Swish

Responsible use

Acceptable Use Policy

Rules designed to protect Swish customers, recipients, connected platforms and the reputation and security of the service.

Effective 11 September 2026Version 1.1
Permission, authority and security come first

This policy forms part of the Swish Terms and applies to customers, users, API clients and connected workspaces.

1. Scope

You must use Swish only for lawful business purposes and only with data, systems and connected accounts that you are authorised to use. You are responsible for activity carried out through your workspace and user accounts.

2. Lawful and authorised use

Do not use Swish to violate law, contractual obligations, intellectual-property rights, privacy rights or a connected provider’s platform rules. You must have an appropriate legal basis and authority for personal data you upload, receive, export, analyse or use for communications.

3. Email and messaging

Swish-managed marketing infrastructure is permission-first. You must not use it for spam, unsolicited bulk consumer marketing, phishing or deceptive communications.

  • Use recipients who have affirmatively opted in to the relevant marketing or explicitly requested the communication.
  • Do not use purchased, rented, scraped, harvested or indiscriminately generated consumer mailing lists.
  • Do not treat a publicly available address or the mere existence of a CRM record as marketing permission.
  • Do not bypass unsubscribe, hard-bounce, complaint or suppression controls.
  • Identify the sending business clearly and do not use misleading sender names, subjects or domains.
  • Use only authenticated sender identities approved for the relevant workspace.

We may restrict sending, require corrective action or suspend affected functionality where complaint, bounce, provider-warning or other evidence indicates abusive or high-risk sending.

4. Security

Do not probe, scan or exploit Swish, bypass access controls, introduce malware, abuse rate limits, share credentials inappropriately or attempt to access another workspace’s data. Good-faith security concerns should be reported to our support/privacy contact.

5. Prohibited activity

Swish must not be used for fraud, impersonation, harassment, unlawful discrimination, exploitation, illegal goods or services, malicious code, intellectual-property infringement or content that creates a serious and unjustified risk of harm.

6. Privacy and sensitive data

Process only information that is necessary, proportionate and lawful. Healthcare and other special-category data require an appropriate legal basis, transparency and safeguards. Do not use Swish to create unlawful secret profiles or to collect information in a way that deliberately avoids required notices or consent.

7. Connected services

If you connect Meta, Google, Microsoft, Dialpad, Dentally or another provider, you must also comply with that provider’s applicable terms, permissions and policies. Do not request access you do not need or direct Swish to use provider data for a prohibited purpose.

8. Enforcement

We may investigate suspected abuse, preserve relevant evidence, limit affected features, require remediation, revoke integration access or suspend/terminate access. Where safe and lawful, we aim to use proportionate measures and give customers an opportunity to remedy remediable issues.