Skip to main content

GDPR, Security, and EU Data Hosting

Written by Bee Keeper

We work with a number of customers that handle European contact data, including regulated financial services organizations, and have built The Swarm accordingly over the last five years!

  • We fully support GDPR compliance and provide a Data Processing Agreement (DPA) for customers that require one.

  • We restrict access to customer data using role-based permissions and audited internal controls. Your data on your Swarm team/workspace is never shared with others!

  • We're currently undergoing a SOC 2 Type II audit through Vanta and have implemented the policies, controls, monitoring, access management, incident response, and security processes required for certification. See trust.theswarm.com

  • Our infrastructure is hosted on AWS, and we offer EU data hosting in Ireland for customers with European data residency requirements.

  • We maintain documented backup, disaster recovery, and breach notification procedures, including an RPO of less than 15 minutes and an RTO of less than 1 hour for critical systems.

  • We maintain a 'Do Not Sell' process and honor all applicable privacy rights requests in <24h.

Regarding importing European contacts specifically, many of our customers include contacts located in the EU. As long as your organization has "legitimate interest" (or consent where applicable), importing those contacts into The Swarm is totally fine (it's the same reason it's ok in any standard CRM like HubSpot or Salesforce!).

Did this answer your question?