Privacy Notice
Last updated 18 September 2026
1. Who we are
Apex Flow Technology Ltd. (“Apex Flow”, “we”, “us”) operates the Swift Ship freight invoice audit service at swiftfreightaudit.com. Apex Flow Technology Ltd. is the data controller for the personal data described in this notice, which means we decide why and how it is processed.
Questions, requests or complaints about this notice or your data: privacy@swiftfreightaudit.com.
2. Personal data we collect, and why
- Contact and account data — name, work email address, job title, telephone number, employer, and (for client accounts) login credentials. Used to create and secure your account, deliver audit results, and reply to enquiries. Legal basis: performance of a contract, and our legitimate interest in responding to business enquiries.
- Documents you submit — carrier invoices, tender baselines and related freight records. Used solely to run the audit you asked for and produce your findings and dispute memos. Legal basis: performance of a contract. We deliberately strip driver telephone numbers, national insurance / social security numbers and similar personal identifiers from submitted documents before storage, and retain only corporate entity names, shipment references and monetary line items.
- Usage and device data — pages viewed, audit actions taken, IP address, browser and device information, referring page. Used to keep the service secure, prevent abuse and rate-limit uploads, and to understand which pages are useful. IP address and browser string are reduced to a short irreversible hash where we only need to recognise repeat activity. Legal basis: legitimate interests in security and service improvement.
- Billing data — company name, billing contact and the record of what you were charged. Card numbers never reach our systems; payment details are collected and processed by our reseller (see section 3). Legal basis: performance of a contract and legal obligation (accounting records).
- Correspondence — emails and support messages you send us, and our replies. Legal basis: legitimate interests in running and evidencing our business.
3. Who we share data with
- Paddle.com Market Ltd. — our online reseller and Merchant of Record. Paddle handles orders, subscription management, payment processing, tax compliance, invoicing and billing-related customer service. Paddle processes your billing data as its own controller for those purposes.
- Service providers (sub-processors) — hosting, database, email delivery and error-monitoring providers who process data on our instructions and under contract.
- Professional advisers — legal, accounting and audit advisers, where needed and confidential.
- Authorities — regulators, courts or law enforcement where we are legally required to disclose.
We do not sell personal data and do not share it for third-party advertising.
4. International transfers
Some of our providers process data outside the United Kingdom and European Economic Area. Where that happens we rely on an adequacy decision for the destination country or on UK/EU Standard Contractual Clauses together with appropriate technical safeguards. You can ask us which safeguard applies to a particular provider.
5. How long we keep data
Audit records and submitted document extracts are kept for the life of your account and for up to 24 months afterwards, so recovery claims and disputes can be evidenced. Billing and accounting records are kept for seven years, as tax law requires. Enquiry correspondence from people who do not become clients is deleted within 24 months. Usage logs are kept for up to 12 months. When data is no longer needed it is deleted or irreversibly anonymised.
6. Your rights
Subject to the conditions in applicable law, you may ask us to give you a copy of your personal data, correct it, delete it, restrict how we use it, transfer it to another provider, or object to processing we carry out on the basis of legitimate interests. Where we rely on consent you may withdraw it at any time. Write to privacy@swiftfreightaudit.com and we will respond within one month. If you are in the UK you may also complain to the Information Commissioner's Office (ico.org.uk); in the EEA, to your local supervisory authority.
7. Security
We apply technical and organisational measures appropriate to the sensitivity of freight and commercial data: encryption in transit, encryption at rest, least-privilege access controls, row-level database access rules, secret management for credentials, personal identifier stripping on ingest, and upload size and rate limits. No system is perfectly secure, but we review these measures as the service changes.
8. Cookies and similar technologies
We use strictly necessary cookies and local browser storage to keep you signed in, to protect forms against cross-site request forgery, and to remember your place in the service. These are essential to provide the site and cannot be switched off from within it. We do not use advertising cookies. If we introduce optional analytics or marketing cookies we will ask for your consent first and offer a way to change your preference. You can clear or block cookies in your browser settings, though the client area will not work without the essential ones.
9. Changes to this notice
If we change how we use personal data we will update this page and the date above, and tell account holders by email where the change is significant.
See also our Terms & Conditions and Refund Policy.