Security, privacy and governance

Keep every customer conversation controlled, visible and reviewable.

Swifty combines operating rules configured by the customer with permission based access to recordings, transcripts, summaries and outcomes. Human escalation and approved legal information remain visible.

Plain English definition

What does governance mean for Swifty?

Governance means agreeing who and what the AI may contact, access, say, book, record, escalate and update. The resulting conversation evidence and operational ownership remain visible to the appropriate users.

Published control model

Make boundaries and ownership explicit.

01

Permission based access

Recordings, transcripts, summaries and conversation outcomes are available only to users with the appropriate access.

02

Configured by the customer controls

The customer defines audiences, contact policy, disclosure, booking authority, escalation, opt outs, retention details and outcome ownership.

03

Conversation privacy boundary

Swifty does not disclose personal information during customer conversations; the remaining permitted scope is agreed with the customer.

04

Recorded conversation evidence

Calls are recorded, transcribed and summarised by AI so authorised users can review what happened and the resulting action.

05

Human escalation

Defined by the dealership routes remain available for complaints, sensitive circumstances, unusual requests and conversations outside the approved scope.

06

Published legal foundation

The approved Privacy Policy and Terms and Conditions explain Swifty's legal roles, processing, service responsibilities and contractual framework.

Implementation governance

Agree the controls before the conversation starts.

  1. 01

    Agree

    Capture the customer journey, data scope, legal purpose, access roles, disclosures, retention needs and accountable owners.

  2. 02

    Configure

    Apply the approved conversation boundaries, booking authority, escalation, opt out, recording and outcome controls.

  3. 03

    Validate

    Test standard, sensitive, out of scope, unavailable system and human handoff cases before launch.

  4. 04

    Review

    Use authorised conversation evidence, exceptions and customer feedback to maintain the approved operating model.

Fixed published Swifty controls

  • Calls are recorded, transcribed and summarised by AI.
  • Only users with the appropriate access can view recordings, transcripts and summaries.
  • Swifty does not disclose personal information during customer conversations.
  • The approved Privacy Policy and Terms and Conditions remain the authoritative public legal documents.

Controls agreed with each customer

The customer defines the audience and source, contact policy, introduction and disclosure, permitted conversation, booking authority, human escalation, opt outs, retention details, outcomes and operational controls. Those choices still need to operate within applicable requirements and the agreed contract.

Controller and processor roles

Swifty may act as a controller for its own business activities and as a processor when providing services on a customer's documented instructions. The approved Privacy Policy explains these roles, the categories of information involved, lawful bases, sharing, international transfers, retention, rights and contact routes.

Claims intentionally not made

This page does not claim a security certification, universal compliance outcome or compatibility with every dealership policy. Independent certifications and assurance statements should be published only after the underlying evidence and permitted wording have been reviewed.

Frequently asked

Questions buyers should ask.

Are Swifty calls recorded?

Yes. Calls are recorded, transcribed and summarised by AI. Only users with the appropriate access can view those records.

Who decides the campaign and conversation controls?

The customer defines the audience and source, contact policy, introduction and disclosure, permitted conversation, booking authority, human escalation, opt outs, retention details, outcomes and operational controls, subject to applicable requirements and agreed contracts.

Does Swifty disclose personal information during customer conversations?

No. Swifty does not disclose personal information during customer conversations. The customer and Swifty still need to agree what data the service may access and how each journey should verify, respond or hand over.

Who can access recordings, transcripts and summaries?

Only users with the appropriate access can view them. The customer's implementation defines the remaining user, role, retention and workflow controls.

Is Swifty a controller or processor?

The role depends on the activity. The approved Privacy Policy explains circumstances in which Swifty acts as a controller and circumstances in which it processes data on a customer's behalf.

Does this page claim a security certification?

No. This page does not claim ISO 27001, SOC 2 or another certification. Any future certification or independent assurance claim should be published only after it has been verified and approved.

Review your requirements

Bring your security, privacy and governance questions.

We will map the intended journeys, data access, recording, user permissions, escalation, retention and customer responsibilities against the proposed implementation.

Book a security review