Global Privacy Notice of swipecor GmbH

Global Privacy Notice of swipecor GmbH

1. Our Commitment

swipecor is an international, AI-powered business platform. We connect people, companies, products, services, events, career opportunities and business opportunities.

The protection of personal data is not a legal add-on for us; it is part of the platform architecture.

Our principle is:

Your data. Your decision. Your control.

This Privacy Notice explains:

  • which personal data we process;
  • where this data comes from;
  • for which purposes we use it;
  • which legal bases we rely on;
  • how swAIper and AI matchmaking work;
  • when data is displayed to other users or companies;
  • which service providers may receive data;
  • in which countries data may be processed;
  • how long we retain data; and
  • which rights users have worldwide.

2. Controller

The controller responsible for the processing activities described in this Privacy Notice is generally:

swipecor GmbH
Innovation Businesscenter
Gewerbering 38a
91341 Röttenbach
Germany
E-mail: info@swipecor.com
Subject line for privacy inquiries: Privacy

The company and contact details currently published are set out in the legal notice of the swipecor website (swipecor.com).

3. Privacy Contact and Data Protection Officer

Privacy inquiries and the exercise of data subject rights may be directed to:

swipecor Privacy Team
E-mail: info@swipecor.com
Subject: Data protection inquiry
Dr. Alexander Chalupka & Jannis Brendel

If a company data protection officer has been appointed or must be appointed by law, the officer's direct contact details must be added before this Notice is published:

Data Protection Officer:
Dr. Stefan Grabmeier, attorney-at-law

If local data protection representatives are required in individual countries, their contact details will be published in the relevant regional supplement to this Privacy Notice and in the swipecor Privacy Center.

4. Scope

This Privacy Notice applies in particular to:

  • the swipecor website;
  • the swipecor web app;
  • the swipecor mobile apps;
  • personal user accounts;
  • personal business profiles;
  • company Spaces;
  • swAIper;
  • AI-supported matchmaking;
  • leads and contact requests;
  • Malls;
  • Stages;
  • livestreams;
  • digital and physical events;
  • BusinessManager;
  • JobManager;
  • application and recruiting functions;
  • digital business cards;
  • messages and chats;
  • referral and recommendation programs;
  • swipeCoins;
  • payment and billing processes;
  • support;
  • newsletters;
  • push notifications; and
  • APIs and integrations.

This Privacy Notice applies worldwide.

For users in certain countries, the regional provisions at the end of this Notice apply in addition. If mandatory local data protection law provides a higher level of protection, that mandatory local law takes precedence.

5. When Other Privacy Information Applies

Additional or overriding privacy information may apply if:

  • a company uses swipecor as a processor;
  • an enterprise customer processes its own employee or applicant data;
  • an external event organizer organizes a Stage, Mall or event;
  • a company processes leads received through swipecor outside swipecor;
  • a user activates an external integration;
  • a particular function requires separate consent; or
  • local laws require additional information.

In these cases, the following may apply in addition to this Notice, in particular:

  • the privacy information of the respective company;
  • a data processing agreement;
  • event privacy notices;
  • applicant privacy notices;
  • cookie policies;
  • AI and swAIper notices; and
  • consent texts within the app.

6. Our Role under Data Protection Law

6.1 swipecor as Controller

swipecor is generally the controller when we decide on the purposes and essential means of processing. This applies in particular to:

  • registration;
  • user accounts;
  • platform operation;
  • swAIper;
  • our own matchmaking;
  • our own recommendations;
  • security;
  • prevention of misuse;
  • billing;
  • swipeCoins;
  • platform communications; and
  • product development.

6.2 swipecor as Processor

For certain enterprise functions, swipecor may process personal data exclusively on behalf of an enterprise customer. This may apply, for example, to:

  • customer-owned employee data;
  • customer-owned applicant data;
  • CRM data uploaded by a customer;
  • a customer's own lead lists; and
  • customer-specific data rooms.

In these cases, the enterprise customer is generally the controller and swipecor is the processor. The data processing agreement concluded with the customer applies in addition.

6.3 Companies as Independent Controllers

A company may itself be the controller if it:

  • receives a lead and processes it further outside swipecor;
  • receives applications;
  • organizes its own events;
  • manages employees within a Space;
  • imports contact details into its CRM; or
  • conducts its own marketing activities; or
  • offers its own products or services.

7. Definitions

Personal data means information relating to an identified or identifiable natural person.

Processing includes, in particular, the collection, storage, organization, analysis, alteration, transmission, display, deletion or other use of personal data.

Sensitive data or special categories of personal data may include, in particular, health data, biometric identification data, information about ethnic origin, religion, political beliefs, sexual orientation or trade-union membership.

Profiling means any form of automated processing through which personal or professional aspects are analyzed, evaluated or predicted.

AI system means a machine-based system that can generate outputs such as recommendations, content, predictions or decisions based on inputs.

8. Data We May Process

Which data is actually processed depends on which functions a user uses.

8.1 Registration and Account Data

This may include:

  • first name;
  • last name;
  • username;
  • business e-mail address;
  • private e-mail address, if provided;
  • telephone number;
  • mobile telephone number;
  • country;
  • language;
  • time zone;
  • account ID;
  • registration date;
  • user status;
  • login and authentication information;
  • password hash;
  • two-factor authentication data; and
  • confirmation and verification status.

Passwords are generally not stored in plain text.

8.2 Personal Profile and Business Data

This may include:

  • profile picture;
  • name;
  • position;
  • role;
  • employer;
  • company;
  • industry;
  • location;
  • professional background;
  • education;
  • skills;
  • qualifications;
  • certificates;
  • languages;
  • interests;
  • business objectives;
  • cooperation interests;
  • investment interests;
  • services offered;
  • services sought;
  • contact options;
  • website;
  • social media links; and
  • profile texts provided voluntarily.

8.3 Company and Space Data

This may include:

  • company name;
  • address;
  • domain;
  • website;
  • logo;
  • company description;
  • industry;
  • company size;
  • products;
  • services;
  • offers;
  • requests;
  • contact persons;
  • employees;
  • certificates;
  • images;
  • videos;
  • posts;
  • events;
  • job advertisements;
  • contact details; and
  • Space roles and permissions.

8.4 Content and Communications

This may include:

  • messages;
  • chats;
  • comments;
  • posts;
  • reactions;
  • requests;
  • files;
  • images;
  • videos;
  • audio content;
  • links;
  • timestamps;
  • sender and recipient information;
  • delivery and read status; and
  • reports concerning prohibited content.

8.5 swAIper and AI Data

This may include:

  • text inputs;
  • voice inputs;
  • prompts;
  • chat histories;
  • uploaded documents;
  • questions;
  • search queries;
  • AI responses;
  • feedback;
  • reported errors;
  • profile and Space information;
  • match preferences;
  • technically generated contextual data;
  • embeddings and vector representations; and
  • security and quality metadata.

8.6 Match, Recommendation and Lead Data

This may include:

  • match criteria;
  • match scores;
  • relevance ratings;
  • interests;
  • offers and requests;
  • preferred industries;
  • locations;
  • interaction history;
  • contact requests;
  • reasons for a match;
  • lead status;
  • time of a lead;
  • response to a lead; and
  • inferred business interests.

8.7 Contact, Referral and Invitation Data

This may include:

  • name;
  • e-mail address;
  • telephone number;
  • company;
  • referral code;
  • inviting user;
  • time of invitation;
  • acceptance or registration status; and
  • allocation of bonuses or swipeCoins.

8.8 Job and Application Data

This may include:

  • résumé/CV;
  • contact details;
  • professional background;
  • qualifications;
  • references and certificates;
  • work samples;
  • desired position;
  • availability;
  • salary expectations;
  • preferred location;
  • messages with employers; and
  • application status.

8.9 Payment, Order and Billing Data

This may include:

  • name;
  • company;
  • billing address;
  • tax number or VAT ID;
  • order data;
  • invoice number;
  • payment method;
  • payment status;
  • transaction ID;
  • swipeCoin balance;
  • swipeCoin purchases;
  • bonus credits; and
  • usage history.

Complete payment card details are generally processed by the respective payment service provider. Where possible, swipecor is intended to receive only token, status and transaction information.

8.10 Event, Stage and Mall Data

This may include:

  • event registration;
  • ticket status;
  • attendance;
  • check-in;
  • match requests;
  • questions;
  • comments;
  • chat posts;
  • interests;
  • agenda selections;
  • participation in livestreams; and
  • photographic, audio and video recordings.

8.11 Device, Usage and Log Data

This may include:

  • IP address;
  • device ID;
  • browser type;
  • operating system;
  • app version;
  • language;
  • screen resolution;
  • time zone;
  • login time;
  • areas accessed;
  • clicks;
  • time spent;
  • crash reports;
  • error reports;
  • referrer;
  • session data;
  • security events; and
  • API calls.

8.12 Location Data

We may derive an approximate location from the IP address.

Precise location data from an end device is processed only if:

  • the relevant function is used;
  • the operating system has granted permission; and
  • the processing is legally permissible.

8.13 Support and Feedback Data

This may include:

  • support requests;
  • messages;
  • screenshots;
  • error descriptions;
  • account information;
  • conversation notes;
  • feedback;
  • survey responses; and
  • satisfaction ratings.

8.14 Security and Verification Data

This may include:

  • login history;
  • failed login attempts;
  • device information;
  • suspicious activities;
  • proof of identity or company verification;
  • domain verification;
  • abuse reports; and
  • blocking and sanction data.

8.15 Inferred Data

We may infer additional information from existing data, for example:

  • presumed business interests;
  • match relevance;
  • preferred functions;
  • likelihood of becoming a lead;
  • security risk; and
  • presumed affiliation with a company.

Such inferences are used only for defined and permissible purposes.

9. Where We Receive Data From

We receive personal data in particular:

  • directly from the user;
  • from a Space administrator;
  • from an employer or enterprise customer;
  • from other users;
  • from invitations and referrals;
  • from activated integrations;
  • from payment service providers;
  • from authentication providers;
  • from event partners;
  • from the end device or browser;
  • from the use of swipecor;
  • from lawfully publicly accessible sources;
  • from company websites or public registers; and
  • through permissible analyses and inferences.

If data is not collected directly from the data subject, we will inform the data subject to the extent required by law.

10. Purposes and Legal Bases

Depending on the country, function and processing activity, we rely on different legal bases.

For users in the EU and EEA, the legal bases under Articles 6 and 9 GDPR apply in particular. The GDPR also requires transparency, purpose limitation, data minimization, storage limitation, security and accountability.

10.1 Registration and Performance of the Contract

We process data in order to:

  • create an account;
  • authenticate the user;
  • manage the account;
  • provide platform functions;
  • bill for paid services; and
  • provide support.

In the EU and EEA, the relevant legal basis is in particular performance of the contract or taking steps at the request of the data subject prior to entering into a contract.

10.2 Profiles and Spaces

We process data in order to:

  • provide personal business profiles;
  • create company Spaces;
  • make companies and contact persons visible;
  • present products and services; and
  • manage company members.

The legal basis may be performance of the contract, consent or a legitimate interest in providing a professional business platform.

10.3 swAIper and AI Functions

We process data in order to:

  • understand requests;
  • generate responses;
  • find relevant content;
  • suggest suitable contacts;
  • identify business opportunities;
  • help users operate swipecor; and
  • ensure security and quality.

The legal basis may be performance of the contract, consent or a legitimate interest.

10.4 Matchmaking and Recommendations

We process data in order to:

  • connect people and companies;
  • suggest suitable products or services;
  • recommend events or jobs; and
  • generate match scores and relevance ratings.

The legal basis may be performance of the contract, consent or a legitimate interest in providing relevant recommendations.

10.5 Leads and Business Development

We process data in order to:

  • transmit contact requests;
  • provide leads;
  • bring together business interests;
  • disclose contact information; and
  • document lead status and the use of swipeCoins.

Depending on the function, this is based on a contract, an active user action, consent or a legitimate interest.

10.6 Communications

We process message and contact data to enable communication between users. The legal basis is generally performance of the contract.

For security checks, there may also be a legitimate interest in preventing spam, malware and misuse.

10.7 Payments and Invoices

We process payment and billing data for:

  • contract processing;
  • payment verification;
  • accounting;
  • tax documentation; and
  • fraud prevention.

The legal bases are performance of the contract and legal obligations.

10.8 Security and Prevention of Misuse

We process technical and security-related data in order to:

  • protect accounts;
  • detect unauthorized access;
  • prevent fraud;
  • defend against malware;
  • investigate security incidents; and
  • protect our rights and the rights of our users.

The legal basis is in particular our legitimate interest in secure platform operation and, where applicable, a legal obligation.

10.9 Analytics and Product Improvement

We process usage and feedback data in order to:

  • detect errors;
  • improve functions;
  • measure platform performance;
  • optimize user guidance; and
  • develop new functions.

A legitimate interest may exist for purely technical and operationally necessary analytics. For optional analytics or tracking technologies, we obtain consent to the extent required by law.

10.10 Marketing and Advertising

We process contact data and communication preferences in order to:

  • send product information;
  • announce events;
  • present new functions;
  • send offers; and
  • measure campaign success.

Electronic advertising is conducted only within the framework of the applicable laws. Where required, we obtain prior consent.

10.11 Legal Obligations and Enforcement of Rights

We may process data in order to:

  • comply with statutory retention obligations;
  • respond to orders from authorities;
  • assert legal claims;
  • conduct litigation; and
  • prevent criminal offenses or misuse.

11. Mandatory and Voluntary Information

Mandatory information is identified as such within the platform.

Users who do not provide required data may not be able to use certain functions. This may concern in particular:

  • registration;
  • authentication;
  • conclusion of a contract;
  • payment;
  • invoicing;
  • company verification; and
  • security.

Voluntary profile information can generally be omitted or deleted later.

12. Visibility of Profiles and Content

swipecor contains:

  • private areas;
  • areas visible only to registered users;
  • areas visible to specific companies; and
  • public areas.

Within the relevant function, users are informed who can see an item of information.

Content visible to the public may:

  • be accessed worldwide;
  • be indexed by search engines;
  • be shared outside swipecor; and
  • be stored or further processed by other users.

Removing content from swipecor does not necessarily result in its immediate removal from search engine caches or copies already created by third parties.

Users should not post confidential trade secrets, passwords or particularly sensitive personal data in public areas.

13. swAIper and Artificial Intelligence

13.1 AI Labeling

swAIper is visibly identified as an AI system, for example:

swAIper · AI Business Agent

Users should be able to recognize at all times that they are interacting with an artificial intelligence.

The EU AI Act contains transparency requirements for systems that interact directly with natural persons. The Regulation was amended again in 2026; the applicable consolidated version is therefore decisive for implementation.

13.2 Data swAIper May Use

Depending on the request and authorization, swAIper may use:

  • the current text input;
  • previous chat messages;
  • profile information;
  • company information;
  • offers and requests;
  • match preferences;
  • content released from Spaces;
  • publicly visible platform information;
  • search and interaction context; and
  • technical security information.

13.3 Voice Inputs

If a user uses voice input, audio may be processed temporarily in order to convert speech into text.

Unless a voice contribution is expressly intended to be stored, voice inputs alone are generally not stored permanently as an audio file after transcription.

13.4 AI Responses May Be Incorrect

AI-generated responses may be:

  • incomplete;
  • inaccurate;
  • ambiguous;
  • outdated; or
  • factually incorrect.

Users must independently verify information relevant to business, legal, medical, tax or financial matters.

13.5 Training of External AI Models

The binding swipecor principle is:

Private swAIper chats, prompts, files and non-public user data are not used for general training of external AI models unless the user has previously given separate, voluntary and express consent.

swipecor contractually obliges the AI service providers it uses to comply accordingly, to the extent technically and contractually possible.

13.6 Our Own Quality Improvement

We may use:

  • anonymized data;
  • aggregated usage data;
  • expressly authorized feedback; and
  • artificially generated test data

in order to test and improve swAIper.

Personal content will be used for broader model improvements only after a separate data protection assessment and on a permissible legal basis.

13.7 User Control

Within the Privacy Center, users should in particular be able to:

  • view chats;
  • delete individual chats;
  • delete the entire history;
  • manage personalization;
  • report incorrect responses;
  • report incorrect matches; and
  • access information about the use of data for AI.

14. AI Matchmaking and Profiling

swipecor may automatically analyze:

  • industry;
  • role;
  • company size;
  • location;
  • products;
  • services;
  • offers;
  • requests;
  • business objectives;
  • interests;
  • interactions;
  • search queries;
  • previous matches;
  • event interests; and
  • voluntarily provided preferences.

This may result in:

  • match scores;
  • relevance ratings;
  • recommendations;
  • rankings;
  • lead suggestions; and
  • personalized results.

14.1 Why a Match Is Displayed

Where technically possible and legally required, swipecor provides an understandable explanation, for example:

This match is suggested because your company is looking for a particular service and the suggested company offers that service.

We are not required to disclose model weights, source code, security mechanisms or trade secrets.

14.2 No Targeted Use of Sensitive Characteristics

Sensitive data is not knowingly used as match criteria unless:

  • this has been expressly requested by the user;
  • a specific function requires it; or
  • express consent or another legal basis exists.

14.3 Objection and Adjustment

Where provided by law, users may:

  • change their match preferences;
  • reduce personalization;
  • object to specific processing activities; and
  • request human review.

15. No Solely Automated Significant Decisions

General swipecor matchmaking does not automatically decide whether:

  • a contract is concluded;
  • a loan is granted;
  • financing is approved;
  • a person is hired;
  • insurance is taken out; or
  • a user is legally admitted to or excluded from the platform.

As a general rule, swipecor does not make solely automated decisions that produce legal effects concerning a person or similarly significantly affect that person.

If such a function is introduced in the future, the following will take place beforehand:

  • a separate legal assessment;
  • transparent information;
  • consent, where applicable;
  • an opportunity for human review; and
  • an opportunity to challenge the decision.

16. Contacts, Contact Import and Invitations

Contacts are imported or synchronized only when a user actively enables this function.

Depending on the technical implementation, selected contact information may be processed or matched in hashed form.

A user may transmit contact details only if the user is authorized to do so.

16.1 No Visible Shadow Profiles

swipecor does not create a publicly visible user profile from a mere invitation.

If the invited person does not register, invitation data alone is generally deleted or anonymized within 30 days, unless:

  • no further invitation has been expressly requested;
  • there is no statutory retention obligation; and
  • a blocklist is not required to prevent further unwanted invitations.

16.2 Opting Out of Invitations

Recipients may object to further invitations. A minimum block record may be stored in order to honor the objection.

17. Leads and Business Matches

A lead may arise if:

  • a user actively expresses interest;
  • a contact request is submitted;
  • a user is looking for a service;
  • a user responds to an offer;
  • contact information is released; or
  • a suggested match is actively accepted.

Depending on the function, the recipient may be shown:

  • name;
  • company;
  • position;
  • profile information;
  • contact information;
  • business interest;
  • request; and
  • reason for the match.

A company that receives a lead and processes it further outside swipecor may be independently responsible under data protection law for that processing.

swipecor does not make private contact details available to other companies without limitation unless a function, authorization or legal basis permits this.

18. Messages and Communications

Private messages are not public.

We may automatically examine messages and attachments where necessary for:

  • spam prevention;
  • malware detection;
  • fraud prevention;
  • detection of misuse;
  • compliance with legal obligations; and
  • handling a user report.

If a user deletes a message only from the user's own view, the message may remain available to the recipient.

End-to-end encryption is guaranteed only if it is expressly stated for the specific function.

19. Company Spaces and Administrators and Employees

Depending on their permissions, Space administrators may:

  • invite employees;
  • assign roles;
  • edit content;
  • remove Space members;
  • manage company data; and
  • view certain activity information.

A company may assign persons to a Space only if there is a legal basis for doing so.

If a person is invited by a company, that person will receive information about:

  • the inviting company;
  • the intended role; and
  • the associated data processing.

Users may report an incorrect company assignment.

20. Malls, Stages and Events

The following may be processed in connection with Malls, Stages and events:

  • registration;
  • participation;
  • check-in;
  • match requests;
  • questions;
  • posts;
  • chat activities;
  • interactions; and
  • event preferences.

Posts in public Stage chats may be visible to other participants.

20.1 Photographic, Audio and Video Recordings

Photographic, audio and video recordings may be made at physical or digital events.

Where required, additional information will be provided before or at the relevant event concerning:

  • recording areas;
  • purpose;
  • publication;
  • recipients; and
  • objection options.

Close-up shots or targeted interviews will be used only on an appropriate legal basis.

21. JobManager and Recruiting

Application data is generally made accessible to companies only if the user:

  • submits an application;
  • releases their profile for this purpose;
  • consents to corresponding contact; or
  • another appropriate legal basis exists.

The respective company is generally independently responsible for its further application process.

swipecor may recommend suitable positions or candidates. The respective company makes the final hiring decision.

Through the general JobManager, swipecor does not make any solely automated hiring or rejection decision.

22. swipeCoins, Purchases and Payments

To manage swipeCoins, we may process:

  • balance;
  • purchase;
  • redemption;
  • bonus;
  • referral credit;
  • refund;
  • transaction time; and
  • associated service.

Payment service providers receive only the data required for payment, fraud checks and legal obligations.

Payment service providers may be independently responsible for certain processing activities.

23. Cookies, SDKs and Similar Technologies

We may use:

  • cookies;
  • local storage;
  • session storage;
  • pixels;
  • SDKs;
  • device identifiers; and
  • comparable technologies.

23.1 Necessary Technologies

These may be required for:

  • login;
  • authentication;
  • security;
  • session management;
  • language;
  • load balancing;
  • payment processes; and
  • storing the privacy decision.

23.2 Functional Technologies

These may enable convenience functions and personal settings.

23.3 Analytics

These may help us understand:

  • which functions are used;
  • where technical errors occur;
  • where registrations are abandoned; and
  • how the platform can be improved.

23.4 Marketing

Marketing technologies may be used to measure campaigns or provide personalized advertising.

Optional technologies are activated only once valid consent has been obtained, to the extent required by the applicable law.

In Germany, Section 25 TDDDG generally requires consent for storing or accessing information on end devices unless a statutory exception applies.

23.5 Privacy Settings

Users can change or withdraw their decision at any time via:

  • privacy settings.

Withdrawal must generally be as easy as giving consent.

23.6 Global Privacy Control

Where legally required, we will technically honor valid universal opt-out signals such as Global Privacy Control.

24. Analytics, Personalization and Advertising

24.1 Operational Analytics

We may carry out necessary analytics to monitor:

  • stability;
  • security;
  • capacity utilization;
  • errors; and
  • misuse.

24.2 Optional Analytics

Optional analytics are carried out only with consent where consent is required.

24.3 Personalization

We may personalize content, for example:

  • match suggestions;
  • relevant Malls;
  • Stages;
  • events;
  • jobs;
  • products; and
  • company offers.

24.4 Sponsored Content

Companies may publish commercial or sponsored content within swipecor.

A company does not receive a user's personal data merely because sponsored content is shown to that user.

Data may be transmitted if the user:

  • contacts the provider;
  • triggers a lead;
  • registers; or
  • expressly consents.

25. Newsletters, Push Notifications and Direct Marketing

We distinguish between:

25.1 Contractual and Service Messages

These include:

  • security notices;
  • login alerts;
  • contractual information;
  • payment information;
  • material platform changes; and
  • requested match or lead notifications.

These messages may be required for use of the platform.

25.2 Advertising and Marketing

These include:

  • new products and features;
  • promotions;
  • event advertising;
  • partner offers; and
  • campaigns.

Promotional communications can be unsubscribed from at any time.

Unsubscribing from advertising does not necessarily end required security or contractual communications.

26. To Whom Data May Be Transferred

Depending on the function and necessity, personal data may be transferred to the following recipients:

26.1 Other Users

For example, in connection with:

  • visible profiles;
  • contact requests;
  • messages;
  • leads;
  • matches;
  • comments; and
  • events.

26.2 Companies and Space Administrators

For example, in connection with:

  • company affiliation;
  • applications;
  • leads;
  • employee administration; and
  • event participation.

26.3 IT and Platform Service Providers

These may include:

  • hosting providers;
  • cloud providers;
  • software developers;
  • database providers;
  • search technology providers;
  • monitoring services;
  • support systems; and
  • security providers.

26.4 AI Service Providers

AI service providers may receive prompts, contextual information and technical metadata to the extent required to provide an AI function.

26.5 Communication Service Providers

These may include:

  • e-mail providers;
  • SMS providers;
  • push services; and
  • video-conferencing or streaming providers.

26.6 Payment Service Providers

These may include:

  • banks;
  • card providers;
  • payment providers; and
  • invoicing and collection service providers.

26.7 Advisors and Auditors

These may include:

  • lawyers;
  • tax advisors;
  • auditors;
  • data protection advisors; and
  • insurers.

26.8 Authorities and Courts

A transfer may take place if:

  • we are legally required to do so;
  • an effective order exists;
  • legal claims must be protected; or
  • criminal offenses or serious misuse are investigated.

26.9 Corporate Transactions

In the event of a merger, financing, restructuring or sale, data may be disclosed to the extent required to:

  • purchasers;
  • investors;
  • advisors; and
  • legal successors.

27. Subprocessors

An up-to-date list of the material processors and subprocessors is provided in the swipecor Privacy Center or in the public Subprocessor List. The list is intended to include in particular:

  • provider;
  • service;
  • processing location;
  • data categories; and
  • third-country transfer mechanism.

Until the online list is published, the current list may be requested at info@swipecor.com.

28. No Sale of Personal Data

swipecor does not sell personal user data to data brokers as a traditional business model. In particular, we do not sell private:

  • contact details;
  • chat messages;
  • swAIper prompts;
  • application data; or
  • payment data.

The terms "sale," "sell," "share" or "targeted advertising" may have broader legal meanings in certain U.S. states than a sale for money.

If processing falls within such a definition, we will provide the legally required opt-out option.

29. International Data Transfers

swipecor is internationally oriented. Data may therefore:

  • be processed in other countries;
  • be processed by service providers in other countries;
  • be accessible worldwide in the case of public profiles; and
  • be accessed by international users.

For transfers from the EU or EEA, we use, where required, in particular:

  • adequacy decisions;
  • EU Standard Contractual Clauses;
  • binding corporate rules;
  • supplementary technical and organizational measures; and
  • other mechanisms permitted by law.

The European Commission identifies adequacy decisions and Standard Contractual Clauses in particular as transfer mechanisms.

For transfers to the United States, the EU-U.S. Data Privacy Framework may be used for appropriately certified recipients. Otherwise, we examine other suitable mechanisms.

Users may request information about the transfer mechanism used in the relevant case.

30. Data Security

We implement appropriate technical and organizational measures. These may include:

  • encryption in transit;
  • encryption of stored data, where appropriate;
  • password hashing;
  • multi-factor authentication;
  • role-based permissions;
  • tenant separation;
  • access restrictions;
  • firewalls;
  • security monitoring;
  • logging;
  • vulnerability management;
  • regular updates;
  • backups;
  • recovery procedures;
  • incident response processes;
  • security training;
  • penetration tests;
  • protection against prompt injection; and
  • protection against cross-tenant data leakage.

No technical system is entirely free of risks. We therefore cannot guarantee absolute security.

31. Personal Data Breaches

We maintain procedures for the:

  • detection;
  • containment;
  • assessment;
  • documentation; and
  • notification

of personal data breaches.

Where legally required, we inform:

  • the competent data protection authorities;
  • affected enterprise customers; and
  • affected individuals.

32. Retention Period

As a general rule, we retain data only for as long as required for the relevant purpose.

The following periods represent the intended swipecor standard. They may be changed by statutory obligations, legal disputes or regional requirements.

Data categoryGeneral retention rule
Incomplete registrationGenerally up to 30 days
Active user accountFor the duration of the account
Profile and Space dataUntil deletion, removal or termination of the account
Deleted accountRemoval from active systems generally within 30 days
BackupsOverwritten in the regular cycle; target maximum of 90 days
swAIper chatsFor as long as the user uses the history function or until deletion
Temporary AI and security logsGenerally up to 90 days
MessagesFor as long as they are stored for the users involved
Contact and invitation data without registrationGenerally up to 30 days
Match and lead dataGenerally up to 24 months after the last relevant activity
Application dataGenerally up to six months after completion of the process, unless another basis exists
Talent poolOnly with consent and generally up to 24 months
Support casesGenerally up to three years after closure
Standard security logsGenerally 90 to 180 days
Invoice and accounting dataIn accordance with statutory obligations, generally six to ten years
Marketing consents and objectionsFor as long as necessary to document or honor the objection
Cookie and SDK dataIn accordance with the cookie and provider overview

32.1 Legal Disputes and Legal Hold

Data may be retained for longer if required for:

  • legal disputes;
  • official investigations;
  • investigating fraud; or
  • asserting or defending claims.

32.2 Deletion from AI and Search Systems

When data is deleted, we also review connected:

  • search indexes;
  • embeddings;
  • vector databases;
  • match signals;
  • summaries;
  • caches; and
  • analytics stores.

33. Anonymized and Aggregated Data

We may anonymize or aggregate data so that it no longer relates to an identifiable person. Such data may be used for:

  • statistics;
  • product development;
  • market analyses;
  • security analyses; and
  • AI quality tests.

We do not attempt to re-identify data that has been effectively anonymized.

34. Global Privacy Rights

Depending on the applicable law, users may have, in particular, the following rights:

  • information about processing;
  • access;
  • obtaining a copy;
  • rectification;
  • completion of incomplete data;
  • erasure;
  • restriction;
  • blocking;
  • data portability;
  • objection;
  • withdrawal of consent;
  • opting out of sale or sharing;
  • opting out of personalized advertising;
  • opting out of certain profiling procedures;
  • human review of automated decisions;
  • lodging a complaint;
  • appealing the rejection of a request; and
  • protection against discrimination for exercising rights.

Not every right applies in every situation. Rights may depend on:

  • the country;
  • the legal basis;
  • the type of data;
  • swipecor's role; and
  • statutory exceptions.

35. Exercising Privacy Rights

Requests may be sent to:

info@swipecor.com
Subject: Data protection inquiry

Alternatively, requests may be submitted via the swipecor Privacy Center.

Where possible, the request should include:

  • name;
  • e-mail address used;
  • affected account;
  • right being requested; and
  • affected data or function.

35.1 Identity Verification

We may request reasonable information in order to:

  • verify identity;
  • prevent unauthorized disclosure of data; and
  • verify authorization.

We do not automatically require a copy of an identity document if a less intrusive form of verification is sufficient.

35.2 Authorized Representatives

Where provided for by local law, an authorized representative may submit a request. We may request proof of authorization.

35.3 Deadlines

We respond to requests within the applicable statutory period.

For users in the EU and EEA, the regular period is generally one month. It may be extended for complex or numerous requests under the statutory conditions.

35.4 No Discrimination

Users will not be unlawfully disadvantaged because they exercise their privacy rights.

36. Account Deletion

Users may request deletion of their account via the Privacy Center or by e-mail.

Identity verification may be required before deletion.

After deletion:

  • active personal data is deleted or anonymized;
  • public profiles are removed;
  • data required to be retained by law may be retained in blocked form;
  • messages may remain with the respective recipient;
  • backups are overwritten in the regular cycle; and
  • removal from search engines may be delayed.

37. Sensitive Data

swipecor is a business platform and generally does not require sensitive data.

Users should not publish information about, in particular:

  • health;
  • religion;
  • ethnic origin;
  • political beliefs;
  • sexual orientation;
  • trade-union membership;
  • genetic data; or
  • biometric identification data,

unless this is required for a specifically offered function.

If sensitive data is processed, this occurs only on a specific legal basis, such as explicit consent.

38. No Biometric Identification as a Standard

swipecor does not automatically use profile pictures or voice recordings for biometric identification. In particular, the following do not take place as a standard:

  • facial recognition;
  • voice recognition for unique identification; or
  • biometric categorization.

If such a function is introduced in the future, separate information and consent will be obtained to the extent required by law.

39. Users Under 18

swipecor is a B2B and business platform for adult users.

Regular use is generally permitted only from the age of 18.

We do not knowingly collect children's personal data for regular user accounts.

If we become aware that an account is being used by a minor without the required legal basis, we may:

  • suspend the account;
  • conduct an age or representation check; and
  • delete the data.

40. Data from Publicly Accessible Sources

We may process business information from lawfully publicly accessible sources. These may include:

  • company websites;
  • public company registers;
  • publicly published professional contact details;
  • press publications; and
  • public event or speaker information.

We use such data only for defined and lawful purposes.

We do not treat publicly accessible information as a blanket authorization for unrestricted profiling or advertising.

Data subjects may request correction or removal to the extent the statutory requirements are met.

41. APIs and Integrations

Users may activate external integrations. Data may be transferred between swipecor and the selected provider.

Before activation, we will inform users, where required, about:

  • the provider involved;
  • the data transferred;
  • the purpose; and
  • withdrawal or deactivation.

The external provider's privacy provisions apply to its independent processing activities.

42. Changes to this Privacy Notice

We may amend this Privacy Notice, for example due to:

  • new functions;
  • new AI systems;
  • new service providers;
  • changes in law;
  • international expansion; or
  • security requirements.

The current version contains the relevant date of amendment.

In the event of material changes, we may also inform users by:

  • e-mail;
  • an in-app notification;
  • a notice upon login; or
  • a notice in the Privacy Center.

If new processing requires consent, we will obtain that consent separately.

REGIONAL PRIVACY SUPPLEMENTS

43. European Union, EEA and Germany

For users in the European Union and the European Economic Area, the GDPR applies in particular.

43.1 Legal Bases

We base processing in particular on:

  • consent;
  • performance of a contract;
  • steps prior to entering into a contract;
  • legal obligations;
  • protection of vital interests;
  • legitimate interests; and
  • public interests, where applicable.

43.2 Legitimate Interests

Legitimate interests may include in particular:

  • secure platform operation;
  • prevention of misuse;
  • improvement of functions;
  • B2B matchmaking;
  • enforcement of rights;
  • internal administration; and
  • permissible B2B communications.

Before processing on the basis of legitimate interests, we assess:

  • necessity;
  • impact on data subjects;
  • reasonable expectations;
  • safeguards; and
  • objection options.

43.3 Special Categories

Special categories of personal data are processed only under the conditions of Article 9 GDPR.

43.4 Automated Decisions

Where Article 22 GDPR applies, users have the right:

  • not to be subject to an unlawful solely automated decision;
  • to request human intervention;
  • to present their own point of view; and
  • to challenge the decision.

43.5 Objection

Users may object to processing based on legitimate interests on grounds relating to their particular situation.

Users may object to the processing of personal data for direct marketing at any time and without stating reasons.

43.6 Supervisory Authority

Based on the current information regarding the registered office of swipecor GmbH, the following supervisory authority is generally responsible:

Bavarian State Office for Data Protection Supervision
Promenade 18
91522 Ansbach
Germany

Data subjects may also contact a supervisory authority at their place of residence or stay. The BayLDA is responsible for the non-public sector in Bavaria and provides an online complaint procedure.

The rights, information obligations, legal bases and transfer requirements arise in particular from the GDPR.

44. United Kingdom

For users in the United Kingdom, the following apply in particular, where applicable:

  • UK GDPR;
  • Data Protection Act 2018; and
  • amendments introduced by the Data (Use and Access) Act 2025.

Depending on the processing, users may in particular request:

  • information;
  • access;
  • rectification;
  • erasure;
  • restriction;
  • data portability;
  • objection; and
  • protection in relation to automated decisions.

UK law requires transparent information about purposes, retention periods, recipients and rights. Since 19 June 2026, there have also been specific requirements for internal data protection complaint procedures.

UK Representative

If the requirements for appointing a representative in the United Kingdom are met:

[APPOINT UK REPRESENTATIVE BEFORE ACTIVE UK MARKET LAUNCH]

Complaints may also be submitted to the Information Commissioner's Office.

45. Switzerland

For persons in Switzerland, the Swiss Federal Act on Data Protection applies in particular.

Depending on the circumstances, Swiss users may in particular request:

  • access;
  • rectification;
  • deletion or destruction;
  • restriction or cessation of unlawful processing; and
  • provision or transfer of certain data.

In the case of automated individual decisions, we will provide information and enable human review to the extent required by law.

International transfers are carried out in accordance with Swiss requirements.

Where required by law, swipecor will appoint a representative in Switzerland:

[APPOINT SWISS REPRESENTATIVE BEFORE MARKET LAUNCH]

Complaints may be addressed to the Swiss Federal Data Protection and Information Commissioner.

Swiss data protection law protects the personality and fundamental rights of natural persons in the processing of personal data.

46. United States of America

This section applies in addition to persons in the United States to the extent a comprehensive data protection law of their state applies to swipecor.

46.1 Categories of Personal Information

Depending on use, we may have processed the following categories during the preceding twelve months:

CategoryExamples
IdentifiersName, e-mail address, IP address, account ID
Customer recordsContact details, billing information
Commercial informationPurchases, swipeCoins, leads, transactions
Online activityClicks, usage, browser and app data
Location dataApproximate or authorized precise location
Audio and visual dataProfile pictures, videos, voice inputs
Professional informationEmployer, position, résumé
InferencesInterests, match relevance, preferences
Sensitive informationLogin data or precise location, where processed

We do not use biometric identifiers as a standard function.

46.2 Purposes and Recipients

The categories are used for the purposes described in this Privacy Notice and may be disclosed to the following categories:

  • platform users;
  • enterprise customers;
  • service providers;
  • payment providers;
  • AI providers;
  • security providers;
  • professional advisors; and
  • authorities.

46.3 No Sale and No Sharing

swipecor does not sell personal information for money.

swipecor also does not intend to share personal information for cross-context behavioral advertising.

If future marketing technology is legally considered "sale" or "sharing," it will be used only after the legally required notices and opt-out options have been introduced.

46.4 Rights

Depending on the state, users may have:

  • the right to know and access;
  • the right to a copy;
  • the right to correction;
  • the right to deletion;
  • the right to data portability;
  • the right to opt out of sale;
  • the right to opt out of sharing;
  • the right to opt out of targeted advertising;
  • the right to opt out of certain profiling procedures;
  • the right to limit the use of sensitive information;
  • the right to appeal a denial; and
  • the right to equal treatment.

46.5 California

Under the CCPA, California consumers may in particular request:

  • information about collection, use and disclosure;
  • deletion;
  • correction;
  • opting out of sale or sharing;
  • limitation of the use of certain sensitive information; and
  • protection against discrimination.

California regulations concerning automated decision-making technology, risk assessments and cybersecurity audits entered into force on 1 January 2026, with certain obligations subject to staggered deadlines.

46.6 Global Privacy Control

We honor Global Privacy Control to the extent required under California or other applicable U.S. law.

California recognizes GPC as an opt-out signal. Colorado also recognizes GPC as a universal opt-out mechanism for certain processing activities.

46.7 Authorized Agents

Where provided for by law, a user may appoint an authorized agent. We may verify the authorization and identity.

46.8 Minors

swipecor is not intended for persons under 18. We do not knowingly sell or share personal information of persons under 18.

47. Canada

For users in Canada, the following apply in particular, where applicable:

  • PIPEDA;
  • the privacy laws of Alberta;
  • the privacy laws of British Columbia;
  • Québec privacy law; and
  • other applicable provincial laws.

We observe in particular:

  • accountability;
  • purpose specification;
  • appropriate consent;
  • data minimization;
  • limits on use and retention;
  • accuracy;
  • security;
  • transparency;
  • access; and
  • complaint options.

Canadian users may in particular request access and correction and submit a complaint to the competent privacy commissioner.

PIPEDA regulates the processing of personal information by private-sector organizations in the course of commercial activities. Alberta, British Columbia and Québec have their own private-sector privacy laws, which may apply instead of PIPEDA in certain cases.

48. Brazil

For persons in Brazil, the Lei Geral de Proteção de Dados Pessoais (LGPD) applies, where applicable.

Depending on the processing, swipecor may act as:

  • Controlador; or
  • Operador.

48.1 Rights

Brazilian data subjects may in particular request:

  • confirmation of processing;
  • access;
  • rectification;
  • anonymization;
  • blocking;
  • deletion;
  • data portability;
  • information about recipients;
  • information about the consequences of consent;
  • withdrawal of consent; and
  • review of certain automated decisions.

48.2 Privacy Contact

The privacy contact or Encarregado responsible for Brazil is:

[APPOINT ENCARREGADO/DPO BEFORE BRAZILIAN MARKET LAUNCH]

Until then, inquiries may be sent to info@swipecor.com.

International transfers are carried out in accordance with the requirements of the LGPD and the ANPD. The ANPD has established mechanisms for this purpose, including adequacy decisions and contractual safeguards.

49. Mexico

For persons in Mexico, the Mexican rules on the protection of personal data in the private sector apply, where applicable.

Data subjects may in particular exercise their ARCO rights:

  • Acceso (access);
  • Rectificación (rectification);
  • Cancelación (cancellation); and
  • Oposición (objection).

We also provide information about:

  • the identity of the controller;
  • processing purposes;
  • transfers;
  • options for restriction; and
  • procedures for exercising rights.

International transfers are carried out in accordance with Mexican requirements.

The Mexican rules define ARCO as the rights of access, rectification, deletion or cancellation, and objection, and contain requirements for controllers, processors and cloud providers.

50. Argentina

For persons in Argentina, Law No. 25,326 and supplementary regulations apply in particular, where applicable.

Data subjects may in particular request:

  • access;
  • rectification;
  • updating;
  • deletion; and
  • suppression of unlawfully processed data.

Complaints may be brought before the competent Argentine data protection authority or by way of a habeas data procedure.

Argentine Law No. 25,326 protects personal data in public and private files and databases.

51. Colombia, Peru, Uruguay and Chile

51.1 Colombia

For persons in Colombia, Law 1581 of 2012 and supplementary regulations apply in particular, where applicable.

Data subjects may in particular:

  • learn about their data;
  • update it;
  • correct it;
  • request deletion or withdrawal; and
  • submit complaints to the competent authority.

The Colombian supervisory authority is the Superintendencia de Industria y Comercio.

51.2 Peru

For persons in Peru, Law No. 29733 and its updated implementing regulations apply in particular, where applicable.

Users may in particular exercise rights to:

  • information;
  • access;
  • rectification;
  • deletion; and
  • objection.

The new Peruvian implementing framework has been in force since 31 March 2025. Certain personal data databases may be subject to registration requirements.

51.3 Uruguay

For persons in Uruguay, Law No. 18,331 and supplementary regulations apply, where applicable.

Data subjects may assert their rights against swipecor and, where applicable, before the Unidad Reguladora y de Control de Datos Personales.

51.4 Chile

Until 30 November 2026, the current provisions of Law No. 19,628 apply in particular.

From 1 December 2026, the new framework under Law No. 21,719 must be taken into account. It expands data protection principles, data subject rights, compliance obligations and regulatory supervision.

52. Australia

For Australian users, the Privacy Act and the Australian Privacy Principles apply in particular, where applicable.

We observe in particular:

  • transparent privacy governance;
  • purpose limitation;
  • appropriate collection;
  • use and disclosure;
  • security;
  • accuracy;
  • access;
  • correction; and
  • overseas disclosures.

Australian users may request access and correction and, where applicable, submit a complaint to the Office of the Australian Information Commissioner.

The 13 Australian Privacy Principles govern, among other things, the collection, use, disclosure, security, access and correction of personal information. The official APP Guidelines were last updated in May 2026.

53. New Zealand

For persons in New Zealand, the Privacy Act 2020 applies, where applicable.

We observe in particular the Information Privacy Principles regarding:

  • collection;
  • use;
  • storage;
  • security;
  • access;
  • correction;
  • disclosure; and
  • overseas transfers.

New Zealand users may in particular request access and correction.

International transfers are conducted taking Information Privacy Principle 12 into account.

New Zealand generally requires organizations to appoint a privacy officer. Local responsibility must therefore be definitively determined before an active market launch.

54. Japan

For persons in Japan, the Act on the Protection of Personal Information applies, where applicable.

We provide information in particular about:

  • purposes of use;
  • categories of data processed;
  • disclosures;
  • security measures;
  • cross-border transfers; and
  • contact for inquiries.

Depending on the circumstances, Japanese users may in particular request:

  • disclosure;
  • rectification;
  • supplementation;
  • deletion;
  • cessation of certain processing activities; and
  • cessation of certain disclosures.

The Japanese Personal Information Protection Commission publishes the consolidated legal framework and supplementary rules for international data transfers.

55. Republic of Korea

For persons in South Korea, the Personal Information Protection Act applies, where applicable.

We observe in particular:

  • lawful processing;
  • transparency;
  • purpose limitation;
  • data minimization;
  • security;
  • storage limitation;
  • data subject rights; and
  • special requirements for cross-border transfers.

Depending on the circumstances, Korean users may request in particular:

  • access;
  • rectification;
  • deletion; and
  • cessation of processing.

Before an active market launch, we will assess whether a local representative or domestic agent must be appointed.

The Korean PIPA also applies to foreign companies under certain conditions. The Korean supervisory authority has published specific guidance for this purpose (www.pipc.go.kr).

56. Singapore

For persons in Singapore, the Personal Data Protection Act applies, where applicable.

We observe in particular:

  • accountability;
  • notification;
  • consent;
  • purpose limitation;
  • data minimization;
  • accuracy;
  • security;
  • storage limitation;
  • access;
  • correction; and
  • international transfers.

A responsible Data Protection Officer must be appointed for Singapore before market launch and made publicly accessible.

The Singaporean PDPC describes organizations' statutory obligations when collecting, using and disclosing personal data. In 2026, it also published guidance on the responsible processing of personal data in generative AI.

57. India

For persons in India, the following apply, where applicable and in force, in particular:

  • Digital Personal Data Protection Act 2023;
  • Digital Personal Data Protection Rules 2025; and
  • supplementary IT and intermediary regulations.

Under Indian law, swipecor may act as a Data Fiduciary.

Depending on applicability, Indian users may in particular:

  • receive information;
  • request access;
  • request rectification;
  • request deletion;
  • withdraw consent;
  • submit complaints; and
  • appoint an authorized person.

Consent should be freely given, specific, informed, unambiguous and provided through clear affirmative action. Withdrawal should generally be as easy as giving consent.

India Contact

Before an active market launch, the responsible privacy contact and, where applicable, the Grievance Officer must be appointed:

[APPOINT INDIA PRIVACY CONTACT BEFORE MARKET LAUNCH]

58. Mainland China

For persons in mainland China, the Personal Information Protection Law applies in particular, where applicable.

Chinese law may also apply to foreign organizations if they offer products or services to persons in China or analyze their behavior.

58.1 Special Requirements

Before an active market launch in mainland China, the following will be assessed and implemented in particular:

  • local representation;
  • separate consents;
  • processing of sensitive personal information;
  • cross-border data transfers;
  • standard contracts or other transfer mechanisms;
  • data protection impact assessments;
  • local information obligations;
  • possible data localization; and
  • requirements for algorithms and platform services.

58.2 Separate Consent

Where required by law, separate consent will be obtained, in particular for:

  • certain disclosures;
  • cross-border transfers; and
  • sensitive personal information.

58.3 Local Representative

The following must be appointed before market activation:

[APPOINT CHINA REPRESENTATIVE AND CONTACT BEFORE MARKET LAUNCH]

Under certain conditions, the PIPL applies extraterritorially and expressly requires defined purposes, data minimization and transparency, as well as specific requirements for processing by processors and disclosures.

59. Hong Kong

For persons in Hong Kong, the Personal Data (Privacy) Ordinance applies, where applicable.

We observe in particular the six Data Protection Principles concerning:

  • collection;
  • accuracy;
  • retention;
  • use;
  • security;
  • transparency; and
  • access and correction.

Hong Kong users may in particular request access and correction.

Personal data is not retained for longer than necessary for the relevant purpose.

60. Taiwan

For persons in Taiwan, the Personal Data Protection Act applies, where applicable.

Taiwanese users may in particular:

  • request information;
  • inspect data;
  • request a copy;
  • request supplementation or rectification;
  • request cessation of collection, processing or use; and
  • request deletion.

These rights generally cannot be excluded in advance by contract.

61. Philippines

For persons in the Philippines, the Data Privacy Act of 2012 applies, where applicable.

We observe in particular:

  • transparency;
  • lawful purpose;
  • proportionality;
  • security;
  • data minimization; and
  • data subject rights.

Depending on the circumstances, Filipino users may in particular:

  • receive information;
  • request access;
  • object;
  • request rectification;
  • request deletion or blocking;
  • request data portability; and
  • submit a complaint.

Before an active market launch, local registration and DPO requirements must be assessed.

The National Privacy Commission publishes the Data Privacy Act, its implementing rules and the rights of data subjects.

62. South Africa

For persons in South Africa, the Protection of Personal Information Act (POPIA) applies, where applicable.

swipecor observes in particular the conditions for lawful processing:

  • accountability;
  • processing limitation;
  • purpose specification;
  • limitation of further processing;
  • information quality;
  • openness;
  • security safeguards; and
  • data subject participation.

Before an active market launch, a responsible Information Officer or local privacy contact will be designated and, where required, registered.

POPIA protects the personal information of natural persons and, in part, legal persons, and contains eight conditions for lawful processing.

63. Türkiye

For persons in Türkiye, the Personal Data Protection Law No. 6698 applies, where applicable.

Depending on the circumstances, Turkish users may in particular:

  • learn whether data is processed;
  • request information;
  • learn the purpose;
  • learn the recipients;
  • request rectification;
  • request deletion or destruction;
  • object to certain results of automated analyses; and
  • assert claims for damages.

Before an active market launch, the following will be assessed in particular:

  • information obligations;
  • explicit consent;
  • VERBIS registration;
  • local representative;
  • data processing inventory; and
  • international transfers.

The Turkish data protection authority provides official English translations of the law, information obligations and new transfer mechanisms.

64. United Arab Emirates

For persons in the United Arab Emirates, Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data applies in particular, where applicable.

Depending on the location and structure, additional data protection regimes may apply, in particular:

  • DIFC Data Protection Law;
  • ADGM Data Protection Regulations; and
  • sector-specific regulations.

Before market launch, the following will be assessed in particular:

  • consent;
  • data subject rights;
  • data protection officer;
  • data protection impact assessment;
  • data transfers; and
  • children's and platform rules.

The official platform of the government of the United Arab Emirates lists the Federal Data Protection Law and special legal frameworks such as the DIFC Data Protection Law.

65. Saudi Arabia

For persons in Saudi Arabia, the Personal Data Protection Law applies, where applicable.

We observe in particular:

  • information;
  • lawful processing;
  • consent, where required;
  • purpose limitation;
  • data minimization;
  • security;
  • data subject rights;
  • cross-border transfers; and
  • possible registration or appointment of a data protection officer.

Before an active market launch, the requirements of the Saudi Data & AI Authority and the National Data Governance Platform will be implemented.

The Saudi data protection authority describes the protection of individual personal data, data subject rights and the obligations of controllers.

66. Israel

For persons in Israel, the following apply in particular, where applicable:

  • Privacy Protection Law;
  • Privacy Protection Regulations;
  • Data Security Regulations; and
  • rules for international data transfers.

We observe in particular:

  • lawful processing of databases;
  • security;
  • purpose limitation;
  • access;
  • rectification; and
  • requirements for transfers.

The competent supervisory authority is the Privacy Protection Authority.

67. Other Countries and Territories

If swipecor is available in a country that is not individually named in the regional supplements, the global provisions apply.

In addition:

  • mandatory local data protection law takes precedence;
  • local rights are granted to the extent applicable;
  • required consents are obtained locally;
  • local representatives are appointed before an active market launch where required;
  • local registrations are completed where required;
  • required data localization is implemented; and
  • required language versions are provided.

Until full local compliance has been achieved, swipecor may:

  • restrict certain functions;
  • exclude individual countries from the offering;
  • temporarily close local registrations; or
  • configure data processing differently by region.

68. Global Complaint Option

Users may initially contact the swipecor Privacy Team:

info@swipecor.com, recht@swipecor.com and, for international matters, law@swipecor.com
Subject: Privacy complaint

We document and review privacy complaints within the applicable statutory periods.

Users may also submit a complaint to the data protection authority in their country or region, where such an option exists.

69. Language and Translations

This German version constitutes the master version for legal and technical finalization.

Before an active international market launch, the required translations will be provided.

Translations may not:

  • restrict rights;
  • change processing purposes; or
  • omit material information.

If mandatory local law requires a particular language version, that version is authoritative.

70. Final Provision

This Privacy Notice is supplemented by:

  • Cookie Policy;
  • Consent Management;
  • Subprocessor List;
  • data processing agreements;
  • swAIper AI Transparency Notice;
  • deletion and retention policy;
  • international transfer documentation;
  • Privacy Center; and
  • data breach process.

Data protection at swipecor means:

No hidden data flows.
No uncontrolled use of AI.
No sale of private user data.
No perpetual retention.
No publication without Privacy Approval.
No Privacy Approval – No Release.

swipecor – swipe & go!

Before publication, the data protection officer, the actual cloud, AI, payment, mail, push and analytics providers, all server countries, and any required representatives for the United Kingdom, Switzerland, Brazil, India, China, Korea, Türkiye and other active target markets must still be entered.

The statements made in this Notice — in particular no training of external AI models, deletion from vector databases, the 30- and 90-day periods, and no sale or sharing — must actually be implemented in technical and contractual terms.