Last updated 16 May 2026

Privacy Policy

This Privacy Policy explains how Swifty AI Limited collects, uses, shares and protects personal data when individuals use our website, contact us, use our software platform, or where we process personal data through our AI-assisted call handling, messaging, analytics, reporting, workflow automation and related services.

Swifty AI provides AI-assisted communication, messaging, analytics, reporting and workflow automation services to business customers, including automotive retailers and dealership groups. This Privacy Policy also explains the different roles we may have under UK data protection law. In some cases, Swifty AI Limited acts as a controller of personal data, for example when we handle website enquiries, sales, billing, account administration, support and our own marketing. In other cases, we act as a processor for our business customers, including automotive retailers and dealership groups, for example when we process call recordings, transcripts, messages, enquiry data, customer or prospect data, staff or advisor data and analytics outputs on their behalf under a data processing agreement.

Interpretation and Definitions

Interpretation

Words with initial capital letters have meanings defined under the following conditions. The following definitions have the same meaning whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:

Our Role as Controller or Processor

Swifty AI Limited acts as a controller when we decide how and why personal data is processed for our own business purposes, including website enquiries, sales activity, contract administration, billing, account management, customer support, service improvement, security, compliance and our own marketing.

Swifty AI Limited acts as a processor when we process personal data on behalf of an business customer, including an automotive retailer or dealership group, under a data processing agreement. This may include processing personal data relating to the customer’s own customers, prospects, end users, employees, contractors, call handlers, advisors, authorised platform users and other staff. In those cases, the customer is responsible for providing any required privacy notices, identifying the lawful basis for processing, handling data subject rights requests and deciding how the personal data and outputs from the Services are used.

If your personal data has been processed by Swifty AI on behalf of a business customer, including an automotive retailer or dealership group, you should usually contact that customer first about your data protection rights. We will provide reasonable assistance to our customer as required under our data processing agreement.

Collecting and Using Personal Data

Types of Data Collected

Personal Data

Depending on how you interact with us or with our business customers, including automotive retailers and dealership groups, personal data may include:

We do not intentionally request special category data or criminal offence data through the Services. However, this type of information may sometimes be included incidentally in call recordings, transcripts, messages or customer communications. Where this happens, we process it only as necessary to provide the Services, comply with our contractual and legal obligations, and protect the security and integrity of the Services.

Usage Data

Usage Data is collected automatically when using the Service.

Usage Data may include information such as your Device’s Internet Protocol address, browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

When you access the Service by or through a mobile device, we may collect certain information automatically, including the type of mobile device you use, your mobile device unique ID, the IP address of your mobile device, your mobile operating system, the type of mobile Internet browser you use, unique device identifiers and other diagnostic data.

We may also collect information that your browser sends whenever you visit our Service or when you access the Service by or through a mobile device.

Sources of Personal Data

We collect personal data directly from you, for example when you contact us, register for an account, use the Services or correspond with us. We also receive personal data from other sources, including our business customers (such as automotive retailers and dealership groups) and their authorised users, individuals who interact with our business customers through the Services (for example, callers, message senders and enquirers), our service providers and sub-processors, publicly available sources, business contact databases and referrals.

Tracking Technologies and Cookies

We use Cookies and similar tracking technologies to operate, secure, improve and analyse our Website and Services. Tracking technologies may include cookies, tags, scripts, web beacons and similar technologies that collect and store certain information.

Cookies can be persistent or session cookies. Persistent cookies remain on your device when you go offline, while session cookies are deleted as soon as you close your web browser.

We use Cookies for the purposes set out below:

We use necessary cookies to operate the Website and Services. We may also use analytics, preference, advertising or similar technologies where permitted by law and, where required, with your consent. You can manage cookies through your browser settings and, where available, through our cookie consent tool.

Analytics and similar technologies may help us understand how visitors use our Website and Services, measure performance, improve functionality and understand the effectiveness of our communications. Where these technologies are not strictly necessary, we will use them only where permitted by applicable law.

Use of Personal Data

We may use personal data for the following purposes:

Where we act as a processor for a business customer, including an automotive retailer or dealership group, we process personal data on that customer’s documented instructions and for the purposes described in the relevant agreement and data processing agreement.

Lawful Bases for Processing

Where Swifty AI Limited acts as a controller, we rely on one or more of the following lawful bases:

Where Swifty AI Limited acts as a processor, the relevant business customer, including any automotive retailer or dealership group, is responsible for identifying the lawful basis for processing personal data and for providing any required privacy notices to data subjects.

AI-Assisted Services, Analytics and Reporting

The Services may use artificial intelligence, speech-to-text, text-to-speech, transcription, analytics and automation technologies to handle calls, process messages, generate transcripts, summarise interactions, classify enquiries, analyse customer experience, support sales or service workflows, and produce reports or performance-related outputs.

AI-generated outputs may be incomplete, inaccurate or require human review. Where the Services are used by a business customer, including an automotive retailer or dealership group, that customer is responsible for deciding how to use any outputs, reports, scores or analytics generated through the Services, including in relation to its own customers, prospects, employees, advisors, call handlers, authorised platform users or other staff.

Swifty AI does not use the Services to make solely automated decisions about individuals that produce legal or similarly significant effects unless this is expressly agreed, lawful and supported by appropriate safeguards.

Marketing Messages Sent Through the Services

Where our business customers, including automotive retailers and dealership groups, use the Services to send SMS, WhatsApp, email or other electronic messages to their own customers or prospects, that customer is responsible for ensuring that the campaign complies with UK GDPR, PECR and applicable direct marketing laws, including any consent, soft opt-in, unsubscribe and suppression requirements.

Sharing Personal Data

We may share personal data with:

Where we appoint sub-processors to process personal data on behalf of a business customer, including an automotive retailer or dealership group, we do so in accordance with our data processing agreement with that customer.

We maintain information about our current sub-processors and can provide it to business customers, including automotive retailers and dealership groups, on request or through our applicable customer documentation.

Retention of Personal Data

We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Services, maintain business records, comply with legal and regulatory obligations, resolve disputes, enforce agreements, maintain security and support audit requirements.

Where we act as a processor for a business customer, including an automotive retailer or dealership group, we retain personal data in accordance with the relevant agreement, data processing agreement, customer instructions and our applicable records retention and disposal policies. The customer may specify shorter retention periods where agreed and technically feasible.

Retention periods may vary depending on the type of data, the nature of the Services, customer configuration, legal requirements and whether the data is held in active systems, logs or backups.

International Transfers

We are based in the United Kingdom, but some of our service providers and sub-processors may process personal data in other countries, including the United States, the European Economic Area and other locations where our providers operate.

Where personal data is transferred outside the United Kingdom, we take steps designed to protect it in accordance with applicable data protection law. These steps may include relying on UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework where applicable, the UK International Data Transfer Agreement, the European Commission standard contractual clauses together with the UK Addendum, or another transfer mechanism permitted under applicable data protection law.

Where we act as a processor for a business customer, including an automotive retailer or dealership group, restricted transfers are handled in accordance with the applicable data processing agreement.

A copy of the relevant safeguards used for international transfers can be requested by contacting us at privacy@swiftyai.co.

Your Data Protection Rights

Depending on the circumstances and subject to applicable legal limits, you may have the right to:

If Swifty AI Limited is the controller of your personal data, you can exercise these rights by contacting privacy@swiftyai.co.

If we process your personal data on behalf of a business customer, including an automotive retailer or dealership group, we may need to refer your request to that customer because they are responsible for responding as controller.

You also have the right to complain to the UK Information Commissioner’s Office. The ICO can be contacted at ico.org.uk/make-a-complaint.

Disclosure of Personal Data

Business Transactions

If the Company is involved in a merger, acquisition, restructuring, financing, asset sale or similar business transaction, personal data may be shared or transferred where permitted by law. We will provide notice before personal data is transferred and becomes subject to a different privacy policy where required by applicable law.

Law Enforcement

Under certain circumstances, the Company may be required to disclose personal data if required to do so by law or in response to valid requests by public authorities, such as a court, regulator, law enforcement body or government agency.

The Company may disclose personal data in the good faith belief that such action is necessary to:

Security of Personal Data

The security of personal data is important to us, but no method of transmission over the Internet or method of electronic storage is completely secure. While we strive to use commercially acceptable means to protect personal data, we cannot guarantee its absolute security.

Children’s Privacy

Our Services are intended for business use and are not directed at children.

We do not knowingly collect personal data from children for our own purposes. However, where we process personal data on behalf of a business customer, including an automotive retailer or dealership group, personal data may be included in calls, messages, enquiries or other communications processed through the Services. In those cases, the customer is responsible for ensuring that the processing is lawful and that appropriate notices are provided.

Our Service may contain links to other websites that are not operated by us. If you click on a third-party link, you will be directed to that third party’s site. We strongly advise you to review the privacy policy of every site you visit.

We have no control over and assume no responsibility for the content, privacy policies or practices of any third-party sites or services.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.

We will let you know via email and/or a prominent notice on our Service prior to the change becoming effective where required by law, and we will update the Last updated date at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Contact Us

If you have any questions about this Privacy Policy or how we handle personal data, please contact us at privacy@swiftyai.co.