Swivel Secure · Secure data intake

Send us your files securely

Three quick steps: verify your email, accept our Data Processing Agreement (DPA), then upload your logs or database. Files are encrypted and only ever accessed by our support team for your case.

1
Verify email
Confirm the address we invited.
2
Accept agreement
Read & accept the DPA.
3
Upload files
Send your logs or database.

Case · invited address

1 · Verify your email

We'll email a 6-digit code to the address your case owner invited. Enter it below to confirm it's you.

2 · Accept the Data Processing Agreement (DPA)

Please read the agreement in full, then confirm the two statements below. This is a one-time acceptance on behalf of your organisation.

Data Processing Agreement

This Data Processing Agreement ("Agreement") forms part of the Terms of Service or other written or electronic agreement between Swivel Secure Limited ("Processor") and the Customer or Partner ("Controller") for the provision of technical support services.

1. Definitions

"Data Protection Laws" means the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and any other applicable data protection legislation. "Personal Data", "Controller", "Processor", "Data Subject", and "Processing" shall have the meanings given to them in the Data Protection Laws. "Portal" means the secure log submission portal provided by the Processor.

2. Subject Matter, Nature, and Purpose of Processing

The Processor shall process Personal Data solely for the purpose of providing technical support, diagnosing system failures, and resolving software bugs related to the Processor's Multi-Factor Authentication (MFA) products. The duration of the processing shall be for the period necessary to resolve the associated support ticket, subject to the retention periods specified in Section 8. The types of Personal Data processed may include IP addresses, usernames, email addresses, and other identifiers inadvertently captured in system logs. The categories of Data Subjects include the Controller's employees, contractors, and end-users (which may include children).

3. Controller Obligations and Warranties

The Controller warrants that it has a valid lawful basis under the Data Protection Laws (e.g., Legitimate Interests) to collect the Personal Data and to transfer it to the Processor for the purposes described herein. Where the Controller is a channel partner acting on behalf of an end-customer, the Controller warrants that it has the necessary contractual authority and lawful basis to share the end-customer's data with the Processor. The Controller agrees to undertake reasonable efforts to sanitise and redact unnecessary Personal Data from log files prior to uploading them to the Portal, in accordance with the principle of data minimisation.

4. Processor Obligations

The Processor shall process Personal Data only on the documented instructions of the Controller, unless required to do otherwise by applicable law. This Agreement and the submission of logs via the Portal constitute the Controller's complete and final instructions. The Processor shall ensure that all personnel authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5. Security Measures

The Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including but not limited to: encryption of Personal Data in transit (using TLS 1.2 or higher) and at rest; Role-Based Access Control (RBAC) ensuring only authorised personnel can access the logs on a least-privilege basis; and regular testing and assessment of the effectiveness of security measures.

6. Sub-processors

The Controller provides general written authorisation for the Processor to engage sub-processors to assist in providing the support services (e.g., cloud hosting providers, contracted developers), in accordance with the Swivel Secure Data Protection Policy. The Processor shall enter into a written agreement with any sub-processor imposing data protection obligations no less protective than those in this Agreement. The Processor remains fully liable to the Controller for the performance of the sub-processor's obligations.

7. Data Subject Rights and Assistance

Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the Data Subject's rights. The Processor shall assist the Controller in ensuring compliance with obligations pursuant to Articles 32 to 36 of the UK GDPR (security, breach notification, and DPIAs). The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data breach affecting the logs. Such incidents will be managed in accordance with the Swivel Secure Incident Response Plan.

8. Deletion and Return of Data

Upon closure of the relevant support ticket, or upon the Controller's request, the Processor shall securely delete all Personal Data contained in the submitted logs within a maximum of 30 days, unless applicable law requires continued storage.

9. Audits and Inspections

The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the UK GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.

Acceptance

By accepting this Agreement, the individual acting on behalf of the Controller confirms that they have read, understood, and accept the terms of this Data Processing Agreement, and that they possess the requisite authority to bind the Controller to these terms.

3 · Upload your files

Drag in a file or browse. Large database exports are supported and resume automatically if a part fails.

Drag & drop your file here
or click to browse — logs and database exports up to 50 GB
0%

Encrypted in transit and at rest · only Swivel Secure support can access your files.