- Swish is a business CRM operated by Modern Synergy Limited, trading as Swish (company number 16859014).
- For practice patient and lead data, the subscribing organisation is normally the controller and Swish acts as its processor.
- We use Meta data only for authorised connections, lead delivery, attribution, messaging and related platform functions.
- We do not sell personal information or Meta Platform Data.
- You can disconnect Meta and request deletion through our Data Deletion page.
1. Who we are
Swish is a customer relationship management, lead management, reporting, communications and business-performance platform operated by Modern Synergy Limited, trading as Swish (company number 16859014) (“Swish”, “we”, “us” or “our”).
2. Our data protection roles
When we act as controller
We are normally the controller for information about website visitors, prospective customers, account holders, tenant administrators, billing contacts, support contacts, authorised integration users and people who communicate with us directly.
When we act as processor
Our customer or tenant is normally the controller for patient, prospective-patient, lead, referral, employee, clinician and practice data entered into Swish or received through a connected source. We process that information on the tenant’s documented instructions to provide the service. The tenant decides why that data is used, which staff may access it, how long it should be retained and what communications are appropriate.
Separate controllers
Meta, Google, Stripe and other third-party providers operate under their own terms and privacy notices and may act as separate controllers for parts of their services.
3. Information we process
Account and identity
Name, business email, telephone, job title, username, authentication records, role, tenant and practice access.
Organisation and service
Business and practice names, addresses, websites, branding, package, configuration, workflows and authorised users.
CRM and lead data
Names, contact details, treatment interests, messages, lead sources, notes, tasks, appointments, status, values, payments, referrals, consent records and activity history.
Billing and contracts
Proposal, subscription, invoice, payment status, Stripe identifiers, acceptance evidence and legally required transaction records. Card details are handled by Stripe and are not stored by Swish.
Communications
Emails, support requests, chat and messaging content, attachments, delivery status, internal notes and contact preferences.
Technical and security
IP address, browser, device, timestamps, login history, audit logs, diagnostic data, webhook records and security events.
Advertising and attribution
UTM parameters, click identifiers, campaign, ad set, advert, creative, form, source, medium, conversion and revenue attribution.
Usage and analytics
Pages viewed, features used, interactions, performance, errors and aggregated product analytics.
4. Facebook, Instagram and Meta data
Where an authorised user connects Meta to Swish, we may process data made available through Meta’s APIs and the permissions granted by that user. Depending on enabled features, this may include:
- the authorising person’s name and Meta app-scoped user identifier;
- Facebook Page IDs, Page names, permitted tasks and connection status;
- access tokens and token expiry information, stored in encrypted form;
- instant-form IDs, names, questions and lead submissions;
- lead name, email, telephone, answers, submission time and Meta lead identifier;
- campaign, ad set, advert, creative and attribution identifiers;
- linked Instagram professional-account identifiers and basic account details when enabled;
- Facebook Messenger and Instagram message content, participants, attachments and delivery information when those channels are enabled;
- conversion events sent back to Meta where the tenant activates conversion feedback.
We use this data only to provide the authorised Swish functions, route and manage enquiries, maintain an audit trail, support reporting, troubleshoot the connection, protect the platform and comply with law and Meta’s applicable terms. We do not use a tenant’s Meta data to market to that tenant’s patients for our own independent purposes.
An authorised tenant administrator can disconnect a Meta connection. The Meta user can also remove Swish through their Facebook Apps and Websites or Business Integrations settings. Disconnecting stops future API access but does not automatically erase records already lawfully stored in Swish; deletion can be requested separately.
5. Purposes and lawful bases
| Purpose | Typical lawful basis |
|---|---|
| Provide accounts, subscriptions, CRM, integrations and support | Contract; legitimate interests in operating the service |
| Process tenant-controlled lead and patient data | Processed on the tenant controller’s instructions under our data-processing terms |
| Billing, tax, proposals and contractual records | Contract; legal obligation; legitimate interests |
| Security, fraud prevention, access control and audit | Legitimate interests; legal obligation where applicable |
| Product analytics, reliability and improvement | Legitimate interests; consent where non-essential cookies require it |
| Sales and service communications | Contract, legitimate interests or consent depending on the communication |
| Compliance, disputes and legal claims | Legal obligation; legitimate interests; establishment, exercise or defence of legal claims |
Where consent is the basis, it may be withdrawn at any time without affecting processing already undertaken. Tenants are responsible for identifying the lawful basis and any additional condition required for their own use of patient or special-category data.
6. Where information comes from
We obtain information directly from users and customers; from tenants and their authorised staff; from forms, campaign pages, referrals and UGC forms; from connected services such as Meta, Google, email providers, Stripe and practice systems; from cookies and technical logs; and from publicly available business sources where appropriate.
Where a tenant obtains a person’s information from another source, the tenant remains responsible for providing required privacy information at the correct time.
8. International transfers
Some service providers or connected platforms may process information outside the United Kingdom. Where required, we use recognised safeguards such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful transfer mechanism. Information about relevant safeguards can be requested from our privacy contact.
9. How long we keep information
We keep information only for as long as needed for the purposes described, the tenant’s instructions and legal obligations. Our typical criteria are:
- account and contract records: while the account is active and normally up to seven years afterwards;
- billing, tax and transaction evidence: normally six years after the relevant financial period or longer where law requires;
- CRM lead and patient data: according to the tenant controller’s configuration, instructions and applicable clinical or legal duties;
- Meta and other connection tokens: until disconnected, expired or no longer required, followed by secure deletion from active systems;
- security and audit logs: generally up to 24 months unless needed for an investigation;
- support records: generally up to three years after closure;
- unsuccessful sales enquiries: normally up to 24 months unless consent or legitimate need supports longer retention;
- backups: removed through normal rotation, which may take up to 90 days after deletion from active systems.
We may retain limited records longer where necessary for legal claims, fraud prevention, safeguarding, regulatory duties or to record a suppression/opt-out preference.
10. Security
We use proportionate technical and organisational measures including role-based access, tenant and practice separation, encryption of sensitive connection credentials, HTTPS, password controls, audit logging, backups, monitoring, controlled administrative access and supplier due diligence. No service can guarantee absolute security, and users must protect their credentials, devices and authorised access.
Tenants must promptly remove leavers, configure permissions appropriately, use supported secure integrations and notify us of suspected unauthorised access.
11. Your data protection rights
Depending on the circumstances and lawful basis, you may have rights to be informed, access, rectify, erase, restrict, object, receive portable data and complain about automated decision-making. You may also withdraw consent where consent is used.
Your right to object: you may object to direct marketing at any time, and may object to processing based on legitimate interests in certain circumstances.
For patient or lead data controlled by a tenant, contact the relevant practice first. We will assist the tenant in responding where required. For Swish-controlled data, email info@swish.click or use the Data Deletion page. We may need to verify identity and authority before acting.
12. Marketing and service messages
Service, security, billing and account messages are necessary to operate Swish. Marketing messages are sent only where permitted. You can unsubscribe using the link provided or contact us. We may retain a minimal suppression record to respect an opt-out.
14. Children
Swish is a business service and is not directed at children. A healthcare tenant may process information about a child patient where it has an appropriate legal basis, authority and safeguards. Tenants must not use Swish to collect children’s data unlawfully or without required notices and consent/authority.
15. Data deletion and disconnection
Meta users can remove Swish from Facebook’s Apps and Websites or Business Integrations settings. Tenant administrators can disconnect integrations inside Swish. To request deletion of data held by Swish, use our Data Deletion page. We will delete or anonymise eligible information and explain any lawful retention that applies.
16. Changes to this notice
We review this notice as the platform, integrations and law develop. The effective date and version appear at the top. Material changes will be brought to account holders’ attention where appropriate before new processing begins.
17. Contact and complaints
Please contact us first so we can investigate. You also have the right to complain to the UK Information Commissioner’s Office. Information about making a complaint is available from the ICO.