Compliance Details
Last updated: · Reviewed quarterly
GDPR Compliance: Be More Swan acts in two roles under UK GDPR / EU GDPR, as most business software does. For the business data you put into your workspace — your content, your contacts, and the data we read from the accounts you connect — we are a Data Processor, handling it on your instructions and for no other purpose. For your own account, login and billing data, and for running and securing the platform itself, we are a Data Controller. A Data Processing Agreement covering the processor role is presented to you in-product when you set up your organisation, and your acceptance is recorded; you can re-read it any time from your account settings. If you need a countersigned copy for your own records, use the request form below. Our full Privacy Policy is available at /privacy.html. For erasure requests, please email hello@bemoreswan.com.
Data Residency
Your primary workspace data is stored in the United Kingdom / European Economic Area — our
managed PostgreSQL database sits in an EU region, video rendering runs in AWS eu-west-2 (London),
and Netlify serves the application through UK/EU edge nodes. Uploaded and generated media is held in
Cloudflare R2 object storage, which is globally distributed rather than pinned to a single region.
Being straight with you: some processing does happen in the United States, because the AI model
providers, our payment processor and our transactional email provider are US-based. Every one of those transfers
runs under adequate safeguards as required by UK GDPR Article 46 — Standard Contractual Clauses, or the UK–US Data
Privacy Framework in Stripe's case — supported by a documented Transfer Impact Assessment and minimisation of the
data sent to model APIs. The table below names each provider and where it sits.
Sub-Processors
Be More Swan uses the following third-party sub-processors to deliver its services. Each is assessed for GDPR compliance before we adopt it, and we rely on the provider's data processing terms for every transfer of personal data. Where a row is marked "copy on request", email us and we will send the current agreement. Several are used only if you choose to connect that service.
| Sub-Processor | Purpose | Location | DPA / Security |
|---|---|---|---|
| Anthropic | AI language model inference — the primary model behind your assistants' drafting, chat and review | USA (SCCs applied) | anthropic.com/legal/privacy |
| OpenAI | Content moderation screening and product tour narration | USA (SCCs applied) | openai.com/enterprise-privacy |
| Voyage AI | Embedding of knowledge-base content so assistants can search it | USA (SCCs applied) | Copy on request |
| fal.ai | AI image and video generation from your prompts | USA (SCCs applied) | Copy on request |
| Stripe | Payment processing & billing | USA / UK (SCCs applied) | stripe.com/gb/privacy |
| Resend | Transactional email delivery | USA (SCCs applied) | resend.com/legal/privacy-policy |
| Netlify | Hosting, serverless functions, CDN | USA / EU edge nodes | netlify.com/gdpr-ccpa |
| Neon | Managed PostgreSQL — where your workspace data is stored | EU (eu-west) — no US transfer for stored data | Copy on request |
| Cloudflare | R2 object storage — uploaded files and generated media | Global distributed network | cloudflare.com/trust-hub/gdpr |
| Amazon Web Services | Lambda video rendering for post and Short overlays | UK (eu-west-2, London) | aws.amazon.com/compliance/gdpr-center |
| Twilio SendGrid | Inbound email parsing — turns mail sent to us into support and CRM records | USA (SCCs applied) | twilio.com/legal/privacy |
| Serper | Web search for outbound lead discovery | USA (SCCs applied) | Copy on request |
| Only where you connect a Google account — Search Console metrics, Drive and calendar data, and sending from your own inbox | USA / global (SCCs applied) | cloud.google.com/terms/dpa | |
| Canva | Only where you connect Canva — importing your designs as post media | Australia / global (SCCs applied) | canva.com/policies/privacy-policy |
| Pexels | Stock photo and video search — receives search terms, not your workspace data | Germany (EU) | pexels.com/privacy-policy |
Encryption Standards
- ✓In transit: All data is encrypted in transit using TLS 1.3. Older cipher suites are disabled.
- ✓At rest: All database storage is encrypted at rest using AES-256 via the managed database provider's native encryption.
- ✓OAuth credentials & API keys: Stored with AES-256-GCM application-layer encryption. Plaintext credentials are never logged or returned to clients.
Penetration Testing
Be More Swan undergoes regular security assessments. Our last penetration test was conducted in Q2 2026. A summary report is available on request to enterprise customers — please email hello@bemoreswan.com with the subject "Security Report Request".
Data Retention
- ✓Active accounts: Data is retained for the duration of your subscription.
- ✓After account deletion: Personal data is permanently deleted within 30 days of account closure. An anonymised erasure record is retained for compliance purposes.
- ✓Archived assistants: Kept for 14 days so you can reinstate them, then permanently deleted with their associated data.
- ✓Rejected and abandoned content: Rejected posts, unused generated media and incomplete setups are automatically cleared after 30 days.
- ✓Integration API call logs: Retained for 90 days, then automatically purged.
- ✓Audit records: Audit logs, DPA acceptances and erasure records are append-only and immutable — the database revokes UPDATE and DELETE on them and a trigger blocks any attempt, so they cannot be altered or removed by anyone, including us. This is deliberate: they are the evidence that the other rules above were followed.
Request a Data Processing Agreement
Enterprise customers and partners may request a signed DPA for their records. Complete the form below and we'll respond within 2 business days.
Happy with how we handle your data?
Pick a plan and hire your first assistant. Rolling monthly — cancel any time.