(Privacy Notice)Pilot phase

Your data, handled with transparency and trust.

How we handle your data during the SwarmMind pilot — described plainly, and honestly about what is and isn't guaranteed yet.

Version: 0.9 (Pilot)Date: 23 Dec 2025Provider / Controller: Intunex Oy
Summary

Quick summary (2 minutes)

  • Customer Hive (organisation data): the customer is the Controller; SwarmMind acts as the Processor.
  • Mandatory platform operations: SwarmMind is the Controller.
  • Learning Identity: by default SwarmMind is the Controller, but the customer can enable an Isolated Tenant mode.
  • EU ambition: we are building towards a Full EU stack ("No data is transferred outside the EU/EEA").
  • Pilot reality: processing is mostly in the EU, but we do not yet promise “no transfers” in the pilot due to some subprocessors.
01

Who is responsible for what

A) Customer Hive Data

Customer = Controller · SwarmMind = Processor

This covers the data the customer uses in their Hive and the data employees process inside that organisation.

B) Platform Operations

SwarmMind = Controller

Data that keeps the service secure and reliable: technical logs, abuse prevention, availability, billing.

C) Learning Identity

Default: SwarmMind = Controller · Isolated: Customer = Controller

Learning Identity is user-managed: the user decides what it contains and who can see it.

02

What data we process

  • User account and roles (employee/admin etc.)
  • Organisation settings and structure
  • Conversations with learning agents (1:1) and swarm conversations, when stored
  • User-saved outputs (notes, reflections, documents)
  • Audit log ("who did what"), with pseudonymisation where needed
  • Technical logs (e.g., IP address, login events, user-agent)
  • Security and abuse-response records
  • Minimum customer admin and billing information
  • The Learning Identity text (as approved by the user) and visibility settings
03

Why we process data

  • To provide the service (login, roles, permissions, features).
  • To keep the service secure and trustworthy (audit trail, abuse prevention).
  • To enable the customer to use the service with their workforce.
  • To provide user value (identity, reflection, learning support).
04

Where data is stored

Pilot phase (now)

Primary storage and processing are in the EU. Honest limitation: during the pilot, non-EU/EEA processing may be possible due to subprocessor chains or optional features.

Target state (roadmap)

Our goal is a Full EU stack so we can say: “No data is transferred outside the EU/EEA, and there is no access from outside the EU/EEA.”

05

Generative AI and training

A key promise: we use AI services only to generate outputs (inference), not to train models on customer content. Our AI providers' terms restrict use of customer data for training. The user decides what is stored permanently.

06

Web search & voice input (privacy first)

  • Searches are performed by SwarmMind agents server-side, not directly by users.
  • Queries are automatically sanitised (identifiers removed); if risky data is detected, the search is not executed at all (hard-stop).
  • We do not store the contents of web search queries in logs.
  • Voice is processed within the EU (Scaleway, France; Whisper Large V3). Audio is never stored — only the transcribed text is returned.
  • We store only technical metadata (duration/success). Retention is 90 days.
07

Retention & your rights

The customer manages users in their Hive: removal, disablement, anonymisation. Security and audit evidence is retained for a limited time to investigate abuse.

You have the right to access, correct, and request deletion of your data. If you are an employee in a customer Hive, your requests are handled primarily by the customer (as Controller).

08

Subprocessors

We use the following key partners to deliver SwarmMind (Pilot Phase):

ProviderPurposeRegion
SupabaseDatabase, auth, storage, edge functionsEU
ScalewayGenAI, Speech-to-Text, System EmailsEU
OpenAIOptionalAgent responses (when enabled)USA
TavilyOptionalAgent web searchUSA

For a full subprocessor breakdown per role (Hive/Platform/Identity), please contact us at info@intunex.fi.