1. Purpose and scope
This Policy explains how Unolia collects, uses, shares, and retains personal data related to the unolia.com website, the app.unolia.com application, support, API, and MCP server.
It distinguishes two roles:
- Unolia as controller for account management, subscriptions, communications, security, and measurement of its own services
- Unolia as the Customer's processor when the Customer chooses to import or process data about its own employees, customers, suppliers, or other people in its Workspace
Commitments that apply when Unolia processes data on behalf of the Customer also appear in Article 14 of the General Terms of Service.
2. Controller and contact details
The controller for Unolia's own processing is:
Eser DENIZ, French sole trader, 10 chemin du Bergeron, 27930 Huest, France, SIREN 801 040 338, SIRET 801 040 338 00023.
For questions or personal data requests, contact privacy@unolia.com.
This address is Unolia's data protection contact point. It does not mean that a Data Protection Officer has been formally appointed with the CNIL.
3. Data collected
The data actually processed depends on your use, role, plan, and Connected Services.
3.1. Account and authentication
Unolia may process:
- name, email address, language, time zone, and profile picture
- data required to display an avatar, such as a URL, public identifier, or email address sent to Unavatar
- hashed password, email verification status, and last login date
- date and version of legal acceptance
- two-factor authentication secret, recovery codes, and active sessions
- interface preferences, favorites, and recent projects
- identifiers for a connected GitHub or GitLab account, username, email, scopes, expiry dates, and encrypted OAuth tokens
3.2. Workspace, team, and access
Unolia may process:
- Workspace name and identifier
- identity of members and invitees
- roles, permissions, project access, and change history
- identities observed in Connected Services, group membership, remote roles, and access differences
- addresses and settings for notification destinations, including email and Slack
3.3. Connected Services and Credentials
When you connect a third-party service, Unolia may process:
- provider name, account name, associated email address, account identifiers, and connection status
- API keys, OAuth tokens, webhook secrets, credential pairs, and granted permissions
- expiry dates, latest synchronizations, errors, and connection health information
- resource selections and synchronization preferences
Tokens, credentials, and secrets supported by dedicated models are encrypted at the application level before storage. Some non-secret technical identifiers remain visible to support relationships, audits, and revocation.
3.4. Projects and infrastructure
Unolia may import, create, or calculate:
- project names, domains, DNS zones, records, nameservers, propagation data, and certificates
- public and private IP addresses, server names, regions, sizes, systems, versions, and statuses
- websites, environments, associated domains, branches, scripts, and deployment history
- names and, where required by a feature, values of environment variables or other technical secrets
- monitoring data, checks, availability, incidents, causes, timelines, and source addresses
- detected issues, technical evidence, proposed fixes, and recheck results
Values stored in dedicated secret stores are encrypted. Technical data such as an IP address, username, domain, or log may be personal data where it identifies a person.
3.5. Repositories, code, and dependencies
For GitHub, GitLab, and connected hosting services, Unolia may process:
- repository name, owner, URL, visibility, default branch, and identifiers
- commits, authors, usernames, email addresses, messages, branches, and references
- CI runs, jobs, statuses, actors, durations, and result links
- paths and limited contents of manifests and lockfiles needed to inventory dependencies
- package names and versions, licenses, CVE alerts, security advisories, end-of-life data, and version differences
- deployments, logs retrieved on request, and webhook metadata
Unolia does not aim to copy an entire repository. Content accessed depends on enabled features and granted permissions.
3.6. Costs, subscriptions, and billing
Unolia may process:
- plan, billing interval, subscription status, trial dates, renewal, and cancellation
- name or company name, billing email, address, country, VAT number, and other invoice details
- Stripe identifiers, payment status, invoices, and the last four digits or card brand when returned by Stripe
- imported or entered costs, uploaded supplier invoices, invoice lines, usage, licenses, currencies, exchange rates, and project allocations
- email addresses designated to receive invoices
Unolia does not receive the full payment card number or card security code.
3.7. Automations, activity, API, and MCP
Unolia may process:
- recipes, steps, triggers, settings, confirmations, outcomes, statuses, errors, and automation durations
- encrypted automation secrets and information about their scope or expiry
- activity performed by Users, tokens, webhooks, or systems
- OAuth clients, API tokens, scopes, expiry, revocation, and last use
- MCP calls, tool name, actor, effective scopes, outcome, duration, limited errors, and a redacted argument summary
MCP arguments are filtered against sensitive key names and truncated before storage. Unolia cannot identify every secret placed in a free-text field. Do not send a secret in a field not intended for it.
3.8. Support, communications, and marketing
Unolia may process:
- name, email address, organization, and support conversation content
- attachments, technical information, and communication dates
- waitlist or newsletter subscription, consent, opt-out, and deliverability data
- account-related aggregate usage information, such as numbers of projects or connections, to tailor service communications
- signup and onboarding progress events, including the name, email address, and Workspace name concerned, forwarded to Unolia's internal Slack workspace for operational follow-up
3.9. Browsing, security, and observability
Unolia may process:
- IP address, user agent, URL, date, time, session identifier, and security events
- server logs, failed requests, error traces, performance data, and technical context required for diagnosis
- marketing website and public application page audience data measured without advertising cookies by Fathom Analytics
- network and security events processed by Cloudflare for the marketing website
The name, email address, and password fields are required to create an account. Without them, registration cannot be completed. Billing details and a payment method are required for a paid plan. Connected Service Credentials are optional, but the related feature cannot be provided without them.
4. Data sources
Data comes from:
- you when you create an account, configure a Workspace, contact support, or enter information
- the owner, administrators, or members of your Workspace
- Connected Services and their webhooks according to granted permissions
- public technical sources, including DNS, certificates, domain registries, version registries, security advisories, and exchange rates
- operation of the Service, including logs, activities, diagnostics, matches, and estimates
- Stripe for billing and payment status
5. Purposes and legal bases
| Purpose | Main data | Legal basis |
|---|---|---|
| Create and administer the Customer's or representative's account | Identity, authentication, and preferences | Performance of the Contract or pre-contract steps |
| Manage Users invited by the Customer | Identity, team, role, permissions, and activity | Legitimate interest in providing the Service requested by the Customer and managing access |
| Secure accounts and the Service | Sessions, IP, user agent, events, and logs | Legitimate interest in preventing unauthorized access and abuse |
| Provide the Workspace and synchronize Connected Services | Team, infrastructure, repository, monitoring, cost, and Credential data | Performance of the Contract for the Customer. For other people in Customer Data, processing on the Customer's instruction |
| Run API, MCP tools, fixes, and automations | Scopes, arguments, actions, outcomes, and logs | Performance of the Contract or processing on the Customer's instruction depending on the data concerned |
| Manage subscriptions, payments, and invoices | Billing details, plan, payment, and invoice | Performance of the Contract and legal accounting and tax duties |
| Provide support and service communications | Contact details, conversations, and technical information | Performance of the Contract and legitimate interest in assisting Users |
| Follow signups and onboarding internally | Name, email address, Workspace name, and onboarding events | Legitimate interest in operating the Service and assisting new Customers |
| Prevent abuse and diagnose incidents | IP, user agent, logs, errors, and traces | Legitimate interest in protecting, maintaining, and improving the Service |
| Measure marketing website and public application page audience | Page views and limited technical information | Legitimate interest in understanding website use, subject to rules applying to tracking technologies |
| Send newsletters or promotional communications | Email, subscription, preferences, and opt-out | Consent where required, or legitimate interest where professional marketing is permitted |
| Defend rights and respond to authorities | Data relevant to a dispute or request | Legal obligation and legitimate interest in establishing, exercising, or defending rights |
Where Unolia is a processor, the legal basis is determined by the Customer as controller. The Customer must inform data subjects and document that basis. Third-party data imported from Customer systems is normally processed only in this processor role. Unolia does not contact those people for its own purposes except under a legal duty or the Customer's documented instruction.
6. Connected Services selected by the Customer
Connected Services are not all Unolia subprocessors. They generally remain the Customer's direct providers. Unolia exchanges data with them on the Customer's instruction.
Depending on available features, they may include:
- DNS, domains, cloud, and CDN: AWS, Bunny.net, Cloudflare, DigitalOcean, Gandi, IONOS, Namecheap, OVHcloud, Porkbun, and Vultr
- repositories and development: GitHub and GitLab
- hosting and deployment: Laravel Forge, Ploi, and Laravel Cloud
- monitoring: Oh Dear
- email: Mailgun and Bento
- collaboration: Slack
- manual or catalog sources: UptimeRobot, Postmark, SendGrid, Bunny CDN, Amazon S3, and Cloudflare R2
For some features, Unolia also consults public sources such as endoflife.date, GitHub Advisory Database, OSV, Packagist, npm, and public exchange-rate services. Those sources receive at least the technical parameters necessary for the request.
Review a third party's terms and privacy policy before connecting it. Limit token permissions to what is necessary.
7. Unolia recipients and service providers
Access is limited to people and providers who need it for the purposes described.
The list below is effective as of August 3, 2026. "Active" status was verified in the Service or public website. "Conditional" means the component is a recipient only if enabled in the deployment. Stripe may also act as a separate controller for some payment and fraud-prevention duties. A Mailcoach instance or search engine operated directly by Unolia without disclosure to a third party is not a separate recipient.
| Provider | Status and role | Data that may be processed |
|---|---|---|
| OVH SAS, OVHcloud | Active. Subprocessor hosting the main application in France | Account data, Customer Data, and application logs |
| Cloudflare, Inc. | Active. CDN, DNS, security, and network logs for the marketing website | IP, user agent, requests, security events, and technical data |
| Stripe Payments Europe, Ltd. and Stripe group | Active when subscribing. Payment, subscriptions, billing, and fraud prevention | Billing details, customer identifiers, payment, and invoice data |
| Mailgun Technologies, Inc. | Conditional. Email transport if Mailgun is configured by Unolia | Name, email address, content, and delivery metadata |
| Laravel Holdings, Inc., Laravel Nightwatch | Conditional. Observability subprocessor if enabled | Errors, traces, performance data, and technical context potentially linked to a User or Customer Data |
| SmartBear Software, Bugsnag | Conditional. Marketing website observability if enabled | Errors, traces, and technical browsing context |
| Conva Ventures, Inc., Fathom Analytics | Active. Audience measurement for the marketing website and public application pages without behavioral advertising | Page views and limited technical information |
| Slack Technologies, LLC, Salesforce group | Active. Internal operational alerts to Unolia's Slack workspace, such as signups and onboarding progress | Name, email address, Workspace name, and event date |
| Unavatar, a Microlink service | Active when displaying an avatar. Profile picture resolution and caching | Email address, public identifier, service name, and avatar source |
Unolia may also disclose data to professional advisers, insurers, authorities, or courts where necessary to comply with law or defend its rights. Unolia does not sell personal data or use it for behavioral advertising.
Any addition or replacement of a subprocessor is announced under the notice and objection mechanism in Article 14.6 of the General Terms of Service.
8. Infrastructure location and international transfers
This section is Unolia's online register for infrastructure location and safeguards against international governmental access. It is updated with the provider list.
| Service component | Main jurisdiction and location |
|---|---|
| Main application and API endpoint | OVHcloud infrastructure located in France, subject to French and European Union law |
| Internal database, cache, queues, and search | Internal services in the main deployment, not exposed as separate SaaS providers |
| Marketing website and network protection | European origin infrastructure with Cloudflare's global edge network, which may process technical data in several countries |
| Payment, internal alerting, and conditional services | Locations described in the contracts and policies of providers in Section 7, including the EEA, Canada, and the United States depending on the enabled service |
To protect personal and non-personal data from international access incompatible with European Union law, Unolia limits disclosed data, encrypts communications, encrypts stored sensitive Credentials, restricts access, and imposes appropriate contractual commitments. To the extent permitted by law, Unolia or its provider reviews government requests, challenges unlawful or disproportionate requests, and informs the Customer when a request affects its data.
Some providers or Connected Services may process data from a country outside the European Economic Area.
For personal data, a transfer relies depending on the case on:
- a European Commission adequacy decision
- the EU-US Data Privacy Framework for certified organizations
- European Commission Standard Contractual Clauses, supplemented by additional measures where necessary
- another safeguard or derogation available under the GDPR
Fathom is established in Canada, which benefits from an adequacy decision within its applicable scope. For United States providers, Unolia relies on the EU-US framework where the relevant entity is certified, or on Standard Contractual Clauses and supplementary measures. You may request the destination and a copy or summary of the safeguard applying to a transfer by contacting privacy@unolia.com.
9. Retention periods
Unolia keeps data only as long as required for its purpose or a legal duty.
| Category | Period or criterion |
|---|---|
| Verified account and active Workspace | During the contractual relationship, then until technical deletion and normal backup rotation |
| Unverified account | Automatically deleted after approximately seven days |
| Evidence of legal acceptance | During the relationship, then for the limitation period applicable to proof of the Contract |
| Live Project, provider, and resource data | While the Workspace exists or until deletion by an authorized User |
| Cost, activity, automation, synchronization, monitoring, issue, version, and MCP history | According to the plan, currently 30, 182, 365, or 1,095 days. The trial uses a 90-day window. Without an active trial or subscription, pruning pauses and history remains frozen until reactivation or Workspace deletion by its Owner |
| Data exceeding a new retention limit after a plan downgrade | Deleted after a grace period currently set to seven days |
| Provider Credentials | Until disconnection, revocation, Workspace deletion, or replacement, subject to required technical logs |
| Expired or revoked OAuth and API tokens | Regularly purged through authentication mechanisms, with non-secret references potentially retained in audits |
| Invoices and accounting records | Ten years from the end of the relevant financial year according to applicable duties |
| Support conversations and claims | For the time needed to handle the request and relationship, then for the period needed to establish, exercise, or defend rights |
| Prospects and waitlist | Until consent is withdrawn, deletion is requested, or the applicable marketing period ends, with inactive contacts reviewed periodically |
| Evidence of consent and marketing objection | As long as needed to demonstrate compliance and avoid renewed contact |
| Security and access logs | Twelve months at most from collection, followed by deletion or anonymization. An incident, a legal duty, or an evidence need may justify longer isolated retention of the relevant entries |
| Observability errors and traces | For the shortest provider setting that enables diagnosis, followed by aggregation or deletion |
| Incoming webhooks | Processed events are deleted after approximately 30 days. A failed or unprocessed event is kept until it is resolved or deleted so it can be diagnosed |
When a Workspace is deleted, subscriptions stop and associated resources are purged by the Service. An isolated backup may temporarily retain a residual copy. It is used only for technical recovery and disappears through normal rotation.
10. Cookies and similar technologies
The application uses cookies and storage that are strictly necessary to:
- maintain an authenticated session
- protect forms against CSRF attacks
- retain required security and interface choices
The marketing website and the public application pages load Fathom Analytics for audience measurement without advertising cookies. Cloudflare may process technical identifiers and place security cookies where required to protect the website.
If a non-essential technology requiring consent is added, Unolia will request consent before activation and allow withdrawal just as easily.
11. Security
Unolia applies measures suited to risk, including:
- TLS encryption for communications
- password hashing
- application-level encryption of OAuth tokens, provider credentials, notification destinations, and dedicated secrets
- logical Workspace isolation and authorization checks
- available two-factor authentication
- scopes for API and MCP tokens
- redaction and limitation of arguments in MCP audits
- access restrictions for systems and logs
- monitoring, updates, backups, and incident response procedures
No system provides absolute security. You must protect your Credentials, apply least privilege, and immediately report anomalies to support@unolia.com.
For a personal data breach, Unolia applies Articles 33 and 34 GDPR. Where Unolia is a processor, it informs the Customer as controller without undue delay after becoming aware.
12. Your rights
Depending on the processing and GDPR conditions, you may request:
- access to your data and a copy
- correction of inaccurate data
- deletion of data
- restriction of processing
- objection to processing based on legitimate interests
- portability of data you supplied where processing is automated and based on consent or the Contract
- withdrawal of consent at any time without affecting prior processing
- information about safeguards for an international transfer
You may also define instructions about the use of your data after death under French law.
Send requests to privacy@unolia.com. Unolia may request proportionate identity evidence where there is reasonable doubt. A response is generally provided within one month, which may be extended under GDPR conditions.
If data was imported by your organization into its Workspace, contact that organization first. It is the controller and Unolia will assist it with the response.
You may lodge a complaint with the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or with your local supervisory authority.
13. Automated decisions
Unolia performs automatic matches, estimates, scores, detections, and suggestions. These processes assist Users but do not by themselves produce a legal decision or similarly significant effect about a natural person.
External actions are triggered by a User, authorized token, Customer-configured automation, or selected event. The Customer remains responsible for permission and confirmation settings.
14. Children
The Service is not intended for children. Unolia does not knowingly collect data directly from a child to create an account.
15. Policy updates
Unolia may update this Policy to reflect changes to the Service, providers, or law. A material change is announced in the Service or by email before it takes effect where reasonably possible.
The date displayed at the top of the page shows the latest update.
Last updated: September 11, 2026