Privacy Policy
Last updated:
1. Introduction
This privacy policy explains how SwingIntel collects, uses, stores, and protects your personal data when you use our website at https://swingintel.com and when we carry out an engagement for you.
The data controller responsible for your personal data, except where section 5 (Our Role: Controller and Processor) says otherwise, is Next Layer Digital Ltd, trading as SwingIntel, a company registered in England and Wales (company number 16932866), with its registered office at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ. We are registered with the Information Commissioner's Office under registration number 00012757628.
SwingIntel is a hands-on AI visibility consultancy. We research how AI search agents — including ChatGPT, Perplexity, Claude, Gemini, Grok, DeepSeek, and Microsoft Copilot — find, read, and describe a business, we report what that research finds, and, where you engage us to do so, we carry out the corrective work ourselves. Engagements run under one of three tiers, agreed with you before any work begins: AI Visibility Research, Research & Repair, and Ongoing Visibility.
The research covers publicly accessible web pages. Repair and ongoing work reach beyond that only where you grant us access to your own systems. Because those phases involve credentials you issue to us and contact with people inside your organisation, this policy describes them separately from the research itself.
If you have any questions about this privacy policy or our data practices, you can contact us at info@swingintel.com.
2. Information We Collect
We collect the following categories of information when you interact with our services:
Account Information
Accounts are created by us, not by you. When we create your account so that you can reach your private client portal, we hold your email address and, optionally, your name. Passwords are never stored in plain text. We store only a cryptographic hash of your password in our own database, using the authentication library that secures your account.
Research Data
When we research your AI visibility, we collect the website URLs you ask us to research, the resulting research data, the scores we generate, and the reports produced from them. This information is necessary to deliver the engagement you have agreed with us.
Client System Credentials
Where an engagement includes repair or ongoing work and you grant us access to your systems, you provide us with credentials and access details. These may include logins for a website, hosting account, or content management system, API keys, analytics access, and repository or deployment access. You provide them so that we can carry out the work agreed with you, and we use them for no other purpose. We hold them outside the SwingIntel application — how they are stored is set out in section 8 (Data Security), and how long we keep them in section 7 (Data Retention).
Client Staff Contact Data
During the repair and ongoing phases of an engagement we work with people inside your organisation. We collect their names, work email addresses, and roles so that we can coordinate the work, agree changes, and hand over what we have done. We do not use these details for marketing. Our role in relation to this data, and in relation to personal data we encounter inside your systems, is set out in section 5 (Our Role: Controller and Processor).
Payment Information
All payment processing is handled by Stripe. We never see, receive, or store your credit card numbers, debit card numbers, or other sensitive payment credentials. From Stripe, we receive only the transaction confirmation, the amount paid, and the email address associated with the payment.
Contact and Inquiry Data
When you submit a message via our contact form or request a consultation, we collect your name, email address, the message content you provide, and, for consultation requests, the website URL you ask us to review. This information is used to respond to your inquiry, review your website, and scope and quote an engagement where relevant.
Automatically Collected Information
Our web server generates access logs as part of normal operations. These may include your IP address, browser user-agent string, and the pages you access. We do not use these logs for analytics, profiling, or marketing purposes.
Cookies
We use essential cookies for session management and authentication, and analytics cookies (Google Analytics 4) to understand how visitors use our website. We do not use advertising cookies, remarketing cookies, or any third-party marketing cookies. For full details, see section 12 (Cookies) below.
3. How We Use Your Information
We use the information we collect for the following purposes:
- To research your AI visibility and produce the reports we have agreed to deliver
- To carry out agreed implementation work inside your systems, where you have granted us access
- To coordinate the work with your staff and respond to them
- To produce, present, and review the Technical Roadmap and Brand Roadmap for your engagement
- To process payments securely via Stripe
- To create and manage your account
- To send transactional emails, including welcome messages, payment confirmations, and notifications when your report is ready
- To improve the quality and accuracy of our research and repair work
- To prevent abuse, fraud, and misuse of our website and services, including rate limiting
4. Legal Basis for Processing (UK GDPR)
We process your personal data on the following legal bases under the UK General Data Protection Regulation (UK GDPR):
Contract Performance
Processing your email address, research data, and payment information is necessary for the performance of the contract between you and Next Layer Digital Ltd — specifically, to deliver the research, the reports, and any repair or ongoing work you have engaged us to carry out.
Where an engagement includes work inside your systems, processing the credentials and access details you issue to us is also necessary for the performance of that contract. Without them we cannot carry out the work you have agreed to.
Legitimate Interests
We process the business contact details of your staff — name, work email address, and role — on the basis of our legitimate interests in running the engagement and coordinating the work with the right people.
We also process certain data on the basis of our legitimate interests, which include improving the quality and effectiveness of our services, preventing abuse and fraud, and conducting internal analytics to understand usage patterns. We ensure that our legitimate interests do not override your fundamental rights and freedoms, or those of any other individual whose data we process.
Consent
Where we introduce marketing communications in the future, we will obtain your explicit consent before sending such communications. You will always have the right to withdraw consent at any time.
Legal Obligation
We may process and retain certain data where required by law, including financial records for tax and accounting purposes, and data necessary for fraud prevention and detection.
5. Our Role: Controller and Processor
Repair and ongoing work bring us into contact with two different kinds of personal data, and our role under the UK GDPR is different for each.
Controller. We are the controller for the business contact details of the client staff we work with during an engagement — name, work email, and role. Our legal basis is our legitimate interests in running the engagement.
Processor. Where we encounter personal data inside your own systems — for example a content management system, analytics, or a database — during repair or ongoing work, you are the controller and we act as processor on your documented instructions. We do not use that data for our own purposes.
The rest of this policy describes the personal data for which we are the controller. Where we act as processor, your own privacy policy governs how that data may be used, and requests from the individuals concerned are for you to answer as controller. We will pass on any such request that reaches us and assist you in responding to it.
Data processing agreement. A data processing agreement is available on request. Write to us at info@swingintel.com. The same position is stated in section 11 (Data Processing) of our Terms of Service.
6. Third-Party Service Providers
We share your personal data with the following third-party service providers, each of whom processes data on our behalf and in accordance with their own privacy policies:
- Stripe (stripe.com) — Processes all payments securely. Stripe receives your payment details directly and provides us only with transaction confirmation information.
- Resend (resend.com) — Delivers transactional emails on our behalf, including payment confirmations and report delivery notifications.
- Anthropic (anthropic.com) — Provides the AI analysis capabilities used to produce our research reports. We send publicly accessible website content and research data to Anthropic's API to generate strategic insights and competitive analysis. We do not send your personal data (such as your name, email, or payment details) to Anthropic.
- Google Analytics (analytics.google.com) — Provides website usage analytics. Google Analytics uses cookies to collect aggregated data about page views and user interactions. We use this data to understand how visitors use our website and to improve our services. Google may process this data on servers outside the UK. See Google's privacy policy at policies.google.com/privacy.
AI Citation Testing Providers
As part of our AI visibility research, we test whether AI search platforms cite your website. To perform these tests, we send queries containing your website URL and publicly available business information to the following AI platforms:
- OpenAI (openai.com) — ChatGPT citation testing.
- Perplexity (perplexity.ai) — Perplexity AI citation testing.
- Google (google.com) — Gemini citation testing.
- xAI (x.ai) — Grok citation testing.
- DeepSeek (deepseek.com) — DeepSeek citation testing.
- Microsoft (microsoft.com) — Copilot citation testing.
No personal data (such as your name, email address, or payment details) is shared with these providers. These queries contain only your website URL and publicly available business information, and are processed under each provider’s API terms of service.
Data Analysis Providers
We use the following services to analyse your website’s visibility and discoverability:
- DataForSEO (dataforseo.com) — Provides page ranking data, keyword analysis, AI search visibility data, and AI Overview detection. Receives your website URL.
- Exa (exa.ai) — Provides neural search testing to assess whether AI systems can discover your website through semantic search. Receives your website URL and publicly available business information.
- Tavily (tavily.com) — Provides AI agent search testing to assess whether AI agents find your website when browsing the web. Receives your website URL and publicly available business information.
Infrastructure Providers
- Cloudflare (cloudflare.com) — Provides bot detection (Turnstile CAPTCHA) on our contact form. Cloudflare may set cookies on your device to distinguish humans from bots. See Cloudflare’s privacy policy at cloudflare.com/privacypolicy.
Our website, application, and database are hosted on dedicated server infrastructure that we operate ourselves within the United Kingdom or the European Economic Area, rather than on a third-party managed hosting platform.
We do not sell your personal data to any third party. We only share data with third parties to the extent necessary to deliver our services.
7. Data Retention
We retain your personal data for the following periods:
- Account data: Retained for as long as your account remains active. If you request deletion of your account, we will delete your account data within 30 days, subject to any legal obligations that require us to retain certain records.
- Reports: Retained indefinitely so that you can access your reports at any time. You may request deletion of your reports at any time.
- Client system credentials: Held only for as long as the engagement they were issued for is running. We delete them within 30 days of the engagement ending, or immediately if you ask us to. You can also revoke them yourself at any time.
- Client staff contact data: Retained for the duration of the engagement, and afterwards only for as long as we need it to answer questions about the work we carried out or to continue a live relationship with you. We delete these details on request.
- Payment records: Retained for as long as required by UK financial regulations, typically a minimum of six years from the date of the transaction.
- Automatically collected data: Technical data such as IP addresses, browser information, and page visit logs are retained for up to 12 months.
8. Data Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it, including:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security).
- Encryption at rest: Data stored by our service providers is encrypted at rest in accordance with their security standards.
- Access controls: Access to personal data is restricted to authorised personnel only, protected by authentication and role-based access controls.
- No card data: Payment card information never touches our systems. All card data is handled exclusively by Stripe, a PCI DSS Level 1 certified payment processor.
Client System Credentials
Credentials and access details you issue to us are handled separately from everything else described above:
- They are held in an encrypted password manager.
- They are never stored in the SwingIntel application or database.
- They are never retained in email or messaging.
- Access is limited to a single person: the engineer carrying out your engagement.
- We ask you to issue scoped, revocable accounts for us in preference to sharing personal logins, so that our access can be limited to what the work requires and withdrawn at any time.
While we take all reasonable precautions to protect your data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to protecting your data to the highest practical standard.
In the unlikely event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours. Where the breach poses a high risk to you, we will notify you directly without undue delay. Where the breach affects personal data we hold as your processor, we will notify you without undue delay so that you can meet your own obligations as controller.
9. International Transfers
Your account data and research reports are stored on server infrastructure that we operate within the United Kingdom or the European Economic Area. Your personal data may also be processed in countries outside the United Kingdom by our third-party service providers. Our primary service providers are based in the United States (Stripe, Resend, Anthropic, OpenAI, Perplexity, xAI, DeepSeek, Microsoft, Exa, Tavily) and the European Union (DataForSEO). Cloudflare and Google operate globally.
Where data is transferred outside the UK, we ensure that appropriate safeguards are in place, including:
- Transfers to countries with UK adequacy decisions, where the UK government has determined that the country provides an adequate level of data protection.
- Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office, which contractually require the receiving party to protect your data to the same standard as required under UK law.
- Other appropriate safeguards as permitted by the UK GDPR.
10. Your Rights (UK GDPR)
Under the UK GDPR, you have the following rights in relation to your personal data:
- Right of access: You have the right to request a copy of the personal data we hold about you.
- Right to rectification: You have the right to request that we correct any inaccurate or incomplete personal data.
- Right to erasure: You have the right to request that we delete your personal data, subject to any legal obligations that require us to retain certain records.
- Right to data portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
- Right to object: You have the right to object to our processing of your personal data where we rely on legitimate interests as our legal basis.
- Right to restrict processing: You have the right to request that we restrict the processing of your personal data in certain circumstances.
To exercise any of these rights, please contact us at info@swingintel.com. We will respond to your request within one month of receiving it, as required by the UK GDPR. If your request is particularly complex or we have received a number of requests from you, we may extend this period by up to two further months. If we need to extend the deadline, we will inform you within one month of receiving your original request and explain why the extension is necessary.
Your first request for a copy of your personal data is provided free of charge. For further copies, or for requests that are manifestly unfounded or excessive (for example, because of their repetitive character), we may charge a reasonable fee based on administrative costs or refuse to act on the request. In either case, we will explain our reasons.
If you are not satisfied with our response or believe that we are processing your data unlawfully, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
11. Automated Processing
Our AI Readiness Score (0–100) is generated through automated analysis of your website’s publicly accessible pages. This score is designed to help you understand your website’s visibility to AI search agents and is advisory in nature.
The AI Readiness Score is not used to make legally binding decisions about you, deny you access to our services, or determine your eligibility for any offer. It is one component of the broader analysis provided in your report.
If you have concerns about any automated assessment, you may contact us at info@swingintel.com to request a human review.
12. Cookies
Our website uses the following types of cookies:
Essential Cookies
These cookies are strictly necessary for the operation of our website. They cannot be disabled.
- Authentication cookies (
better-auth.session_token,better-auth.session_data): Maintain your login session and verify your identity. Set when you log in; expire at end of session or after the configured session duration. - API security token (
api-guard): Protects against cross-site request forgery (CSRF) attacks. Set on each page visit; expires after 24 hours. - Cloudflare bot detection (
cf_clearance,__cf_bm): Set by Cloudflare Turnstile on our contact form to distinguish humans from automated bots. Expire after 30 minutes of inactivity. See Cloudflare’s privacy policy for details.
Analytics Cookies
- Google Analytics (
_ga): Distinguishes unique visitors to our website. Expires after 2 years. - Google Analytics (
_ga_*): Maintains session state. Expires after 2 years.
Google Analytics 4 automatically anonymises IP addresses before storage. We use analytics data in aggregate to understand how visitors use our website and to improve our services. Google may process this data on servers outside the UK — see Google’s privacy policy at policies.google.com/privacy.
We do not use advertising cookies, remarketing cookies, or any third-party marketing cookies.
Your Cookie Choices
Under the Privacy and Electronic Communications Regulations 2003 (PECR), non-essential cookies require your consent. We are in the process of implementing a cookie consent mechanism for our analytics cookies. In the meantime, you can control cookies through your browser settings. You can also opt out of Google Analytics specifically by installing the Google Analytics opt-out browser add-on.
13. Children’s Data
Our services are not directed at individuals under 18, and we do not knowingly collect personal data from children.
14. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our services, legal requirements, or business practices. When we make material changes to this policy, we will notify you by email (if we have your email address) or by displaying a prominent notice on our website.
We encourage you to review this page periodically to stay informed about how we protect your data. The “Last updated” date at the top of this page indicates when the policy was most recently revised.
15. Contact Us
If you have any questions, concerns, or requests regarding this privacy policy or the way we handle your personal data, please contact us:
- Email: info@swingintel.com
- Postal address: Next Layer Digital Ltd, trading as SwingIntel, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ
- Company number: 16932866
- ICO registration: 00012757628