Skip to content
PosSwift

Data processing agreement

Last updated: 2 August 2026

If you use PosSwift and personal data of your own customers or staff is involved, you are the controller of that data and we may act as a processor. This page sets out the terms on which we do that, and how to get a signed copy.

When this applies

PosSwift is offline-first. The customer records, sales, and invoices you create in the application are stored on your device and are not transmitted to us. In the ordinary course, we process no personal data on your behalf at all.

This agreement matters for the narrow cases where we do: licence administration, support sessions where you send us information, and any optional service you switch on that involves sending data to us.

If you need a counter-signed DPA for your own compliance file — common for larger organisations and public-sector buyers — email contact@posswift.com with your legal entity name and address and we will send one for signature.

Roles

  • You are the controller. You decide what personal data enters PosSwift, why, and for how long it is kept.
  • PosSwift is the processor for data you route to us. We act only on your documented instructions.
  • For our own billing records, account data, and website analytics, PosSwift is the controller — that is covered by our privacy policy, not by this agreement.

Our obligations

  • Process personal data only on your documented instructions, including for international transfers, unless we are legally required to do otherwise — in which case we will tell you before processing, where the law permits.
  • Ensure everyone authorised to process the data is bound by an appropriate duty of confidentiality.
  • Implement appropriate technical and organisational security measures, described below.
  • Not engage another processor without your general written authorisation, and impose equivalent obligations on any we do engage.
  • Assist you in responding to requests from individuals exercising their rights.
  • Assist you with security, breach notification, and impact assessments, taking into account the information available to us.
  • Delete or return the personal data at the end of the engagement, at your choice, unless retention is legally required.
  • Make available the information needed to demonstrate compliance, and allow and contribute to audits on reasonable notice.

Security measures

  • Encryption of personal data in transit over public networks.
  • Access control on a need-to-know basis, with individual accounts and no shared credentials for production systems.
  • Cryptographic signing and verification of licence tokens.
  • Data minimisation as a design rule — operational data stays on your device precisely so that it cannot be exposed by a breach of ours.
  • Logging and monitoring of access to systems that hold personal data.
  • Regular review of the above as the product changes.

Sub-processors

We use a small set of sub-processors for hosting, transactional email, payment processing, error monitoring, product analytics, and customer relationship management. Each is bound by written terms no less protective than these.

You may request the current list at any time. We will give you notice of any intended addition or replacement, and a reasonable opportunity to object.

International transfers

Where personal data is transferred to a country other than the one it was collected in, we rely on a lawful transfer mechanism — typically standard contractual clauses, or the provider's own certified transfer framework. We will identify the mechanism in the signed agreement.

Breach notification

If we become aware of a personal data breach affecting data we process for you, we will notify you without undue delay and in any event within 72 hours of becoming aware. The notice will describe the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken.

Duration and deletion

This agreement lasts as long as we process personal data on your behalf. On termination, we will delete or return that data at your choice within 30 days, except where we are required by law to keep it — for example, billing records retained for tax purposes.

Requesting a signed copy

Email contact@posswift.com with your legal entity name, registered address, and the name and title of the signatory. We aim to return a counter-signed copy within one business day.

◂ Back to home