Third Party Index

Snapshot 34751

Document
Subprocessor list
URL
https://www.unipile.com/privacy-policy/#subprocessors
Fetched
HTTP status
200
Content type
text/html
Fetch mode
static
Size
99266 bytes
SHA-256 (raw)
8f5d98694cd8f9736c1e3b66ef2f42bb5f934dd1e6b12c985e49e992d4cd9d58
SHA-256 (normalized text)
bed535711ffa20052e6f3be029c5a367f893bb374d379f9705d899305b28098d

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Privacy Policy
Last updated: September 28, 2026
This Privacy Policy explains how Unipile SAS (“Unipile”, “we”, “us” or “our”) processes personal data in connection with its website, its relationships with prospects and customers, and the provision of its unified APIs.
Unipile processes personal data in accordance with Regulation (EU) 2016/679 of 27 April 2016 (the “GDPR”), the amended French Data Protection Act No. 78-17 of 6 January 1978, and any other applicable data protection laws.
1. WHO ARE WE?
Unipile SAS is a company incorporated under French law, with its registered office at:
168 rue de la Rotonde
42153 Riorges
France
You can contact us:
for general questions about this Privacy Policy: [email protected];
to contact our Data Protection Officer (DPO): [email protected].
2. OUR ROLES WHEN PROCESSING PERSONAL DATA
2.1. When you visit our website or have a business relationship with Unipile
Unipile acts as a data controller when it determines the purposes and means of processing related in particular to:
browsing the unipile.com website;
contact or demonstration requests;
the creation and administration of customer accounts;
subscription, billing and support management;
administrative communications and, where permitted by law, marketing communications;
the security of the website and our services.
2.2. When our customers use the Unipile APIs
For data processed through accounts and services connected to the API, the Unipile customer determines the purposes and means of processing. The customer therefore acts as the data controller, and Unipile acts as its data processor.
In this context, Unipile processes data solely to provide the services, in accordance with the customer’s documented instructions and the Data Processing Agreement (“DPA”) entered into with that customer. The customer is responsible in particular for the lawfulness of the collection, informing data subjects, and handling requests to exercise their rights.
If you are an end user, prospect, contact or correspondent of an Unipile customer and your request concerns data processed on that customer’s behalf, please contact the customer directly. If such a request is sent directly to us, we will forward it to the relevant customer as soon as possible.
3. DATA SUBJECTS
This Privacy Policy may apply to:
visitors to the unipile.com website;
prospects, customers and customer representatives;
employees, staff, developers and API account administrators authorised by our customers;
end users, prospects, leads, customers and other contacts communicating through accounts connected by our customers.
4. DATA PROCESSED BY UNIPILE AS A CONTROLLER
Depending on your relationship with Unipile, we may process the following categories of data:
Identification and contact data: first and last name, professional email address, company name, job title and contact details provided when creating an account or contacting us.
Contract and account data: account identifiers, subscription details, service preferences, support history and administrative communications.
Billing data: billing address, information required to issue invoices, and limited payment-related information. Full payment card details are processed by our payment provider and are not stored by Unipile.
Technical and browsing data: IP address, browser type and version, operating system, device identifier, language, pages visited, date and time of access, connection data, and information obtained through cookies or similar technologies.
Aggregated usage data: statistics relating to the use of the website and the API services selected, used to understand usage and improve our services.
5. PURPOSES AND LEGAL BASES
We process this data for the following purposes and on the following legal bases:
Purpose	Legal basis
Responding to contact, demonstration or information requests	Unipile’s legitimate interest in responding to requests and, where applicable, steps taken before entering into a contract
Creating and administering customer accounts, providing the services and managing subscriptions	Performance of a contract or pre-contractual steps
Managing billing, payments and accounting	Performance of a contract and compliance with our legal obligations
Providing support and sending service-related notifications	Performance of a contract and our legitimate interest in ensuring that the service operates properly
Securing the website, preventing misuse and investigating incidents	Our legitimate interest in protecting our systems, users and services
Measuring audiences and improving the website and our services	Consent where required; otherwise, our legitimate interest
Sending marketing communications	Consent where required, or our legitimate interest where permitted by law
Responding to data-subject requests and competent authorities	Compliance with our legal obligations
Where processing is based on your consent, you may withdraw it at any time. Withdrawal will not affect the lawfulness of processing carried out before it was withdrawn.
6. DATA PROCESSED THROUGH THE API SERVICES
The Unipile APIs allow our customers to connect platforms such as LinkedIn, WhatsApp and Telegram, as well as email and calendar providers, through a unified schema.
Whether and for how long data is stored depends on the service version, the connected channel and the configuration selected by the customer.
Category	Examples	Storage and retention
Messaging content	Text messages, attachments, images, documents and voice notes	V1: messages, conversations and participants are stored until the account is deleted. V2 WhatsApp: the same categories are stored in encrypted form until the account is deleted. V2 other channels: transient processing without storage.
Email content and metadata	Headers, sender and recipient addresses, plain-text or HTML body, and attachments	V1 Microsoft/IMAP: metadata only is stored until account deletion; email bodies are not stored. V1 Gmail: no storage. V2: transient processing.
Social profiles and conversation metadata	Contact names, profile links, avatar URLs and conversation status	V1 and V2: no storage or caching; no retention.
Calendar data	Event titles, dates and times, descriptions, meeting links and participant email addresses	V1: no storage or caching. V2: cached for one hour by default; the user may configure this period.
Network and proxy metadata	Destination host, connection timing, request IP addresses and data transmission volume	Processed transiently in memory during an active connection where the customer chooses to use Unipile proxies; not retained after transmission. Proxy providers only route network connections. Message content is encrypted in transit and is not decrypted, accessed or stored by the proxy providers.
Authentication data for connected accounts	OAuth tokens, encrypted access tokens and session identifiers	V1 and V2 IMAP: credentials are stored in encrypted form. Other V1 and V2 connections: only an encrypted session token is stored. Google and Microsoft use external OAuth, and credentials do not transit through Unipile. Retained until the account is deleted or the service ends.
Transient login credentials	Password supplied during the initial account connection	Where the user chooses this method for a messaging service, the credential transits solely for login and is not retained; only the token is stored.
Unipile does not use data processed on behalf of its customers for its own purposes. Data is collected, accessed, transmitted, cached or stored only to the extent necessary to provide the relevant service and in accordance with the customer’s instructions.
7. RETENTION PERIODS
Data processed on behalf of our customers is retained for the periods set out in Section 6.
When the agreement ends, Unipile will, at the customer’s choice, return or delete the personal data received in connection with the service, including copies held in its systems, except where retention is required by law or necessary for statutory archiving purposes. The same obligations apply to our sub-processors.
For processing carried out by Unipile as a controller:
account registration data is retained for the duration of the contractual relationship and for 30 days after account deletion, without prejudice to applicable statutory retention periods;
technical and browsing information is retained for 30 days from collection, unless longer retention is necessary for security purposes or to investigate an incident;
limited payment information retained in the event of a payment anomaly is kept for no more than 7 days;
data required for billing and accounting is retained for the periods prescribed by applicable law;
cookies are retained for the period stated in our cookie-management tool and, in all cases, within the limits prescribed by applicable law.
8. RECIPIENTS AND SUB-PROCESSORS
Access to data is limited to Unipile personnel who need it to perform their duties and who are subject to confidentiality obligations.
Unipile uses the following sub-processors in connection with its API services. Each provider name links to its own privacy policy (external links, opens in a new tab).
Sub-processor	Activity	Country of establishment	Data location	Transfer safeguard
SCALEWAY SAS	Cloud hosting and infrastructure	France	France (EU)	Not applicable, intra-EEA transfer
OVH SAS	Cloud hosting and infrastructure	France	France (EU)	Not applicable, intra-EEA transfer
OXYLABS UAB	Network proxy services	Lithuania	European Union	Not applicable, intra-EEA transfer
DECODO UAB (formerly Smartproxy)	Network proxy services	Lithuania	European Union	Not applicable, intra-EEA transfer
BRIGHT DATA LTD	Network proxy services	Israel	Israel / EU	European Commission adequacy decision
WEBSHARE SOFTWARE COMPANY	Network proxy services	United States	United States	Standard Contractual Clauses, Module 3, and a transfer impact assessment
INFATICA PTE. LTD.	Network proxy services	Singapore	Singapore / EU	Standard Contractual Clauses, Module 3, and a transfer impact assessment
CRISP IM SAS	Customer support platform (V1)	France	France (EU)	Not applicable, intra-EEA transfer
INTERCOM R&D UNLIMITED COMPANY	Customer support platform (V2)	Ireland	United States / EU (Dublin)	EU-U.S. Data Privacy Framework certification, UK Extension and Swiss framework, and/or Standard Contractual Clauses, Module 3
Unipile may also use service providers required for processing carried out for its own purposes, including a payment provider to process online payments.
Unipile does not sell personal data. We disclose it only where necessary to provide our services, comply with the law, defend our rights, or protect our systems and users.
Unipile contractually requires its sub-processors to comply with data protection obligations that are at least equivalent to those imposed on Unipile. Unipile remains responsible to its customers for the performance of obligations entrusted to its sub-processors.
9. TRANSFERS OUTSIDE THE EUROPEAN ECONOMIC AREA
Where personal data is transferred outside the European Economic Area, Unipile ensures that the transfer is based on a mechanism recognised under Chapter V of the GDPR, such as:
an adequacy decision adopted by the European Commission;
the European Commission’s Standard Contractual Clauses, supplemented where necessary by a transfer impact assessment and additional safeguards;
valid certification under the EU-U.S. Data Privacy Framework where that mechanism applies.
You may contact our DPO for further information about the applicable safeguards.
10. SECURITY AND CONFIDENTIALITY
Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the risks to individuals, Unipile implements appropriate technical and organisational measures to protect the confidentiality, integrity and security of personal data.
These measures include limiting access to authorised personnel, confidentiality commitments, appropriate staff training, and encrypting data or tokens where stated in this Privacy Policy.
If a personal data breach affects processing carried out on behalf of a customer, Unipile will notify that customer without undue delay after becoming aware of it and will provide the available information needed to help the customer meet its regulatory obligations.
11. YOUR RIGHTS
Subject to the conditions and limitations set by applicable law, you may request:
access to your personal data;
correction of inaccurate or incomplete data;
deletion of your data;
restriction of processing;
objection to processing based on legitimate interests;
portability of data you provided to us where processing is based on consent or a contract and is carried out by automated means;
withdrawal of your consent at any time;
not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you, in the circumstances covered by the GDPR.
For processing for which Unipile is the controller, you may exercise your rights by writing to [email protected] or [email protected]. To protect your data, we may request information reasonably necessary to verify your identity.
We will respond within the time limits prescribed by law, generally within one month after receiving a complete request. This period may be extended by two further months depending on the complexity and number of requests; if so, we will inform you.
Where Unipile processes your data on behalf of one of its customers, please submit your request to that customer as the data controller. Unipile will provide the customer with the necessary assistance.
You may also lodge a complaint with the French Data Protection Authority (CNIL) or the competent supervisory authority in the country where you live or work.
12. DATA FROM GOOGLE API SERVICES
Unipile’s use and transfer to any other application of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
13. COOKIES
When you visit unipile.com, cookies or similar technologies may be placed on your device. Some are strictly necessary for the operation and security of the website and do not require consent. Non-essential cookies, including those used for audience measurement or personalisation, are placed only after obtaining your consent where required.
You may accept or reject cookies and change your choices at any time through the cookie-management tool available on the website. Withdrawal of consent does not affect the lawfulness of processing carried out before that withdrawal.
The purposes, providers and retention periods for individual cookies are listed in the cookie-management tool. Your choices will remain valid for no longer than the period permitted by applicable law.
You can also manage cookies directly in your browser settings:
Google Chrome
Mozilla Firefox
Microsoft Edge
Apple Safari
14. CHANGES TO THIS PRIVACY POLICY
We may amend this Privacy Policy to reflect changes in our services, processing activities or applicable law. The date of the latest update appears at the beginning of the document. If a change is material, we will take appropriate steps to inform you.
15. CONTACT US
For any question or complaint concerning this Privacy Policy or our personal data practices, please contact:
Data Protection Officer, Unipile SAS
168 rue de la Rotonde
42153 Riorges
France
[email protected]
Language of this Privacy Policy. This Privacy Policy is written in English, and the English version is the authoritative version. Versions in other languages are provided through automatic translation for convenience only. In the event of any discrepancy or inconsistency, the English version prevails.