1. Governance and accountability
Swish is operated by Modern Synergy Limited, trading as Swish (company number 16859014). We maintain internal policies, registers and review procedures covering public-authority requests, personal-data incidents, access control, retention, data-subject requests, supplier oversight and Meta Platform Data. Responsibility for significant data-handling decisions is assigned to a senior accountable person and decisions are documented.
Swish customers remain responsible for the lawful use of patient, lead, staff and practice data within their own workspaces. Swish acts as controller for its own website, account, support and commercial records and normally acts as processor for tenant-controlled CRM data.
2. Security approach
- Role-based access and tenant/practice isolation are applied within the platform.
- Administrative and integration credentials are restricted to authorised users and protected in storage.
- Material actions are logged to support investigation and accountability.
- Security updates, backups, restoration and vulnerability remediation form part of platform operations.
- Access to production systems and personal data is limited to people who require it for their role.
No internet service can guarantee absolute security. We assess risks, improve controls and respond to identified weaknesses proportionately.
3. Access control and staff changes
Access is granted according to role and business need. Platform, tenant and practice permissions are separated. Access should be reviewed when responsibilities change and removed promptly when a user leaves or no longer requires access. Shared credentials are discouraged and account activity may be logged for security and support purposes.
4. Retention and deletion
Information is retained only for as long as required for the service, contractual records, security, dispute handling and legal obligations. Tenant administrators control many CRM retention decisions. Swish supports deletion requests through the Data Deletion page, subject to identity checks and lawful retention exceptions.
5. Incident response
Suspected security and personal-data incidents are recorded, triaged and contained. We assess the affected systems, data, people and likely consequences; preserve relevant evidence; notify affected controllers; and determine whether regulators or individuals must be informed. Corrective actions and lessons learned are documented.
7. Third parties and international transfers
Swish uses carefully selected providers for hosting, communications, payment processing, analytics, integrations and support. Providers are reviewed for purpose, data access, contractual safeguards, security and processing location. Where personal data is transferred internationally, appropriate safeguards are used where required. Specific provider use may vary by tenant configuration and enabled integrations.
8. Contact
Questions about security, privacy, government requests or data handling can be sent to info@swish.click.