Skip to content

What we do with data

This page is for two kinds of people: customers who want to know what they are installing, and visitors of a site that uses us who want to know what is recorded about them. The answer is the same for both, so it is here once.

What we recognise

We establish which company visited a website, not which person. We do that by looking up the visitor's network address in a map of Dutch business networks that we build ourselves from public sources: the RIPE registry, the mail settings companies publish in their DNS, and what we learn from submitted forms.

For every recognition we keep how certain it is and where it came from. That is not an extra but a required column in our data model: a recognition without provenance does not exist with us.

What we record about a visit

The network address, encrypted and not reversible. The pages viewed and for how long. The type of browser. The page someone came from. Nothing more.

The network address is encrypted within a second of arrival with a key only we hold. The unencrypted address is only needed to look up the company and is deleted within an hour.

What we do not do

Nothing on your device. No cookie, no storage, no fingerprint of your browser. Our script writes nothing to and reads nothing from your device. That is why no consent is needed and it can run before a cookie banner. You are not followed from one site to the next either, because there is nothing you carry along.

One exception, and it needs your yes. A customer can switch on “also recognise on the phone and later”. Only after you accept marketing cookies in that site's cookie banner does our script set one cookie (sw_v) on that site, valid for six months and usable by that one customer only. If you say no or withdraw later, the cookie is deleted together with everything we had attached to it.

No recognising people. We do not know and do not try to find out who sits behind the screen. There is one exception, and it is below.

No made-up email addresses. Some providers guess an address from the pattern within a company domain. We only show addresses a company published itself, and we say on which page we found them.

The exception: a link in an email

A customer of ours can use links with a code in them in their own email campaign. If the recipient clicks one, that customer knows it was them. That is not a trick: it concerns someone they sent an email to themselves, and the link only exists because that person clicked it themselves.

The link never contains an email address, only a signed code that only we can read. Here too nothing is written to the device; the code comes along in the link and is removed from the address bar straight away.

After such a click, that customer remembers for thirty days that the encrypted network address belongs to that company, so a next visit from the same address is recognised too. That memory belongs to that one customer, is not shared, never touches your device, does not apply to phones or shared networks, and the customer can switch it off.

What we learn from forms

If someone fills in a form on a customer's site with a business email address, we derive from it which company sits behind that network. We then use that knowledge for other customers too, and that is how recognition gets better every month.

What ends up in the shared map is only the part after the at sign. The address itself and the name never enter that map and are never used for another customer.

The customer whose form it is can see the person themselves: name and business email address then go into their own contact list, just like the contacts they upload. That is on by default and the customer can switch it off. An address at an ordinary email provider never comes in, not even for that customer.

Nothing is learned until the same company domain has been entered twice from the same network, at least an hour apart, and no other company enters from that same network. Addresses at ordinary email providers never yield anything. A customer can switch this off for their own site.

How long it is kept

  • Pages viewed: 90 days.
  • Visits: 12 months.
  • Unencrypted network addresses: at most one hour.
  • What we learned from forms: the observation, 12 months.
  • What a customer remembers about a network address after a click or form: 30 days.
  • The cookie after consent: 6 months, or until you withdraw it.
  • Counts without a company or visitor in them: those stay.

These are not intentions. The cleanup runs automatically in the database every night.

Who else sees it

Everything about visitors is in Europe: the database in Frankfurt, the servers that process it in Frankfurt, and the email we send goes through Ireland.

Two tools are outside Europe, and it is more honest to say so than to hide it. To find contacts we fetch public pages of company websites, and to make something of them we use a language model. Both services are in the United States.

What goes there: the content of public web pages, and per recognised company the name, which pages were viewed and how often. The latter is needed to write the sentence our customer sees on their screen. What does not go there is a network address, a name, an email address or anything else that leads to a person.

On our own website and in the product we measure, through Vercel, how fast pages load and which pages are visited. That too happens without a cookie and without storage on your device, and without a visitor being identifiable: one irreversible code is made per day from address and browser, and it is thrown away afterwards.

swungby.com also runs our own script, with exactly the same line our customers put on their site. Everything above therefore applies to a visit to this website too: we see which company came by, not who, and we write nothing to your device.

Not wanting to be recognised

A company that does not want to appear in this system can opt out, without an account and without emailing us: swungby.com/afmelden. One button, works immediately, and whatever was already there about that company is deleted. That page is in Dutch.

If you want to exclude a whole domain instead of a network, or have a question about data that could be about you, email privacy@swungby.com.

Why this is allowed

Establishing which company visits a business website is done on the basis of legitimate interest. It concerns company information, not people, and nothing is written to the visitor's device. For the exception above, where someone clicks a link in an email from our customer, the basis is the existing relationship between that customer and that recipient.

If anything above changes, this page changes with it. We put nothing here that we do not do, and we do nothing that is not here.