Table of Contents

Questions about security & data protection

Sven Frauen Updated by Sven Frauen

Questions about security & data protection

All data in Sweap is processed on servers within the European Union, primarily in Germany. We place the highest value on data protection and data security. Details on this can also be found in our order processing agreement (AVV) and our technical and organisational measures (TOMs) as an appendix to our GTC here.

Where is my data stored?

Your data is stored in our secure IBM Deutschland GmbH data centres in Frankfurt am Main (Germany).

General security information about the IBM Cloud

The IBM Cloud offers an open and secure public cloud for enterprises, with extensive compliance and security certifications to protect clients' data and applications. The IBM Cloud platform is based on secure engineering practices and offers multi-layered security controls across the network and infrastructure. In addition, IBM is committed to complying with European regulatory requirements regarding the protection of its clients' data and applications.

Certifications include international standards for data security (ISO 27001) and data protection (ISO 27018 and 27701), detailed written documentation of internal controls (SOC 1-3), specific cloud security certifications (CSA STAR) and, of course, GDPR compliance. For more information on compliance and security certifications, please see the IBM Cloud Compliance Programme Overview.

What is IBM's position on the CLOUD Act?

What does the CLOUD Act say?

It obliges US IT providers to grant US authorities access to customer data outside the US under certain circumstances.

What does it not contain?

  • fundamental change in the legal situation from the point of view of the IBM public cloud
  • Actual relaxation of requirements for US authorities before they gain access

IBM Public Cloud policy and practice for such disclosure requests is based on the fact that client data belongs to the client, and is only released by the client, i.e.

How does IBM relate to Privacy Shield

What happened?

In its judgment of 16 July 2020 (Case C 311/18 - "Schrems II"), the ECJ declared this Privacy Shield Implementing Decision invalid.

What does that mean?

  • EU-US Privacy Shield no longer valid for data exports from the EU to the US
  • IBM Public Cloud uses EU standard contractual clauses (EUMCs)
  • EUMCs explicitly not invalidated by Schrems-II
  • Data exporters and importers must ensure that the EUMCs are supported by "supplementary measures to ensure an essentially equivalent level of protection".

Supplementary measures:

Further comprehensive information on IBM's obligation to protect international data transfers can be found here.

What security measures does Sweap take?

The technical and organisational measures for the protection of your data can be found here in Annex 2 of our AV contract. Furthermore, we ensure the protection of your data on the IBM Cloud by, among other things, the following:

Is my data backed up should an emergency occur?

All data is hosted on very secure and highly available servers in the IBM Cloud. Data is backed up daily in encrypted form and stored in a redundant and distributed manner. In the event of an unforeseen event and system-wide emergencies, we can perform a full backup restore.

How does Sweap protect accounts from brute-force attacks?

Sweap uses Keycloak’s built-in security features to detect repeated failed login attempts and slow them down automatically. After several incorrect passwords, the account becomes temporarily locked to prevent automated attacks. The waiting time increases gradually but never results in a permanent lockout. After a longer period without failed attempts, all counters reset automatically.

Details for administrators
• After 5 failed login attempts, temporary lockout begins.
• Each further failure increases the wait time by 1 minute.
• The maximum wait time is 15 minutes.
• After 12 hours without new failures, all counters reset.

Where are my emails sent?

The emails in Sweap are sent via our email provider Mailjet using the secure Google Cloud Platform data centres in Frankfurt am Main (Germany) and Saint-Ghislain (Belgium).

General security information of the provider Mailjet.

Mailjet is ISO 27001 certified and DSGVO compliant. EU customer data is stored exclusively on EU servers. All data is subject to SCCs (Standard Contractual Clauses) and is encrypted. Access to data outside the EU is very limited and data is minimized, encrypted and SCC compliant.

For more information about Mailjet's security & privacy, click here.

For more information on the processing of data (AVV) by Mailjet, please click here.

Is Sweap compatible with the GDPR?

Yes, Sweap meets all the requirements of the EU General Data Protection Regulation and is data protection compliant as an organisation as well as software according to EU-DSGVO. To this end, as part of the preparations for the EU GDPR, we have checked our product for the essential legal requirements and made the corresponding adjustments, as you can read here.

Has a data protection officer been appointed?

Yes, for advice on data protection issues and support as company data protection officer, we rely on Proliance GmbH /

www.datenschutzexperte.de:

Proliance GmbH, Leopoldstr. 21, 80802 München.

You can find out more about the official data protection seal from Datenschutzexperte.de here.

Datenschutzsiegel

If you have any questions about data protection at Sweap, please contact us at privacy@sweap.io.

How can I ensure that my data protection rights are guaranteed?

We have processes in place to ensure your right to erasure, rectification, portability, access and to be forgotten or restricted. Details can also be found here in our data protection concept.

Does tracking take place in Sweap?

In general, Sweap applies the principle of data avoidance and data economy. We therefore try to collect only the necessary data. When it comes to tracking, we distinguish between guests (participants) at your event and Sweap users of the Sweap application.

Guests and websites

When a guest (an attendee of your event) opens a registration page, no cookies are set - not even technically necessary ones. The registration pages are stateless and do not require cookies to operate. No tracking cookies are used, and no data is collected for further purposes (e.g. marketing). Sweap does not use Google Analytics or comparable web trackers on these pages.

Fonts, images and JavaScript libraries are hosted by us; nothing is loaded dynamically from external servers. A cookie banner is therefore not required for the registration pages – and Sweap does not provide one.

However, a Sweap user can embed their own web trackers, for example via JavaScript in the „Custom Head HTML" field. It is also possible to voluntarily embed Google Maps or other third-party services (e.g. YouTube when embedding a video). Using these services requires an IP address to be transmitted, and cookies from those providers may be set. What happens to that data is then the responsibility of the respective third-party provider (Google, YouTube, etc.).

You can check at any time whether cookies are present on a page, for example with https://www.cookiemetrix.com/.

Guests and e-mails

By default, no tracking takes place for the e-mails. Only the bounce rates (incorrect transmissions) and the correct transmission of the e-mails are saved. Optionally, the Sweap user can also track the opening rates of the e-mails. This is done with the help of an invisible tracking pixel which is used by our e-mail provider Mailjet. However, this option can be freely activated or deactivated by the Sweap user. By default, this function is deactivated and must be activated. Sweap does not evaluate this data further.

Sweap users

Within the Sweap application (Sweap web application and Sweap guest list iOS app) we use tools for error reporting and for our help and support function. These collect usage data in order to detect and fix errors, ensure the stability of the software and develop the application further. This applies only to users who log in to our software – not to the guests of an event.

The cookie information below relates to the web application. In addition to the technically necessary cookies listed there, the tools mentioned above may set further cookies.

These technically necessary cookies are used for signing in to the Sweap application and for operating it. No cookie consent is required for them:

Name

Purpose

Scope

Duration

JSESSIONID

Assigns your browser's requests to your active session in the application

app.sweap.io

Session

ssp

Ensures that your requests are handled by the same application instance throughout a session. The application runs on several instances for resilience and load balancing

app.sweap.io

Session

AUTH_SESSION_ID

Identifies your login session with our authentication service

auth.sweap.io

Session

KC_RESTART

Preserves the state of an interrupted login so that it can be resumed

auth.sweap.io

Session

KC_AUTH_SESSION_HASH

Detects changes to the login session so that the sign-in state stays current in your browser

auth.sweap.io

Short-lived

eg

Ensures that, during login, your requests are handled by the same instance of the authentication service

auth.sweap.io

Session

Some of these cookies are not set in the application itself but on auth.sweap.io, the domain used for signing in. The cookies listed above serve technical operation only; they are not used to analyse usage behaviour.

In addition, error reporting and support tools are used within the application to keep the software stable and to provide in-app help.

These cookies are only set in the area for logged-in Sweap users. Guests of an event do not enter this area – the section „Guests and Websites" above applies to them.

For further details, please see our privacy policy.

How did we do?

Privacy policy and GDPR

Sweap AI - Questions about security & data protection

Contact