- Swish is a business CRM operated by Modern Synergy Limited, trading as Swish (company number 16859014).
- For practice patient and lead data, the subscribing organisation is normally the controller and Swish acts as its processor.
- We use Meta and Google data only for authorised connected-service functions selected by the customer.
- Our use of Google API data follows Google API Services User Data Policy requirements, including Limited Use.
- We do not sell personal information, Meta Platform Data or Google user data received through connected APIs.
- You can disconnect Meta and request deletion through our Data Deletion page.
1. Who we are
Swish is a customer relationship management, lead management, reporting, communications and business-performance platform operated by Modern Synergy Limited, trading as Swish (company number 16859014) (“Swish”, “we”, “us” or “our”).
2. Our data protection roles
When we act as controller
We are normally the controller for information about website visitors, prospective customers, account holders, tenant administrators, billing contacts, support contacts, authorised integration users and people who communicate with us directly.
When we act as processor
Our customer or tenant is normally the controller for patient, prospective-patient, lead, referral, employee, clinician and practice data entered into Swish or received through a connected source. We process that information on the tenant’s documented instructions to provide the service. The tenant decides why that data is used, which staff may access it, how long it should be retained and what communications are appropriate.
Separate controllers
Meta, Google, Stripe and other third-party providers operate under their own terms and privacy notices and may act as separate controllers for parts of their services.
3. Information we process
Account and identity
Name, business email, telephone, job title, username, authentication records, role, tenant and practice access.
Organisation and service
Business and practice names, addresses, websites, branding, package, configuration, workflows and authorised users.
CRM and lead data
Names, contact details, treatment interests, messages, lead sources, notes, tasks, appointments, status, values, payments, referrals, consent records and activity history.
Billing and contracts
Proposal, subscription, invoice, payment status, Stripe identifiers, acceptance evidence and legally required transaction records. Card details are handled by Stripe and are not stored by Swish.
Communications
Emails, support requests, chat and messaging content, attachments, delivery status, internal notes and contact preferences.
Technical and security
IP address, browser, device, timestamps, login history, audit logs, diagnostic data, webhook records and security events.
Advertising and attribution
UTM parameters, click identifiers, campaign, ad set, advert, creative, form, source, medium, conversion and revenue attribution.
Usage and analytics
Pages viewed, features used, interactions, performance, errors and aggregated product analytics.
4. Facebook, Instagram and Meta data
Where an authorised user connects Meta to Swish, we may process data made available through Meta’s APIs and the permissions granted by that user. Depending on enabled features, this may include:
- the authorising person’s name and Meta app-scoped user identifier;
- Facebook Page IDs, Page names, permitted tasks and connection status;
- access tokens and token expiry information, stored in encrypted form;
- instant-form IDs, names, questions and lead submissions;
- lead name, email, telephone, answers, submission time and Meta lead identifier;
- campaign, ad set, advert, creative and attribution identifiers;
- linked Instagram professional-account identifiers and basic account details when enabled;
- Facebook Messenger and Instagram message content, participants, attachments and delivery information when those channels are enabled;
- conversion events sent back to Meta where the tenant activates conversion feedback.
We use this data only to provide the authorised Swish functions, route and manage enquiries, maintain an audit trail, support reporting, troubleshoot the connection, protect the platform and comply with law and Meta’s applicable terms. We do not use a tenant’s Meta data to market to that tenant’s patients for our own independent purposes.
An authorised tenant administrator can disconnect a Meta connection. The Meta user can also remove Swish through their Facebook Apps and Websites or Business Integrations settings. Disconnecting stops future API access but does not automatically erase records already lawfully stored in Swish; deletion can be requested separately.
5. Google connected-service data
Where an authorised user connects a supported Google service to Swish, we process only the Google data and permissions needed for the enabled feature. For Google Ads and Data Manager functions this can include Google account and customer identifiers, OAuth connection information, advertising account structure, campaign/ad group/advert identifiers, performance metrics, conversion-action identifiers, click identifiers and conversion/event data that the customer instructs Swish to send back to Google.
We use this information to provide the customer-requested connection, display advertising performance, support attribution and conversion measurement, create or manage supported conversion actions, transmit customer-directed conversion events, maintain the connection, troubleshoot errors, protect the service and comply with law and Google’s applicable terms.
Swish’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use it for unrelated advertising, or allow human access except where necessary to provide or support the requested feature, investigate security or abuse, comply with law, or where the user has given appropriate consent.
Authorised administrators can disconnect supported Google integrations in Swish. Users can also revoke access through their Google account security settings. Disconnecting stops future API access; eligible stored data can be deleted or anonymised in accordance with this notice, the customer controller’s instructions and our Data Deletion process.
6. Email delivery and messaging
Where a customer enables Swish-managed email, we may process sender identity and domain information, recipient addresses, campaign/message content, delivery status, opens and clicks where enabled, unsubscribe events, hard bounces, complaints, suppression state and technical delivery records. Amazon Simple Email Service (Amazon SES) is used as email-delivery infrastructure for supported Swish sending.
The customer remains responsible for deciding whether it may lawfully send a particular communication. For production marketing sent through Swish-managed sending infrastructure, customers are required to contact recipients who have affirmatively opted in to the relevant marketing or explicitly requested the communication. Swish supports confirmation/double-opt-in workflows where configured.
We do not permit purchased, rented, scraped or harvested consumer mailing lists in the managed sending programme. Marketing emails must identify the sending business and provide an effective unsubscribe route. Opt-outs, hard bounces and complaint events are used to suppress future marketing as described in our Email & Messaging Practices.
7. Purposes and lawful bases
| Purpose | Typical lawful basis |
|---|---|
| Provide accounts, subscriptions, CRM, integrations and support | Contract; legitimate interests in operating the service |
| Process tenant-controlled lead and patient data | Processed on the tenant controller’s instructions under our data-processing terms |
| Billing, tax, proposals and contractual records | Contract; legal obligation; legitimate interests |
| Security, fraud prevention, access control and audit | Legitimate interests; legal obligation where applicable |
| Product analytics, reliability and improvement | Legitimate interests; consent where non-essential cookies require it |
| Sales and service communications | Contract, legitimate interests or consent depending on the communication |
| Compliance, disputes and legal claims | Legal obligation; legitimate interests; establishment, exercise or defence of legal claims |
Where consent is the basis, it may be withdrawn at any time without affecting processing already undertaken. Tenants are responsible for identifying the lawful basis and any additional condition required for their own use of patient or special-category data.
8. Where information comes from
We obtain information directly from users and customers; from tenants and their authorised staff; from forms, campaign pages, referrals and UGC forms; from connected services such as Meta, Google, email providers, Stripe and practice systems; from cookies and technical logs; and from publicly available business sources where appropriate.
Where a tenant obtains a person’s information from another source, the tenant remains responsible for providing required privacy information at the correct time.
10. International transfers
Some service providers or connected platforms may process information outside the United Kingdom. Where required, we use recognised safeguards such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful transfer mechanism. Information about relevant safeguards can be requested from our privacy contact.
11. How long we keep information
We keep information only for as long as needed for the purposes described, the tenant’s instructions and legal obligations. Our typical criteria are:
- account and contract records: while the account is active and normally up to seven years afterwards;
- billing, tax and transaction evidence: normally six years after the relevant financial period or longer where law requires;
- CRM lead and patient data: according to the tenant controller’s configuration, instructions and applicable clinical or legal duties;
- Meta and other connection tokens: until disconnected, expired or no longer required, followed by secure deletion from active systems;
- security and audit logs: generally up to 24 months unless needed for an investigation;
- support records: generally up to three years after closure;
- unsuccessful sales enquiries: normally up to 24 months unless consent or legitimate need supports longer retention;
- backups: removed through normal rotation, which may take up to 90 days after deletion from active systems.
We may retain limited records longer where necessary for legal claims, fraud prevention, safeguarding, regulatory duties or to record a suppression/opt-out preference.
12. Security
We use proportionate technical and organisational measures including role-based access, tenant and practice separation, encryption of sensitive connection credentials, HTTPS, password controls, audit logging, backups, monitoring, controlled administrative access and supplier due diligence. No service can guarantee absolute security, and users must protect their credentials, devices and authorised access.
Tenants must promptly remove leavers, configure permissions appropriately, use supported secure integrations and notify us of suspected unauthorised access.
13. Your data protection rights
Depending on the circumstances and lawful basis, you may have rights to be informed, access, rectify, erase, restrict, object, receive portable data and complain about automated decision-making. You may also withdraw consent where consent is used.
Your right to object: you may object to direct marketing at any time, and may object to processing based on legitimate interests in certain circumstances.
For patient or lead data controlled by a tenant, contact the relevant practice first. We will assist the tenant in responding where required. For Swish-controlled data, email hello@swish.click or use the Data Deletion page. We may need to verify identity and authority before acting.
14. Marketing and service messages
Service, security, billing and account messages are used to operate Swish and are distinct from promotional marketing. For Swish’s own marketing we use an appropriate lawful basis and provide a clear opt-out where required.
For production marketing sent by customers through Swish-managed email infrastructure, the customer must have affirmative marketing permission or another form of explicit request that lawfully covers the communication. Merely having an email address in a CRM is not treated by this policy as sufficient permission for promotional email. Customers must honour channel preferences, unsubscribe requests and suppression records and may use double opt-in where appropriate.
You can unsubscribe using the link provided or contact the sender. We may retain a minimal suppression record so that an opt-out, complaint or hard-bounce state can continue to be respected.
16. Children
Swish is a business service and is not directed at children. A healthcare tenant may process information about a child patient where it has an appropriate legal basis, authority and safeguards. Tenants must not use Swish to collect children’s data unlawfully or without required notices and consent/authority.
17. Data deletion and disconnection
Meta users can remove Swish from Facebook’s Apps and Websites or Business Integrations settings. Tenant administrators can disconnect integrations inside Swish. To request deletion of data held by Swish, use our Data Deletion page. We will delete or anonymise eligible information and explain any lawful retention that applies.
18. Changes to this notice
We review this notice as the platform, integrations and law develop. The effective date and version appear at the top. Material changes will be brought to account holders’ attention where appropriate before new processing begins.
19. Contact and complaints
Please contact us first so we can investigate. You also have the right to complain to the UK Information Commissioner’s Office. Information about making a complaint is available from the ICO.