalf.
- Subprocessor: a third party Swelv engages to process Customer Personal Data.
- Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of, or access to, Customer Personal Data.
- SCCs: the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914.
- UK Addendum: the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner.
3. Processing on instructions
Swelv processes Customer Personal Data only on the Customer’s documented instructions, unless the law requires otherwise, in which case Swelv will tell the Customer first unless the law prohibits it. The Agreement, the Order Form, and the Customer’s configuration of the Services are the Customer’s instructions.
Swelv will tell the Customer if, in its opinion, an instruction infringes Data Protection Law. Swelv does not sell Customer Personal Data and does not process it for its own purposes.
The subject matter, nature, and purpose of the processing, and the types of data and people involved, are set out in Annex 1.
4. Confidentiality and security
Swelv ensures that the people it authorises to process Customer Personal Data are bound by confidentiality, and limits access to those who need it.
Swelv implements the technical and organisational measures in Annex 2. It may update them, provided the overall level of protection is not reduced.
5. Subprocessors
The Customer gives Swelv general authorisation to engage Subprocessors. The current list is on the Subprocessors page.
Swelv will give at least 30 days’ notice before a new Subprocessor starts processing Customer Personal Data. The Customer may object on reasonable data protection grounds within that period, and the parties will discuss the objection in good faith. If it cannot be resolved, the Customer may terminate the affected Services and receive a refund of prepaid fees for the period after termination.
Swelv imposes data protection obligations on each Subprocessor, by written contract, that are no less protective than this DPA, and remains responsible to the Customer for each Subprocessor’s performance.
6. International transfers
Swelv transfers Customer Personal Data outside the UK or the European Economic Area only where an adequacy decision or an appropriate safeguard under Data Protection Law covers the transfer.
- For transfers subject to the GDPR, the SCCs apply and are incorporated into this DPA: Module 2 where the Customer is a controller, and Module 3 where it is a processor. For Clauses 17 and 18, they are governed by the law of Ireland, and disputes go to the courts of Ireland.
- For transfers subject to the UK GDPR, the SCCs apply as amended by the UK Addendum.
- Where the recipient is certified under a framework the law recognises as adequate, such as the EU-US Data Privacy Framework, that certification may be relied on instead.
The particulars the SCCs require are in Annexes 1 and 2 and on the Subprocessors page.
7. Helping the Customer
Requests from individuals. If Swelv receives a request from an individual about Customer Personal Data, it will pass the request to the Customer and will not respond itself, other than to acknowledge it and direct the individual to the Customer. The Services let platform users export their own personal data and erase their accounts, and Swelv will give the Customer any other reasonable help it needs to respond.
Assessments. Swelv will give reasonable help with data protection impact assessments, and with prior consultations with supervisory authorities, that relate to the Services.
8. Personal data breaches
Swelv will notify the Customer without undue delay after becoming aware of a Personal Data Breach. The notice will describe, as far as Swelv then knows, the nature of the breach, the categories and approximate number of people and records concerned, its likely consequences, and the measures taken or proposed. Swelv will provide further information as it becomes available, and cooperate with the Customer’s response.
Notifying a breach is not an admission of fault.
9. Deletion and return
When the Agreement ends, the Customer can export its Customer Data for 30 days. After that, Swelv will delete or irreversibly anonymise Customer Personal Data, unless the law requires Swelv to keep it. Anything kept for that reason stays protected by this DPA for as long as it is kept.
10. Audits
Swelv will make available the information reasonably needed to demonstrate that it meets its obligations under this DPA, and will allow audits, including inspections, by the Customer or an independent auditor it appoints, subject to reasonable confidentiality undertakings.
The Customer will give at least 30 days’ notice. Audits take place no more than once a year, unless a Personal Data Breach or a supervisory authority requires otherwise, during business hours so as to limit disruption, and at the Customer’s cost.
11. Liability, precedence, and governing law
Each party’s liability under this DPA is subject to the limits in the Agreement, to the extent the SCCs allow.
If this DPA conflicts with the Agreement on the processing of personal data, this DPA prevails. If it conflicts with the SCCs or the UK Addendum, they prevail.
This DPA is governed by the same law as the Agreement, which follows the Swelv entity in clause 1, except where the SCCs or the UK Addendum provide otherwise.
Details of the processing
| Item | Details |
|---|---|
| Subject matter | Providing the swelv platform to the Customer under the Agreement. |
| Duration | The term of the Agreement, followed by the export and deletion period in clause 9. |
| Nature and purpose | Hosting, storing, and organising Customer Data; calculating and allocating capital calls, distributions, fees, and equalisation as the Customer configures them; generating and delivering notices and reports; matching payments against account information; extracting data from uploaded documents; and supporting and securing the Services. |
| People concerned | Investors in the Customer's Funds and their authorised signatories, beneficial owners, and advisers; the Customer's personnel and other Authorised Users; and individuals named in documents the Customer uploads. |
| Categories of personal data | Identification and contact details; account and login data; investment data such as commitments, capital account balances, contributions, and distributions; bank account details used for payments; personal data contained in documents the Customer uploads; and records of activity in the Services. |
| Special categories | None intended. The Customer should not submit special category data or criminal offence data unless the parties have agreed in writing how it will be handled. |
| Frequency | Continuous, for the duration of the Agreement. |
Technical and organisational measures
| Area | Measure |
|---|---|
| Encryption in transit | Connections to the Services are encrypted with TLS. |
| Access control | Role-based access separates fund manager and investor views. Each customer's data is scoped to that customer, and investors see only the information made available to them. |
| Personnel | Access to Customer Personal Data by Swelv personnel is limited to those who need it, and bound by confidentiality. |
| Activity records | Sign-ins and other account actions are recorded in an activity log. |
| Change review | Changes to the platform are reviewed before release for tenant isolation, personal data in logs, and retention handling. |
| Banking credentials | Investors authorise pay-by-bank payments at their own bank. Swelv does not receive or store their online banking credentials. |
| Individual rights | Platform users can export their personal data and erase their accounts themselves. Erasure reports what was removed, and what was kept and why. |
| Breaches and subprocessors | Personal Data Breaches are handled and notified as clause 8 describes, and subprocessors are engaged as clause 5 describes. |
Subprocessors
The Subprocessors authorised under clause 5 are listed on the Subprocessors page, which forms part of this DPA.