Legal

Privacy Policy

Last updated:

This is a translation. The French version is the authoritative text and prevails in the event of any discrepancy.

Contents

Controller

This policy describes how Unileva collects, uses and protects the personal data it processes on its own behalf, on the unileva.com website and in the Unileva service. It complies with the General Data Protection Regulation (GDPR) and the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data.

The controller is Loïc Hollay (sole trader), enterprise number 1028.697.569, rue Guido Gezelle 25, 1780 Wemmel, Belgium, who can be reached at hello [at] unileva.com.

The data our customers put into Unileva (their contacts, deals, quotes, emails) is not covered by this policy: for that data, the customer is the controller and Unileva acts as processor, under the terms of the data processing agreement.

Data we process

  • Appointment booking, through the website form: first name, last name, email address, phone number, company and trade; if you provide them, the size of your team, your current tools and your needs.
  • Accounts of customers and their users: name, email address, password (stored as a hash, never readable), two-factor authentication secret (encrypted), display preferences.
  • Billing: company name, address, VAT number, payment history. Card details are processed by Stripe; we neither see nor store them.
  • Technical data: log of actions carried out in the service (with IP address and device), login sessions, server logs, for security and troubleshooting purposes.

Purposes and legal bases

  • Preparing and holding the call you booked, and sending you its confirmation, its reminder and the link to reschedule it: pre-contractual steps taken at your request.
  • Contacting you again after the call about the offer presented: our legitimate interest, which you may object to at any time.
  • Providing the service, creating and securing accounts, preventing abuse: performance of the contract and legitimate interest.
  • Invoicing and keeping the accounts: performance of the contract and legal obligations.
  • Improving the reliability of the service and fixing faults: legitimate interest.

Recipients

Your data is never sold. It is processed by the following providers, solely for the purposes described above:

  • OVH SAS (France): hosting of the website, the application, the database and the files.
  • Amazon Web Services EMEA SARL (Ireland region): delivery of emails sent by the service.
  • Stripe: subscription payments.
  • Mistral AI (France): AI assistant responses, only if the customer activates the AI assistant in its plan.

The discovery call takes place by video conference on Google Meet: by joining it, you are subject to Google’s privacy rules.

Transfers outside the European Union

Hosting, where nearly all the data resides, is located in France. Stripe may process some payment data in the United States; this transfer relies on the EU-US Data Privacy Framework or, failing that, on the standard contractual clauses of the European Commission.

Cookies and local storage

The unileva.com website sets no cookies, uses no analytics tools and loads no third-party scripts. That is why it shows no banner.

Once you are logged in, the application uses only what is strictly necessary for it to work:

  • a session cookie, which keeps you logged in, for 120 minutes of inactivity;
  • an XSRF-TOKEN cookie, which protects forms against request forgery, for the same duration;
  • two values in your browser’s local storage, which remember how the sidebar looks: sidebar-collapsed (collapsed or not) and sidebar-groups (the groups you have folded).

None of these is used to track you from one website to another.

Retention periods

  • Appointment booking data: three years after the last contact.
  • Accounts: for the duration of the contract, then thirty days to allow export, before deletion.
  • Billing: seven years, the statutory retention period for accounting records.
  • Conversations with the AI assistant: ninety days, then automatic deletion.
  • Action log and server logs: twelve months, then deletion.
  • Recycle bin: deleted items stay there for thirty days by default, a period the customer can adjust, and are then erased.
  • Login sessions: 120 minutes of inactivity.

Security

Passwords are stored as hashes and are never readable. Two-factor authentication is offered to every user. Exchanges with the service are encrypted in transit, credentials for connected mailboxes are encrypted at rest, and access is partitioned by organisation and by role: everyone sees only what their role allows.

Your rights

You have the right to access, rectify, erase and port your data, and to object to or restrict its processing. To exercise these rights, write to hello [at] unileva.com.

If your data was entered into Unileva by one of our customers, for example because you are their customer, please contact them first: they are the controller. If you write to us directly, we will forward your request to them.

You may also lodge a complaint with the Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels.

Minors

The service is intended for professionals. It is not aimed at people under the age of sixteen, and we do not knowingly collect their data.

Changes

This policy may be updated. The date of the last update appears at the top of the page, and any significant change is notified to customers by email.