Legal
We publish this in full because the way an organisation handles data is itself a statement of governance. This site collects almost nothing, and we would rather show you than claim it.
Common Swift is a venture development and commercialization platform managed by PT Synaptech Synergy Group ("SSG"), a limited liability company incorporated in the Republic of Indonesia. SSG is the data controller for this website and for the Common Swift executive platform.
| Controller | PT Synaptech Synergy Group |
| Registered office | Arcade Business Center, 6th Floor, Jl. Pantai Indah Utara 2 Kav. C1, PIK Jakarta Utara 14460, Indonesia |
| Privacy contact | privacy@common-swift.pro |
| General contact | info@common-swift.pro |
This policy applies to common-swift.pro (this public website) and common-swift.online (the authenticated executive platform). It does not apply to third-party websites reached from links on this site.
This site sets no cookies, runs no analytics and loads nothing from a third party. Typography is served from this domain, so no font provider receives your IP address. Visiting a page therefore creates only the standard server access record our hosting provider keeps to operate and secure the service:
We do not use these records to build a profile of you and we do not attempt to identify you from them.
If you write to one of our published addresses we hold your email address, your name as given, and the contents of your message.
If you request platform access we collect the information you provide on the registration form or by email to us — typically name, business email address, organisation, role, jurisdiction and stated interest — together with the account credentials and access tier assigned to you, and a record of your consent. Counterparty verification may require further documentation, which we will request from you directly and describe at the time.
Under the EU and UK General Data Protection Regulation we rely on the legal bases set out below. Where Indonesian law applies, the equivalent basis is that set out in Law No. 27 of 2022 on Personal Data Protection.
| Purpose | Legal basis |
|---|---|
| Operating, securing and maintaining the website | Legitimate interests — Art. 6(1)(f) |
| Answering your enquiry | Legitimate interests, or performance of a contract where one is in contemplation — Art. 6(1)(f) and 6(1)(b) |
| Registering you, verifying you as a counterparty and assigning an access tier | Performance of a contract, and consent for the disclosures identified at the point of collection — Art. 6(1)(b) and 6(1)(a) |
| Meeting legal, regulatory, tax and anti-money-laundering obligations | Legal obligation — Art. 6(1)(c) |
We do not sell personal data, we do not share it with advertising networks, and we do not use it for automated decision-making that produces legal effects for you.
This website uses no cookies, no local storage, no tracking pixels, no session recording and no third-party analytics.
Nothing on this page is loaded from an external domain, which is why you are not asked for cookie consent — there is nothing to consent to.
The authenticated executive platform at common-swift.online necessarily uses a strictly functional session cookie or token to keep you signed in. That is technically required to deliver the service you have asked for and is not used for tracking or advertising.
We use a small number of service providers who process personal data on our instructions only, under contract, and who may not use it for their own purposes.
| Provider | Function | Location |
|---|---|---|
| Hostinger International Ltd. | Website hosting, server logs, email | Indonesia (Jakarta) |
| Supabase, Inc. | Registration and account database for the executive platform | Zurich, Switzerland |
We will also disclose personal data where we are legally required to do so, and to our professional advisers where necessary and under a duty of confidence.
Our website and email services are hosted in Indonesia. The registration and account database supporting the executive platform is hosted in Switzerland.
Switzerland benefits from an adequacy decision of the European Commission and applies data protection standards materially equivalent to the EU General Data Protection Regulation. Transfers to our database processor in Switzerland are made on the basis of that adequacy finding together with contractual data processing terms.
Transfers are made in accordance with Law No. 27 of 2022 on Personal Data Protection of the Republic of Indonesia, which permits transfer to a jurisdiction with an equivalent or higher level of protection, or where adequate and binding safeguards are in place.
We do not transfer personal data to any other jurisdiction without an equivalent legal basis.
SSG is established in Indonesia. Indonesia is not the subject of an adequacy decision by the European Commission, so a transfer of personal data from the EEA or the United Kingdom to us is a transfer to a third country.
Where you send us personal data from the EEA or the UK, that transfer is safeguarded by one of the following:
To request a copy of the safeguards in place for a specific transfer, write to privacy@common-swift.pro.
| Category | Period |
|---|---|
| Server access logs | Retained by the hosting provider for its standard operational period, then deleted or aggregated |
| Email correspondence | Up to 24 months from the last exchange, unless it forms part of a live or completed transaction record |
| Registration and account records | For the life of the account, then up to 24 months after closure |
| Verification and transaction records | For the period required by applicable corporate, tax and anti-money-laundering law |
When a period ends we delete the data or irreversibly anonymise it.
Subject to the conditions in the applicable law, you may:
Equivalent rights of access, correction, erasure, termination of processing and objection are provided under Law No. 27 of 2022 on Personal Data Protection.
To exercise any of these, write to privacy@common-swift.pro. We answer without undue delay and in any event within one month of receipt, and will tell you if we need longer and why. There is no charge unless a request is manifestly unfounded or excessive. We may ask you to confirm your identity before we act.
Tell us first — we would rather fix it. You also have the right to complain to a supervisory authority: in the EEA or the UK, the authority for your country of residence, place of work or the place of the alleged infringement; in Indonesia, the authority designated under Law No. 27 of 2022.
The measures we apply to this site and platform include:
No system is perfectly secure. If you believe you have found a vulnerability, report it to privacy@common-swift.pro and we will respond.
This website and platform are directed at institutional counterparties and are not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
We may update this policy as the platform develops or the law changes. The version number and effective date at the top of this page always reflect the current text. Where a change materially affects how we handle personal data already provided to us, we will notify registered users directly.