Legal & Compliance
Please read these documents carefully. They govern your use of the SwiftFund platform.
Privacy Policy & GDPR Compliance
Introduction and Regulatory Baseline
SwiftFund is resolutely committed to safeguarding your personal and financial data. This Global Privacy Policy details our exhaustive protocols for data collection, processing, storage, and cross-border transfer. Regardless of your global jurisdiction, SwiftFund operates on a strict baseline of the General Data Protection Regulation (GDPR) (EU) 2016/679. By engaging with our financial infrastructure, you consent to the data practices defined herein.
Categories of Data Processed
We systematically collect and process specific data categories to fulfil our regulatory obligations and execute our underwriting processes:
- Biometric and Identity Data: Government-issued identification documents and facial recognition geometry processed securely via our verified third-party partner, Stripe Identity, strictly for Know Your Customer (KYC) compliance.
- Financial and Cash-Flow Data: Read-only transaction histories, account balances, and payment metadata accessed continuously through licenced Account Information Service Providers (AISPs) via Open Banking integrations.
- Technical and Telemetry Data: IP addresses, device fingerprinting, browser types, and session geolocation data utilised strictly for fraud prevention and network security.
Open Banking Continuous Consent
By initiating an application, you grant explicit, ongoing consent for SwiftFund to access your designated bank accounts on a strictly read-only basis. We cannot initiate outgoing transfers or alter your banking credentials. This consent remains active for the duration of your loan term or Pro Membership.
Data Retention and AML Statutory Overrides
Under GDPR, users possess the "Right to be Forgotten" (data erasure). However, you legally acknowledge that this right is not absolute in the financial sector. SwiftFund is mandated by international Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) regulations to retain all transactional ledgers, KYC verification documents, and signed loan agreements for a statutory minimum period of five (5) to seven (7) years following the closure of an account. Requests for data erasure that conflict with these statutory AML retention mandates will be unequivocally denied.
Cross-Border Data Transfer Protocols
Given our distributed operational footprint, your data may be transferred to and stored in jurisdictions outside the European Economic Area (EEA). SwiftFund ensures all such transfers are strictly governed by Standard Contractual Clauses (SCCs) approved by the European Commission, guaranteeing that your data maintains GDPR-equivalent protections regardless of its physical server location.