● Legal
Privacy Policy
How Swelv handles personal data. For this website, our marketing, and our sales conversations, we decide how data is used. For data inside the swelv platform, we act for the customer that engaged us.
Last updated 10 Sept 2026
Who we are
Swelv operates through the entities below. For the personal data in Part A of this policy, the controller is the entity listed for your location, and “Swelv”, “we” and “us” mean that entity.
Contracting entity
For website visitors, marketing contacts, and sales contacts, the controller is the entity listed for your location. Swelv Ltd’s registration with the UK Information Commissioner’s Office is shown against it.
| Contracts with | Entity | Registered office | Governing law |
|---|---|---|---|
| UK customers | Swelv LtdUnited KingdomCompany number 17372800VAT {{VAT_NUMBERS}}ICO registration {{ICO_REG_NUMBER}} | 82A James Carter RoadMildenhall, IP28 7DEUnited Kingdom | England and Wales |
| EEA customers | {{SWELV_IE_LEGAL_NAME}}IrelandCompany number {{SWELV_IE_COMPANY_NUMBER}}VAT {{VAT_NUMBERS}} | {{SWELV_IE_REGISTERED_OFFICE}}Ireland | Ireland |
| US customers | Hammerstone Enterprises, Inc.Delaware, United StatesDelaware file number 10668153 | Registered agent: Harvard Business Services16192 Coastal HighwayLewes, DE 19958United States | Delaware |
| Customers elsewhere | {{ROW_CONTRACTING_ENTITY}} | ||
| Not a contracting party | Swelv Group LimitedIsle of ManCompany number 139338COwns the swelv intellectual property and licenses it to the entities above. | Cayman National House, 4-8 Hope StreetDouglas, IM1 1AQIsle of Man | Not applicable |
Swelv Group Limited owns the swelv intellectual property and licenses it to the entities above. It does not contract with customers.
For anything in this policy, including a request to exercise your rights, write to {{PRIVACY_CONTACT_EMAIL}}.
Two roles
We handle personal data in two different capacities, and the rules differ.
- As controller. For swelv.io, our marketing, and the people we speak to about working with us, we decide what is collected and why. Part A covers this.
- As processor. For data held in the swelv platform, such as investor records, capital accounts, and fund documents, we act on the instructions of the fund manager, administrator, or other customer that engaged us. That customer is the controller, and our commitments to it are in the Data Processing Addendum. Part B covers what this means for you.
Where we are the controller
This part covers three groups of people: visitors to swelv.io, people who receive our marketing, and the people we deal with at prospective and existing customers.
Website visitors
swelv.io is an informational website. It has no accounts, no login, no payment flow, and no connection to the databases behind the swelv platform. Nothing you do here touches fund data, investor records, or capital account information.
Analytics. We use Google Analytics 4 to understand which pages people read and which calls to action they use, and only if you allow it. It records the pages you view, the referring link, your device and browser, an approximate location derived from your IP address, and a small number of named interactions such as opening the booking drawer or expanding an FAQ. This is pseudonymous: we cannot tie it to your name.
Server logs. Our host records standard request logs, including IP address, user agent, and timestamps. These exist for reliability, abuse prevention, and security investigation.
Fonts. Typefaces are delivered by Fontshare. Loading a page means your browser requests those files, so Fontshare sees your IP address.
Settings in your browser. Your analytics choice and your light or dark theme are stored in your own browser. The Cookie Policy lists each one.
Marketing
We run no advertising networks on this site, and we do not sell personal data or share it with anyone for their own marketing.
If we send you news about swelv by email, it is because you asked for it, or because you are a business contact who has dealt with us and the law allows it. Every message tells you how to stop them, and we act on that request.
Sales and customer contacts
Booking a call. Our scheduling drawer is provided by Cal.com, running on its European instance. If you book, you give it your name, email address, timezone, and anything you type into the booking form. We receive that booking so we can meet you.
Correspondence and meetings. When you email us or we meet, we keep your name, work contact details, organisation, role, and what we discussed, so we can follow up and keep track of the conversation.
Customer relationships. Once your organisation is a customer, we keep the details of the people we deal with there for the contract, invoicing, and support.
Most of this comes from you. Some may come from a colleague who introduces you, or from professional information your organisation publishes about its team.
Legal bases
Under the GDPR and the UK GDPR we rely on the following:
- Consent for analytics. Google Analytics is not loaded until you allow it, and you can withdraw that permission at any time. If you decline, we do not fall back to another basis; there is simply no analytics. We also rely on consent for marketing email where the law requires it.
- Legitimate interests for security, abuse prevention, and keeping the site running, which is what our host’s server logs are for; for running our sales conversations and customer relationships; and for marketing email to business contacts where the law allows it. We weigh each of these against your interests and keep them to what the purpose needs.
- Steps taken at your request before entering a contract when you book a call or ask about working with us.
- Legal obligation for the invoicing and accounting records we are required to keep.
Who helps us, and international transfers
We use a small number of processors for the activities in this part: Vercel for hosting, Google for analytics, Cal.com for scheduling, Fontshare for typefaces, and the providers of our email and calendar tools. Some of them process data outside the UK or the European Economic Area. Where no adequacy decision covers the destination, the transfer relies on the European Commission’s Standard Contractual Clauses, the UK’s International Data Transfer Addendum, or an equivalent safeguard.
How long we keep things
Analytics data is retained according to the retention period configured in Google Analytics and is then deleted automatically. Booking records and correspondence are kept for as long as we have a live conversation with you and for a reasonable period afterwards, unless you ask us to erase them sooner. Customer contact records are kept for the life of the contract and afterwards for as long as accounting and tax law requires. Server logs are short lived and rotate on our host’s schedule.
Your rights
If your data is processed in the UK or the EEA, you can ask us for a copy of it, and ask us to correct it, erase it, restrict how we use it, or hand it to another provider. You can object to processing we base on legitimate interests, ask us to stop marketing to you at any time, and withdraw consent without affecting what came before. If you are elsewhere, you can make the same requests and we will answer them.
Write to {{PRIVACY_CONTACT_EMAIL}} and we will respond within one month. If you are not satisfied with our answer, you can complain to a data protection supervisory authority: in the UK, the Information Commissioner’s Office; in Ireland, the Data Protection Commission; elsewhere in the EEA, the authority in the country where you live or work.
Cookies and similar technologies
The only non-essential identifiers this site sets are the analytics cookies described above, and they are off until you allow them. Declining does not stop any part of the site working. The Cookie Policy lists everything the site stores, and how to change your choice.
Where we act for your fund
If you are an investor, a member of a fund manager’s team, or anyone else whose details are in the swelv platform because a customer uses it, that customer is the controller of your data, and its own privacy notice explains how your data is used. We process it only on the customer’s instructions and under the Data Processing Addendum. The third parties we use to do so are listed on the Subprocessors page.
To exercise your rights over that data, contact the fund manager or administrator first. If you write to us instead, we will pass your request to the customer and help it respond.
If you use the platform, you can also act directly: under User settings → Privacy & your data you can export a copy of your personal data or erase your account. Some records may be kept after erasure where a fund needs them for its own legal, tax, or anti-money-laundering obligations, and you are told what was kept and why.
Changes
If this policy changes in a way that matters, we will update the date at the top of the page. We suggest checking it whenever you are about to share something with us.