Privacy Policy
This page is maintained by Apex Flow Technology Ltd to explain how SwiftInvoicePro handles personal data, and to set out the rights available to you under the UK GDPR and EU GDPR.
Last updated: 19 July 2026
Controller: Apex Flow Technology Ltd
Company number: 17347345 (registered in England & Wales)
Registered office: 29 Railway Road, Rhoose, Barry, Wales, CF62 3FE
For any question about this policy or to exercise a right listed below, contact the address above. We aim to respond within 30 days.
Account data
Email address, display name, and authentication identifiers when you create an account. Used to sign you in, secure the account, and provide the service. Lawful basis: contract.
Hotel & invoice data
Folio, invoice, and billing information supplied by you or your connected PMS (e.g. Mews, Opera). Used to aggregate and generate invoices on your behalf. Lawful basis: contract; legitimate interest in operating the service.
Guest data (transient)
When aggregating invoices, guest names and folio charges pass through stateless edge workers and are released from memory when the response completes. Not written to persistent storage by the aggregator. Lawful basis: your legitimate interest as controller of the guest data.
Payment data
Card details are handled by Stripe. SwiftInvoicePro does not store full card numbers.
Operational logs
Request metadata (timestamps, status codes, error traces) used for security, debugging, and abuse prevention. Lawful basis: legitimate interest.
Right of access
Request a copy of the personal data we hold about you.
Right to rectification
Ask us to correct data that is inaccurate or incomplete.
Right to erasure
Ask us to delete your personal data where no lawful basis to retain it applies.
Right to restrict processing
Ask us to pause processing while a dispute is resolved.
Right to data portability
Receive your data in a structured, machine-readable format.
Right to object
Object to processing based on legitimate interests, including profiling.
Rights re: automated decisions
SwiftInvoicePro does not make solely automated decisions with legal effect.
Right to withdraw consent
Where processing relies on consent, withdraw it at any time.
To exercise any right, email natromrich@googlemail.com. You also have the right to lodge a complaint with your local supervisory authority — in the UK that is the Information Commissioner's Office (ico.org.uk).
SwiftInvoicePro relies on a small number of infrastructure and integration providers to deliver the service. A current list, together with each provider's role and processing region, is available on request from natromrich@googlemail.com.
Account and invoice records are stored in a single EU region (Ireland). We do not replicate guest or invoice records to a second continent.
Where personal data is transferred outside the UK or EEA — for example to a sub-processor operating globally — we rely on the EU Standard Contractual Clauses (SCCs), supplemented by the UK International Data Transfer Addendum (IDTA) for UK-originating data.
Apex Flow Technology Ltd is established in the United Kingdom and therefore does not self-certify under the EU-US Data Privacy Framework, which is open only to US-established organisations. Where one of our sub-processors holds a Data Privacy Framework certification, that certification is the sub-processor's own transfer mechanism; we do not present it as ours.
For technical controls (row-level tenant isolation, zero-retention edge processing, encryption in transit), see our Security & Compliance page.
This page is app-owner editable content, not an independent certification. We will update it as our practices change.