unolia

Privacy Policy

The Privacy Policy translated into English is provided for informational purposes for the English-speaking public.
Only the French version holds contractual value. See the French version

1. Purpose and scope

This Policy explains how Unolia collects, uses, shares, and retains personal data related to the unolia.com website, the app.unolia.com application, support, API, and MCP server.

It distinguishes two roles:

  • Unolia as controller for account management, subscriptions, communications, security, and measurement of its own services
  • Unolia as the Customer's processor when the Customer chooses to import or process data about its own employees, customers, suppliers, or other people in its Workspace

Commitments that apply when Unolia processes data on behalf of the Customer also appear in Article 14 of the General Terms of Service.

2. Controller and contact details

The controller for Unolia's own processing is:

Eser DENIZ, French sole trader, 10 chemin du Bergeron, 27930 Huest, France, SIREN 801 040 338, SIRET 801 040 338 00023.

For questions or personal data requests, contact privacy@unolia.com.

This address is Unolia's data protection contact point. It does not mean that a Data Protection Officer has been formally appointed with the CNIL.

3. Data collected

The data actually processed depends on your use, role, plan, and Connected Services.

3.1. Account and authentication

Unolia may process:

  • name, email address, language, time zone, and profile picture
  • data required to display an avatar, such as a URL, public identifier, or email address sent to Unavatar
  • hashed password, email verification status, and last login date
  • date and version of legal acceptance
  • two-factor authentication secret, recovery codes, and active sessions
  • interface preferences, favorites, and recent projects
  • identifiers for a connected GitHub or GitLab account, username, email, scopes, expiry dates, and encrypted OAuth tokens

3.2. Workspace, team, and access

Unolia may process:

  • Workspace name and identifier
  • identity of members and invitees
  • roles, permissions, project access, and change history
  • identities observed in Connected Services, group membership, remote roles, and access differences
  • addresses and settings for notification destinations, including email and Slack

3.3. Connected Services and Credentials

When you connect a third-party service, Unolia may process:

  • provider name, account name, associated email address, account identifiers, and connection status
  • API keys, OAuth tokens, webhook secrets, credential pairs, and granted permissions
  • expiry dates, latest synchronizations, errors, and connection health information
  • resource selections and synchronization preferences

Tokens, credentials, and secrets supported by dedicated models are encrypted at the application level before storage. Some non-secret technical identifiers remain visible to support relationships, audits, and revocation.

3.4. Projects and infrastructure

Unolia may import, create, or calculate:

  • project names, domains, DNS zones, records, nameservers, propagation data, and certificates
  • public and private IP addresses, server names, regions, sizes, systems, versions, and statuses
  • websites, environments, associated domains, branches, scripts, and deployment history
  • names and, where required by a feature, values of environment variables or other technical secrets
  • monitoring data, checks, availability, incidents, causes, timelines, and source addresses
  • detected issues, technical evidence, proposed fixes, and recheck results

Values stored in dedicated secret stores are encrypted. Technical data such as an IP address, username, domain, or log may be personal data where it identifies a person.

3.5. Repositories, code, and dependencies

For GitHub, GitLab, and connected hosting services, Unolia may process:

  • repository name, owner, URL, visibility, default branch, and identifiers
  • commits, authors, usernames, email addresses, messages, branches, and references
  • CI runs, jobs, statuses, actors, durations, and result links
  • paths and limited contents of manifests and lockfiles needed to inventory dependencies
  • package names and versions, licenses, CVE alerts, security advisories, end-of-life data, and version differences
  • deployments, logs retrieved on request, and webhook metadata

Unolia does not aim to copy an entire repository. Content accessed depends on enabled features and granted permissions.

3.6. Costs, subscriptions, and billing

Unolia may process:

  • plan, billing interval, subscription status, trial dates, renewal, and cancellation
  • name or company name, billing email, address, country, VAT number, and other invoice details
  • Stripe identifiers, payment status, invoices, and the last four digits or card brand when returned by Stripe
  • imported or entered costs, uploaded supplier invoices, invoice lines, usage, licenses, currencies, exchange rates, and project allocations
  • email addresses designated to receive invoices

Unolia does not receive the full payment card number or card security code.

3.7. Automations, activity, API, and MCP

Unolia may process:

  • recipes, steps, triggers, settings, confirmations, outcomes, statuses, errors, and automation durations
  • encrypted automation secrets and information about their scope or expiry
  • activity performed by Users, tokens, webhooks, or systems
  • OAuth clients, API tokens, scopes, expiry, revocation, and last use
  • MCP calls, tool name, actor, effective scopes, outcome, duration, limited errors, and a redacted argument summary

MCP arguments are filtered against sensitive key names and truncated before storage. Unolia cannot identify every secret placed in a free-text field. Do not send a secret in a field not intended for it.

3.8. Support, communications, and marketing

Unolia may process:

  • name, email address, organization, and support conversation content
  • attachments, technical information, and communication dates
  • waitlist or newsletter subscription, consent, opt-out, and deliverability data
  • account-related aggregate usage information, such as numbers of projects or connections, to tailor service communications
  • signup and onboarding progress events, including the name, email address, and Workspace name concerned, forwarded to Unolia's internal Slack workspace for operational follow-up

3.9. Browsing, security, and observability

Unolia may process:

  • IP address, user agent, URL, date, time, session identifier, and security events
  • server logs, failed requests, error traces, performance data, and technical context required for diagnosis
  • marketing website and public application page audience data measured without advertising cookies by Fathom Analytics
  • network and security events processed by Cloudflare for the marketing website

The name, email address, and password fields are required to create an account. Without them, registration cannot be completed. Billing details and a payment method are required for a paid plan. Connected Service Credentials are optional, but the related feature cannot be provided without them.

4. Data sources

Data comes from:

  • you when you create an account, configure a Workspace, contact support, or enter information
  • the owner, administrators, or members of your Workspace
  • Connected Services and their webhooks according to granted permissions
  • public technical sources, including DNS, certificates, domain registries, version registries, security advisories, and exchange rates
  • operation of the Service, including logs, activities, diagnostics, matches, and estimates
  • Stripe for billing and payment status

5. Purposes and legal bases

Purpose Main data Legal basis
Create and administer the Customer's or representative's account Identity, authentication, and preferences Performance of the Contract or pre-contract steps
Manage Users invited by the Customer Identity, team, role, permissions, and activity Legitimate interest in providing the Service requested by the Customer and managing access
Secure accounts and the Service Sessions, IP, user agent, events, and logs Legitimate interest in preventing unauthorized access and abuse
Provide the Workspace and synchronize Connected Services Team, infrastructure, repository, monitoring, cost, and Credential data Performance of the Contract for the Customer. For other people in Customer Data, processing on the Customer's instruction
Run API, MCP tools, fixes, and automations Scopes, arguments, actions, outcomes, and logs Performance of the Contract or processing on the Customer's instruction depending on the data concerned
Manage subscriptions, payments, and invoices Billing details, plan, payment, and invoice Performance of the Contract and legal accounting and tax duties
Provide support and service communications Contact details, conversations, and technical information Performance of the Contract and legitimate interest in assisting Users
Follow signups and onboarding internally Name, email address, Workspace name, and onboarding events Legitimate interest in operating the Service and assisting new Customers
Prevent abuse and diagnose incidents IP, user agent, logs, errors, and traces Legitimate interest in protecting, maintaining, and improving the Service
Measure marketing website and public application page audience Page views and limited technical information Legitimate interest in understanding website use, subject to rules applying to tracking technologies
Send newsletters or promotional communications Email, subscription, preferences, and opt-out Consent where required, or legitimate interest where professional marketing is permitted
Defend rights and respond to authorities Data relevant to a dispute or request Legal obligation and legitimate interest in establishing, exercising, or defending rights

Where Unolia is a processor, the legal basis is determined by the Customer as controller. The Customer must inform data subjects and document that basis. Third-party data imported from Customer systems is normally processed only in this processor role. Unolia does not contact those people for its own purposes except under a legal duty or the Customer's documented instruction.

6. Connected Services selected by the Customer

Connected Services are not all Unolia subprocessors. They generally remain the Customer's direct providers. Unolia exchanges data with them on the Customer's instruction.

Depending on available features, they may include:

  • DNS, domains, cloud, and CDN: AWS, Bunny.net, Cloudflare, DigitalOcean, Gandi, IONOS, Namecheap, OVHcloud, Porkbun, and Vultr
  • repositories and development: GitHub and GitLab
  • hosting and deployment: Laravel Forge, Ploi, and Laravel Cloud
  • monitoring: Oh Dear
  • email: Mailgun and Bento
  • collaboration: Slack
  • manual or catalog sources: UptimeRobot, Postmark, SendGrid, Bunny CDN, Amazon S3, and Cloudflare R2

For some features, Unolia also consults public sources such as endoflife.date, GitHub Advisory Database, OSV, Packagist, npm, and public exchange-rate services. Those sources receive at least the technical parameters necessary for the request.

Review a third party's terms and privacy policy before connecting it. Limit token permissions to what is necessary.

7. Unolia recipients and service providers

Access is limited to people and providers who need it for the purposes described.

The list below is effective as of August 3, 2026. "Active" status was verified in the Service or public website. "Conditional" means the component is a recipient only if enabled in the deployment. Stripe may also act as a separate controller for some payment and fraud-prevention duties. A Mailcoach instance or search engine operated directly by Unolia without disclosure to a third party is not a separate recipient.

Provider Status and role Data that may be processed
OVH SAS, OVHcloud Active. Subprocessor hosting the main application in France Account data, Customer Data, and application logs
Cloudflare, Inc. Active. CDN, DNS, security, and network logs for the marketing website IP, user agent, requests, security events, and technical data
Stripe Payments Europe, Ltd. and Stripe group Active when subscribing. Payment, subscriptions, billing, and fraud prevention Billing details, customer identifiers, payment, and invoice data
Mailgun Technologies, Inc. Conditional. Email transport if Mailgun is configured by Unolia Name, email address, content, and delivery metadata
Laravel Holdings, Inc., Laravel Nightwatch Conditional. Observability subprocessor if enabled Errors, traces, performance data, and technical context potentially linked to a User or Customer Data
SmartBear Software, Bugsnag Conditional. Marketing website observability if enabled Errors, traces, and technical browsing context
Conva Ventures, Inc., Fathom Analytics Active. Audience measurement for the marketing website and public application pages without behavioral advertising Page views and limited technical information
Slack Technologies, LLC, Salesforce group Active. Internal operational alerts to Unolia's Slack workspace, such as signups and onboarding progress Name, email address, Workspace name, and event date
Unavatar, a Microlink service Active when displaying an avatar. Profile picture resolution and caching Email address, public identifier, service name, and avatar source

Unolia may also disclose data to professional advisers, insurers, authorities, or courts where necessary to comply with law or defend its rights. Unolia does not sell personal data or use it for behavioral advertising.

Any addition or replacement of a subprocessor is announced under the notice and objection mechanism in Article 14.6 of the General Terms of Service.

8. Infrastructure location and international transfers

This section is Unolia's online register for infrastructure location and safeguards against international governmental access. It is updated with the provider list.

Service component Main jurisdiction and location
Main application and API endpoint OVHcloud infrastructure located in France, subject to French and European Union law
Internal database, cache, queues, and search Internal services in the main deployment, not exposed as separate SaaS providers
Marketing website and network protection European origin infrastructure with Cloudflare's global edge network, which may process technical data in several countries
Payment, internal alerting, and conditional services Locations described in the contracts and policies of providers in Section 7, including the EEA, Canada, and the United States depending on the enabled service

To protect personal and non-personal data from international access incompatible with European Union law, Unolia limits disclosed data, encrypts communications, encrypts stored sensitive Credentials, restricts access, and imposes appropriate contractual commitments. To the extent permitted by law, Unolia or its provider reviews government requests, challenges unlawful or disproportionate requests, and informs the Customer when a request affects its data.

Some providers or Connected Services may process data from a country outside the European Economic Area.

For personal data, a transfer relies depending on the case on:

  • a European Commission adequacy decision
  • the EU-US Data Privacy Framework for certified organizations
  • European Commission Standard Contractual Clauses, supplemented by additional measures where necessary
  • another safeguard or derogation available under the GDPR

Fathom is established in Canada, which benefits from an adequacy decision within its applicable scope. For United States providers, Unolia relies on the EU-US framework where the relevant entity is certified, or on Standard Contractual Clauses and supplementary measures. You may request the destination and a copy or summary of the safeguard applying to a transfer by contacting privacy@unolia.com.

9. Retention periods

Unolia keeps data only as long as required for its purpose or a legal duty.

Category Period or criterion
Verified account and active Workspace During the contractual relationship, then until technical deletion and normal backup rotation
Unverified account Automatically deleted after approximately seven days
Evidence of legal acceptance During the relationship, then for the limitation period applicable to proof of the Contract
Live Project, provider, and resource data While the Workspace exists or until deletion by an authorized User
Cost, activity, automation, synchronization, monitoring, issue, version, and MCP history According to the plan, currently 30, 182, 365, or 1,095 days. The trial uses a 90-day window. Without an active trial or subscription, pruning pauses and history remains frozen until reactivation or Workspace deletion by its Owner
Data exceeding a new retention limit after a plan downgrade Deleted after a grace period currently set to seven days
Provider Credentials Until disconnection, revocation, Workspace deletion, or replacement, subject to required technical logs
Expired or revoked OAuth and API tokens Regularly purged through authentication mechanisms, with non-secret references potentially retained in audits
Invoices and accounting records Ten years from the end of the relevant financial year according to applicable duties
Support conversations and claims For the time needed to handle the request and relationship, then for the period needed to establish, exercise, or defend rights
Prospects and waitlist Until consent is withdrawn, deletion is requested, or the applicable marketing period ends, with inactive contacts reviewed periodically
Evidence of consent and marketing objection As long as needed to demonstrate compliance and avoid renewed contact
Security and access logs Twelve months at most from collection, followed by deletion or anonymization. An incident, a legal duty, or an evidence need may justify longer isolated retention of the relevant entries
Observability errors and traces For the shortest provider setting that enables diagnosis, followed by aggregation or deletion
Incoming webhooks Processed events are deleted after approximately 30 days. A failed or unprocessed event is kept until it is resolved or deleted so it can be diagnosed

When a Workspace is deleted, subscriptions stop and associated resources are purged by the Service. An isolated backup may temporarily retain a residual copy. It is used only for technical recovery and disappears through normal rotation.

10. Cookies and similar technologies

The application uses cookies and storage that are strictly necessary to:

  • maintain an authenticated session
  • protect forms against CSRF attacks
  • retain required security and interface choices

The marketing website and the public application pages load Fathom Analytics for audience measurement without advertising cookies. Cloudflare may process technical identifiers and place security cookies where required to protect the website.

If a non-essential technology requiring consent is added, Unolia will request consent before activation and allow withdrawal just as easily.

11. Security

Unolia applies measures suited to risk, including:

  • TLS encryption for communications
  • password hashing
  • application-level encryption of OAuth tokens, provider credentials, notification destinations, and dedicated secrets
  • logical Workspace isolation and authorization checks
  • available two-factor authentication
  • scopes for API and MCP tokens
  • redaction and limitation of arguments in MCP audits
  • access restrictions for systems and logs
  • monitoring, updates, backups, and incident response procedures

No system provides absolute security. You must protect your Credentials, apply least privilege, and immediately report anomalies to support@unolia.com.

For a personal data breach, Unolia applies Articles 33 and 34 GDPR. Where Unolia is a processor, it informs the Customer as controller without undue delay after becoming aware.

12. Your rights

Depending on the processing and GDPR conditions, you may request:

  • access to your data and a copy
  • correction of inaccurate data
  • deletion of data
  • restriction of processing
  • objection to processing based on legitimate interests
  • portability of data you supplied where processing is automated and based on consent or the Contract
  • withdrawal of consent at any time without affecting prior processing
  • information about safeguards for an international transfer

You may also define instructions about the use of your data after death under French law.

Send requests to privacy@unolia.com. Unolia may request proportionate identity evidence where there is reasonable doubt. A response is generally provided within one month, which may be extended under GDPR conditions.

If data was imported by your organization into its Workspace, contact that organization first. It is the controller and Unolia will assist it with the response.

You may lodge a complaint with the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or with your local supervisory authority.

13. Automated decisions

Unolia performs automatic matches, estimates, scores, detections, and suggestions. These processes assist Users but do not by themselves produce a legal decision or similarly significant effect about a natural person.

External actions are triggered by a User, authorized token, Customer-configured automation, or selected event. The Customer remains responsible for permission and confirmation settings.

14. Children

The Service is not intended for children. Unolia does not knowingly collect data directly from a child to create an account.

15. Policy updates

Unolia may update this Policy to reflect changes to the Service, providers, or law. A material change is announced in the Service or by email before it takes effect where reasonably possible.

The date displayed at the top of the page shows the latest update.


Last updated: September 11, 2026