This policy explains how Swopi s.r.o. handles personal data when you visit swopi.co, buy in our shop, use the Swopi app, the web dashboard at dash.swopi.co or a Swopi digital business card, or when a Swopi user captures your details as a lead. We follow the General Data Protection Regulation (EU) 2016/679 (the “GDPR”) and Czech data protection law.
1.Who we are
Swopi s.r.o., company ID (IČO) 10871659, VAT ID CZ10871659, with its registered office at Lidická 700/19, Veveří, 602 00 Brno, Czech Republic, registered in the Commercial Register kept by the Regional Court in Brno, file C 123287 (“Swopi”, “we” or “us”).
For any question about your personal data, write to info@swopi.co or call +420 774 915 861.
2.Our role: controller or processor
We are the controller (we decide why and how data is used) for: your Swopi account and card, subscriptions and billing, shop orders, visits to our websites, sales enquiries and support, our marketing, our own enrichment records (section 5) and security logs.
We are a processor (we act on someone else's instructions) for: the leads that our users capture, import or enrich, and the data of team members that an organisation manages in Swopi. For this data, the Swopi user or organisation is the controller. For business customers, our data processing agreement (DPA) sets out the rules. Business customers can ask for it at info@swopi.co.
Other companies are separate controllers for their own services, for example Apple and Google (app stores, sign-in, Wallet), Microsoft (sign-in), Stripe (for its own anti-fraud checks) and the CRM or other tools that a user connects to Swopi.
3.Data about you as a Swopi user
- Account data: name, email address, password (stored only in a protected, hashed form by Google Firebase), the ID of the sign-in service you use (email, Google, Apple, Microsoft, company SSO with Microsoft Entra ID, or Facebook for older accounts) and your profile photo.
- Card data: everything you put on your card, for example job title, company, phone, address, links, photos, logos, videos and files. Your card is public: anyone with its link, QR code or NFC device can see it.
- Organisation data: your team, your role, and, if your organisation connects Microsoft Entra ID, the details it syncs to Swopi (for example name, email, job title, department, phone and photo).
- Subscription and billing data: your plan, trial and renewal dates, purchase records from the App Store or Google Play, your Stripe customer ID, billing address, company ID and VAT ID. We never see your full card number.
- Card statistics: how often your card is viewed and saved and which links are clicked. The statistics on card pages are collected without cookies and do not identify visitors.
- Device and usage data: app version, device model, operating system, language, IP address, crash reports, error reports and how you use features. We use it to keep the services working and to improve them.
- Location (optional): if you allow it, the place where you saved a contact, so you can see your contacts on a map.
- Voice (optional): if you dictate a note, your device's speech recognition turns it into text. Apple or Google may process the audio under their own terms. We only receive the text.
- Messages with us: emails and other messages you send us, and our replies.
4.Data about people our users meet (leads)
Swopi users capture the details of people they meet, for example at trade fairs and meetings. If a Swopi user has captured your details, this section is for you.
- What data: name, job title, company, email, phone, address, website, LinkedIn profile, the photo of your business card or event badge, the event, notes the user writes, when the lead was saved and, if the user allows it, where. Swopi AI can add a business email and phone, LinkedIn profile, job title, seniority and company details (for example size, industry, address and registration numbers), an intent score and a draft follow-up email.
- Where it comes from: from you (your business card, your badge, or the form on a Swopi card that you filled in), from the Swopi user who met you, from an import or a CRM, and from enrichment through data partners and public sources such as company registers (section 5).
- Who is responsible: the Swopi user or their organisation is the controller. They usually rely on their legitimate interest in following up a business meeting. We process the data on their behalf, as their processor.
- Your rights: please contact the person or company who captured your details. If you do not know who that is, or if you contact us, we will pass your request to them or help them answer it.
If you fill in the form on someone's Swopi card, your details go to the owner of that card. On the owner's behalf, we send you an email with their contact details (a vCard). If the owner has turned on follow-up emails, you may also get an email from them, sent through Swopi.
5.Swopi AI and enrichment
Scanning. When a user scans a business card or badge, the image is read by Google Cloud Vision and by Google Gemini through Google Vertex AI. Anthropic Claude is used as a backup. The image and the text stay with the lead in the user's account.
Enrichment. When a user enriches a lead, we send only the details needed to find a match (for example name, company, email, website or LinkedIn profile) to these sources:
- Anthropic (Claude AI, which searches public web sources such as company websites and public professional profiles),
- business data partners: Apollo, Prospeo and BetterContact,
- public company registers: ARES (Czech Republic), RPO (Slovakia), the EU VIES VAT database, UK Companies House and OpenCorporates,
- public logo and profile picture services (Clearbit logos and Gravatar).
The results are added to the lead in the user's account. We never overwrite details that the user entered.
Our own enrichment records. So that we do not buy the same data again, we keep the results that our data partners return about a person (only professional data: name, job title, company, business email, business phone and LinkedIn profile). We may use them again when another Swopi user enriches the same person. For these records we are the controller, and our legal basis is our legitimate interest in providing accurate enrichment at a fair cost. We keep each record for at most 24 months after it was last used. Public company facts (not personal data) may be kept longer. You can object to this processing and ask us to delete your record at info@swopi.co.
Follow-up emails and intent score. Anthropic Claude drafts follow-up emails from the lead's details and the user's settings. The user decides whether and when the email is sent, in their own name. The intent score is an automated estimate that helps a user decide whom to contact first. It does not lead to decisions with legal or similarly important effects on anyone.
No training. We do not use leads or user content to train AI models. Our AI providers are not allowed to use them to train their models.
6.Website visitors, shop customers and enquiries
Websites. Our websites run on Vercel. Vercel keeps technical logs (for example IP address and browser) to deliver and protect the site. We measure visits with Vercel Web Analytics, which does not use cookies. Only if you accept analytics cookies do we use PostHog, hosted in the EU, including session recordings with form inputs hidden. We do not use advertising cookies, Google Analytics or the Facebook pixel. Details are in our cookie policy.
Shop. When you order, we process your name, email, phone, delivery and billing address, and, if you buy as a company, the company name, company ID and VAT ID (which we check in the Czech ARES register or the EU VIES database). We also process the items you ordered, the designs and logos you upload for custom products, the payment status and your invoice. Stripe handles the payment. We never see your full card number. Invoices are created in Fakturoid and sent by email. The carrier gets your name, address, phone and email to deliver the parcel.
Sales enquiries. When you send the form on our contact page, your details go to our CRM, HubSpot (EU data centre). If HubSpot is not available, the form is sent to us by email.
Marketing emails. We send news and offers only if you agreed to it, or if you are our customer and we write about similar products. You can unsubscribe at any time with the link in each email.
7.Why we use personal data and on what legal basis
- To provide the services (account, cards, lead capture, Swopi AI, CRM sync, subscriptions, shop orders and support): performance of our contract with you (Article 6(1)(b) GDPR).
- To meet legal duties (invoices, accounting, tax, answering authorities): legal obligation (Article 6(1)(c) GDPR).
- To keep the services secure and working (logs, error and crash reports, fraud and abuse prevention): our legitimate interest (Article 6(1)(f) GDPR).
- To improve the services (product analytics in the app and dashboard): our legitimate interest. On our websites, analytics cookies are used only with your consent (Article 6(1)(a) GDPR).
- Our own enrichment records: our legitimate interest (section 5).
- Marketing: your consent, or our legitimate interest in writing to our customers about similar products.
- Legal claims: our legitimate interest in defending and enforcing our rights.
- Leads and team data: we process these on behalf of our users, who choose the legal basis.
Where we rely on legitimate interest, you can object at any time (section 11).
8.Who helps us (processors)
We use these providers to run Swopi. They process personal data only on our instructions and under a data processing agreement:
- Google Cloud and Firebase (Google Ireland Ltd and Google LLC): database, file storage, sign-in, server functions, push notifications, crash reports (Crashlytics), text recognition (Cloud Vision) and Gemini AI through Vertex AI. Our database and files are stored in the EU (Belgium and the Netherlands).
- Vercel Inc.: hosting of swopi.co, the dashboard and card pages, with server functions in Frankfurt, Germany.
- Stripe (Stripe Payments Europe Ltd, Ireland): payments for web subscriptions and the shop.
- RevenueCat Inc. (USA): managing the status of subscriptions bought in the app.
- Anthropic PBC (USA): AI for scanning (backup), enrichment research and follow-up drafts.
- Apollo.io, Prospeo and BetterContact: business contact data partners for enrichment.
- Resend (USA) and Twilio SendGrid (USA, backup): sending emails.
- Fakturoid s.r.o. (Czech Republic): invoicing.
- PostHog (EU cloud): product analytics.
- Sentry (Functional Software Inc.): error reports from the web dashboard.
- HubSpot (EU data centre): sales enquiries and customer relationships.
- Shopify: our former online shop. It holds records of orders placed there before the shop moved to swopi.co. We no longer use it for new orders.
- Carriers and postal services: delivery of shop orders.
We also share data with: the other services a user connects (for example their CRM), organisation admins (for the data of their team), anyone who opens a public card (for the content of that card), our accountants, auditors and lawyers (who must keep it confidential), authorities when the law requires it, and a buyer or successor if Swopi is sold or merged. We do not sell personal data.
The current list of sub-processors is part of our DPA and is available on request at info@swopi.co.
9.Transfers outside the European Economic Area
Our main database and files are stored in the EU. Some of our providers are based in the United States or can access data from outside the European Economic Area (EEA), in particular Anthropic, Apollo, RevenueCat, Resend, Twilio SendGrid, Sentry and Vercel, and Google when Gemini AI reads a scan.
When data leaves the EEA, we protect it with the EU-US Data Privacy Framework (an adequacy decision of the European Commission) where the provider is certified under it, and otherwise with the Standard Contractual Clauses approved by the European Commission, together with extra safeguards where needed. You can ask for a copy of these safeguards at info@swopi.co.
10.How long we keep data
- Account and card: for as long as your account exists. When you delete your account, we delete the data within 30 days, except data we must keep by law. Backup copies are overwritten within a further 90 days.
- Leads and team data: for as long as the user or organisation keeps them. They are deleted when the user deletes them, or within 30 days after the account or contract ends, unless the DPA says otherwise.
- Our own enrichment records: at most 24 months after the record was last used.
- Invoices and accounting records: 10 years, as Czech tax law requires.
- Other data about orders, contracts and support: up to 4 years after the order or contract ends, so that we can deal with claims.
- Sales enquiries without a contract: up to 3 years after our last contact.
- Marketing: until you unsubscribe or withdraw your consent.
- Analytics: session recordings at most 90 days, other analytics data at most 24 months.
- Technical and security logs and crash reports: usually up to 90 days, longer only if we need them to look into a security incident.
11.Your rights
Under the GDPR you have the right to:
- get access to your personal data and a copy of it,
- have wrong data corrected,
- have your data deleted,
- limit how we use your data,
- get your data in a common machine readable format (portability),
- object to processing based on our legitimate interest, and to direct marketing at any time,
- withdraw your consent at any time, without affecting processing before that, and
- not be subject to a decision based only on automated processing that has legal or similarly important effects on you.
To use your rights, write to info@swopi.co. We may ask you to confirm your identity. We answer within one month. In complex cases, we can extend this by two more months and will tell you why. You can see and change most of your data yourself in the app or the dashboard.
If your data was captured as a lead by a Swopi user, see section 4.
You also have the right to file a complaint with a supervisory authority. In the Czech Republic, this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, ÚOOÚ), Pplk. Sochora 27, 170 00 Prague 7, www.uoou.gov.cz. You can also complain to the authority in the EU country where you live or work.
12.Security
All data is sent over encrypted connections (HTTPS) and is encrypted at rest by our hosting providers. Access to personal data is limited to people who need it for their work, and our admin tools require strong sign-in. For organisations we offer single sign-on, SCIM provisioning, roles and an audit log. If a data breach puts your rights at risk, we will tell you and the supervisory authority as the law requires.
13.Children
Swopi is a business tool and is not meant for anyone under 18. We do not knowingly collect personal data from children. If we find out that we have, we delete it.
14.Cookies
On swopi.co we use only necessary cookies, and analytics cookies if you accept them. Card pages measure views without cookies. The details are in our cookie policy.
15.Changes to this policy
We update this policy when our services or the law change. The date at the top shows the last update. We will tell users about important changes by email or in the app.
16.Contact us
- Swopi s.r.o., Lidická 700/19, Veveří, 602 00 Brno, Czech Republic
- Email: info@swopi.co
- Phone: +420 774 915 861
- Website: swopi.co
This policy applies from 28 September 2026 and replaces all earlier versions, including the separate privacy policy of our former shop.