UniFlow DeskBack to the launch site
PRIVACY NOTICE

Privacy that follows the data, not the marketing.

Effective and last updated: July 29, 2026

Plain-language policy

This page describes current UniFlow Desk practices. It is not a claim of certification, and it does not reduce any mandatory rights under applicable law.

1. Who this notice covers

This notice covers the UniFlow Desk website, contact enquiries, account creation, personal workspaces, and business workspaces. UniFlow Desk is the product name. See the legal notice.

For account administration, launch communications, security, and personal-workspace service data, the UniFlow Desk operator acts as data controller. When an organization provides UniFlow Desk to its personnel, that organization ordinarily controls the connected workspace content and UniFlow Desk processes that content on its instructions under an applicable data processing agreement.

2. Data we collect

CategoryExamples
Contact dataName, email address, enquiry topic, message, acknowledgement, status, and timestamps.
Account dataLogin identifiers, verification state, workspace membership, role, preferences, MFA status, and recovery events.
Connection dataProvider, granted scopes, encrypted tokens or provider-issued credentials, cursors, subscription health, and last synchronization.
Communication dataMessage metadata and bounded content from authorized sources, thread identifiers, sender and recipient details, dates, and source links.
Derived service dataCategories, suggested actions, deadlines, amounts, evidence excerpts, confidence, status, drafts, and digest snapshots.
Product activityAccount and workspace identifiers, page or feature route, request method, result, duration, client type, and timestamp. Activity records do not contain message bodies, form bodies, search text, OAuth tokens, or full URLs.
Website analyticsPage path, selected call-to-action events, referring hostname, and timestamp. The website does not assign a visitor identifier or use an analytics cookie.
Security and diagnosticsIP address, timestamps, authentication and permission events, delivery failures, device or browser information, and integrity records.

Connected messages can incidentally contain sensitive or special category information. UniFlow Desk does not ask users to provide that information, does not infer sensitive traits for advertising, and processes it only as needed to provide the user-requested communication service.

3. Purposes and legal bases

PurposeDataEU/UK legal basis
Create an account and answer enquiriesAccount and contact dataSteps requested before a contract and legitimate interests in answering enquiries and operating the service.
Provide, personalize, and support the serviceAccount, connection, communication, and derived dataPerformance of the service contract; for business content, the customer's documented instructions.
Protect accounts and investigate misuseSecurity and diagnostic dataLegitimate interests in a secure and reliable service, and legal obligations where applicable.
Send optional product news and offersEmail and marketing preferenceConsent. Creating an account does not require marketing consent.
Improve relevance and reliabilityContent-free correction events and aggregate operational metricsLegitimate interests, balanced against privacy and data minimization.
Meet legal requirementsRecords reasonably required by lawLegal obligation or establishment, exercise, or defense of legal claims.

4. Where the data comes from

We receive data directly from you, from your organization, and from providers you authorize, such as Google, Microsoft, Slack, approved IMAP providers, Meta's WhatsApp Business platform, and Telegram. We may also receive message data about correspondents who are not UniFlow Desk users when it appears in an authorized mailbox or business channel.

5. Provider access and product boundaries

Gmail, Outlook, Slack, and Microsoft Teams use scoped provider authorization. Regional email uses direct-TLS, read-only IMAP. WhatsApp Business is limited to official Cloud API events for an approved business number. Telegram is limited to messages delivered to an authorized bot. These modes do not provide universal access to every private conversation.

UniFlow Desk does not call provider send, edit, delete, archive, mark-read, payment, signature, or renewal actions. Reply drafts stay encrypted inside UniFlow Desk until a user chooses to copy them into the source application.

6. AI-assisted processing

UniFlow Desk can operate with deterministic local classification. When optional structured AI extraction is enabled, bounded message text may be sent to the configured model provider solely to produce structured fields. Requests are configured not to be stored by the model API where that control is available. Output must match a strict schema and cite evidence present in the source message; refused, invalid, or unavailable output falls back to local rules.

We do not use connected communication content to train a general model. Provider credentials, recovery codes, and encryption keys are never supplied to the extraction model.

7. Sharing and subprocessors

We disclose data only to service providers needed to host, secure, deliver, support, or analyze the operation of UniFlow Desk; to an organization administering your business workspace; to professional advisers under confidentiality; or where law requires it. We do not sell personal data or use connected messages for advertising.

The current categories, purposes, and processing locations are listed on the subprocessors page. Connection providers remain subject to their own terms and privacy notices.

8. International transfers

We prefer European hosting for controlled product data. Some infrastructure, security, support, or optional AI providers may process data outside the EEA or UK. Where required, transfers rely on an adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful safeguard. Business customers may request the applicable transfer information before onboarding.

9. Retention

  • Contact enquiry records are reviewed and deleted no later than 24 months after the last interaction, unless they remain necessary to provide the service or you ask us to delete them sooner.
  • Cookieless website event records are deleted after 13 months.
  • Optional marketing details are retained until consent is withdrawn or after 24 months without engagement, whichever comes first.
  • Account and workspace records are retained while the account is active and as reasonably needed to complete export, deletion, fraud prevention, or legal obligations.
  • Connected messages and derived attention items remain until the user deletes them, disconnects with local-data deletion, or closes the account, subject to workspace policy.
  • Encrypted backup copies are isolated from ordinary use and expire through the applicable backup rotation rather than being restored to active service after a valid deletion request.
  • Security records may be kept longer when reasonably necessary to investigate an incident, prevent abuse, or establish legal claims.

10. Your rights and choices

Depending on applicable law, you may request access, correction, deletion, restriction, portability, or a copy of personal data. You may withdraw consent at any time without affecting earlier lawful processing.

Your right to object: You may object at any time to direct marketing. You may also object to processing based on legitimate interests, and we will stop unless we demonstrate compelling lawful grounds or need the data for legal claims.

Send requests through the contact form. We may need to verify identity and authority before disclosing or deleting data. Business-workspace requests may be referred to the organization that controls the workspace.

11. Automated decisions

UniFlow Desk ranks and classifies communications, but it does not make solely automated decisions with legal or similarly significant effects. Its outputs are advisory, source-linked, correctable, and subject to human review. Users must verify original messages before financial, legal, security, medical, or contractual action.

12. Security

Security measures include encrypted provider tokens and content, TLS in transit, workspace isolation, expiring sessions, optional authenticator-app MFA, role controls, bounded rate limits, hash-chained security activity, backups with integrity checks, and source-linked auditability. No internet service can guarantee absolute security. See the security page for current controls and limitations.

13. Children

UniFlow Desk is intended for adults and authorized workplace users, not children. We do not knowingly invite people under 18 to create accounts or connect communication sources.

14. Complaints

Contact us first so we can investigate. You also have the right to complain to the supervisory authority where you live, work, or believe an infringement occurred. In France this is the CNIL; in the UK it is the ICO.

15. Contact and changes

Privacy questions and requests may be sent through the contact form. Material updates will be posted here with a revised date and, where required, notified through the account or onboarding channel.

© 2026 UniFlow Desk
PrivacyTermsCookiesSecuritySubprocessorsLegal noticeData deletionAccessibility