Privacy Policy
GDPR · Regulation (EU) 2016/679
1.1 Data Controller
SwiftCodeBase is the data controller for personal data processed through this website and our client engagement workflows. Registered office: Elisabeth-Feller-Weg 28, 12205 Berlin, Germany. Privacy enquiries: [email protected].
1.2 Categories of Data We Process
We collect and process the following categories of personal data when you use our site or engage our services:
- Identity data — full name, company name, role/title.
- Contact data — business email address, telephone number, postal address.
- Project data — architecture briefs, budgets, timelines, and technical requirements you submit.
- Technical data — IP address, browser type, device identifiers, pages viewed, referral source (via essential analytics).
- Contract data — statements of work, invoices, payment references, correspondence.
1.3 Purposes and Legal Bases
- Contract performance (Art. 6(1)(b) GDPR) — to respond to inquiries, prepare proposals, deliver contracted engineering work, and manage billing.
- Legitimate interests (Art. 6(1)(f) GDPR) — to secure our systems, improve service quality, and maintain professional correspondence with prospective and current clients.
- Legal obligation (Art. 6(1)(c) GDPR) — to retain records required under German commercial and tax law.
- Consent (Art. 6(1)(a) GDPR) — only where you have explicitly opted in (e.g., optional marketing messages). You may withdraw consent at any time.
1.4 Retention
Inquiry data is retained for up to 24 months after last contact unless a contract is executed. Contract, invoice, and tax records are retained for the statutory periods required under German law (typically 6–10 years). Technical logs are rotated on a short cycle not exceeding 12 months unless needed for security investigation.
1.5 Recipients and Processors
We do not sell personal data. Data may be shared with tightly controlled processors — including hosting providers within the European Union/EEA, email infrastructure providers, payment processors (Stripe), and professional advisors (legal, accounting) — each bound by data processing agreements that meet GDPR requirements.
1.6 International Transfers
Where processing involves transfers outside the EU/EEA, we rely on Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms, and we apply supplementary technical safeguards appropriate to the sensitivity of the data.
1.7 Your Rights
Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data; to object to processing based on legitimate interests; and to withdraw consent where processing is consent-based. You may also lodge a complaint with a supervisory authority, including the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).
To exercise any right, contact [email protected] from the address associated with your request. We respond within one month of receipt, extendable for complex requests in accordance with GDPR timelines.
1.8 Security
We implement technical and organizational measures — including encryption in transit (TLS), access control, least-privilege administration, and encrypted backups — designed to protect personal data against unauthorized access, alteration, disclosure, or destruction.