Legal · Privacy Policy
Privacy Policy
Last updated: 2026-07-21
SwapToSaaS ("we", "us", "our") operates AgentValet. This Privacy Policy explains what personal data we collect, how we use it, and your rights. We comply with the UK GDPR and EU GDPR where applicable.
1. Data controller
Weisung Technology Ltd, a private limited company registered in England and Wales, trading as SwapToSaaS and AgentValet. For all privacy inquiries, email [email protected].
2. What we collect
A. Account and billing data
- Name and email address (provided at checkout)
- Billing address (collected by Stripe for tax compliance)
- Payment information (processed by Stripe; we never see card details)
B. Setup credentials (temporary)
To perform the setup service, we require access to:
- SSH credentials to your VPS (public key or password, your choice)
- API keys for the AI model provider you designate
- Bot tokens for the communication channel you choose (Telegram, WhatsApp, etc.)
These credentials are used only to complete your setup. They are stored encrypted during the setup window and permanently deleted within 7 days of delivery unless you subscribe to ongoing support.
C. Support communications
Emails you send to us are stored in our support system (Gmail) for the duration of the support relationship, typically 90 days after the last interaction.
D. Website analytics
We use Cloudflare Web Analytics on swaptosaas.com. It is cookieless and collects only aggregate visitor counts, page views, and referrers. No personal data.
3. What we DO NOT collect or store
- Your AI agent's conversation history (lives on your VPS)
- Your business data, MEMORY.md contents, or SOUL.md contents (lives on your VPS)
- Credit card numbers (Stripe handles this)
- Passwords other than the temporary VPS credentials you provide for setup
4. Legal basis for processing
- Contract performance: to deliver the service you purchased
- Legal obligation: tax and accounting record-keeping (UK: 6 years)
- Legitimate interest: fraud prevention, service improvement
5. Data sharing
We share data only with the following processors:
- Stripe Payments Europe, Ltd. — payment processing. Stripe's Privacy Policy.
- Google Workspace — email hosting (support inbox).
- Cloudflare — CDN and web analytics.
We do not sell your data. We do not share it for marketing.
6. International transfers
Some processors (Cloudflare, Google) may transfer data outside the UK/EEA. These transfers are covered by Standard Contractual Clauses and adequacy decisions where applicable.
7. Retention
- Setup credentials: deleted within 7 days of delivery
- Account and billing data: 6 years (UK tax law)
- Support emails: 90 days after last interaction
8. Your rights
Under UK/EU GDPR you have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data (right to be forgotten), subject to legal retention obligations
- Restrict or object to processing
- Data portability
- Lodge a complaint with the UK Information Commissioner's Office (ICO) or your local supervisory authority
To exercise these rights, email [email protected]. We respond within 30 days.
9. Security
We use industry-standard measures: encryption in transit (TLS), encryption at rest for stored credentials, principle of least privilege for staff access, and regular security reviews. No system is 100% secure; we notify affected customers within 72 hours of a personal data breach as required by UK GDPR.
10. Cookies
We do not use tracking cookies. Cloudflare Web Analytics is cookieless. Stripe's checkout may set functional cookies required for the transaction; these are essential and do not require consent.
11. Changes to this policy
We will notify customers by email of material changes at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the current version.
12. Contact
Email: [email protected]