Table of Contents
- Questions about security & data protection
- Where is my data stored?
- General security information about the IBM Cloud
- What security measures does Sweap take?
- Is my data backed up should an emergency occur?
- How does Sweap protect accounts from brute-force attacks?
- Where are my emails sent?
- General security information of the provider Mailjet.
- Is Sweap compatible with the GDPR?
- Has a data protection officer been appointed?
- How can I ensure that my data protection rights are guaranteed?
- Does tracking take place in Sweap?
Questions about security & data protection
Updated
by Sven Frauen
- Questions about security & data protection
- Where is my data stored?
- General security information about the IBM Cloud
- What security measures does Sweap take?
- Is my data backed up should an emergency occur?
- How does Sweap protect accounts from brute-force attacks?
- Where are my emails sent?
- General security information of the provider Mailjet.
- Is Sweap compatible with the GDPR?
- Has a data protection officer been appointed?
- How can I ensure that my data protection rights are guaranteed?
- Does tracking take place in Sweap?
Questions about security & data protection
All data in Sweap is processed on servers within the European Union, primarily in Germany. We place the highest value on data protection and data security. Details on this can also be found in our order processing agreement (AVV) and our technical and organisational measures (TOMs) as an appendix to our GTC here.
Where is my data stored?
Your data is stored in our secure IBM Deutschland GmbH data centres in Frankfurt am Main (Germany).
General security information about the IBM Cloud
The IBM Cloud offers an open and secure public cloud for enterprises, with extensive compliance and security certifications to protect clients' data and applications. The IBM Cloud platform is based on secure engineering practices and offers multi-layered security controls across the network and infrastructure. In addition, IBM is committed to complying with European regulatory requirements regarding the protection of its clients' data and applications.
Certifications include international standards for data security (ISO 27001) and data protection (ISO 27018 and 27701), detailed written documentation of internal controls (SOC 1-3), specific cloud security certifications (CSA STAR) and, of course, GDPR compliance. For more information on compliance and security certifications, please see the IBM Cloud Compliance Programme Overview.
What is IBM's position on the CLOUD Act?
What does the CLOUD Act say?
It obliges US IT providers to grant US authorities access to customer data outside the US under certain circumstances.
What does it not contain?
- fundamental change in the legal situation from the point of view of the IBM public cloud
- Actual relaxation of requirements for US authorities before they gain access
IBM Public Cloud policy and practice for such disclosure requests is based on the fact that client data belongs to the client, and is only released by the client, i.e.
- Requests for information are defended against in court as far as possible.
- Clients are informed about such requests
- In detail: https://www.ibm.com/blogs/policy/dataresponsibility-at-ibm/
- IBM Public Cloud can support this technically
How does IBM relate to Privacy Shield
What happened?
In its judgment of 16 July 2020 (Case C 311/18 - "Schrems II"), the ECJ declared this Privacy Shield Implementing Decision invalid.
What does that mean?
- EU-US Privacy Shield no longer valid for data exports from the EU to the US
- IBM Public Cloud uses EU standard contractual clauses (EUMCs)
- EUMCs explicitly not invalidated by Schrems-II
- Data exporters and importers must ensure that the EUMCs are supported by "supplementary measures to ensure an essentially equivalent level of protection".
Supplementary measures:
- Cloud Service Provider müssen belegen, dass sie „praktizieren, was die EUMCs predigen“
- In der IBM Public Cloud:
- International standards on data security (ISO 27001) and data protection (ISO 27018 and 27701)
- Founding membership and involvement in the European Cloud Code of Conduct
- IBM Principles for Trust and Transparency
- Disclosure of the Security Posture in the CSA Star Alliance
Further comprehensive information on IBM's obligation to protect international data transfers can be found here.
What security measures does Sweap take?
The technical and organisational measures for the protection of your data can be found here in Annex 2 of our AV contract. Furthermore, we ensure the protection of your data on the IBM Cloud by, among other things, the following:
- The use of extensive security options of the IBM Cloud to ensure the encryption of the data. This is done both in transport via SSL/TLS 1.2 and at rest during storage. For example, the data for our PostgreSQL database is encrypted both in transit and at rest with LUKS using AES-256.
- The use of the IBM option that support is only provided or monitored within the EU.
- Comprehensive system and application logging using IBM Log Analysis, with log data retained for no longer than 30 days.
- A detailed monitoring of the status of services and applications with IBM Cloud Monitoring.
- Using IBM Cloud Activity Tracker to gain insight into actions that change the state of a service in IBM Cloud. This service is used to look for abnormal activity and critical actions and to meet regulatory audit requirements.
- Key management via IBM Key Protect. This allows us to implement encryption with our own key (Bring Your Own Key - BYOK) and use it for the integrated IBM services.
- Encrypted backups that are automatically created daily and kept for no longer than 30 days, for example for our PostgreSQL database.
Is my data backed up should an emergency occur?
All data is hosted on very secure and highly available servers in the IBM Cloud. Data is backed up daily in encrypted form and stored in a redundant and distributed manner. In the event of an unforeseen event and system-wide emergencies, we can perform a full backup restore.
How does Sweap protect accounts from brute-force attacks?
Sweap uses Keycloak’s built-in security features to detect repeated failed login attempts and slow them down automatically. After several incorrect passwords, the account becomes temporarily locked to prevent automated attacks. The waiting time increases gradually but never results in a permanent lockout. After a longer period without failed attempts, all counters reset automatically.
Details for administrators
• Each further failure increases the wait time by 1 minute.
• The maximum wait time is 15 minutes.
• After 12 hours without new failures, all counters reset.
Where are my emails sent?
The emails in Sweap are sent via our email provider Mailjet using the secure Google Cloud Platform data centres in Frankfurt am Main (Germany) and Saint-Ghislain (Belgium).
General security information of the provider Mailjet.
Mailjet is ISO 27001 certified and DSGVO compliant. EU customer data is stored exclusively on EU servers. All data is subject to SCCs (Standard Contractual Clauses) and is encrypted. Access to data outside the EU is very limited and data is minimized, encrypted and SCC compliant.
For more information about Mailjet's security & privacy, click here.
For more information on the processing of data (AVV) by Mailjet, please click here.
Is Sweap compatible with the GDPR?
Yes, Sweap meets all the requirements of the EU General Data Protection Regulation and is data protection compliant as an organisation as well as software according to EU-DSGVO. To this end, as part of the preparations for the EU GDPR, we have checked our product for the essential legal requirements and made the corresponding adjustments, as you can read here.
Has a data protection officer been appointed?
Yes, for advice on data protection issues and support as company data protection officer, we rely on Proliance GmbH /
Proliance GmbH, Leopoldstr. 21, 80802 München. You can find out more about the official data protection seal from Datenschutzexperte.de here. | ![]() |
If you have any questions about data protection at Sweap, please contact us at privacy@sweap.io.
How can I ensure that my data protection rights are guaranteed?
We have processes in place to ensure your right to erasure, rectification, portability, access and to be forgotten or restricted. Details can also be found here in our data protection concept.
Does tracking take place in Sweap?
In general, Sweap applies the principle of data avoidance and data economy. We therefore try to collect only the necessary data. When it comes to tracking, we distinguish between guests (participants) at your event and Sweap users of the Sweap application.
Guests and websites
When a guest (an attendee of your event) opens a registration page, no cookies are set - not even technically necessary ones. The registration pages are stateless and do not require cookies to operate. No tracking cookies are used, and no data is collected for further purposes (e.g. marketing). Sweap does not use Google Analytics or comparable web trackers on these pages.
Fonts, images and JavaScript libraries are hosted by us; nothing is loaded dynamically from external servers. A cookie banner is therefore not required for the registration pages – and Sweap does not provide one.
However, a Sweap user can embed their own web trackers, for example via JavaScript in the „Custom Head HTML" field. It is also possible to voluntarily embed Google Maps or other third-party services (e.g. YouTube when embedding a video). Using these services requires an IP address to be transmitted, and cookies from those providers may be set. What happens to that data is then the responsibility of the respective third-party provider (Google, YouTube, etc.).
You can check at any time whether cookies are present on a page, for example with https://www.cookiemetrix.com/.
Guests and e-mails
By default, no tracking takes place for the e-mails. Only the bounce rates (incorrect transmissions) and the correct transmission of the e-mails are saved. Optionally, the Sweap user can also track the opening rates of the e-mails. This is done with the help of an invisible tracking pixel which is used by our e-mail provider Mailjet. However, this option can be freely activated or deactivated by the Sweap user. By default, this function is deactivated and must be activated. Sweap does not evaluate this data further.
Sweap users
Within the Sweap application (Sweap web application and Sweap guest list iOS app) we use tools for error reporting and for our help and support function. These collect usage data in order to detect and fix errors, ensure the stability of the software and develop the application further. This applies only to users who log in to our software – not to the guests of an event.
The cookie information below relates to the web application. In addition to the technically necessary cookies listed there, the tools mentioned above may set further cookies.
These technically necessary cookies are used for signing in to the Sweap application and for operating it. No cookie consent is required for them:
Name | Purpose | Scope | Duration |
| Assigns your browser's requests to your active session in the application |
| Session |
| Ensures that your requests are handled by the same application instance throughout a session. The application runs on several instances for resilience and load balancing |
| Session |
| Identifies your login session with our authentication service |
| Session |
| Preserves the state of an interrupted login so that it can be resumed |
| Session |
| Detects changes to the login session so that the sign-in state stays current in your browser |
| Short-lived |
| Ensures that, during login, your requests are handled by the same instance of the authentication service |
| Session |
Some of these cookies are not set in the application itself but on auth.sweap.io, the domain used for signing in. The cookies listed above serve technical operation only; they are not used to analyse usage behaviour.
In addition, error reporting and support tools are used within the application to keep the software stable and to provide in-app help.
These cookies are only set in the area for logged-in Sweap users. Guests of an event do not enter this area – the section „Guests and Websites" above applies to them.
For further details, please see our privacy policy.
