SwiftRegistry Privacy Notice
How Red Swift Systems Ltd handles personal data in connection with SwiftRegistry.
| Operator | Red Swift Systems Ltd |
|---|---|
| Company number | 14891467 |
| Registered office | 2nd Floor College House, 17 King Edwards Road, Ruislip, London HA4 7AE, United Kingdom |
| Draft date | 17 August 2026 |
DRAFT FOR LEGAL REVIEW. Before publication: confirm the privacy mailbox is monitored; confirm the Clever Cloud data-processing terms are in force for Red Swift Systems Ltd and document the selected London/Ionos processing chain; and resolve the immutable evidence-chain deletion issue.
This notice explains how Red Swift Systems Ltd handles personal data when people visit, sign in to or administer SwiftRegistry, and explains our role when customers use SwiftRegistry to maintain a company's register of members.
1. Who we are
SwiftRegistry is operated by Red Swift Systems Ltd, registered in England and Wales under company number 14891467, with its registered office at 2nd Floor College House, 17 King Edwards Road, Ruislip, London HA4 7AE, United Kingdom.
Privacy questions may be sent to privacy@redswift.systems.
ICO registration reference: ZC223017.
2. Our different data-protection roles
2.1 For information about people who use or administer SwiftRegistry - for example names, work email addresses, account roles, sign-in security data and service relationship information - Red Swift Systems Ltd is an independent controller.
2.2 For personal data contained in a Client Company's register of members, share certificates, transfers, allotments, rectifications and related records, Red Swift Systems Ltd normally acts as a processor or sub-processor. The relevant Client Company, and in some arrangements the professional practice acting for it, determines why the statutory record is kept and is responsible for the lawful basis, transparency and responses to data-subject requests.
2.3 If you are a shareholder or former shareholder whose information is held in a register on SwiftRegistry, the privacy notice of the relevant company or professional practice is the primary notice governing that processing. If you contact us, we will help identify or contact the relevant controller where reasonably possible.
3. Personal data we hold about SwiftRegistry users
Name and email address.
A hashed representation of the account password. We do not store the password in plain text.
IP address and browser user-agent information recorded as part of sign-in session data.
Organisation or practice membership, role and the Client Companies the user is permitted to access.
Session token and session expiry information needed to keep a signed-in user authenticated.
OAuth-related fields exist in the authentication system but OAuth login is not currently used.
4. Why we use user and account data
| Purpose | Data | Typical lawful basis |
|---|---|---|
| Provide and administer accounts and organisation access | Name, email, account role, organisation membership and access grants | Legitimate interests in providing and administering a business service; contract where the individual is personally party to the contract. |
| Authenticate users and maintain sessions | Hashed password, session token, expiry, IP address and user-agent | Legitimate interests in providing secure authenticated access and preventing misuse. |
| Security, incident investigation and abuse prevention | Session and access information | Legitimate interests in protecting the Service, customers and records. |
| Meet legal, regulatory and dispute obligations | Relevant account, access and audit information | Legal obligation where applicable; otherwise legitimate interests in establishing, exercising or defending legal claims. |
5. Data contained in Client Company registers
Where customers use SwiftRegistry to maintain a register of members, the system may process:
A member's forename and surname, or corporate name, and details of joint holders.
The address recorded in the register of members. For an individual, this may be a home address.
Dates of registration and cessation as a member.
Shares held or formerly held, share certificates and related allotments and transfers.
Rectification and correction history relating to the statutory record.
This information is supplied by or on behalf of the relevant company or its professional adviser. Red Swift Systems Ltd does not ordinarily collect it directly from the shareholder.
The relevant controller is responsible for deciding the lawful basis for this processing and for providing privacy information required by law, including the transparency requirements that apply where information is obtained indirectly.
6. The evidence chain and correction model
6.1 Statutory events committed in SwiftRegistry are also written to an append-only evidence chain. For a member-registration event, the event statement currently contains the member's name and address.
6.2 The database is deliberately designed to reject ordinary deletion or truncation of evidence-chain entries. This means a committed entry is not silently removed from history.
6.3 Where a committed entry is inaccurate, the Service records a correction or rectification linked to the original entry rather than overwriting the original. This preserves the fact that a mistake existed and how it was corrected.
LEGAL / ARCHITECTURAL BLOCKER: selective erasure of personal data already written into the evidence chain is not currently technically possible. The right to erasure is not absolute, but the current design also affects processor end-of-contract deletion obligations. This point requires resolution before the Service stores live shareholder personal data.
7. What we do not do
We do not sell personal data.
We do not use personal data for behavioural advertising.
We do not profile shareholders or website visitors for marketing purposes.
There is currently no analytics, tag manager, session recording or third-party advertising script on the site.
A signed-out visitor currently receives no cookies from SwiftRegistry.
8. Certificate verification and cryptographic anchoring
8.1 Share certificates may contain a verification link or QR code that allows a person holding the certificate to check that the corresponding recorded event remains intact.
8.2 The verification response is designed not to disclose the register, shareholder names, addresses or holdings.
8.3 For timestamp anchoring, the Service sends a cryptographic commitment or digest to OpenTimestamps calendar infrastructure. It does not send the underlying name, address, holding or certificate record. A digest is used to attest to the existence of the commitment without publishing the record itself.
9. Who receives personal data
Clever Cloud SAS provides application and database infrastructure. The SwiftRegistry application and its PostgreSQL database are deployed in Clever Cloud's London availability zone, which runs on Ionos infrastructure in the United Kingdom. Clever Cloud SAS is established in France.
OpenTimestamps calendar infrastructure receives cryptographic commitment data used for timestamp anchoring, not the underlying register content.
GitHub is used for source code and is not intended to receive production personal data.
No document-extraction or AI provider is currently used to process Client Company documents. If such a feature is introduced, this notice and the relevant data-processing terms will be updated before it is used for live personal data.
10. International transfers
Clever Cloud SAS is established in France, and the SwiftRegistry application and database are hosted in Clever Cloud's London availability zone on Ionos infrastructure in the United Kingdom. The United Kingdom treats the EEA, including France, as adequate for UK data-transfer purposes, so this hosting route itself does not require an additional restricted-transfer safeguard.
Clever Cloud publishes a list of downstream processors, currently version 1.5 dated 5 November 2025. For the London region that list identifies Ionos in the United Kingdom, and it records that the data centre is chosen by the customer when an application is set up rather than selected by Clever Cloud. The same list names providers in the United States, including Twilio and Pipedrive, for Clever Cloud's own telephone support and customer-relationship management. Those providers do not host the register. If SwiftRegistry personal data were made available to a recipient in a country not covered by UK adequacy regulations, Red Swift Systems Ltd would put an appropriate UK transfer mechanism and any required additional safeguards in place before that processing began.
We keep Clever Cloud's sub-processor arrangements under review. Before production use with live Customer Personal Data, Red Swift Systems Ltd must confirm that the Clever Cloud data-processing terms are contractually in force for its account and that the resulting processor chain satisfies the UK GDPR.
11. How long data is kept
| Category | Current retention |
|---|---|
| Register-of-members entries | While the person remains a member and, for former members, for the statutory retention period applicable to the company, including the ten-year period referred to in section 121 of the Companies Act 2006. |
| Certificates, allotments, transfers and rectifications | For as long as the relevant company records are maintained in the Service, subject to the Customer's legal obligations and the immutable-chain limitation described above. |
| Evidence-chain entries | Currently permanent by technical design; they cannot be selectively deleted through the system. |
| Sign-in sessions | Until expiry, currently seven days. |
| User accounts | Until deleted. There is currently no self-service account-deletion flow. |
| Draft registers | A draft may be discarded before it is opened because draft statutory events have not yet been committed to the Client Company's evidence chain. |
12. Your rights
Depending on the circumstances and our role, UK data-protection law may give you rights of access, rectification, erasure, restriction, objection and data portability, and rights relating to certain automated decisions.
These rights are not absolute. In particular, erasure may not apply where continued processing is required by law or another statutory exception applies.
If your request concerns a Client Company's register, we will normally refer the request to the relevant controller and assist that controller as required by our data-processing agreement.
If your request concerns your SwiftRegistry user account or Red Swift Systems Ltd's own processing, contact privacy@redswift.systems.
You also have the right to complain to the Information Commissioner's Office (ICO).
13. Cookies
SwiftRegistry currently uses one strictly necessary authentication cookie when a user signs in. See the Cookie Notice for details.
14. Changes to this notice
We may update this notice when the Service, our suppliers or the law changes. The current version will show its last-updated date. Where a change materially affects how we use personal data, we will take reasonable steps to bring it to the attention of affected users or customers.
Last updated: 17 August 2026.