SwiftLabs Solutions

English courtesy translation. In case of any discrepancy the German version is the binding one.

Legal

Privacy policy

This website works without cookies, without tracking and without external fonts. What is processed anyway is set out here - and below it, what applies in client projects.

Last updated: 3 September 2026

01

Controller

SwiftLabs UG (haftungsbeschränkt), Schanzenstraße 19, 90478 Nürnberg, Deutschland. Email: kontakt@swiftlabs.studio

SwiftLabs Solutions is a line of business of SwiftLabs UG. The provider details are in the legal notice.

02

Principle

This website is a static information site. It embeds no tracking or analytics services and loads no content from third-party servers - fonts and images sit on our own hosting. That is why there is no consent banner here.

One exception is the appointment booking on our contact page. It runs on a server we operate ourselves and is described in section 05.

Your choice between light and dark appearance is stored locally in your browser only, never leaves your device and never reaches us.

03

Server logs

When the website is called up, our host Hostinger International Ltd. (Jonavos g. 60C, 44192 Kaunas, Lithuania), as a processor under Art. 28 GDPR, processes technically necessary access data - IP address, time, page requested, user agent - in server log files. The legal basis is Art. 6(1)(f) GDPR, our legitimate interest in secure and stable operation. The log files are deleted after a short period unless they are exceptionally needed to investigate a specific security incident.

04

Contact form and email

If you write to us through the form or by email, we process the data you provide - name, email address, company and your message - solely to handle your enquiry. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures), otherwise Art. 6(1)(f) GDPR.

The form message is sent via the service Resend (Resend, Inc., USA) on the basis of standard contractual clauses. We store enquiries for as long as handling them requires, at most 12 months, unless statutory retention obligations apply.

We run our mailboxes on Microsoft 365 (Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland) as a processor under Art. 28 GDPR. Your message and our reply are held there for as long as handling and the statutory retention periods require.

The form asks for nothing that is not needed for a reply. Please do not send us special categories of personal data under Art. 9 GDPR through it.

05

Appointment booking

On our contact page you can book a conversation directly. For that we embed an appointment booking that we operate ourselves. No third-party script is loaded.

We process the details you enter into the booking form - name, email address, chosen time, time zone and an optional message - together with the technically necessary access data of the server. The legal basis is Art. 6(1)(b) GDPR. Confirmation and reminder emails are sent via the service Resend (Resend, Inc., USA) on the basis of standard contractual clauses.

The server the booking runs on is provided for us by Hetzner Online GmbH (Industriestrasse 25, 91710 Gunzenhausen, Germany) as a processor under Art. 28 GDPR; it is located in their data centre in Helsinki, Finland. We delete booking data once the appointment has been handled and the enquiry is closed, at the latest after 12 months.

06

Contract handling

If a contract comes about, we process the data required to perform it - contact and invoicing data, order and contract data, and the documents and access you provide for the project. The collaboration runs directly by email, phone and invoice; we operate no online client area. We invoice directly and use no payment service provider for this.

As processors under Art. 28 GDPR we use: Resend (Resend, Inc., USA) for transactional email, Microsoft 365 (Microsoft Ireland Operations Limited, Ireland) for our mailboxes, and Hetzner Online GmbH (Industriestrasse 25, 91710 Gunzenhausen, Germany; data centre Helsinki, Finland) for the server the appointment booking in section 05 runs on.

The legal basis is performance of the contract under Art. 6(1)(b) GDPR. We store contract data for the duration of the contract plus the statutory retention periods - in particular commercial and tax periods of up to ten years for invoicing and accounting records. After that the data is deleted or anonymised unless statutory obligations prevent it.

07

Marketing approaches to businesses

We approach companies for which working together may be of interest. We do not collect the details used for this from you, but from publicly accessible sources: trade and map directories, public company registers and the companies own websites. We process company name, address, business telephone number and email address, the website address and publicly named contacts.

The purpose is initiating a business relationship. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is direct marketing towards businesses. If we make contact, we inform you about this processing and about the source of the data at that point at the latest (Art. 14 GDPR).

The approach is made for us by self-employed commercial agents who work solely on our instructions and solely in the systems we provide; their own contact lists, local copies and private mailboxes are contractually prohibited. Your data is not passed on to third parties for marketing purposes.

You may object to processing for marketing purposes at any time (Art. 21(2) GDPR), informally by email to kontakt@swiftlabs.studio. We will then no longer process your data for that purpose; in order to honour the objection permanently, we keep the details needed for that on a suppression list. Without an objection, we delete prospect data once there has been no contact for 24 months and no contract has come about.

08

AI services in client projects

When we build a system for you that processes personal data, we become your processor to that extent. The basis is a data processing agreement under Art. 28 GDPR, concluded before processing begins and naming the sub-processors individually.

Which models are used, where they are operated and what a provider may do with the transmitted data is decided and documented per project - not stated in blanket form on this page. A fixed list of providers here would simply be wrong for most projects. For processing outside the EU we agree standard contractual clauses; where that does not hold, we build on services within the EU or on models we operate ourselves.

What that means in practice - exclusion from training, provider retention periods, logging, deletion policy - is set out in detail under AI and data protection.

09

Your rights

Under the GDPR you have the right to information, rectification, erasure, restriction of processing and data portability, as well as the right to object to processing based on legitimate interests (Art. 21(1) GDPR). Where your objection is directed at direct marketing, it applies unconditionally (Art. 21(2) GDPR). No automated decision-making, including profiling, takes place on this website.

You may also lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 27, 91522 Ansbach, Germany. An informal email to kontakt@swiftlabs.studio is enough for a request to us.