Legal
Privacy Policy
Last updated: 20 July 2026
1. Who we are
This Privacy Policy explains how dataswap - Data layer for AI agents ("Dataswap", "we", "us"), collects and processes personal data when you use the Dataswap API and dashboard (the "Service"). For the purposes of the EU/UK General Data Protection Regulation (GDPR), Dataswap is the data controller of the account and usage data described below.
The controller is dataswap.io, Rua do Bairro, 4715-163 Braga, Portugal, VAT PT268119465.
For any privacy question, or to exercise your rights, contact our privacy team at privacy@dataswap.io.
2. Data we collect
- Account data — the name and email address you provide at sign-up, a securely hashed password, and account status (e.g. activation).
- Usage and logs — API requests you make (endpoint, timestamps, credits used, request ids), rate-limit counters, and technical metadata such as IP address and user agent, used for billing, security and abuse prevention.
- Query content — the parameters you send to the API (for example search terms or target domains), which we process to fulfil your request and may cache transiently to serve and price it.
- Payment data — purchases are handled by Stripe. We do not store full card numbers; we retain a customer reference and transaction metadata needed for billing and accounting.
- Communications — messages you send us (e.g. support email) and email delivery events.
3. How and why we use data
We process personal data to:
- provide, operate and secure the Service, and authenticate your requests;
- meter and bill credit usage, and prevent fraud and abuse;
- send transactional email (activation, password reset, receipts, service notices);
- provide support and respond to your requests;
- comply with legal, accounting and tax obligations.
Our legal bases under GDPR are: performance of a contract (providing the Service you signed up for), legitimate interests (security, abuse prevention, product improvement), legal obligation (accounting and tax), and consent where required (e.g. optional marketing email, which you can withdraw at any time).
4. Sub-processors and sharing
We do not sell personal data. We share it only with vendors that process it on our behalf, under contract, to run the Service:
- Upstream data providers — API query parameters are sent to our upstream data providers to fulfil requests.
- Stripe — payment processing and billing.
- Mandrill / Mailchimp — delivery of transactional and (where applicable) marketing email.
- Hosting & infrastructure — our cloud infrastructure provider, which hosts the Service and stores data on our behalf.
We may also disclose data where required by law, to protect our rights, or in connection with a corporate transaction. A current list of sub-processors is available on request.
5. International transfers
Some of our sub-processors are located outside your country, including outside the European Economic Area. Where personal data is transferred internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision. You can request more detail at privacy@dataswap.io.
6. Data retention
We keep account data for as long as your account is active and as needed to provide the Service. Billing records are kept for as long as required by applicable accounting and tax law (typically up to 10 years). Cached query results are short-lived and expire automatically.
Each API call produces a usage record — the operation, credits spent, status and latency. That record is part of your billing history and is kept for the life of the account.
Alongside it we store, for 30 days, two things that let you inspect a call in your dashboard: the IP address the request came from and the arguments you sent (truncated). After 30 days both are erased; the usage record itself remains, because it is proof of what you were billed for.
We do not store the responses we return to you. If you need to correlate a result with a call, every response carries a request_id that appears in your activity history.
7. Your rights
Subject to applicable law, you have the right to:
- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- erase your data ("right to be forgotten"), where applicable;
- restrict or object to certain processing;
- data portability — receive your data in a structured, machine-readable format;
- withdraw consent at any time, where processing is based on consent.
You also have the right to lodge a complaint with a data protection supervisory authority. In Portugal that is the Comissão Nacional de Proteção de Dados (CNPD); you may also complain to the authority where you live or work.
To exercise any of these rights, email privacy@dataswap.io. We will respond within the timeframe required by law. You also have the right to lodge a complaint with your local supervisory authority (in the EU) or the Portuguese data protection authority (CNPD).
8. Security
We use technical and organisational measures to protect personal data, including encryption in transit, hashed passwords and API-key secrets, scoped access controls, and audit logging. No method of transmission or storage is perfectly secure; if we become aware of a breach affecting your data, we will notify you and the relevant authorities as required by law.
10. Children
The Service is intended for businesses and professional users and is not directed to children. We do not knowingly collect personal data from anyone under the age of 16.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the date above and, where appropriate, notify you. Please review this page periodically.