Legal

Privacy Policy

How we collect, use and protect personal information across our website, our applications and every client engagement.

Last updated: 3 July 2026

Who we are

Swarm Labs is a software studio building custom applications, internal tools, integrations and automations, operated by Swarm Labs IO Ltd, a company registered in England and Wales (company number 17048541) with its registered office at Beehive Lofts, Beehive Mill, Jersey Street, Manchester, England, M4 6JG ("we", "us", "our" and "Swarm Labs").

As an organisation that processes primarily business-related data, Swarm Labs has determined "legitimate interests" as the most suitable lawful basis for the processing of data for the purposes of our marketing and sales activities. Where we act as a processor of personal data inside applications we build or operate for clients, we process that data strictly on the client's instructions.

Privacy for our clients

This section applies to the personal information we collect and process from a client, potential client or website visitor. If you are not an active client, the "Potential clients and website visitors" section may be more applicable to you. In this section, "you" and "your" refer to clients.

The information we collect

Information you provide to us during an engagement may include personal information about you, your organisation and your employees. Personal information is often, but not exclusively, provided to us when you request a quotation, complete a form on our website, sign up for one of our services or applications, consult with our team, send us an email, raise a support request, provide login credentials, or communicate with us in any other way.

We will let you know prior to collection whether the provision of the personal information we are collecting is compulsory or voluntary, and the consequences, if any, of not providing it. By providing us with this information, you agree to it being collected, used and disclosed as described in our Terms & Conditions and in this privacy policy.

Login credentials: we often require credentials to your systems and third-party services in order to build and test integrations. If you are unable to share credentials securely (for example through your own password manager), we will provide a secure method for you to do so. Credentials we hold are stored in a hardened password manager protected by multi-factor authentication, and access is limited to the team members working on your project.

How we use personal information

We may use the information we collect about you through our services or other sources for a variety of reasons, including:

  • To provide quotations and proposals
  • To invoice and collect money owed to us
  • To send account activity messages such as password resets, payment reminders or alerts
  • To effectively manage your account and expectations
  • To provide customer and technical support
  • To enforce compliance with our Terms & Conditions
  • To meet legal requirements
  • To provide essential information to external representatives and advisors, including lawyers and accountants, to help us comply with legal, accounting or security requirements
  • To prosecute and/or defend any legal proceedings
  • To respond to lawful requests by public authorities
  • To analyse data and improve our services and applications
  • To carry out other legitimate business purposes, as well as other lawful purposes about which we will notify you

Potential clients and website visitors

This section applies to personal information that we collect and process through our website and in the usual course of our business, for example in association with events, networking or sales and marketing activity. In this section "you" and "your" refers to potential clients and website visitors. We may use this information:

  • To optimise and maintain our website
  • To send you information for marketing purposes, in accordance with your marketing preferences
  • To provide quotations
  • For recruitment purposes if you have applied for a role with Swarm Labs
  • To respond to your online enquiries and requests
  • To improve the navigation and content of our website
  • To identify server problems or other IT or network issues
  • To analyse site usage and better understand the preferences of our visitors
  • To carry out research and development to improve our products and services
  • To carry out other legitimate business purposes, as well as other lawful purposes

Cookies, analytics & tracking

To improve your experience on our site, we may use cookies. Cookies are an industry standard and most major websites use them. A cookie is a small text file that our site may place on your computer as a tool to remember your preferences. You may refuse the use of cookies by selecting the appropriate settings in your browser, however please note that doing so may limit some functionality of this website.

Google Analytics: our website uses Google Analytics, a service which transmits website traffic data to Google servers. Google Analytics does not identify individual users or associate your IP address with any other data held by Google. We use reports provided by Google Analytics to help us understand website traffic and page usage.

We and our partners may also use similar technologies in the emails we send (for example to confirm whether an email was delivered, opened or clicked) to measure performance and improve the relevance of what we send.

Links to third-party websites

Our website includes links to other websites, whose privacy practices may be different from ours. If you submit personal information to any of those sites, your information is governed by their privacy policies. We encourage you to carefully read the privacy policy of any website you visit.

Marketing: PECR

We primarily focus our B2B data acquisition on businesses classed as "corporate subscribers" under the Privacy and Electronic Communications Regulations (PECR): corporate bodies with separate legal status such as companies and limited liability partnerships. Sole traders and some partnerships are classed as "individual subscribers" and PECR treats them the same as individuals. The PECR rule on direct marketing by electronic mail does not apply to corporate subscribers, so we do not need consent under PECR to send such messages to corporate bodies. If we are not sure whether a business is a corporate subscriber, we ensure that we have consent to send electronic mail (unless contacting previous customers about our own similar products, where an opt-out was offered when details were provided).

In all cases we comply with the regulations by:

  • not disguising or concealing our identity; and
  • providing a valid address for businesses to opt out or unsubscribe from our messages.

Unless otherwise requested we keep your details in a "do not contact" list to ensure we can screen any new B2B direct marketing lists against it. Where we process personal data for direct marketing purposes, even in a business context, the UK GDPR applies (see below).

Marketing: UK GDPR

The UK GDPR applies to the processing of personal data. If we can identify an individual either directly or indirectly it constitutes personal data, even if they are acting in their business capacity, for example where we hold the name and number of a business contact, or where the email address we use identifies an individual (e.g. firstname.lastname@company.com). When we acquire personal data and intend to send direct marketing messages, we will inform you of this along with our lawful basis under the UK GDPR for the processing.

Right to be informed

If your personal data (i.e. name and direct company email) has been sourced publicly or via a third party, when we add you to our database you will receive: the name and contact details of our organisation; the purposes of and lawful basis for the processing; the legitimate interests for the processing (if applicable); the categories of personal data obtained; the recipients of the personal data; details of any transfers outside the UK (if applicable); the retention period; the rights available to you, including the right to withdraw consent and the right to lodge a complaint with a supervisory authority; and the source of the personal data.

Data retention

Swarm Labs records personal data in GDPR-compliant systems with accountability and traceability for records, alongside the ability to update contact preferences and opt in or out of communications. We periodically cleanse the data we hold; records found to be out of date or no longer relevant are securely deleted.

Children's privacy

Our services are not available to children under the age of 18, and we will not intentionally maintain information about anyone under the age of 18.

Your data protection rights

Access, correction, updates and removal

Swarm Labs takes reasonable steps to ensure that the data we collect is reliable for its intended use, accurate, complete and up to date. To access, correct, update or request removal of your personal information, contact us at info@swarmlabs.io.

Withdrawal of consent

If personal information is collected or processed on the basis of consent, you can withdraw your consent at any time. Withdrawing consent will not affect the lawfulness of any processing conducted prior to withdrawal, nor processing conducted on lawful grounds other than consent.

The right to complain

You have the right to lodge a complaint with the UK's supervisory authority, the Information Commissioner's Office (ico.org.uk).

Processing a request

We will endeavour to respond to all requests in a timely manner. Anyone wishing to exercise their data protection rights under applicable data protection law will need to verify their identity so we can respond efficiently to the request.

Contact

Questions about this policy or how we handle your data: info@swarmlabs.io, or write to Swarm Labs IO Ltd, Beehive Lofts, Beehive Mill, Jersey Street, Manchester, M4 6JG.