Privacy Policy

Last updated: September 7, 2026

This Privacy Policy explains how Unipile SAS (“Unipile”, “we”, “us” or “our”) processes personal data in connection with its website, its relationships with prospects and customers, and the provision of its unified APIs.

Unipile processes personal data in accordance with Regulation (EU) 2016/679 of 27 April 2016 (the “GDPR”), the amended French Data Protection Act No. 78-17 of 6 January 1978, and any other applicable data protection laws.

1. WHO ARE WE?

Unipile SAS is a company incorporated under French law, with its registered office at:

168 rue de la Rotonde
42153 Riorges
France

You can contact us:

2. OUR ROLES WHEN PROCESSING PERSONAL DATA

2.1. When you visit our website or have a business relationship with Unipile

Unipile acts as a data controller when it determines the purposes and means of processing related in particular to:

  • browsing the unipile.com website;
  • contact or demonstration requests;
  • the creation and administration of customer accounts;
  • subscription, billing and support management;
  • administrative communications and, where permitted by law, marketing communications;
  • the security of the website and our services.

2.2. When our customers use the Unipile APIs

For data processed through accounts and services connected to the API, the Unipile customer determines the purposes and means of processing. The customer therefore acts as the data controller, and Unipile acts as its data processor.

In this context, Unipile processes data solely to provide the services, in accordance with the customer’s documented instructions and the Data Processing Agreement (“DPA”) entered into with that customer. The customer is responsible in particular for the lawfulness of the collection, informing data subjects, and handling requests to exercise their rights.

If you are an end user, prospect, contact or correspondent of an Unipile customer and your request concerns data processed on that customer’s behalf, please contact the customer directly. If such a request is sent directly to us, we will forward it to the relevant customer as soon as possible.

3. DATA SUBJECTS

This Privacy Policy may apply to:

  • visitors to the unipile.com website;
  • prospects, customers and customer representatives;
  • employees, staff, developers and API account administrators authorised by our customers;
  • end users, prospects, leads, customers and other contacts communicating through accounts connected by our customers.

4. DATA PROCESSED BY UNIPILE AS A CONTROLLER

Depending on your relationship with Unipile, we may process the following categories of data:

  • Identification and contact data: first and last name, professional email address, company name, job title and contact details provided when creating an account or contacting us.
  • Contract and account data: account identifiers, subscription details, service preferences, support history and administrative communications.
  • Billing data: billing address, information required to issue invoices, and limited payment-related information. Full payment card details are processed by our payment provider and are not stored by Unipile.
  • Technical and browsing data: IP address, browser type and version, operating system, device identifier, language, pages visited, date and time of access, connection data, and information obtained through cookies or similar technologies.
  • Aggregated usage data: statistics relating to the use of the website and the API services selected, used to understand usage and improve our services.

5. PURPOSES AND LEGAL BASES

We process this data for the following purposes and on the following legal bases:

Purpose Legal basis
Responding to contact, demonstration or information requests Unipile’s legitimate interest in responding to requests and, where applicable, steps taken before entering into a contract
Creating and administering customer accounts, providing the services and managing subscriptions Performance of a contract or pre-contractual steps
Managing billing, payments and accounting Performance of a contract and compliance with our legal obligations
Providing support and sending service-related notifications Performance of a contract and our legitimate interest in ensuring that the service operates properly
Securing the website, preventing misuse and investigating incidents Our legitimate interest in protecting our systems, users and services
Measuring audiences and improving the website and our services Consent where required; otherwise, our legitimate interest
Sending marketing communications Consent where required, or our legitimate interest where permitted by law
Responding to data-subject requests and competent authorities Compliance with our legal obligations

Where processing is based on your consent, you may withdraw it at any time. Withdrawal will not affect the lawfulness of processing carried out before it was withdrawn.

6. DATA PROCESSED THROUGH THE API SERVICES

The Unipile APIs allow our customers to connect platforms such as LinkedIn, WhatsApp and Telegram, as well as email and calendar providers, through a unified schema.

Whether and for how long data is stored depends on the service version, the connected channel and the configuration selected by the customer.

Category Examples Storage and retention
Messaging content Text messages, attachments, images, documents and voice notes V1: messages, conversations and participants are stored until the account is deleted. V2 WhatsApp: the same categories are stored in encrypted form until the account is deleted. V2 other channels: transient processing without storage.
Email content and metadata Headers, sender and recipient addresses, plain-text or HTML body, and attachments V1 Microsoft/IMAP: metadata only is stored until account deletion; email bodies are not stored. V1 Gmail: no storage. V2: transient processing.
Social profiles and conversation metadata Contact names, profile links, avatar URLs and conversation status V1 and V2: no storage or caching; no retention.
Calendar data Event titles, dates and times, descriptions, meeting links and participant email addresses V1: no storage or caching. V2: cached for one hour by default; the user may configure this period.
Network and proxy metadata Destination host, connection timing, request IP addresses and data transmission volume Processed transiently in memory during an active connection where the customer chooses to use Unipile proxies; not retained after transmission. Proxy providers only route network connections. Message content is encrypted in transit and is not decrypted, accessed or stored by the proxy providers.
Authentication data for connected accounts OAuth tokens, encrypted access tokens and session identifiers V1 and V2 IMAP: credentials are stored in encrypted form. Other V1 and V2 connections: only an encrypted session token is stored. Google and Microsoft use external OAuth, and credentials do not transit through Unipile. Retained until the account is deleted or the service ends.
Transient login credentials Password supplied during the initial account connection Where the user chooses this method for a messaging service, the credential transits solely for login and is not retained; only the token is stored.

Unipile does not use data processed on behalf of its customers for its own purposes. Data is collected, accessed, transmitted, cached or stored only to the extent necessary to provide the relevant service and in accordance with the customer’s instructions.

7. RETENTION PERIODS

Data processed on behalf of our customers is retained for the periods set out in Section 6.

When the agreement ends, Unipile will, at the customer’s choice, return or delete the personal data received in connection with the service, including copies held in its systems, except where retention is required by law or necessary for statutory archiving purposes. The same obligations apply to our sub-processors.

For processing carried out by Unipile as a controller:

  • account registration data is retained for the duration of the contractual relationship and for 30 days after account deletion, without prejudice to applicable statutory retention periods;
  • technical and browsing information is retained for 30 days from collection, unless longer retention is necessary for security purposes or to investigate an incident;
  • limited payment information retained in the event of a payment anomaly is kept for no more than 7 days;
  • data required for billing and accounting is retained for the periods prescribed by applicable law;
  • cookies are retained for the period stated in our cookie-management tool and, in all cases, within the limits prescribed by applicable law.

8. RECIPIENTS AND SUB-PROCESSORS

Access to data is limited to Unipile personnel who need it to perform their duties and who are subject to confidentiality obligations.

Unipile uses the following sub-processors in connection with its API services. Each provider name links to its own privacy policy (external links, opens in a new tab).

Sub-processor Activity Country of establishment Data location Transfer safeguard
SCALEWAY SAS Cloud hosting and infrastructure France France (EU) Not applicable, intra-EEA transfer
OXYLABS UAB Network proxy services Lithuania European Union Not applicable, intra-EEA transfer
DECODO UAB (formerly Smartproxy) Network proxy services Lithuania European Union Not applicable, intra-EEA transfer
BRIGHT DATA LTD Network proxy services Israel Israel / EU European Commission adequacy decision
WEBSHARE SOFTWARE COMPANY Network proxy services United States United States Standard Contractual Clauses, Module 3, and a transfer impact assessment
INFATICA PTE. LTD. Network proxy services Singapore Singapore / EU Standard Contractual Clauses, Module 3, and a transfer impact assessment
CRISP IM SAS Customer support platform (V1) France France (EU) Not applicable, intra-EEA transfer
INTERCOM R&D UNLIMITED COMPANY Customer support platform (V2) Ireland United States / EU (Dublin) EU-U.S. Data Privacy Framework certification, UK Extension and Swiss framework, and/or Standard Contractual Clauses, Module 3

Unipile may also use service providers required for processing carried out for its own purposes, including a payment provider to process online payments.

Unipile does not sell personal data. We disclose it only where necessary to provide our services, comply with the law, defend our rights, or protect our systems and users.

Unipile contractually requires its sub-processors to comply with data protection obligations that are at least equivalent to those imposed on Unipile. Unipile remains responsible to its customers for the performance of obligations entrusted to its sub-processors.

9. TRANSFERS OUTSIDE THE EUROPEAN ECONOMIC AREA

Where personal data is transferred outside the European Economic Area, Unipile ensures that the transfer is based on a mechanism recognised under Chapter V of the GDPR, such as:

  • an adequacy decision adopted by the European Commission;
  • the European Commission’s Standard Contractual Clauses, supplemented where necessary by a transfer impact assessment and additional safeguards;
  • valid certification under the EU-U.S. Data Privacy Framework where that mechanism applies.

You may contact our DPO for further information about the applicable safeguards.

10. SECURITY AND CONFIDENTIALITY

Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the risks to individuals, Unipile implements appropriate technical and organisational measures to protect the confidentiality, integrity and security of personal data.

These measures include limiting access to authorised personnel, confidentiality commitments, appropriate staff training, and encrypting data or tokens where stated in this Privacy Policy.

If a personal data breach affects processing carried out on behalf of a customer, Unipile will notify that customer without undue delay after becoming aware of it and will provide the available information needed to help the customer meet its regulatory obligations.

11. YOUR RIGHTS

Subject to the conditions and limitations set by applicable law, you may request:

  • access to your personal data;
  • correction of inaccurate or incomplete data;
  • deletion of your data;
  • restriction of processing;
  • objection to processing based on legitimate interests;
  • portability of data you provided to us where processing is based on consent or a contract and is carried out by automated means;
  • withdrawal of your consent at any time;
  • not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you, in the circumstances covered by the GDPR.

For processing for which Unipile is the controller, you may exercise your rights by writing to dpo@unipile.com or start@unipile.com. To protect your data, we may request information reasonably necessary to verify your identity.

We will respond within the time limits prescribed by law, generally within one month after receiving a complete request. This period may be extended by two further months depending on the complexity and number of requests; if so, we will inform you.

Where Unipile processes your data on behalf of one of its customers, please submit your request to that customer as the data controller. Unipile will provide the customer with the necessary assistance.

You may also lodge a complaint with the French Data Protection Authority (CNIL) or the competent supervisory authority in the country where you live or work.

12. DATA FROM GOOGLE API SERVICES

Unipile’s use and transfer to any other application of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

13. COOKIES

When you visit unipile.com, cookies or similar technologies may be placed on your device. Some are strictly necessary for the operation and security of the website and do not require consent. Non-essential cookies, including those used for audience measurement or personalisation, are placed only after obtaining your consent where required.

You may accept or reject cookies and change your choices at any time through the cookie-management tool available on the website. Withdrawal of consent does not affect the lawfulness of processing carried out before that withdrawal.

The purposes, providers and retention periods for individual cookies are listed in the cookie-management tool. Your choices will remain valid for no longer than the period permitted by applicable law.

You can also manage cookies directly in your browser settings:

14. CHANGES TO THIS PRIVACY POLICY

We may amend this Privacy Policy to reflect changes in our services, processing activities or applicable law. The date of the latest update appears at the beginning of the document. If a change is material, we will take appropriate steps to inform you.

15. CONTACT US

For any question or complaint concerning this Privacy Policy or our personal data practices, please contact:

Data Protection Officer, Unipile SAS
168 rue de la Rotonde
42153 Riorges
France

dpo@unipile.com

Language of this Privacy Policy. This Privacy Policy is written in English, and the English version is the authoritative version. Versions in other languages are provided through automatic translation for convenience only. In the event of any discrepancy or inconsistency, the English version prevails.

en_USEN