Privacy Policy
This notice explains how SwitchToSwift processes personal data when you browse this website, contact us or request a quote.
Controller and contact
The controller is the person or entity operating under the SwitchToSwift trade name, established in Lisbon, Portugal. The full legal identity, tax number and geographical address must be completed in the Legal Notice before the website is commercially launched.
For privacy questions or to exercise your rights, email management@switchtoswift.dev with ‘Privacy’ in the subject.
Data, purposes, legal bases and retention
- Contact enquiries
- Name, email, subject, message and optional company and phone details, to reply and take requested pre-contractual steps. Retained for up to 24 months after the matter closes.
- Quote requests
- Contact details, selected services, budget information, timing and message, to prepare and discuss a proposal. Retained for up to 24 months after the last interaction, unless a contract follows.
- Clients and contracts
- Data needed to perform the contract, support the client, establish or defend legal claims and meet accounting or tax duties. Contract records are retained for the applicable limitation periods and accounting documents for the statutory period, normally 10 years.
- Website security
- IP address, date, request and device or browser data may appear in infrastructure logs for security, availability and abuse prevention, based on legitimate interests. Logs are kept for the shortest configured period necessary, normally no more than 90 days unless an incident requires longer.
- Language and interface
- The selected language and whether the home introduction was shown are stored to provide the requested interface. See the Cookie Policy for exact durations.
Recipients and providers
Access is limited to authorised SwitchToSwift personnel and providers that need the data to deliver the service. The website is hosted on Google Firebase App Hosting and contact and quote emails are delivered using Resend. Email, hosting, security, professional advisers and public authorities may also receive data where necessary or legally required.
We do not sell personal data and we do not use it for behavioural advertising or solely automated decisions.
International transfers
Some technology providers may process data outside the European Economic Area. Where that happens, transfers must rely on an adequacy decision, the European Commission’s standard contractual clauses or another safeguard recognised by the GDPR. Further information may be requested through the privacy contact.
Your rights
Depending on the processing, you may request access, correction, deletion, restriction or portability, object to processing based on legitimate interests, and withdraw consent without affecting earlier lawful processing. We normally respond within one month and may request information strictly needed to confirm identity.
You may complain to the Portuguese Data Protection Authority (CNPD).
Security and required information
We use access restrictions, server-side validation, transport encryption and data minimisation measures appropriate to the risk. No internet transmission or storage system can be guaranteed completely secure.
Fields marked as required are needed to answer an enquiry or prepare a quote. Without them, we cannot process the request. Please do not send special-category data, passwords or payment card details through these forms.
Changes
We update this notice when processing activities or legal requirements change. Material changes will be identified by a new date.