Privacy that follows the data, not the marketing.
Effective and last updated: July 29, 2026
1. Who this notice covers
This notice covers the UniFlow Desk website, contact enquiries, account creation, personal workspaces, and business workspaces. UniFlow Desk is the product name. See the legal notice.
For account administration, launch communications, security, and personal-workspace service data, the UniFlow Desk operator acts as data controller. When an organization provides UniFlow Desk to its personnel, that organization ordinarily controls the connected workspace content and UniFlow Desk processes that content on its instructions under an applicable data processing agreement.
2. Data we collect
Connected messages can incidentally contain sensitive or special category information. UniFlow Desk does not ask users to provide that information, does not infer sensitive traits for advertising, and processes it only as needed to provide the user-requested communication service.
3. Purposes and legal bases
4. Where the data comes from
We receive data directly from you, from your organization, and from providers you authorize, such as Google, Microsoft, Slack, approved IMAP providers, Meta's WhatsApp Business platform, and Telegram. We may also receive message data about correspondents who are not UniFlow Desk users when it appears in an authorized mailbox or business channel.
5. Provider access and product boundaries
Gmail, Outlook, Slack, and Microsoft Teams use scoped provider authorization. Regional email uses direct-TLS, read-only IMAP. WhatsApp Business is limited to official Cloud API events for an approved business number. Telegram is limited to messages delivered to an authorized bot. These modes do not provide universal access to every private conversation.
UniFlow Desk does not call provider send, edit, delete, archive, mark-read, payment, signature, or renewal actions. Reply drafts stay encrypted inside UniFlow Desk until a user chooses to copy them into the source application.
6. AI-assisted processing
UniFlow Desk can operate with deterministic local classification. When optional structured AI extraction is enabled, bounded message text may be sent to the configured model provider solely to produce structured fields. Requests are configured not to be stored by the model API where that control is available. Output must match a strict schema and cite evidence present in the source message; refused, invalid, or unavailable output falls back to local rules.
We do not use connected communication content to train a general model. Provider credentials, recovery codes, and encryption keys are never supplied to the extraction model.
7. Sharing and subprocessors
We disclose data only to service providers needed to host, secure, deliver, support, or analyze the operation of UniFlow Desk; to an organization administering your business workspace; to professional advisers under confidentiality; or where law requires it. We do not sell personal data or use connected messages for advertising.
The current categories, purposes, and processing locations are listed on the subprocessors page. Connection providers remain subject to their own terms and privacy notices.
8. International transfers
We prefer European hosting for controlled product data. Some infrastructure, security, support, or optional AI providers may process data outside the EEA or UK. Where required, transfers rely on an adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful safeguard. Business customers may request the applicable transfer information before onboarding.
9. Retention
- Contact enquiry records are reviewed and deleted no later than 24 months after the last interaction, unless they remain necessary to provide the service or you ask us to delete them sooner.
- Cookieless website event records are deleted after 13 months.
- Optional marketing details are retained until consent is withdrawn or after 24 months without engagement, whichever comes first.
- Account and workspace records are retained while the account is active and as reasonably needed to complete export, deletion, fraud prevention, or legal obligations.
- Connected messages and derived attention items remain until the user deletes them, disconnects with local-data deletion, or closes the account, subject to workspace policy.
- Encrypted backup copies are isolated from ordinary use and expire through the applicable backup rotation rather than being restored to active service after a valid deletion request.
- Security records may be kept longer when reasonably necessary to investigate an incident, prevent abuse, or establish legal claims.
10. Your rights and choices
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or a copy of personal data. You may withdraw consent at any time without affecting earlier lawful processing.
Your right to object: You may object at any time to direct marketing. You may also object to processing based on legitimate interests, and we will stop unless we demonstrate compelling lawful grounds or need the data for legal claims.
Send requests through the contact form. We may need to verify identity and authority before disclosing or deleting data. Business-workspace requests may be referred to the organization that controls the workspace.
11. Automated decisions
UniFlow Desk ranks and classifies communications, but it does not make solely automated decisions with legal or similarly significant effects. Its outputs are advisory, source-linked, correctable, and subject to human review. Users must verify original messages before financial, legal, security, medical, or contractual action.
12. Security
Security measures include encrypted provider tokens and content, TLS in transit, workspace isolation, expiring sessions, optional authenticator-app MFA, role controls, bounded rate limits, hash-chained security activity, backups with integrity checks, and source-linked auditability. No internet service can guarantee absolute security. See the security page for current controls and limitations.
13. Children
UniFlow Desk is intended for adults and authorized workplace users, not children. We do not knowingly invite people under 18 to create accounts or connect communication sources.
14. Complaints
Contact us first so we can investigate. You also have the right to complain to the supervisory authority where you live, work, or believe an infringement occurred. In France this is the CNIL; in the UK it is the ICO.
15. Contact and changes
Privacy questions and requests may be sent through the contact form. Material updates will be posted here with a revised date and, where required, notified through the account or onboarding channel.