Legal
Privacy Policy
Last updated: September 2026
1. Who We Are
This website and the Swarm platform (swarm.velocitynorth.ai) are operated by Suya AB (org. no. 559024-5717), trading as Velocity North — a performance marketing agency based in Gothenburg, Sweden and Oslo, Norway. Suya AB acts as data controller for the personal data collected through this website, and as data processor for the marketing data our clients connect to Swarm.
Contact: hello@velocitynorth.ai
This policy covers both velocitynorth.ai and the Swarm application. Sections 7–11 apply specifically to data we access from your Google account with your permission.
2. Data We Collect
We collect the following categories of personal data:
- // Contact information you submit via our contact form (name, email, phone, company)
- // Usage data collected via analytics tools (pages visited, session duration, referrer)
- // Conversion data collected server-side for campaign attribution purposes
- // Technical data such as IP address, browser type, and device type
- // Swarm account data (name, work email, hashed password, multi-factor authentication secret, role and client assignments)
- // Marketing platform data you choose to connect to Swarm, including data from your Google account (see section 7)
3. How We Use Your Data
We use your personal data for the following purposes:
- // Responding to enquiries submitted through our contact form
- // Improving our website and marketing performance
- // Providing performance marketing services to our clients
- // Operating the Swarm platform: authenticating you, rendering your dashboards and reports, and executing changes you or your colleagues explicitly approve
- // Complying with legal obligations
4. Legal Basis (GDPR)
- // Legitimate interest — analytics and website improvement
- // Consent — marketing cookies, contact form submissions, and connecting a Google or other advertising account to Swarm
- // Contract — data processing for clients under a signed agreement
- // Legal obligation — where required by law
5. Cookies and Tracking
We use strictly necessary cookies, analytics cookies (Google Analytics 4), and marketing cookies (Google Ads, Meta Ads) — the latter only with your consent. We also use server-side tracking via our Digtective attribution platform under a separate data processing agreement.
6. Data Sharing
We do not sell your personal data. We may share data with Google, Meta, HubSpot, and hosting providers acting under a data processing agreement. We do not transfer or disclose your information to third parties for purposes other than those described in this policy, except where required by law.
7. Google User Data: What Swarm Accesses
Swarm is a marketing analytics platform for agencies and their clients. If you choose to connect your Google account, Swarm accesses data from your own Google accounts and properties, using the narrowest scopes Google makes available for each task:
- // Google Ads (
adwords) — reads daily campaign performance (spend, impressions, clicks, conversions) from your own Google Ads accounts for reporting. Changes such as budget adjustments are written to your own campaigns only after a named human user approves each individual change in our audit-logged approval queue. Google Ads offers no read-only scope, so this is the narrowest scope available. - // Google Analytics (
analytics) — reads GA4 metrics (sessions, engagement, conversions) for your own properties, so site performance can be shown alongside advertising data. We do not create, modify or delete your Analytics configuration. - // Search Console (
webmasters.readonly) — reads impressions, clicks and query data for your own verified sites for organic search reporting. - // Google account identity — the email address and account identifiers associated with the connection, so we can label the connection and refresh it.
The connection is made through Google OAuth. You grant it explicitly, you can see exactly which scopes are requested on Google’s consent screen, and you can withdraw it at any time (see section 10). Swarm never asks for, receives or stores your Google password.
8. How We Use and Share Google User Data
Google user data is used solely to render your own dashboards, reports and recommendations, and to execute changes a human on your team has approved. Specifically:
- // We never sell Google user data, and we never transfer it to data brokers, resellers or information resellers.
- // We never use it for advertising, including targeted, personalised or retargeted advertising, or for determining creditworthiness or lending purposes.
- // We never share it across tenants. Each customer’s data is isolated and accessible only to users explicitly assigned to that customer.
- // We do not use it to develop, improve or train generalised or non-personalised AI or machine learning models. Where Swarm uses AI models to generate recommendations for your own account, data is processed under contract solely to produce output for you, and our AI providers are contractually prohibited from retaining it or training on it.
- // Humans do not read your Google user data except: with your explicit consent (for example, when you ask our support team to investigate); where necessary for security purposes such as investigating abuse; to comply with applicable law; or where the data has been aggregated and anonymised for internal operations such as capacity planning.
- // We share Google user data only with infrastructure sub-processors that host or transmit it on our behalf under a data processing agreement (our EU hosting provider and our AI model provider as described above), and only to the extent needed to operate the service for you.
Velocity North’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
9. How We Protect Your Data
We apply the following technical and organisational security measures to all personal data, and in particular to sensitive data such as OAuth credentials and the Google account data described in section 7:
- // Encryption in transit — all traffic to velocitynorth.ai and to Swarm is served over HTTPS using TLS 1.2 or higher, with HTTP Strict Transport Security (HSTS) enforced. All calls to Google APIs are made over TLS.
- // Encryption at rest — OAuth access and refresh tokens are encrypted at rest with authenticated encryption (AES with HMAC integrity protection). Personal data fields such as account email addresses, contact details and multi-factor authentication secrets are encrypted at the field level in the database, so they are unreadable in database dumps and backups.
- // Credential handling — OAuth client secrets and encryption keys are held in a dedicated secret store, never in source code, never in configuration files committed to version control, and never exposed to the browser. Tokens are never written to application logs, and personal data is excluded from structured logging by design.
- // Access control — access to Swarm is authenticated and governed by role-based access control on the principle of least privilege. Read-only client users can only reach the specific accounts assigned to them, enforced on every data-returning endpoint. Multi-factor authentication (TOTP) is available for all accounts and required for administrative access.
- // Staff access — administrative access to production systems and to Google user data is limited to a small number of named Velocity North personnel, granted on a need-to-know basis, bound by confidentiality obligations, and revoked when no longer required or when someone leaves.
- // Human approval for write operations — no change is written back to your Google Ads account automatically. Every individual change passes through an approval queue where a named human approves or rejects it, and rate limits cap the volume of actions that can be taken.
- // Audit logging — every action taken on a connected account is recorded in an append-only audit log including who approved it, when, and what changed, so activity can be reconstructed and reviewed.
- // Infrastructure — Swarm runs on access-controlled, firewalled servers hosted in the EU (Hetzner, Finland). Services run in isolated containers, database accounts are separated by privilege level, backups are encrypted and access-restricted, and dependencies are patched on an ongoing basis.
- // Monitoring and incident response — systems are monitored for anomalies and failures. We maintain a documented incident response process; where a personal data breach occurs we notify the competent supervisory authority within 72 hours and affected individuals without undue delay, as required by the GDPR.
- // Review — access rights and security controls are reviewed at least annually and whenever personnel or infrastructure change materially.
No system can be guaranteed absolutely secure, but these measures are designed to protect the confidentiality and integrity of your data against unauthorised access, disclosure, alteration and loss.
10. Retention and Deletion of Google User Data
We retain Google user data only for as long as needed for the purposes described above:
- // Performance metrics imported from Google Ads, Analytics and Search Console are retained for up to 2 years so that year-over-year reporting works, then deleted automatically.
- // OAuth tokens are retained only while the connection is active.
- // Records of approved changes are retained as audit records for as long as required to evidence the lawful basis for those actions.
Revoking access: you can disconnect your Google account at any time from the connections screen in Swarm, or from your Google Account at myaccount.google.com/permissions. When you revoke access, we delete the stored OAuth tokens immediately and stop all further data collection.
Deleting your data: you may request deletion of the Google user data we hold by emailing hello@velocitynorth.ai. We delete imported Google user data within 30 days of a verified request, and in any case within 90 days of the termination of your account or contract, except where we are legally required to retain specific records.
11. Data Retention (Website)
Contact form submissions are retained for up to 2 years. Analytics data follows the default retention periods set by the respective platforms.
12. Your Rights
Under GDPR you have the right to access, correct, delete, restrict, or port your data, and to lodge a complaint with your national data protection authority. Contact us at hello@velocitynorth.ai.
13. Changes to This Policy
We may update this policy from time to time. The date at the top reflects the most recent revision, and we notify users of material changes affecting connected accounts by email or in-app notice.