SWIFT NAVIGATION, INC.
DATA PROCESSING ADDENDUM
Version Date: September 12, 2026
This Data Processing Addendum (“DPA”) is incorporated into and forms part of the Agreement. This DPA applies to Swift’s Processing of Customer Personal Data in connection with the Services.
Customer and Swift are each a “Party” and together the “Parties.”
1. Definitions
“Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with a Party.
“Agreement” means the agreement, order form, statement of work, online terms, or other written or electronic agreement that references this DPA and governs Customer’s access to and use of the Services.
“Applicable Data Protection Laws” means all privacy, data protection, and data security laws and regulations applicable to the Processing of Customer Personal Data under the Agreement, including, as applicable, the GDPR, UK GDPR, Swiss FADP, U.S. State Privacy Laws, and implementing regulations.
“CCPA/CPRA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and its implementing regulations.
“Controller” means the entity that determines the purposes and means of Processing Personal Data, and includes equivalent terms under Applicable Data Protection Laws, including a “Business” under the CCPA/CPRA.
“Customer” means the entity that has entered into the Agreement with Swift.
“Customer Personal Data” means Personal Data that Customer submits or otherwise makes available to Swift, or that is collected or generated through the Services, for Processing on Customer’s behalf under the Agreement.
“Data Subject” means an identified or identifiable natural person to whom Personal Data relates and includes equivalent terms such as “consumer” under U.S. State Privacy Laws.
“Deidentified Data” means data that cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable natural person, household, or device linked to such a person or household, subject to safeguards required by Applicable Data Protection Laws.
“EU SCCs” means the standard contractual clauses for international transfers adopted by the European Commission in Implementing Decision (EU) 2021/914, as amended or replaced.
“GDPR” means Regulation (EU) 2016/679.
“Personal Data” means any information relating to an identified or identifiable natural person, and includes “personal information,” “personal data,” and equivalent terms under Applicable Data Protection Laws.
“Processing” means any operation or set of operations performed on Personal Data, including collection, recording, organization, storage, use, disclosure, transmission, restriction, deletion, or destruction. “Process,” “Processed,” and “Processes” have corresponding meanings.
“Processor” means an entity that Processes Personal Data on behalf of a Controller, and includes equivalent processor, service provider, contractor, or similar roles under Applicable Data Protection Laws, including the CCPA/CPRA.
“Security Incident” means a breach of security that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data Processed by Swift or its Subprocessors. Security Incident does not include unsuccessful attempts or activities that do not compromise Customer Personal Data, including unsuccessful log-in attempts, pings, port scans, denial-of-service attacks, or other network attacks on firewalls or networked systems.
“Sensitive Data” means special categories of Personal Data under the GDPR, sensitive personal information under the CCPA/CPRA, precise geolocation data where regulated as sensitive data, children’s data, protected health information, payment card data, government identification numbers, biometric data, and other data subject to heightened legal protection. For clarity, precise positioning, localization, geolocation, trajectory, telemetry, device, vehicle, diagnostic, usage, and log data processed in connection with the Services are not prohibited solely because they include location-related or operational data, but remain Customer Personal Data to the extent they identify or relate to an identifiable individual.
“Service Operations Data” means telemetry, diagnostic, usage, performance, security, log, and operational data generated by or relating to the Services that Swift uses to provide, secure, support, monitor, troubleshoot, analyze, or improve the Services.
“Services” means Swift’s precise positioning products, correction services, cloud services, software, APIs, support, and related services provided under the Agreement.
“Subprocessor” means any third party engaged by Swift or its Affiliates to Process Customer Personal Data on Customer’s behalf in connection with the Services.
“Swift” means Swift Navigation, Inc. and, where applicable, its Affiliates that Process Customer Personal Data.
“Swiss FADP” means the Swiss Federal Act on Data Protection, as amended or replaced.
“Transfer Risk Assessment” means an assessment of whether Customer Personal Data transferred internationally receives protection required by Applicable Data Protection Laws.
“UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner’s Office under section 119A of the UK Data Protection Act 2018, as amended or replaced.
“UK GDPR” means Regulation (EU) 2016/679 as it forms part of UK domestic law, as amended.
“U.S. State Privacy Laws” means U.S. state privacy laws applicable to the Processing of Customer Personal Data, including the CCPA/CPRA and similar state consumer privacy laws.
2. Roles and Scope
(a) Roles. Customer acts as a Controller or Processor of Customer Personal Data, and Swift acts as a Processor or subprocessor on Customer’s behalf. Each Party’s role for a particular Processing activity is determined by Applicable Data Protection Laws. If Customer acts as a Processor, Customer will ensure that its instructions to Swift, including Swift’s appointment, are authorized by the relevant Controller.
(b) Customer Responsibilities. Customer is responsible for determining whether the Services are appropriate for Customer’s intended Processing and for providing all notices and obtaining all rights, permissions, consents, and lawful bases required for Customer to use the Services and provide Customer Personal Data to Swift, including any required notices and consents for location data and access to information on end-user devices.
(c) Instructions. Swift will Process Customer Personal Data only on Customer’s documented instructions, including with regard to international transfers, except where otherwise required by applicable law, subject to Sections 12 and 14. For Customer Personal Data subject to the GDPR, the exception for legally required Processing applies only where Union or Member State law to which Swift is subject requires that Processing. For Customer Personal Data subject to the UK GDPR, this exception applies only where UK domestic law requires the Processing. Swift will inform Customer of that legal requirement before Processing unless the law prohibits such notice on important grounds of public interest. The Agreement, this DPA, applicable orders, and Customer’s configuration and use of the Services constitute Customer’s documented instructions to provide, secure, support, maintain, monitor, troubleshoot, improve, and document the Services. The Parties may agree on additional documented instructions. Swift will promptly inform Customer if, in Swift’s opinion, an instruction infringes Applicable Data Protection Laws.
3. Processing Details
The subject matter, duration, nature, purpose, categories of Personal Data, and categories of Data Subjects are described in Annex A. Customer acknowledges that precise positioning services may involve location, device, telemetry, diagnostic, and network data depending on Customer’s configuration and use of the Services. Location records may be Processed as necessary to provide, secure, and support the Services, including investigating and resolving support requests and troubleshooting service issues. Swift’s use of location records for product development is limited to Deidentified Data in accordance with Section 11.
4. Customer Obligations
- Customer will use the Services in compliance with Applicable Data Protection Laws and the Agreement.
- Customer will not submit Sensitive Data to the Services unless the Agreement expressly permits such data and the Parties have agreed on any required additional safeguards; provided that the Services may process precise positioning, localization, geolocation, trajectory, telemetry, device, vehicle, diagnostic, usage, and log data and account credentials used to authenticate access to the Services, as described in Annex A, when Customer configures or uses the Services for those purposes. Customer is responsible for ensuring that its configuration and use of the Services comply with Applicable Data Protection Laws for any Sensitive Data it submits or generates through the Services.
- Customer is responsible for the accuracy, quality, and legality of Customer Personal Data and the means by which Customer acquired Customer Personal Data. Customer is responsible for securing the systems it controls and safeguarding its account credentials and configuration of the Services. Swift is responsible for implementing the measures in Annex B for the systems it controls.
5. Swift Obligations
- Swift will keep Customer Personal Data confidential and require personnel authorized to Process Customer Personal Data to be subject to confidentiality obligations.
- Swift will limit access to Customer Personal Data to personnel and Subprocessors with a business need to know for purposes permitted under this DPA.
- Swift will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data as described in Annex B.
- Swift will not sell Customer Personal Data, as “sell” is defined under applicable U.S. State Privacy Laws, or share Customer Personal Data for cross-context behavioral advertising, as “share” is defined under the CCPA/CPRA.
- Subject to Section 2, Swift will not retain, use, or disclose Customer Personal Data except for the business purposes described in this DPA and the Agreement, as reasonably necessary to perform the Services, or as otherwise permitted by Applicable Data Protection Laws.
- Swift will not combine Customer Personal Data with Personal Data received from another source except as permitted for a Processor under Applicable Data Protection Laws, including for security, fraud prevention, debugging, internal service operations, or other permitted business purposes.
6. Assistance
(a) Required Assistance. Taking into account the nature of the Processing and information available to Swift, Swift will provide the assistance required by Applicable Data Protection Laws for Customer’s compliance, including assistance through appropriate technical and organizational measures, insofar as possible, for responding to Data Subject requests, and assistance with security, breach notification, data protection impact assessments, Transfer Risk Assessments, and consultations with supervisory authorities. Swift will also provide assistance required under applicable U.S. State Privacy Laws with Customer’s risk assessments and cybersecurity audits.
(b) Costs. To the extent legally permitted, Customer will be responsible for Swift’s reasonable costs for assistance that is not required due to Swift’s breach of this DPA. Cost allocation will not limit Swift’s obligations under Applicable Data Protection Laws.
(c) Direct Requests. If Swift receives a request from a Data Subject relating to Customer Personal Data, Swift will not respond to the request except on Customer’s documented instructions, to redirect the Data Subject to Customer, to confirm that the request relates to Customer, or as legally required. Swift will notify Customer of the request where legally permitted and will provide the assistance required by Applicable Data Protection Laws if Customer cannot fulfill the request through the Services or its own systems.
7. Security Incidents
Swift will notify Customer without undue delay after becoming aware of a Security Incident and within any timeframe required by Applicable Data Protection Laws, unless prohibited by law. Swift’s notification will include information reasonably available to Swift that Customer reasonably requires to meet its legal obligations, such as the nature of the Security Incident, affected data categories, likely consequences, and measures taken or proposed to address the Security Incident. Swift will provide additional relevant information as it becomes reasonably available and will take reasonable steps to investigate, contain, and remediate the Security Incident. Swift’s notification of or response to a Security Incident is not an acknowledgement of fault or liability.
8. Subprocessors
(a) Authorization and Obligations. Customer grants Swift general written authorization to engage the Subprocessors identified in the current list described in Annex C. Swift will keep that list current and available to Customer, identifying each Subprocessor’s name, address and contact details, Processing activities, and Processing countries. Swift will bind each Subprocessor by a written agreement imposing the same data protection obligations as this DPA to the extent applicable to its services. Swift remains responsible for its Subprocessors as required by Applicable Data Protection Laws and the applicable transfer terms in Section 12.
(b) Changes. Swift will notify Customer in writing of any intended addition or replacement at least ten (10) business days before authorizing the proposed Subprocessor to Process Customer Personal Data. The notice will include the information necessary for Customer to exercise its right to object. Customer may object on reasonable data protection grounds by giving written notice within ten (10) business days after Swift’s notice.
(c) Objections and Termination. Swift will not authorize the proposed Subprocessor to Process the affected Customer Personal Data while a timely objection on reasonable data protection grounds remains unresolved. If Swift cannot reasonably resolve the objection, Swift may terminate only the affected Services that cannot reasonably be provided without that Subprocessor.
9. Audits and Information
(a) Information and Audits. Swift will make available to Customer all information necessary to demonstrate compliance with its obligations under this DPA and Applicable Data Protection Laws relating to the Processing. Swift may initially provide existing reports, certifications, or other relevant documentation. To the extent required by Applicable Data Protection Laws or the applicable transfer terms in Section 12, Swift will allow and contribute to audits, including inspections, by Customer or an independent auditor appointed by Customer that is not a competitor of Swift.
(b) Procedures. Audits will be limited to once annually, on reasonable prior notice, during normal business hours, and subject to appropriate confidentiality obligations, unless Applicable Data Protection Laws or the applicable transfer terms in Section 12 require otherwise. Audits must not unreasonably disrupt Swift’s operations and must protect security, confidentiality, legal privilege, and other customers’ data.
(c) Costs and Required Rights. Customer will bear its own audit costs. Customer will reimburse Swift for reasonable costs of supporting an audit unless the audit identifies a material breach of this DPA by Swift. The procedures and charges in this Section will not prevent an effective audit or limit rights or obligations under Applicable Data Protection Laws or the applicable transfer terms in Section 12.
10. Return and Deletion
(a) Return or Deletion. At the end of the Services involving Processing, Swift will, at Customer’s choice, return or delete all Customer Personal Data Processed on Customer’s behalf and delete existing copies. Unless Customer requests return, Swift will delete the data. Swift will certify deletion to Customer where required by Applicable Data Protection Laws or the applicable transfer terms in Section 12.
(b) Required Retention. Swift may retain data only to the extent and for as long as applicable law requires. For data subject to the GDPR, this exception applies only where Union or Member State law requires storage, subject to Section 12. For Customer Personal Data subject to the UK GDPR, this exception applies only where UK domestic law requires storage, subject to Section 12. Retained data remains protected under this DPA and may be Processed only for the purpose requiring retention.
(c) Backups. Subject to Applicable Data Protection Laws and Section 12, where immediate deletion from backups is not technically practicable, Swift will protect the data from further use pending deletion under its documented backup-retention schedule. If a backup is restored, Swift will reapply deletion before further use of the affected data. Swift will complete deletion as soon as reasonably practicable and within any mandatory period.
11. Deidentified, Aggregated, and Service Operations Data
(a) Service Operations Data. Swift may use Service Operations Data to provide, secure, support, maintain, monitor, troubleshoot, analyze, develop, and improve the Services, subject to Section 3. Swift will Process any Customer Personal Data within Service Operations Data only in accordance with Customer’s documented instructions, this DPA, and Applicable Data Protection Laws.
(b) Creating and Using Deidentified Data. If Swift elects to create Deidentified Data under this Section 11, Customer instructs Swift to Process Customer Personal Data for that purpose, including through aggregation, in accordance with Applicable Data Protection Laws. Swift may use the resulting data for lawful business purposes only if it meets the applicable legal requirements for deidentified or anonymous data.
(c) Safeguards. For Deidentified Data created under this Section 11, Swift will take reasonable measures to prevent association with an identified or identifiable individual or household. Swift will maintain and use Deidentified Data in deidentified form and will not attempt to reidentify it, except solely to test the effectiveness of deidentification where permitted by Applicable Data Protection Laws. Swift will publicly commit to these restrictions. Swift will contractually require recipients of Deidentified Data to comply with these requirements.
(d) Data That Remains Personal Data. Data that remains Personal Data under Applicable Data Protection Laws remains subject to this DPA, including when aggregated or pseudonymized.
12. International Transfers
(a) EU Transfers. To the extent a transfer of Customer Personal Data to Swift requires safeguards under Chapter V of the GDPR and is not covered by an applicable adequacy decision, the Parties enter into and incorporate by reference the EU SCCs. Module Two (Controller to Processor) applies where Customer is a Controller, and Module Three (Processor to Processor) applies where Customer is a Processor. The Parties’ entry into the Agreement constitutes their signature of the applicable EU SCCs and Annex I.A as of that date.
(b) SCC Selections. The following selections apply to the EU SCCs:
| SCC Clause | Selection |
| Clause 7 | Optional docking applies. |
| Clause 9 | Option 2 (general written authorization) applies, with the advance notice period in Section 8. |
| Clause 11 | The optional language is not selected. |
| Clause 17 | Irish law governs unless the Agreement specifies another EU Member State law that allows third-party beneficiary rights. |
| Clause 18 | The courts of Ireland have jurisdiction unless the Agreement specifies the courts of another EU Member State. |
(c) SCC Annexes. The SCC annexes are completed as follows:
| SCC Annex | Information Completing the Annex |
| Annex I.A | The party, role, activity, and contact information in the Agreement and Annex A of this DPA. |
| Annex I.B | The Processing details in Annex A. |
| Annex I.C | The competent supervisory authority identified under Annex A. |
| Annex II | The technical and organizational measures in Annex B. |
Annex C and Swift’s current Subprocessor list identify the authorized Subprocessors for Clause 9.
(d) Transfer Safeguards. The Parties will comply with their obligations under the applicable EU SCCs, including assessment of the transfer and any necessary supplementary safeguards.
(e) UK Transfers. To the extent a transfer of Customer Personal Data to Swift requires safeguards under Chapter V of the UK GDPR and is not covered by applicable UK adequacy regulations, the Parties incorporate the UK Addendum. Tables 1 through 3 of the UK Addendum are completed by the information in the Agreement, this DPA, the EU SCC selections above, Annex A, Annex B, Annex C, and Swift’s current Subprocessor list. For Table 4, both Parties may end the UK Addendum subject to the conditions in Section 19 of the UK Addendum.
(f) Swiss Transfers. To the extent a transfer of Customer Personal Data to Swift requires safeguards under the Swiss FADP and is not covered by an applicable adequacy decision under the Swiss FADP, the EU SCCs apply using the module, selections, and annex information specified in Sections 12(a) through (c), with the following adaptations for purposes of the Swiss FADP:
- References to the GDPR and its provisions mean the Swiss FADP and its corresponding provisions.
- The Federal Data Protection and Information Commissioner is the competent supervisory authority under Clause 13 and Annex I.C.
- Clause 18(c) permits Data Subjects habitually resident in Switzerland to bring proceedings in Switzerland.
Where the GDPR also applies to a transfer, the unmodified EU SCCs continue to apply for purposes of the GDPR, including the competent supervisory authority identified in Annex A. The governing law and forum for disputes between the Parties remain as selected under Section 12(b).
13. U.S. State Privacy Laws
(a) Role and Permitted Purposes. For Customer Personal Data subject to U.S. State Privacy Laws, Swift acts as a Processor, including as a service provider or contractor under the CCPA/CPRA, as applicable. Customer discloses Customer Personal Data to Swift only for the limited and specified business purposes described in Sections 2 and 3 and Annex A.
(b) Restrictions on Use. Swift will not sell Customer Personal Data, as “sell” is defined under applicable U.S. State Privacy Laws, or share Customer Personal Data for cross-context behavioral advertising, as “share” is defined under the CCPA/CPRA. Swift will not retain, use, or disclose Customer Personal Data for any purpose other than the specified business purposes, outside the direct business relationship between the Parties, or combine it with Personal Data from other sources, except as permitted for a Processor by Applicable Data Protection Laws.
(c) Compliance and Notice. Swift will comply with applicable U.S. State Privacy Laws and their implementing regulations, including providing the same level of privacy protection required of businesses by the CCPA/CPRA for Customer Personal Data subject to that law. To the extent Swift acts as a contractor under the CCPA/CPRA, Swift certifies that it understands and will comply with the restrictions applicable to that role under this Section 13. For Customer Personal Data subject to the CCPA/CPRA, Swift will notify Customer if Swift determines that it can no longer meet its obligations under the CCPA/CPRA.
(d) Customer Oversight and Requests. For Customer Personal Data subject to the CCPA/CPRA, Customer may take reasonable and appropriate steps to help ensure Swift uses that Customer Personal Data consistently with Customer’s obligations under the CCPA/CPRA and, upon notice, to stop and remediate unauthorized use. The procedures in Section 9 apply without limiting Customer’s rights under Applicable Data Protection Laws. Swift will cooperate with Customer in responding to requests from Data Subjects as required by applicable U.S. State Privacy Laws and Section 6.
14. Government and Legal Requests
If Swift receives a legally binding request from a governmental or regulatory authority for Customer Personal Data, Swift will notify Customer and provide related assistance to the extent required by Applicable Data Protection Laws or the applicable transfer terms in Section 12. Swift will disclose only the Customer Personal Data it reasonably believes is legally required.
15. Order of Precedence
If there is a conflict between this DPA and the Agreement, this DPA controls with respect to Customer Personal Data. If there is a conflict between this DPA and the applicable transfer terms in Section 12, those transfer terms control to the extent of the conflict. The liability limitations and exclusions in the Agreement apply to this DPA except to the extent prohibited by the applicable transfer terms in Section 12 or Applicable Data Protection Laws.
ANNEX A: DETAILS OF PROCESSING
| Subject matter | Swift’s Processing of Customer Personal Data in connection with Customer’s access to and use of the Services. |
| Duration | The term of the Agreement and any period thereafter during which Swift Processes Customer Personal Data in accordance with Section 10. |
| Nature and purpose | Providing, configuring, authenticating, securing, supporting, maintaining, monitoring, troubleshooting, improving, and documenting precise positioning products and services, including correction services, cloud services, software, APIs, account administration, support, diagnostics, billing, and service communications, in accordance with Sections 2, 3, and 11. |
| Data subjects | Customer personnel and authorized users; Customer’s contractors, agents, and representatives; end users or operators of Customer applications, devices, vehicles, equipment, or systems that interact with the Services; individuals whose Personal Data Customer submits to or generates through the Services. |
| Categories of Personal Data | Business contact information; account credentials and identifiers; user and organization identifiers; IP addresses and network metadata; device, receiver, vehicle, equipment, application, and API identifiers; precise positioning, localization, geolocation, trajectory, telemetry, correction, diagnostic, event, usage, and log data; support ticket content; billing and order administration data; other Personal Data submitted by Customer to the Services. |
| Sensitive Data | Precise positioning, localization, geolocation, trajectory, telemetry, device, vehicle, diagnostic, usage, and log data may be processed through the Services and may constitute Sensitive Data under certain Applicable Data Protection Laws when linked or linkable to an identifiable individual. Account credentials used to authenticate access to the Services may also be processed, subject to the safeguards in Annex B. No other Sensitive Data is intended. Customer must not submit other Sensitive Data unless expressly authorized in the Agreement and subject to any required additional safeguards. |
| Frequency of transfer | Continuous or as initiated by Customer, its users, devices, applications, or systems through the Services. |
| Retention | For no longer than necessary for the permitted Processing purposes, taking into account the Services, Customer’s documented instructions, and applicable legal requirements. Post-termination retention and backup deletion are governed by Section 10. |
| Competent supervisory authority | For purposes of the EU SCCs, the competent supervisory authority is determined under Clause 13. Where Customer is established in the European Economic Area (EEA), it is the authority competent to supervise Customer’s compliance with the GDPR, including the lead supervisory authority where applicable. Where Customer is not established in the EEA but is subject to the GDPR, it is the authority for the Member State where Customer’s Article 27 representative is established or, if Customer is exempt from appointing a representative, an authority for a Member State where the affected Data Subjects are located. Where more than one authority could be designated under Clause 13, the Parties will identify the applicable authority in a written record forming part of this Annex before the transfer. |
| SCC parties and contacts | For Annex I.A to the EU SCCs, Customer is the data exporter and Swift Navigation, Inc. is the data importer unless the Agreement identifies another participating Swift entity. Customer’s role is Controller or Processor, and Swift’s role is Processor, as described in Section 2. The activities relevant to the transfer are Customer’s use of the Services and Swift’s provision of the Services under the Agreement. Each Party’s address, contact details, and authorized contact person are as set forth in the Agreement, applicable order form, or other notice/contact information exchanged between the Parties. If Customer uses a Swift online ordering or website flow, Customer’s contact is the account, billing, privacy, or legal contact provided by Customer, and Swift’s contact is the notice, privacy, or legal contact identified by Swift for the Services or in the Agreement. Signature and date are established as provided in Section 12. |
ANNEX B: TECHNICAL AND ORGANIZATIONAL MEASURES
- Security governance: Swift maintains written information security policies, assigns security responsibilities, and periodically reviews security controls appropriate to the nature of the Services.
- Access controls: Swift uses role-based access controls, least-privilege principles, authentication controls, and access review processes designed to limit access to Customer Personal Data.
- Encryption: Swift uses encryption or comparable protective measures for Customer Personal Data in transit over public networks and at rest where appropriate to the Services and risk.
- Network and system security: Swift maintains controls designed to protect systems against unauthorized access, including network segmentation, vulnerability management, patching, endpoint protections, and secure configuration practices.
- Logging and monitoring: Swift maintains logging, monitoring, and alerting designed to detect, investigate, and respond to security events affecting the Services.
- Data segregation: Swift implements logical segregation controls designed to prevent unauthorized access to Customer Personal Data of other customers.
- Secure development: Swift maintains secure development practices appropriate to the Services, including code review, change management, vulnerability remediation, and testing practices.
- Personnel security: Swift requires confidentiality commitments and provides privacy and security awareness or role-based training for personnel with access to Customer Personal Data.
- Incident response: Swift maintains incident response procedures for identifying, investigating, escalating, mitigating, and notifying affected customers of Security Incidents.
- Business continuity: Swift maintains backup, disaster recovery, and business continuity practices designed to support the availability and resilience of the Services.
- Subprocessor management: Swift assesses and contracts with Subprocessors using data protection and security obligations appropriate to the nature of the Processing.
- Deletion and disposal: Swift maintains procedures for deletion, retention, and disposal of Customer Personal Data in accordance with the Agreement and Swift retention practices.
- Data Subject request assistance: Customer may submit requests for assistance through the support or notice contact identified in the Agreement and provide the information reasonably needed to identify the relevant data and requested action. Swift will verify that the requester is authorized by Customer and limit access to personnel who need it to fulfill the request. Using available service functionality or controlled support procedures, Swift will locate relevant Customer Personal Data and assist with access, correction, restriction, export, or deletion as required by Section 6, taking into account the nature of the Processing. Customer is responsible for verifying the Data Subject’s identity and determining the response unless applicable law requires Swift to act directly. Requests received directly by Swift will be handled under Section 6. For security and assessment assistance, Swift will provide relevant security information under Section 9 and explanations reasonably necessary for the assistance required by Section 6.
ANNEX C: SUBPROCESSORS
Swift’s Subprocessors may include cloud infrastructure providers, hosting providers, content delivery and network security providers, monitoring and logging providers, customer support tools, identity/authentication providers, professional services providers, and other vendors used to provide, secure, support, maintain, or improve the Services. Swift’s current Subprocessor list, made available under Section 8, forms part of this Annex C and identifies each Subprocessor’s name, address and contact details, the Processing entrusted to it, and the countries in which it Processes Customer Personal Data. The categories in this Annex do not replace that list.









