Privacy Notice

Last updated: 28 August 2026

Applicability

This notice describes how Swarmlabs B.V. (“Swarmlabs”, “we”) collects, uses and discloses personal information in connection with our website and platform.

Swarmlabs acts as a controller for information relating to our own users and website visitors, as described below. Where our customers use the platform to process information about their own contacts and end users — including content they choose to connect from messaging and email accounts — Swarmlabs acts as their processor under a data processing agreement, and the customer is the controller. If you are an end user of one of our customers, please direct requests about your information to that organisation in the first instance.

Information we collect

How we use information

We use personal information to provide, secure, support and improve the platform; to communicate with you about your account and our services; to meet our legal and contractual obligations; and to detect and prevent fraud, abuse and security incidents.

Where the GDPR applies, we rely on the performance of our contract with you, our legitimate interests in operating and securing our services, compliance with legal obligations, and — where applicable — your consent.

Connected services

Our customers may connect third-party messaging and email accounts, including WhatsApp Business and Microsoft or Google mailboxes, so that communications arriving there can be handled in the platform. Where a customer does so, we receive and process the content and associated metadata of those communications on the customer’s instructions, for the purpose of providing the service they have configured.

Access is limited to the accounts a customer designates and to the permissions their administrator approves, which can be withdrawn at any time. We do not use information obtained through connected services for advertising, and we do not sell it.

Artificial intelligence

The platform uses AI models to classify, summarise and answer questions about content. Requests are routed through our AI gateway provider to model providers acting on our behalf, under terms that restrict their use of the content to fulfilling the request.

Customer content is not used to train AI models, by us or by the providers we route to. We apply automated measures to reduce personal information in content before it is submitted for processing. AI output is advisory and remains subject to human review.

How we disclose information

We do not sell personal information and we do not share it for advertising purposes. We disclose information to categories of service providers who process it on our behalf, including cloud infrastructure and hosting providers, AI service providers, communications and messaging platforms, and email delivery providers. Each is engaged under terms requiring appropriate safeguards.

We may also disclose information where required by law, to enforce our agreements, or in connection with a corporate transaction. A current list of our subprocessors is available on request.

International transfers

We host and process platform data within the European Union. Certain service providers operate global infrastructure and may process information outside the European Economic Area; where they do, transfers are made under appropriate safeguards, including the European Commission’s Standard Contractual Clauses.

How we retain information

We retain personal information for as long as necessary to provide the platform and for the purposes described in this notice. Customer content is retained according to the customer’s configuration and is deleted following termination, subject to routine backup cycles. We retain certain records for longer where required by law, such as financial records under applicable tax legislation.

How we secure information

We maintain appropriate technical and organisational measures designed to protect personal information against unauthorised access, disclosure, alteration and loss. These include encryption in transit and at rest, access controls, and logical separation between customers’ environments. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Further detail is available to customers on request.

Cookies

We use strictly necessary cookies to authenticate users and maintain sessions. We do not use advertising or third-party tracking cookies, and we do not track users across other websites. Because we set only strictly necessary cookies, no consent banner is presented.

Your privacy rights

Subject to applicable law, you may request access to the personal information we hold about you, its correction or deletion, restriction of or objection to its processing, and a portable copy. Where processing is based on consent, you may withdraw it at any time.

To exercise these rights, contact us at privacy@swarmlabs.eu. If you are an end user of one of our customers, we will refer your request to that organisation. You also have the right to lodge a complaint with your local supervisory authority; in the Netherlands this is the Autoriteit Persoonsgegevens.

Minimum age

The platform is intended for business use and is not directed to children. We do not knowingly collect personal information from children.

Changes to this notice

We may update this notice from time to time. The date above indicates when it was last revised, and we will provide notice of material changes where required.

Contact us

Swarmlabs B.V.
Uilenstede 500-85, 1183 DE Amstelveen, Netherlands
Chamber of Commerce (KvK) 42060009
privacy@swarmlabs.eu