Who we are
Shubham Raut, an individual doing business as SwaSec ("SwaSec," "we," "us"), based in Pune, Maharashtra, India, operates the SwaSec at swasec.com.
This policy explains what personal data we collect when you use the tool, why, who we share it with, and what rights you have. Questions or rights requests: hello@swasec.com.
What this covers
This covers the assessment tool itself: the organization profile intake, the questionnaire, the results dashboard, the report email gate, and the Security Posture Card. Cookies are covered separately in our Cookie Policy. General site use is covered by our Terms of Use.
What we collect
Organization profile data
Company name, industry, employee count range, operating regions, whether you develop or deploy AI, current certifications held.
Assessment responses
Your maturity-level answer per question, plus "I don't know" and "Not Applicable" flags.
Session identifier
A token stored in your browser and against your assessment record, so you can resume later.
Report gate data
Work email, full name, job title, and the timestamp of your consent, collected only if you request the detailed report.
Usage and analytics data
Via PostHog (EU Cloud, hosted in Frankfurt, Germany): pages viewed, funnel events, approximate device and browser, approximate location.
Anything you send us directly
Support or feedback correspondence.
We do not currently collect any payment information, since the assessment and report are free. If we introduce paid services, this policy will be updated before any payment data is collected.
Why we use it
- Run the assessment, calculate scores, generate the report and posture card
- Let you resume an in-progress assessment
- Understand drop-off points and improve the tool, at an aggregate level
- Send the report and, only with opt-in consent, follow-up compliance emails
- Follow up personally if you request a consultation
- Produce anonymized, aggregated benchmarking statistics, no individual company is identifiable
- If you start an assessment but do not complete it or request the report, we may use the organization information you provided to research your company and contact you about our services, for up to 6 months. See Section 8 for retention and your right to object at any time.
Legal basis (EU/EEA/UK users)
- Running the assessment and delivering the report: performance of a contract you initiated, or our legitimate interest in providing the service you asked for
- Outreach to organizations with abandoned assessments: legitimate interest, disclosed above, you can object anytime by contacting hello@swasec.com
- Marketing beyond the report itself: your consent, withdrawable anytime
- Analytics: legitimate interest, balanced against your ability to opt out via our cookie banner
International transfers
Supabase stores data in Japan, which the European Commission has formally recognized as providing an adequate level of data protection, so data originating in the EU can move there without additional safeguards. Our analytics provider stores EU visitor data in Frankfurt, Germany, inside the EU, so no international transfer occurs for that data. Our email provider, Resend, is US-based, transfers to the US are covered by their pre-signed Data Processing Agreement, which relies on Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.
How long we keep it
Assessment started, no report requested
Kept up to 6 months. During this period we may use the organization information to research your company and reach out, as described in Section 4. After 6 months, deleted or anonymized.
Report requested (lead data)
Kept until you unsubscribe or ask us to delete it, or automatically after 24 months with no interaction (open, click, or reply) on either side, whichever comes first.
Anonymized aggregate statistics
Kept indefinitely. Once genuinely anonymized, meaning no session ID, IP address, or company name attached, this data no longer identifies anyone and isn't subject to a retention limit.
Security
Encryption in transit and at rest via Supabase, database access restricted by row-level security scoped to session tokens. In the event of a breach affecting personal data, we will notify affected users and the relevant regulator within the timeframe required by applicable law.
Your rights
EU/EEA/UK (GDPR)
Access, correction, deletion, restriction, portability, objection, withdraw consent, complain to your local supervisory authority.
India (DPDP Act, 2023)
Access a summary of your data, correct or erase it, nominate someone to act on your behalf if you die or become incapacitated, file a grievance with us and then with the Data Protection Board of India if unresolved.
California
Ability to know what we hold and request deletion. We don't sell or share personal information for cross-context behavioral advertising.
To exercise any of these, email hello@swasec.com.
Children
Not directed at anyone under 18. We don't knowingly collect their data.
Changes
Posted here with an updated date. Material changes trigger an email to report-gate leads.