GDPR Compliance & Data Protection
GDPR Compliance • SwiftFileConvert
Our Data Protection Commitment
SwiftFileConvert complies with the EU General Data Protection Regulation (GDPR). We operate on a strict privacy-first principle: we do not sell, rent, or monetize your personal files or data.
1. Data controller
SwiftFileConvert operates this website and acts as the data controller for the personal data described here. You can reach us at contact@swiftfileconvert.com.
2. What we process
We deliberately minimise the data we process:
- Files you upload — processed only to perform the conversion you requested. Files and conversion results are stored temporarily and deleted automatically no later than one hour after upload.
- Anonymous session identifier — a random ID stored in a first-party cookie so you can retrieve your recent conversions. It contains no name, email, or identity information unless you sign in voluntarily.
- Request metadata — IP address and user agent, used exclusively for rate limiting, abuse prevention, and security logging.
- Contact emails — if you email us, we use your address solely to reply to your request.
We do not sell personal data, we do not share it with advertisers, and we do not run third-party advertising or behavioural tracking scripts.
3. Legal bases for processing
- Performance of service (GDPR Art. 6(1)(b)) — processing uploaded files to deliver the conversion you request.
- Legitimate interests (GDPR Art. 6(1)(f)) — request metadata for security, rate limiting, and abuse prevention.
- Consent (GDPR Art. 6(1)(a)) — optional preference storage such as theme and language selection.
1-Hour Automatic File Deletion
Uploaded and converted files are automatically and permanently deleted from our servers within one hour of conversion. We never retain backups or archives of user files.
Authorized Subprocessors
We use a minimal set of infrastructure providers, each bound by data protection agreements:
| Provider | Role | Data involved | Processing location |
|---|---|---|---|
| Cloudflare, Inc. | Edge network, static hosting (Pages), object storage (R2) | Uploaded files (temporary), converted files (temporary), standard request metadata | Global edge network |
| Akamai Technologies, Inc. (Linode) | Application & conversion server hosting | Uploaded files (temporary), converted files (temporary), request logs | Singapore |
Your Rights Under GDPR
- Right of Access — You may request confirmation of whether we process personal data about you and receive a copy of that data.
- Right to Erasure — You may request deletion of personal data. Note that converted files are deleted automatically within one hour.
- Right to Rectification — You may request correction of inaccurate personal data that we hold about you.
- Right to Data Portability — Where processing is based on consent or contract, you may request your data in a structured, machine-readable format.
- Right to Restrict Processing — You may request that we restrict processing while a dispute or inquiry is resolved.
- Right to Object — You may object to processing based on legitimate interests at any time.
- Right to Withdraw Consent — Where processing relies on consent, you may withdraw it at any time.
7. Contact & Data Protection Requests
If you have any questions about this policy or wish to exercise your rights, please reach out directly at contact@swiftfileconvert.com.
