SWIPA
Legal

Privacy policy

Last updated Jun 1, 2026
This policy explains what SWIPA collects when you use the customer portal, why we collect it, and the choices you have. It applies to SWIPA staff and authorized users accessing their SWIPA account.

Information we collect

We collect the information needed to operate the platform and keep it secure:

  • Account data — your name, work email, role, and the organization you belong to.
  • Authentication data — credentials, one-time verification codes, and the devices and IP addresses you sign in from.
  • Activity logs — the actions you take in the portal, retained for security and audit purposes.

How we use it

Information is used only to authenticate you, provide the customer portal, monitor for fraud and abuse, meet our legal and regulatory obligations, and improve the reliability of the service. We do not sell personal data, and we do not use it for advertising.

Retention

Audit and access logs are retained for the period required by applicable financial regulations, then deleted or anonymized. Account records are removed within 90 days of your access being revoked, except where we must retain them by law.

Security

Access to the customer portal is restricted to authorized users, protected by multi-factor authentication, and encrypted in transit and at rest. Access is logged and reviewed.

Your choices

You can review and correct your account information from your profile settings. To request access, correction, or deletion of your personal data, contact our privacy team at [email protected].