Data Protection & Privacy Page
Protecting your data. Respecting your privacy. Building trust by design.
At Swazzy, protecting personal and business data is fundamental to how we operate. We are committed to handling information responsibly, transparently, and securely, in line with applicable privacy laws and recognised security standards.
This page explains how Swazzy approaches data protection and privacy.
Our Privacy Commitment
Swazzy is committed to:
- Protecting personal and confidential information
- Using data only for legitimate business purposes
- Preventing unauthorised access, misuse, or disclosure
- Being transparent about how data is handled
- Respecting the rights of individuals and customers
Privacy and data protection are embedded into our systems, processes, and culture.
Information We Collect
Depending on our relationship with you, Swazzy may collect:
- Contact information (name, email address, phone number)
- Business information related to service delivery
- System and usage information required to support services
- Limited technical data for security, monitoring, and troubleshooting
We only collect information that is necessary to provide our services or meet legal obligations.
How We Use Information
Swazzy uses information to:
- Deliver and support services
- Communicate with customers and partners
- Maintain security and prevent fraud or misuse
- Meet legal, regulatory, and contractual obligations
- Improve service quality and reliability
We do not sell personal information.
Data Protection & Security Controls
Swazzy protects data through a layered security approach, including:
- Access controls based on least privilege
- Multi-Factor Authentication (MFA) for sensitive access
- Encryption of sensitive data in transit and at rest
- Regular patching and system hardening
- Secure backup and recovery processes
These controls are aligned with ISO/IEC 27001 principles and the ACSC Essential Eight.
Data Retention
Swazzy retains information only for as long as necessary to:
- Provide services
- Meet contractual obligations
- Comply with legal and regulatory requirements
When data is no longer required, it is securely deleted or anonymised.
Third Parties & Data Sharing
Swazzy may share information with trusted third parties only where necessary to deliver services. We:
- Assess suppliers based on security and privacy risk
- Require contractual obligations to protect data
- Limit third-party access to what is necessary
We do not authorise third parties to use data for their own purposes.
Cross-Border Data Handling
Where data is stored or processed outside Australia, Swazzy ensures appropriate safeguards are in place to protect privacy and security in accordance with applicable laws.
Your Privacy Rights
Depending on applicable laws, individuals may have the right to:
- Access personal information held about them
- Request correction of inaccurate information
- Request deletion where permitted by law
- Ask questions about how data is handled
Requests can be made using the contact details below.
Data Breaches
Swazzy maintains processes to identify, respond to, and manage data breaches. Where required, affected customers and individuals are notified in accordance with legal and contractual obligations.
Contact & Privacy Enquiries
If you have questions about privacy or data protection, or wish to make a request, please contact:
Email: privacy@swazzy.co