Legal

Privacy Policy

Version 1.0. Last updated 9 August 2026.

This Privacy Policy explains how SQUAREZONE SOFTWARE PUBLISHING LLC-FZ, operating Swarmhit from Dubai, United Arab Emirates, collects, uses, discloses, and protects personal data in connection with Swarmhit’s websites, SaaS platform, APIs, infrastructure, integrations, professional data features, and related services.

1. Who this Policy covers

This Policy applies to:

  • visitors to Swarmhit websites;
  • prospects, Customers, Account owners, Authorized Users, and support contacts;
  • individuals whose professional data appears in discovery, enrichment, or contact features;
  • individuals whose data a Customer uploads or processes through Swarmhit;
  • recipients of outreach sent by Customers using Swarmhit;
  • developers and end users interacting with Swarmhit APIs, infrastructure, embedded, or white-label functionality.

2. Our roles

Swarmhit may have different data protection roles depending on the processing.

Swarmhit acts as a controller or business for personal data used to manage Accounts, billing, security, fraud prevention, support, product analytics, marketing, legal compliance, and certain business contact discovery or enrichment services.

Swarmhit generally acts as a processor or service provider when it hosts or processes Customer prospect lists, campaign data, messages, replies, and other Customer Content on Customer’s instructions. In that situation, Customer is responsible for the processing and the Data Processing Addendum applies.

If you received outreach from a Swarmhit Customer, that Customer normally determines why and how you were contacted. You should direct your request or objection to the sender. You may also contact us, and we will take reasonable steps to identify or notify the relevant Customer where appropriate.

3. Personal data we collect

Depending on how Swarmhit is used, we may collect the following categories.

3.1 Account and identity data

Name, business email, company, job title, profile image, user ID, login information, organization membership, account permissions, country, and verification information.

3.2 Billing and transaction data

Billing contact, billing address, subscription, invoices, payment status, tax information, transaction references, and limited payment method information. Full payment card details are generally processed by payment providers rather than stored by Swarmhit.

3.3 Connected Account data

Connected Account identifiers, public profile information, authentication or session tokens, connection status, network information, messages, replies, invitations, campaign activity, and other data needed to provide enabled features.

3.4 Customer Content and outreach data

Prospect lists, names, professional contact details, profile URLs, companies, job titles, segmentation data, notes, tags, campaign settings, message content, replies, prompts, workflow instructions, and analytics.

3.5 Professional discovery and enrichment data

Business and professional information such as name, job title, employer, company details, professional email, professional profile URL, location, industry, seniority, and other professional attributes. This data may come from public sources, licensed partners, Customers, integrations, or third-party data providers.

3.6 Usage, device, and log data

IP address, browser, device, operating system, timestamps, pages and features used, clicks, referring pages, API calls, webhook events, diagnostic data, crash data, approximate location derived from IP, and security logs.

3.7 Communications and support data

Emails, chat messages, call notes, support tickets, survey responses, demo information, feedback, and other communications with Swarmhit.

3.8 Cookie and marketing data

Cookie identifiers, consent choices, campaign attribution, website interactions, and marketing preferences, as further described in the Cookie Policy.

We do not intend the Services to be used for unnecessary special-category or highly sensitive personal data. Customers must avoid uploading such data unless it is lawful, necessary, and expressly supported by the Services.

4. How we obtain personal data

We obtain personal data:

  • directly from users, Customers, and people who contact us;
  • from Connected Accounts and integrations authorized by a Customer;
  • from Customer uploads, API calls, agents, workflows, and downstream applications;
  • from public professional sources and company websites;
  • from licensed data, enrichment, verification, infrastructure, and integration providers;
  • automatically through cookies, logs, and use of the Services;
  • from partners, referrals, and publicly available business sources.

5. Why we process personal data

We process personal data to:

  • create, authenticate, administer, and secure Accounts;
  • provide outreach, campaign, inbox, API, infrastructure, discovery, enrichment, analytics, and support features;
  • connect and maintain Connected Accounts and execute Customer-configured actions;
  • process subscriptions, usage, payments, invoices, and credits;
  • respond to demos, questions, support requests, and service communications;
  • detect fraud, abuse, spam, security threats, platform instability, and violations of our policies;
  • enforce rate limits, safeguards, technical rules, and contractual rights;
  • analyze and improve reliability, usability, performance, and product features;
  • develop new features using aggregated, de-identified, or appropriately protected data;
  • send product updates and marketing communications where permitted;
  • comply with law, respond to legal requests, establish or defend claims, and protect rights and safety;
  • provide business contact discovery and enrichment features and process related privacy requests.

6. Legal bases

Where applicable law requires a legal basis, we rely on one or more of the following:

  • performance of a contract or steps requested before entering a contract;
  • compliance with legal and regulatory obligations;
  • legitimate interests, including operating and securing a B2B SaaS and infrastructure service, preventing abuse, supporting Customers, improving products, and providing professional discovery or enrichment, where those interests are not overridden by individual rights;
  • consent, including for certain cookies, marketing, integrations, or optional features;
  • establishment, exercise, or defense of legal claims;
  • another basis recognized by applicable law.

Where processing relies on consent, consent may be withdrawn at any time without affecting prior lawful processing.

7. Customer-directed outreach

Customers control their campaign recipients, message content, timing, purpose, and legal basis. Swarmhit processes recipient and campaign data to execute Customer instructions, maintain the Services, prevent abuse, and meet legal obligations.

Swarmhit does not treat the availability of professional data as proof that an individual consented to outreach. Customers must independently comply with privacy, direct marketing, anti-spam, platform, and consumer protection requirements.

8. How we disclose personal data

We may disclose personal data to:

  • cloud hosting, storage, security, logging, proxy, and infrastructure providers;
  • payment, billing, tax, and fraud prevention providers;
  • communication, customer support, analytics, CRM, scheduling, and marketing providers;
  • AI, data, enrichment, verification, and integration providers used to supply enabled features;
  • professional advisers, auditors, insurers, and legal counsel;
  • affiliates, contractors, and personnel who need access to provide the Services;
  • third-party platforms and Connected Accounts at Customer’s direction;
  • authorities, courts, law enforcement, or regulators when disclosure is required or reasonably necessary to protect rights, safety, and security;
  • a buyer, investor, lender, or successor in a merger, financing, reorganization, or sale, subject to appropriate confidentiality protections.

Service providers are permitted to process personal data only for agreed purposes and subject to contractual or legal safeguards appropriate to their role.

9. Business contact data and opt-out rights

Swarmhit may provide access to business contact and company data as part of paid discovery, enrichment, database, or infrastructure features. Depending on the applicable law, making professional data available for value may be treated as a sale, sharing, or another regulated disclosure even when the data is used for B2B purposes.

Individuals may request access, correction, deletion, suppression, or an opt-out from future provision of their professional data by contacting contact@swarmhit.com. We may need information to verify identity and locate the relevant record.

Where legally required and technically supported, we will also process recognized browser-based opt-out signals, such as Global Privacy Control, for the browser or device sending the signal.

10. International transfers

Swarmhit operates from the United Arab Emirates and uses service providers and infrastructure in multiple countries. Personal data may therefore be processed outside the country where it was collected.

Where required, we use recognized transfer mechanisms and safeguards, which may include adequacy decisions, standard contractual clauses, the UK International Data Transfer Addendum, contractual commitments, consent, or another lawful transfer mechanism.

11. Data retention

We retain personal data for as long as reasonably necessary to provide the Services, maintain Accounts, comply with law, resolve disputes, enforce agreements, prevent fraud and abuse, and meet legitimate business needs.

Retention depends on the data and context. For example:

  • Account, subscription, and billing records may be retained for the relationship and applicable legal, tax, and accounting periods;
  • Customer Content is generally retained while the Account is active and for a limited period after termination to support export, recovery, security, and backup cycles;
  • Connected Account authentication data is retained while needed to maintain the connection and is removed or rendered unusable after disconnection or termination within a commercially reasonable period;
  • security, API, and activity logs are retained for a limited period appropriate to security, diagnostics, and abuse prevention;
  • suppression and opt-out records may be retained to ensure that requests continue to be honored;
  • professional data may be retained while it remains relevant, lawful, and subject to correction, deletion, or opt-out rights.

We may retain information longer where required by law, a legal hold, investigation, or dispute. When data is no longer needed, we delete, aggregate, de-identify, or restrict it.

12. Security

Swarmhit uses technical and organizational measures designed to protect personal data, including access controls, encryption in transit, authentication controls, logging, monitoring, backup processes, incident response procedures, and supplier oversight where appropriate.

No system is completely secure. Customers are responsible for securing their Accounts, Authorized Users, API keys, devices, Connected Accounts, and downstream applications.

13. Privacy rights

Depending on location and applicable law, an individual may have the right to:

  • receive information about processing;
  • access personal data;
  • correct inaccurate or incomplete data;
  • request deletion;
  • restrict, stop, or object to processing;
  • withdraw consent;
  • receive or transfer certain data in a portable format;
  • object to direct marketing;
  • opt out of certain sales, sharing, profiling, or targeted advertising;
  • request review of certain automated decisions;
  • lodge a complaint with a competent data protection authority;
  • receive equal service and not be discriminated against for exercising privacy rights.

Requests may be sent to contact@swarmhit.com. We may verify identity and authority before responding. Authorized agents may submit requests where permitted by law. Some rights are subject to exceptions, including legal retention, security, freedom of expression, third-party rights, and the establishment or defense of claims.

14. California disclosures

California residents may have rights to know, access, correct, delete, and receive information about categories of personal information collected, sources, purposes, and recipients. They may also have the right to opt out of sale or sharing and to limit certain uses of sensitive personal information.

Swarmhit does not use sensitive personal information to infer characteristics about individuals. As described in Section 9, certain paid professional data features may be treated as a sale or sharing under some laws. California residents may submit an opt-out request through contact@swarmhit.com or a supported browser preference signal.

15. Marketing communications

Users may unsubscribe from marketing emails through the link in the message or by contacting us. Service, billing, security, and legal communications are not marketing and may continue while relevant.

16. Cookies

Swarmhit uses cookies and similar technologies for essential functions, preferences, analytics, security, and, where enabled with required consent, marketing. More information appears in the Cookie Policy.

17. Children

The Services are intended for business users and are not directed to children under 18. Swarmhit does not knowingly collect children’s personal data through the Services. If you believe a child provided personal data, contact us.

18. Third-party links and services

The Services may link to or integrate with third-party services. Their privacy practices are governed by their own policies. Swarmhit is not responsible for independent third-party processing.

19. Changes to this Policy

We may update this Policy to reflect changes in the Services, law, or practices. The current version will show the last-updated date. We will provide additional notice of material changes where required.

20. Contact

Privacy questions and requests may be sent to contact@swarmhit.com.

Stop building the execution layer.
Start shipping outreach.

Get an API key in minutes, or launch your first campaign in the app. Same engine either way.