1. Introduction

This Privacy Policy explains how AppSwing s.r.o. ("we", "us", or "our"), the operator of the InfraPoint platform, collects, uses, stores, and protects your personal data when you access or use our IT Service Management software-as-a-service ("Service"). InfraPoint is a multi-tenant, ITIL-aligned platform that provides incident management, problem management, change management, release management, and related IT service management capabilities to business customers.

We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), applicable national data protection legislation, and other relevant privacy laws. This policy is provided in fulfilment of our obligations under Articles 13 and 14 of the GDPR.

By accessing the InfraPoint platform, creating an account, or using any of our services, you acknowledge that you have read and understood this Privacy Policy. If you are using the Service on behalf of an organisation, you confirm that you have the authority to bind that organisation to these terms.

2. Data Controller

The data controller responsible for processing your personal data is:

AppSwing s.r.o.

Privacy contact: hello@infrapoint.io

Where your organisation has entered into a subscription agreement with us for InfraPoint, your organisation acts as the data controller for any personal data submitted to the platform by its users, and we act as the data processor. A data processing agreement meeting the requirements of Article 28 of the GDPR is available on request.

3. Data We Collect

Personal Data

When you register for an account or are invited to a tenant workspace, we collect your full name, business email address, and your department and team assignments within your organisation's workspace. If your organisation provides billing details, we also collect the company billing address, tax identifiers, a billing email address, and optionally a business phone number.

Usage Data

The platform records the actions you perform on records as part of its audit trail: tickets created or modified, status changes, approvals, comments, and similar workflow actions, together with their timestamps. This record exists so that your organisation has a complete history of its IT service management activity.

Device & Technical Data

Our server logs record standard HTTP request data: your IP address, browser type and version, operating system as reported by your browser, and the requested URL. These logs are used for security monitoring and troubleshooting. Your interface language preference is stored with your user profile.

4. How We Use Your Data

Service Delivery

We process your personal data to provision and maintain your tenant workspace, authenticate your identity, manage role-based access controls, deliver ITSM functionality including ticket management, workflow automation, change approval processes, and release scheduling, and to provide customer support.

Communication

We use your contact information to send transactional notifications related to your use of the Service, such as ticket assignment alerts, approval requests, SLA breach warnings, release window reminders, and system status updates. We may also send you service announcements, security advisories, and product updates relevant to your subscription.

Service Improvement

We analyse aggregated and anonymised usage data to identify trends, diagnose technical issues, optimise platform performance, develop new features, and improve the overall user experience. This analysis does not involve the identification of individual users.

Legal Compliance

We may process your data where necessary to comply with applicable legal obligations, respond to lawful requests from public authorities, enforce our terms of service, or protect our rights, property, or safety or that of our users and the public.

6. Data Sharing & Third Parties

We do not sell your personal data. We may share data with the following categories of recipients, each bound by contractual data protection obligations:

  • • Infrastructure providers: Cloud hosting and database services that store and process data on our behalf, operating under strict data processing agreements.
  • • Communication services: Email delivery services used to send transactional messages, such as ticket notifications, on our behalf.
  • • Payment processing: Subscription billing is handled by Stripe. Card details are entered with and stored by Stripe; we never see or store card numbers on our servers.
  • • Identity providers: If you choose to sign in with Google, Google processes your sign-in according to its own privacy policy; we receive your name and email address from that sign-in.
  • • Legal and regulatory authorities: Where required by law, court order, or regulatory obligation.

7. International Data Transfers

Your data is primarily stored and processed within the European Economic Area (EEA). Where we transfer personal data outside the EEA, we ensure that appropriate safeguards are in place in accordance with Chapter V of the GDPR, including Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions, or other lawful transfer mechanisms.

In our cloud service, each organisation's data is stored in its own dedicated database, physically separate from every other customer. Tenant data is never co-mingled or accessible across organisational boundaries. Organisations that require full control can run InfraPoint on their own infrastructure instead.

8. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. Specifically:

  • • Account data is retained for the duration of your organisation's active subscription and for 90 days thereafter to allow for reactivation.
  • • ITSM operational data (tickets, changes, releases, audit logs) is retained for as long as your workspace exists, so that your organisation's operational history stays complete, and is removed together with the workspace.
  • • Server logs are retained for up to 12 months for security and troubleshooting purposes.
  • • Billing records are retained for the period required by applicable tax and financial regulations.

Upon termination of a subscription, your data remains available for export on request for 30 days, after which it is permanently deleted within a further 30 days, unless a longer retention period is required by law or has been agreed upon in writing.

9. Your Rights

Under the GDPR (Articles 15 through 22), you have the following rights in relation to your personal data:

  • • Right of access (Article 15): You may request a copy of the personal data we hold about you, along with information about how it is processed.
  • • Right to rectification (Article 16): You may request the correction of inaccurate personal data or the completion of incomplete data.
  • • Right to erasure (Article 17): You may request the deletion of your personal data where it is no longer necessary for the purposes for which it was collected, or where you withdraw consent.
  • • Right to restriction of processing (Article 18): You may request that we restrict the processing of your data in certain circumstances, such as when you contest the accuracy of the data.
  • • Right to data portability (Article 20): You may request to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
  • • Right to object (Article 21): You may object to the processing of your personal data where we rely on legitimate interests as the legal basis, including profiling based on those interests.
  • • Right not to be subject to automated decision-making (Article 22): You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.

To exercise any of these rights, please write to hello@infrapoint.io. We will respond to your request within 30 days. You also have the right to lodge a complaint with your local supervisory authority if you believe your data protection rights have been violated.

10. Cookie Usage

InfraPoint sets only the cookies that are strictly necessary for the Service to function: session state, authentication, and protection against request forgery. We do not use analytics, advertising, or tracking cookies, which is also why you will not see a cookie consent banner on our site.

For detailed information about the specific cookies we use, their purposes, and how to manage your cookie preferences, please refer to our Cookie Policy.

11. Children's Privacy

InfraPoint is a business-to-business platform designed for use by organisations and their authorised employees. Our Service is not directed at individuals under the age of 16, and we do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child under 16, we will take prompt steps to delete that information. If you believe a child has provided us with personal data, please contact us at hello@infrapoint.io.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or the functionality of the Service. When we make material changes, we will notify you by posting a prominent notice within the InfraPoint dashboard and, where appropriate, sending an email to your registered address. The "Last updated" date at the bottom of this page indicates when the most recent revision was published. We encourage you to review this policy periodically.

13. Contact Us

If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have concerns about how we handle your personal data, please contact us:

AppSwing s.r.o.

Privacy contact: hello@infrapoint.io

Last updated: 13 September 2026