SSWISH

Trust and transparency

Privacy Notice

This notice explains how Swish handles personal information across our website, CRM platform, integrations, sales, support and connected services.

Effective 1 August 2026Version 1.0
Key points
  • Swish is a business CRM operated by Modern Synergy Limited, trading as Swish (company number 16859014).
  • For practice patient and lead data, the subscribing organisation is normally the controller and Swish acts as its processor.
  • We use Meta data only for authorised connections, lead delivery, attribution, messaging and related platform functions.
  • We do not sell personal information or Meta Platform Data.
  • You can disconnect Meta and request deletion through our Data Deletion page.

1. Who we are

Swish is a customer relationship management, lead management, reporting, communications and business-performance platform operated by Modern Synergy Limited, trading as Swish (company number 16859014) (“Swish”, “we”, “us” or “our”).

Modern Synergy Limited, trading as Swish (company number 16859014)Email: info@swish.click

2. Our data protection roles

When we act as controller

We are normally the controller for information about website visitors, prospective customers, account holders, tenant administrators, billing contacts, support contacts, authorised integration users and people who communicate with us directly.

When we act as processor

Our customer or tenant is normally the controller for patient, prospective-patient, lead, referral, employee, clinician and practice data entered into Swish or received through a connected source. We process that information on the tenant’s documented instructions to provide the service. The tenant decides why that data is used, which staff may access it, how long it should be retained and what communications are appropriate.

Separate controllers

Meta, Google, Stripe and other third-party providers operate under their own terms and privacy notices and may act as separate controllers for parts of their services.

3. Information we process

Account and identity

Name, business email, telephone, job title, username, authentication records, role, tenant and practice access.

Organisation and service

Business and practice names, addresses, websites, branding, package, configuration, workflows and authorised users.

CRM and lead data

Names, contact details, treatment interests, messages, lead sources, notes, tasks, appointments, status, values, payments, referrals, consent records and activity history.

Billing and contracts

Proposal, subscription, invoice, payment status, Stripe identifiers, acceptance evidence and legally required transaction records. Card details are handled by Stripe and are not stored by Swish.

Communications

Emails, support requests, chat and messaging content, attachments, delivery status, internal notes and contact preferences.

Technical and security

IP address, browser, device, timestamps, login history, audit logs, diagnostic data, webhook records and security events.

Advertising and attribution

UTM parameters, click identifiers, campaign, ad set, advert, creative, form, source, medium, conversion and revenue attribution.

Usage and analytics

Pages viewed, features used, interactions, performance, errors and aggregated product analytics.

4. Facebook, Instagram and Meta data

Where an authorised user connects Meta to Swish, we may process data made available through Meta’s APIs and the permissions granted by that user. Depending on enabled features, this may include:

  • the authorising person’s name and Meta app-scoped user identifier;
  • Facebook Page IDs, Page names, permitted tasks and connection status;
  • access tokens and token expiry information, stored in encrypted form;
  • instant-form IDs, names, questions and lead submissions;
  • lead name, email, telephone, answers, submission time and Meta lead identifier;
  • campaign, ad set, advert, creative and attribution identifiers;
  • linked Instagram professional-account identifiers and basic account details when enabled;
  • Facebook Messenger and Instagram message content, participants, attachments and delivery information when those channels are enabled;
  • conversion events sent back to Meta where the tenant activates conversion feedback.

We use this data only to provide the authorised Swish functions, route and manage enquiries, maintain an audit trail, support reporting, troubleshoot the connection, protect the platform and comply with law and Meta’s applicable terms. We do not use a tenant’s Meta data to market to that tenant’s patients for our own independent purposes.

Meta connection control

An authorised tenant administrator can disconnect a Meta connection. The Meta user can also remove Swish through their Facebook Apps and Websites or Business Integrations settings. Disconnecting stops future API access but does not automatically erase records already lawfully stored in Swish; deletion can be requested separately.

5. Purposes and lawful bases

PurposeTypical lawful basis
Provide accounts, subscriptions, CRM, integrations and supportContract; legitimate interests in operating the service
Process tenant-controlled lead and patient dataProcessed on the tenant controller’s instructions under our data-processing terms
Billing, tax, proposals and contractual recordsContract; legal obligation; legitimate interests
Security, fraud prevention, access control and auditLegitimate interests; legal obligation where applicable
Product analytics, reliability and improvementLegitimate interests; consent where non-essential cookies require it
Sales and service communicationsContract, legitimate interests or consent depending on the communication
Compliance, disputes and legal claimsLegal obligation; legitimate interests; establishment, exercise or defence of legal claims

Where consent is the basis, it may be withdrawn at any time without affecting processing already undertaken. Tenants are responsible for identifying the lawful basis and any additional condition required for their own use of patient or special-category data.

6. Where information comes from

We obtain information directly from users and customers; from tenants and their authorised staff; from forms, campaign pages, referrals and UGC forms; from connected services such as Meta, Google, email providers, Stripe and practice systems; from cookies and technical logs; and from publicly available business sources where appropriate.

Where a tenant obtains a person’s information from another source, the tenant remains responsible for providing required privacy information at the correct time.

7. Who we share information with

We may share information only where necessary with:

  • the tenant, practices and authorised users responsible for the relevant lead, patient, employee or account;
  • hosting, database, security, email, communications, analytics, document, customer-support and infrastructure providers acting under contract;
  • Stripe and connected payment providers;
  • Meta, Google and other integrations when a user directs Swish to receive or send data through them;
  • professional advisers, insurers, auditors and prospective purchasers under confidentiality obligations;
  • regulators, courts, law-enforcement or public authorities where legally required;
  • another organisation involved in a merger, acquisition, restructuring or transfer, subject to appropriate safeguards.

We do not sell personal data. We do not sell, license or purchase Meta Platform Data.

8. International transfers

Some service providers or connected platforms may process information outside the United Kingdom. Where required, we use recognised safeguards such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful transfer mechanism. Information about relevant safeguards can be requested from our privacy contact.

9. How long we keep information

We keep information only for as long as needed for the purposes described, the tenant’s instructions and legal obligations. Our typical criteria are:

  • account and contract records: while the account is active and normally up to seven years afterwards;
  • billing, tax and transaction evidence: normally six years after the relevant financial period or longer where law requires;
  • CRM lead and patient data: according to the tenant controller’s configuration, instructions and applicable clinical or legal duties;
  • Meta and other connection tokens: until disconnected, expired or no longer required, followed by secure deletion from active systems;
  • security and audit logs: generally up to 24 months unless needed for an investigation;
  • support records: generally up to three years after closure;
  • unsuccessful sales enquiries: normally up to 24 months unless consent or legitimate need supports longer retention;
  • backups: removed through normal rotation, which may take up to 90 days after deletion from active systems.

We may retain limited records longer where necessary for legal claims, fraud prevention, safeguarding, regulatory duties or to record a suppression/opt-out preference.

10. Security

We use proportionate technical and organisational measures including role-based access, tenant and practice separation, encryption of sensitive connection credentials, HTTPS, password controls, audit logging, backups, monitoring, controlled administrative access and supplier due diligence. No service can guarantee absolute security, and users must protect their credentials, devices and authorised access.

Tenants must promptly remove leavers, configure permissions appropriately, use supported secure integrations and notify us of suspected unauthorised access.

11. Your data protection rights

Depending on the circumstances and lawful basis, you may have rights to be informed, access, rectify, erase, restrict, object, receive portable data and complain about automated decision-making. You may also withdraw consent where consent is used.

Your right to object: you may object to direct marketing at any time, and may object to processing based on legitimate interests in certain circumstances.

For patient or lead data controlled by a tenant, contact the relevant practice first. We will assist the tenant in responding where required. For Swish-controlled data, email info@swish.click or use the Data Deletion page. We may need to verify identity and authority before acting.

12. Marketing and service messages

Service, security, billing and account messages are necessary to operate Swish. Marketing messages are sent only where permitted. You can unsubscribe using the link provided or contact us. We may retain a minimal suppression record to respect an opt-out.

13. Cookies and analytics

Swish uses essential cookies for security, authentication, preferences and service delivery. We may use analytics or advertising technologies where configured and legally permitted. Non-essential cookies should be presented through an appropriate consent mechanism before use where required. Browser settings can also restrict cookies, but essential service functions may be affected.

14. Children

Swish is a business service and is not directed at children. A healthcare tenant may process information about a child patient where it has an appropriate legal basis, authority and safeguards. Tenants must not use Swish to collect children’s data unlawfully or without required notices and consent/authority.

15. Data deletion and disconnection

Meta users can remove Swish from Facebook’s Apps and Websites or Business Integrations settings. Tenant administrators can disconnect integrations inside Swish. To request deletion of data held by Swish, use our Data Deletion page. We will delete or anonymise eligible information and explain any lawful retention that applies.

16. Changes to this notice

We review this notice as the platform, integrations and law develop. The effective date and version appear at the top. Material changes will be brought to account holders’ attention where appropriate before new processing begins.

17. Contact and complaints

Modern Synergy Limited, trading as Swish (company number 16859014)Email: info@swish.click

Please contact us first so we can investigate. You also have the right to complain to the UK Information Commissioner’s Office. Information about making a complaint is available from the ICO.