This Data Processing & Data Sharing Notice ("Notice") is issued by Central Services & Solutions Ltd, a company incorporated in England and Wales, trading as SwiftBusiness ("we", "us", "our").
This Notice explains in detail how we collect, use, store, share, and protect personal data and business data when you use the SwiftBusiness platform ("Platform") at swiftbusiness.co.uk and any associated subdomains, applications, or services.
This Notice supplements and should be read alongside our Privacy Policy, Terms & Conditions, Supplier & Partner Disclaimer, and Acceptable Use Policy.
This Notice applies to:
Central Services & Solutions Ltd is the Data Controller for personal data processed through the SwiftBusiness Platform. This means we are responsible for determining the purposes and means of processing your personal data.
Registered in England & Wales. Company No. 13735404. SwiftBusiness is a trading name of Central Services & Solutions Ltd.
We are registered with the Information Commissioner's Office (ICO) as a Data Controller. Our ICO registration number is available upon request.
Depending on the context of processing, Central Services & Solutions Ltd acts in different capacities under UK GDPR. Understanding this distinction is important for your rights:
In these cases, the third-party receiving your data may also act as an independent Data Controller for their own processing purposes, subject to their own privacy policies.
Once your data is shared with a Supplier or Partner (e.g. a utility supplier, lender, or service provider), that party becomes an independent Data Controller for the processing they conduct. We are not responsible for their processing, and you should review their own privacy notices directly.
We process the following categories of personal data, depending on the services you use:
Under UK GDPR Article 6, we rely on the following lawful bases for processing personal data:
| Processing Activity | Legal Basis (UK GDPR Art. 6) |
|---|---|
| Account registration and profile management | Art. 6(1)(b) — Performance of a contract |
| Utility quote generation and comparison | Art. 6(1)(b) — Performance of a contract / Art. 6(1)(a) — Consent |
| Submitting switching applications to suppliers | Art. 6(1)(b) — Performance of a contract |
| Business finance application processing | Art. 6(1)(a) — Consent + Art. 6(1)(b) — Contract steps |
| Credit checks and identity verification | Art. 6(1)(a) — Explicit consent |
| Document signing via DocuSign | Art. 6(1)(b) — Performance of a contract |
| Sending transactional emails and platform notifications | Art. 6(1)(b) — Contract / Art. 6(1)(f) — Legitimate interests |
| Marketing communications (email, SMS) | Art. 6(1)(a) — Consent (PECR-compliant opt-in) |
| Fraud prevention and security monitoring | Art. 6(1)(f) — Legitimate interests |
| Compliance with legal obligations (e.g. AML, tax) | Art. 6(1)(c) — Legal obligation |
| Platform analytics and service improvement | Art. 6(1)(f) — Legitimate interests |
| AI-assisted recommendations and profiling | Art. 6(1)(f) — Legitimate interests (with opt-out right) |
Where we rely on legitimate interests (Art. 6(1)(f)), we have conducted a Legitimate Interests Assessment (LIA) and determined that our interests are not overridden by your rights. You may request a copy of our LIA by contacting us.
Where processing involves special category data (e.g. biometric verification), we will rely on Art. 9(2) and seek explicit consent at the relevant point of collection.
The following table sets out who we share your data with, what data is shared, the purpose of sharing, the legal basis, and their role under UK GDPR:
| Provider | Data Shared | Purpose | Legal Basis | Their Role |
|---|---|---|---|---|
| Approvity | Business & director details, financial data, company number | Finance application processing, lender matching, credit underwriting | Consent + Contract | Independent Controller / Processor |
| Jellyfish Energy | Site address, MPAN/MPRN, meter type, consumption, postcode | Live tariff comparisons, switching API, contract activation | Contract (your instruction) | Processor on our behalf |
| Online Direct and relevant suppliers | Company number and the minimum details required for supplier eligibility; director details only where separately required and consented | Manual business-credit and supplier-eligibility assessment | Explicit Consent | Independent Controller |
| DocuSign | Full name, email address, electronic signature, IP address, timestamp | LOA and contract e-signing, audit trail, certificate of completion | Contract | Processor on our behalf |
| Utility Warehouse | Name, contact details, site address, meter data | Energy, water, broadband & telecoms supply referral and onboarding | Consent + Contract | Independent Controller |
| Blizzard Telecom | Contact details, site address, business information | Business telephony and connectivity product fulfilment | Consent + Contract | Independent Controller |
| Teya Merchant Services | Business details, director information, contact details | Payment terminal and merchant acquiring applications | Consent + Contract | Independent Controller |
| Online Direct | Business name, contact details | Business services referral and introduction | Consent | Independent Controller |
| Finance Lenders (via Approvity) | Full application data, financial information, director details | Credit assessment, lending decisions, facility issuance | Consent | Independent Controller |
| Utility Suppliers | Site address, meter data, contact details, LOA | Contract switching, activation, and supply management | Contract + LOA authority | Independent Controller |
| Google (OAuth / Analytics) | Authentication token, email address (OAuth only); anonymised usage data (Analytics) | Social login services; platform usage analytics | Consent (OAuth) / Legitimate Interests (Analytics) | Independent Controller |
| Microsoft (OAuth) | Authentication token, email address | Social login services | Consent | Independent Controller |
| Base44 Ltd | All Platform data (encrypted at rest and in transit) | Application hosting, database services, backend infrastructure | Contract (Data Processing Agreement in place) | Processor on our behalf |
| Email / SMS Providers | Email address, phone number, message content | Transactional notifications, account alerts, marketing (with consent) | Contract / Consent | Processor on our behalf |
We require all third-party processors to have appropriate Data Processing Agreements (DPAs) in place and to process data only on our documented instructions. Independent Controllers are responsible for their own lawful basis and compliance.
We retain personal data only for as long as necessary for the purpose for which it was collected, or as required by law. Our standard retention periods are:
| Data Category | Retention Period | Reason |
|---|---|---|
| Account and profile data | Duration of account + 6 years after closure | Contract and legal obligation |
| Utility quote and comparison records | 6 years from quote date | Legal obligation / audit trail |
| Signed Letters of Authority (LOAs) | 6 years from signing date | Legal obligation / regulatory audit |
| Finance application records | 6 years from application date | FCA / AML regulatory requirement |
| Credit check records | 2 years from check date | Compliance and audit purposes |
| Uploaded documents (bills, ID, contracts) | Duration of account + 6 years | Legal obligation / dispute resolution |
| Communications and support records | 3 years from last interaction | Legitimate interests / dispute resolution |
| Activity logs and technical access logs | 12 months | Security monitoring / fraud prevention |
| Marketing consent records | 3 years from last consent action | PECR / ICO guidance compliance |
| Anonymised analytics data | Indefinitely (anonymised — no longer personal data) | Legitimate interests / service improvement |
Where data must be retained for legal, regulatory, or audit purposes, it will be held securely and access will be restricted during the retention period. At the end of the retention period, data will be securely deleted or anonymised.
The Platform uses artificial intelligence and algorithmic processing to generate personalised market insights, savings recommendations, tariff suggestions, and contract intelligence. This involves:
These recommendations are informational and indicative only and do not constitute regulated financial advice. The legal basis for this processing is legitimate interests (Art. 6(1)(f)) and you have the right to object to this profiling (see Section 12).
Certain products (particularly finance applications) may involve automated or manual pre-eligibility screening conducted by the relevant finance or supplier partners before human underwriting review. Where this occurs:
The Platform applies automated risk and anomaly detection tools to identify potential fraud, account compromise, or misuse. This is conducted on the basis of legitimate interests and legal obligation. Accounts identified as high-risk may be flagged for manual review or temporarily restricted pending investigation.
We take the security of your personal data seriously and implement appropriate technical and organisational measures in accordance with UK GDPR Article 32, including:
No method of electronic transmission or storage is 100% secure. We will notify you in accordance with our breach notification obligations if a security incident affects your data.
In the event of a personal data breach, we will follow the procedures required under UK GDPR Articles 33 and 34:
To report a suspected data breach or security incident, contact: garrykelly@centralservicessolutions.co.uk
Some of our service providers and sub-processors may be located outside the United Kingdom or the European Economic Area (EEA). Where personal data is transferred internationally, we ensure appropriate safeguards are in place in accordance with UK GDPR Chapter V:
| Provider / Transfer | Location | Transfer Safeguard |
|---|---|---|
| Base44 Ltd (hosting infrastructure) | EU / UK | UK adequacy / contractual DPA |
| DocuSign | USA | UK International Data Transfer Agreement (IDTA) / Standard Contractual Clauses (SCCs) |
| Google (OAuth / Analytics) | USA / global | UK adequacy decision / SCCs / Google's Data Processing Terms |
| Microsoft (OAuth) | USA / EU | SCCs / Microsoft Data Protection Addendum |
| Approvity and lender network | UK / EU | UK GDPR compliant / contractual DPA |
| Email / SMS infrastructure providers | UK / EU / USA | SCCs / IDTA / contractual DPA |
You may request a copy of the relevant transfer safeguards by contacting us at garrykelly@centralservicessolutions.co.uk.
We do not transfer personal data to countries without an appropriate UK adequacy decision or equivalent safeguard unless explicitly required and documented.
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, you have the following rights in relation to your personal data:
| Right | What It Means |
|---|---|
| Right of Access (Art. 15) | Request a copy of all personal data we hold about you (a "Subject Access Request" or SAR) |
| Right to Rectification (Art. 16) | Request correction of inaccurate or incomplete personal data |
| Right to Erasure (Art. 17) | Request deletion of your personal data where there is no longer a lawful basis for retention ("right to be forgotten"), subject to legal retention obligations |
| Right to Restrict Processing (Art. 18) | Request that we limit how we use your data while a dispute or review is ongoing |
| Right to Data Portability (Art. 20) | Request a copy of data you provided to us in a structured, machine-readable format, where processing is based on consent or contract |
| Right to Object (Art. 21) | Object to processing based on legitimate interests, including profiling and direct marketing — we will cease processing unless we can demonstrate compelling legitimate grounds |
| Right Not to Be Subject to Automated Decisions (Art. 22) | Request human review of any automated decision that significantly affects you, including AI-assisted recommendations or eligibility screening |
| Right to Withdraw Consent | Withdraw consent at any time where processing is based on consent — this does not affect lawfulness of prior processing |
To exercise any of these rights, contact us at: garrykelly@centralservicessolutions.co.uk
We will respond to your request within one calendar month of receipt. For complex or multiple requests, we may extend this by a further two months and will notify you accordingly. We will not charge a fee for reasonable requests. We may need to verify your identity before processing a request.
Where data has been shared with a third-party independent Controller, you will need to exercise your rights directly with that organisation.
We use the following sub-processors to deliver the Platform's infrastructure and services. All sub-processors are bound by Data Processing Agreements requiring compliance with UK GDPR:
We will update this Notice when we add or replace sub-processors. You may object to the addition of a new sub-processor by contacting us — if we cannot reasonably accommodate your objection, you may close your account.
The Platform uses cookies and similar tracking technologies in accordance with the Privacy and Electronic Communications Regulations 2003 (PECR) and ICO cookie guidance.
Full details are in our Cookie Policy.
The SwiftBusiness Platform is intended for use by businesses, sole traders, and adults aged 18 and over. We do not knowingly collect or process personal data from individuals under the age of 18. If you believe we have inadvertently collected data from a minor, please contact us immediately at garrykelly@centralservicessolutions.co.uk and we will delete the data promptly.
We may update this Notice from time to time to reflect changes in our processing activities, legal obligations, or Platform functionality. Where material changes are made:
Continued use of the Platform after an updated Notice is published constitutes acceptance, where permitted by applicable law. Where changes require fresh consent, we will seek this from you separately.
If you have a complaint about how we handle your personal data, please contact us in the first instance:
We will acknowledge your complaint within 5 working days and aim to resolve it within 30 days. If you are not satisfied with our response, or if we fail to respond within 30 days, you have the right to lodge a complaint directly with the Information Commissioner's Office (ICO):
You also have the right to seek a judicial remedy through the courts in England and Wales.
Other Legal Documents
© 2026 Central Services & Solutions Ltd. All rights reserved. Company No. 13735404.
SwiftBusiness is a trading name of Central Services & Solutions Ltd. Registered in England & Wales.
Registered Office: Wansbeck Workspace, Rotary Parkway, Ashington, Northumberland, NE63 8QZ