Privacy Policy
Last updated: July 18, 2026
This Privacy Policy explains how SwishX collects, uses, discloses, and safeguards information when you use Content IQ and our related websites, applications, and services (together, the “Services”). We built this policy to meet the expectations of customers and users across the United States, the European Economic Area, the United Kingdom, and other jurisdictions with comprehensive privacy laws. Please read it carefully.
1. Introduction & scope
SwishX ("SwishX," "we," "us," or "our") provides Content IQ, an agentic content platform that helps pharmaceutical and medtech commercial teams plan, draft, produce, and govern marketing content. This Privacy Policy applies to personal data we process in connection with:
- Our marketing websites, including swishx.com and its subdomains;
- The Content IQ application, including any account, workspace, brief, Brand Dossier, or generated asset created within it;
- Sales, support, and partnership communications with us; and
- Events, webinars, and other interactions you have with SwishX.
This policy does not apply to third-party websites, applications, or services that we do not own or control, even if they are linked from our Services, or to information processed by our customers as independent data controllers within their own systems (for example, a customer's Veeva Vault instance).
Where a customer organization ("Customer") has deployed Content IQ for its own commercial or medical teams, SwishX generally acts as a data processor (or "service provider" under U.S. state law) on behalf of that Customer with respect to the content, briefs, and business data the Customer submits to the Services, and the terms of our Data Processing Addendum with that Customer govern that processing. This policy separately describes how SwishX acts as a data controller with respect to account administrators, authorized users, website visitors, and prospective customers.
2. Who we are
SwishX is the company responsible for the Content IQ platform described in this policy. For purposes of the EU General Data Protection Regulation ("GDPR") and the UK GDPR, SwishX is the data controller for the personal data described in Section 4, except where we act as a processor on behalf of a Customer as described above.
SwishX serves customers globally, with a primary focus on the United States market and growing operations supporting the European Union, the United Kingdom, and other regions. Where required by applicable law, SwishX maintains a representative for GDPR and UK GDPR purposes; contact details are provided in Section 22.
3. Definitions
- Personal Data means any information relating to an identified or identifiable natural person.
- Processing means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
- Data Subject means the individual to whom Personal Data relates.
- Controller means the entity that determines the purposes and means of processing Personal Data.
- Processor / Service Provider means the entity that processes Personal Data on behalf of, and under the instructions of, a Controller.
- Brand Dossier means the brand, label, reference, and creative materials a Customer supplies to Content IQ as the source of truth for generated content.
- Generated Content means video, visual aid, email, document, or other output produced by Content IQ from a Customer's brief and Brand Dossier.
4. Information we collect
We collect the following categories of information:
4.1 Account & profile information
Name, work email address, job title, employer, phone number, password (stored in hashed form), and profile preferences, collected when you or your organization creates a Content IQ account or when we set up a demo or trial on your behalf.
4.2 Customer content
Briefs, objectives, Brand Dossier materials (approved labeling, reference libraries, brand visual identity, fair-balance and safety language), and any other content a Customer or its authorized users upload, paste, or connect (including via a Veeva Vault or similar integration) in order to generate assets. This may include content that references named individuals (for example, a physician featured in a Digital Twin Video), consent records, and likeness or voice samples submitted for that purpose.
4.3 Usage & product data
Log data, feature usage, session duration, click and navigation events, device and browser type, IP address, approximate location derived from IP address, and diagnostic/crash data, collected automatically as you use the Services.
4.4 Communications data
Records of your correspondence with us, including support tickets, sales conversations, survey responses, and event registrations.
4.5 Payment information
Billing name, billing address, and payment method details, processed on our behalf by a PCI-compliant third-party payment processor. SwishX does not store full payment card numbers on its own systems.
4.6 Cookies and similar technologies
See Section 8 for details on cookies and tracking technologies.
5. How we use information
We use the information described in Section 4 to:
- Provide, operate, and maintain the Services, including generating content from a Brand Dossier and brief;
- Authenticate users, administer accounts, and manage subscriptions and billing;
- Provide customer support and respond to inquiries;
- Monitor, analyze, and improve the performance, reliability, and features of the Services;
- Detect, investigate, and prevent fraud, abuse, and security incidents;
- Communicate with you about updates, security notices, and (where you have opted in) product news and marketing;
- Comply with legal obligations, enforce our Terms of Service, and protect the rights, property, and safety of SwishX, our customers, and others; and
- With respect to Customer content, provide the generation, review, and governance functionality Content IQ is contracted to perform for that Customer.
6. Legal bases for processing
Where the GDPR or UK GDPR applies, we rely on the following legal bases to process personal data:
- Contract: processing necessary to provide the Services under our agreement with you or your organization.
- Legitimate interests: processing necessary for our legitimate interests in operating, securing, and improving the Services, provided those interests are not overridden by your rights and interests.
- Consent: processing based on your consent, such as opt-in marketing communications or certain cookies, which you may withdraw at any time.
- Legal obligation: processing necessary to comply with a legal or regulatory obligation to which we are subject.
7. AI and content generation
Content IQ uses artificial intelligence and machine learning models, including third-party foundation models, to help generate drafts, claims linkage, and creative assets from the Brand Dossier and brief a Customer provides. In connection with this functionality:
- We do not use Customer content (including Brand Dossier materials, briefs, or generated assets) to train foundation models on behalf of third-party AI providers, and we contractually restrict our model providers from doing so with Customer content processed through the Services.
- Generated Content is produced to assist your team; it is not a substitute for your organization’s own Medical, Legal, and Regulatory (MLR) review, and we do not make final publication decisions on your behalf.
- Where a brief involves a named individual (for example, a Digital Twin Video built from a physician’s voice and photo), the Customer is responsible for obtaining and documenting that individual’s consent before submitting the material to the Services, and SwishX processes it solely to render the requested asset.
- We may use de-identified or aggregated usage data (which does not identify any individual or Customer) to monitor and improve the accuracy and performance of our own generation pipelines.
10. International data transfers
SwishX is based in the United States and works with service providers located in the United States and other countries. If you are located in the European Economic Area, the United Kingdom, or Switzerland, your information may be transferred to, stored, and processed in a country that has not been deemed to offer an adequate level of data protection by the European Commission or the UK authorities.
Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on recognized transfer mechanisms, including the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), and, where applicable, participation in the EU-U.S. Data Privacy Framework and its UK and Swiss extensions. We conduct transfer impact assessments where required and implement supplementary technical and organizational measures, including encryption, to protect transferred data.
11. Data retention
We retain personal data for as long as necessary to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Retention periods vary by data category:
- Account and profile data: retained for the life of the account, and for a limited period after closure to allow reactivation and meet legal retention obligations.
- Customer content, including Brand Dossier materials and Generated Content: retained per the retention terms in the applicable Customer agreement, and deleted or returned upon termination in accordance with that agreement.
- Usage and log data: typically retained for up to 24 months for security, analytics, and troubleshooting purposes.
- Billing records: retained for the period required by applicable tax and accounting law, typically up to 7 years.
- Marketing communication preferences and consent records: retained until you withdraw consent or opt out, plus a reasonable period to evidence compliance.
Where we no longer need personal data for the purposes described in this policy, we delete or de-identify it, unless a longer retention period is required or permitted by law.
12. Data security
We maintain technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, and destruction, including encryption in transit and at rest, role-based access controls, network segmentation, logging and monitoring, and regular security testing. Full details of our security program are published on our Security page. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Your privacy rights
If you are located in the EEA, the UK, Switzerland, or another jurisdiction that grants similar rights, you have the right, subject to applicable law and certain exemptions, to:
- Access the personal data we hold about you and receive a copy of it;
- Request correction of inaccurate or incomplete personal data;
- Request erasure of your personal data;
- Request restriction of, or object to, our processing of your personal data;
- Receive your personal data in a portable, machine-readable format (data portability); and
- Withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, contact us using the details in Section 22. We will respond within the timeframe required by applicable law (generally one month under the GDPR, extendable in certain circumstances). You also have the right to lodge a complaint with your local data protection supervisory authority; a list of EU authorities is available from the European Data Protection Board, and UK residents may contact the Information Commissioner's Office (ICO).
14. California privacy rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), grants you the following rights with respect to your personal information:
- Right to know the categories and specific pieces of personal information we have collected, the sources, the purposes of collection, and the categories of third parties with whom we share it.
- Right to delete personal information we have collected from you, subject to certain exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of the "sale" or "sharing" of personal information. SwishX does not sell personal information and does not share it for cross-context behavioral advertising in the sense contemplated by the CCPA.
- Right to limit the use and disclosure of sensitive personal information, where applicable.
- Right to non-discrimination for exercising any of these rights.
You may exercise these rights by contacting privacy@swishx.com. We will verify your request using information already associated with your account or, for non-account holders, information you provide for verification purposes. You may also designate an authorized agent to make a request on your behalf, subject to proof of authorization.
15. Other U.S. state privacy rights
If you reside in a U.S. state with a comprehensive consumer privacy law (including, among others, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana), you may have rights similar to those described in Section 14, such as the right to access, correct, delete, and port your personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. We honor valid requests from residents of these states in accordance with the applicable law. To exercise these rights, contact us using the details in Section 22.
16. Children's privacy
The Services are directed at business professionals and are not directed to, marketed to, or intended for use by children. We do not knowingly collect personal data from individuals under the age of 16. If we learn that we have collected personal data from a child in violation of this policy, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us at privacy@swishx.com.
17. Automated decision-making
Content IQ uses AI to assist in drafting and structuring marketing content, but it does not make solely automated decisions that produce legal effects concerning you or similarly significantly affect you. Generated Content is designed to enter your organization's own Medical, Legal, and Regulatory review process, and publication decisions remain with your organization's human reviewers. If you have questions about the logic underlying a specific generation, contact us using the details in Section 22.
18. Health information & HIPAA
Content IQ is a marketing content platform for pharmaceutical and medtech commercial teams. It is designed to process brand, label, claims, and creative materials, not individual patient health records. SwishX is not, by virtue of providing the Services, a "covered entity" or "business associate" under the U.S. Health Insurance Portability and Accountability Act ("HIPAA"), and the Services are not intended to be used to process protected health information ("PHI") as defined by HIPAA. If your use case requires the processing of PHI, please contact us before submitting such information to the Services so we can discuss whether a Business Associate Agreement or an alternative solution is appropriate.
19. Do Not Track
Some browsers offer a "Do Not Track" ("DNT") signal. Because there is no common industry standard for DNT, our Services do not currently respond differently to DNT browser signals. We will update this policy if that changes.
20. Third-party links
Our websites and Services may contain links to third-party websites, including reference sources, industry publications, and integration partners. We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies before providing them with personal data.
21. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will post the updated policy on this page with a revised "Last updated" date, and, where a change is material, we will provide additional notice, such as an email to account administrators or a notice within the Services.
22. Contact us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
SwishX Privacy Team
privacy@swishx.com
EEA and UK residents may also contact our designated representative using the same email address, and may lodge a complaint with their local supervisory authority at any time.