Privacy Policy
Last updated: 31 July 2026
1. General Information and Scope
1.1 Purpose of the Privacy Policy. This Privacy Policy explains how OneType Prosta Spółka Akcyjna ("Unabyss", "we", "us", or "our") collects, uses, processes, and protects personal data of users ("User" or "you") who access or use the Service available at unabyss.com, app.unabyss.com, and related web applications and APIs.
1.2 Compliance with Law. Unabyss processes personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Polish Act on the Protection of Personal Data, and other applicable privacy laws and regulations.
1.3 Data Controller. The controller of your personal data is OneType Prosta Spółka Akcyjna, with its registered office in Warsaw (ul. Fabryczna 4A/11, 00-446 Warszawa, Poland), entered in the Register of Entrepreneurs of the National Court Register maintained by the District Court for the Capital City of Warsaw in Warsaw, XII Commercial Division of the National Court Register, under KRS number: 0001224271; NIP: 7011299839; share capital (kapitał akcyjny): PLN 200,000. Email: legal@unabyss.com.
1.4 Contact for Data Protection. Unabyss has not designated a Data Protection Officer, as it is not required to do so under Article 37 of the GDPR, and has made no corresponding notification to the President of the Personal Data Protection Office. For any questions regarding data protection, Users may contact Unabyss's privacy contact by email at privacy@unabyss.com.
1.5 Scope of Application. This Privacy Policy applies to:
(a) Visitors of the Unabyss website (unabyss.com).
(b) Registered Users of the Unabyss platform (app.unabyss.com).
(c) Individuals whose data is processed in connection with imports from third-party services connected by a User.
(d) Individuals whose data is processed in connection with communication, billing, and support.
This Privacy Policy also applies to Team administrators, Team members, and individuals invited to join a Team, including persons who have not yet created an Account.
1.6 Relationship with Terms and Conditions. This Privacy Policy is an information document provided under Articles 13 and 14 of the GDPR. It describes how Unabyss processes personal data and does not form part of the contractual terms governing use of the Service, which are set out separately in the Terms and Conditions. An update to this Privacy Policy made in accordance with Section 13 does not amend the Terms and Conditions. By using the Service, you acknowledge that you have read and understood both documents.
1.7 Updates to the Privacy Policy. This Privacy Policy may be updated from time to time. The latest version will always be available at unabyss.com/privacy. Users will be informed of significant updates via email or in-app notification before they take effect.
2. Categories of Data Collected
2.1 Data Provided by the User
When creating an Account or communicating with Unabyss, the User may provide the following data:
(a) Identification and contact information such as name, surname, email address, and company name.
(b) Billing and payment information (processed through Stripe).
(c) Context Data, including structured context files, text documents, and other content uploaded to the Platform.
(d) Authorization tokens issued when connecting external accounts (such as LinkedIn, X/Twitter, or Facebook) via OAuth. Unabyss does not collect or store passwords or other login credentials for third-party platforms.
(e) Voice recordings submitted through the speech-to-text feature (processed by ElevenLabs Scribe).
(f) Correspondence and communication history with Unabyss, including support requests and feedback.
2.2 Data Collected Automatically
When the User visits the website or uses the Service, certain information may be collected automatically, including:
(a) IP address, browser type, operating system, and device identifiers.
(b) Date, time, and duration of visits.
(c) Referring pages, pages viewed, and interaction data.
(d) Cookies and similar tracking technologies used to improve performance and analyze usage.
2.3 Data from Integrated Services
When connecting external accounts or integrations (for example, LinkedIn or Google OAuth), Unabyss may receive limited account information necessary to provide the Service, such as name, profile picture, email address, and authorization tokens. Unabyss does not store or have access to passwords from third-party platforms.
Google APIs: Unabyss's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
When a User connects Gmail, Google Calendar, or Google Drive, Unabyss accesses the following data via Google APIs: email messages and threads (gmail.readonly), calendar events (calendar.readonly), and document content (drive.readonly). This data is used solely to build the User's personal context within the Unabyss assistant --- to surface relevant information when the User interacts with the AI. Google user data is never used for advertising, never sold or shared with third parties except subprocessors strictly necessary to operate the Service, and is not used to train AI models. Users may revoke Google access at any time in account settings.
Meta Platform Data: When a User connects their Meta (Facebook) ad account via OAuth using read-only access (ads_read), Unabyss imports campaign-level advertising performance data from the Meta Marketing API --- including spend, impressions, clicks, reach, and conversion metrics --- for the ad accounts the User selects. This data is used solely to provide reporting and analysis back to the connecting User within the Service. Unabyss does not sell Meta Platform Data, does not share it with third parties except subprocessors strictly necessary to operate the Service, and does not use it for advertising, audience building, or to train AI models. Users may disconnect their Meta account at any time in account settings and request deletion of imported data by contacting legal@unabyss.com. Unabyss's use of Platform Data obtained from Meta adheres to the Meta Platform Terms and Developer Policies, including all applicable limited use requirements.
2.4 Data Collected for AI Processing
When using the Unabyss platform, Context Data and conversation messages may be processed by third-party AI systems (including OpenAI, Anthropic/Claude, and Google/Gemini) for the purpose of generating AI Output and performing semantic search. Such processing is limited to the scope necessary for the requested functionality and is performed in accordance with GDPR and contractual safeguards. Context Data is not used to train or improve external AI models.
2.5 Analytics and Tracking Tools
Unabyss uses cookies and tracking technologies for analytics, performance measurement, and marketing. The following third-party tools are used:
(a) Google Analytics --- for website traffic analysis and performance monitoring.
(b) Google Tag Manager --- for managing and deploying tracking scripts.
(c) Meta Pixel (Facebook) --- for conversion tracking and advertising performance.
(d) LinkedIn Insight Tag --- for conversion tracking, retargeting, and campaign analytics.
(e) X (Twitter) Pixel --- for conversion tracking and advertising performance measurement on X.
(f) Microsoft Clarity --- for session analytics, heatmaps, and session replay to understand website usage and improve usability.
Users can manage or disable cookies through their browser settings or by using cookie consent tools available on the website.
2.6 Data from Communication Channels
If the User contacts Unabyss through email, chat, or other communication channels, Unabyss may retain the content of such communications and related metadata for record-keeping and support purposes.
2.7 Marketing Contact Data
Users may provide or maintain contact data, such as name and email address, in connection with an Account or through a newsletter or marketing form. Where a User provides or maintains an email address in connection with an Account and accepts the Terms and Conditions, the address may be used for marketing purposes as described in the Terms and in Section 9 below. Individuals who do not have an Account may voluntarily provide their contact data through a form clearly designated for marketing communications.
2.8 Team Account Data
When a User creates, administers, joins, is removed from, or is invited to a Team, Unabyss may process the Organization name and identifier; Team subscription status; administrator and member identifiers; roles and membership status; invited email addresses and invitation tokens; invitation creation, acceptance, decline, revocation, and expiry events; Seat allocations and Seat changes; Team activation, payment-failure, cancellation, and dissolution events; administrator audit events; Organization billing address and tax identification number; Stripe customer and payment-method metadata (without storing full payment card details); invoices; and related support and dispute records.
2.9 User-Directed External Destinations
Where a User configures MCP distribution, Gbrain outbound mirroring or pull-mode local sync, a webhook, an S3-compatible bucket, or another external destination, Unabyss may process the destination address, authentication or connection details, synchronization settings, transfer logs, and the Context Data selected by the User for transfer.
2.10 Eligibility and Sanctions Screening Data
To verify eligibility to use the Service under Section 3.9 of the Terms and Conditions, Unabyss may process the User's name, entity name, country of residence or establishment, billing address and country, tax identification number, location indicators derived from the IP address, and the outcome of a comparison of that information against the sanctions lists referred to in that Section, together with a record of any potential match, the review decision taken, and related correspondence.
3. Purpose and Legal Basis of Processing
3.1 Provision of the Service. Personal data is processed to register and maintain User Accounts, authenticate access, manage Context Data, provide the functionalities of the Unabyss platform, administer Teams, enforce the one-Team-per-User rule, manage roles and membership, and implement account deletion and offboarding instructions. Legal basis: Article 6(1)(b) GDPR --- processing is necessary for the performance of a contract to which the User is a party; Article 6(1)(f) GDPR --- legitimate interest in secure account and Team administration where the data subject is not the contracting party.
3.2 Payment, Credits, Subscriptions, and Invoicing. Billing details, billing addresses, tax identification numbers, credit balances, Personal and Team Subscription status, Seat quantity and changes, transaction and proration history, payment-method metadata, invoices, pre-authorization records, and payment or chargeback communications are processed to manage payments, operate Stripe billing and Customer Portal functions, issue and archive invoices, calculate taxes, and maintain accounting records. Personal billing data relates to the individual billing profile; Team billing data relates to the Organization billing profile and is available to the Team Administrator or authorized billing contact. Legal basis: Article 6(1)(b) GDPR --- contract performance; Article 6(1)(c) GDPR --- compliance with tax, invoicing, and accounting obligations; Article 6(1)(f) GDPR --- legitimate interest in payment security, fraud prevention, and resolving billing disputes.
3.3 AI Content Generation. Context Data and conversation messages are processed using Unabyss's AI systems and trusted third-party AI providers (OpenAI, Anthropic, Google/Gemini) to generate AI Output. Processing is limited to what is necessary for the requested functionality and is not used for unrelated purposes. Legal basis: Article 6(1)(b) GDPR --- contract performance.
3.4 User-Directed External Distribution and Storage. When Users distribute Context Data through MCP or direct Unabyss to mirror, synchronize, tunnel, or transfer Context Data to a User-configured external destination, including a local Gbrain instance, webhook, S3-compatible bucket, or another destination, Unabyss processes the Context Data and connection settings necessary to facilitate on-demand or continuous transfer. Depending on the User's selected settings or plan, Context Data may be stored within the Unabyss Platform, transferred to the external destination without persistent storage by Unabyss, or both. The destination is selected and controlled by the User and, unless separately identified as a Unabyss subprocessor, is not engaged by Unabyss. Once data is delivered, its subsequent processing is governed by the User's arrangements with the destination or its operator. Legal basis: Article 6(1)(b) GDPR --- contract performance.
3.5 Service Improvement and Product Development. Aggregated and anonymized data may be used to improve the accuracy, efficiency, and usability of the Service. If personal data is required for this purpose, separate consent will be obtained from the User. Legal basis: Article 6(1)(f) GDPR --- legitimate interest in improving the Service.
3.6 Customer Support and Communication. Data such as contact details and message history are processed to respond to inquiries, provide assistance, manage customer relationships, and send essential service communications, including security, billing, account, subscription, legal, and material service notices. Essential service communications do not include marketing content. Legal basis: Article 6(1)(b) GDPR --- contract performance; Article 6(1)(c) GDPR --- compliance with legal obligations, where applicable; Article 6(1)(f) GDPR --- legitimate interest in providing effective support and ensuring secure and reliable operation of the Service.
3.7 Marketing and Product Communications. Unabyss processes Users' contact details for the purpose of promoting Unabyss's own Services, including providing information about features, plans, offers, events, surveys, and educational content. The processing of personal data for direct marketing purposes is based on Unabyss's legitimate interest under Article 6(1)(f) GDPR. Commercial information is sent by email or other electronic means where the User has consented to such communication in accordance with applicable electronic communications laws, including by providing or maintaining an electronic address for that purpose in the manner described in Section 4.11 of the Terms and Conditions. For individuals who do not have an Account and provide contact data solely through a marketing form, processing is based on consent under Article 6(1)(a) GDPR. The User may withdraw consent to the use of the electronic communication channel or object to the processing of personal data for direct marketing purposes at any time; in either case, Unabyss will cease sending marketing communications without affecting essential service communications.
3.8 Analytics and Website Optimization. Cookies and analytics tools (including Google Analytics, Google Tag Manager, Meta Pixel, LinkedIn Insight Tag, X (Twitter) Pixel, and Microsoft Clarity) are used to understand website traffic, performance, and effectiveness of marketing campaigns. Legal basis: Article 6(1)(a) GDPR --- consent through cookie banner or preferences; Article 6(1)(f) GDPR --- legitimate interest in maintaining secure and efficient website performance (for essential cookies only).
3.9 Compliance with Legal Obligations. Personal data may be processed to comply with legal obligations, including bookkeeping, fraud prevention, or responding to lawful requests by public authorities. Legal basis: Article 6(1)(c) GDPR --- compliance with legal obligations.
3.10 Protection of Rights and Interests. Personal data may be processed when necessary to establish, exercise, or defend legal claims, or to prevent abuse, fraud, or misuse of the Service. Legal basis: Article 6(1)(f) GDPR --- legitimate interest in protecting the company's rights and ensuring service integrity.
3.11 Recruitment and Collaboration. If individuals apply for employment or partnership opportunities with Unabyss, their personal data will be processed for recruitment or evaluation purposes. Legal basis: Article 6(1)(b) GDPR --- pre-contractual measures; Article 6(1)(a) GDPR --- consent, where applicable.
3.12 Team Accounts. Unabyss processes Team and Organization details, administrator and member identifiers, roles, membership status, invitation email addresses and tokens, invitation and role-change audit events, Seat allocations and changes, Team subscription and billing metadata, payment status, cancellation and dissolution events, and administrator instructions to create and administer Teams, enforce one Organization per User, send and manage invitations, assign roles, manage Seats and billing, prevent misuse, process offboarding, and dissolve Teams safely. Unless a different period is displayed, invitation tokens expire after seven (7) days. Only Team Administrators may access the list of members, roles, pending invitations, Seat usage, invoices, and payment portal information; ordinary Team Members do not have access to Team billing information. Team Administrators do not gain access to another Member's Context Data, AI Output, memory, Integrations, or other private Content, and Unabyss does not provide an Organization-wide export or transfer of a departing Member's Content; a removed Member may export their own Content during the grace period described in Section 11.8. The Service does not technically separate work and personal Content within a Member Account. Invitation emails are sent only to operate the invitation flow and are not used for unrelated marketing. Legal basis: Article 6(1)(b) GDPR where processing is necessary to perform an Agreement with the data subject; Article 6(1)(f) GDPR --- legitimate interest in providing and securely administering Team functionality, including for invitees who do not yet have an Account; Article 6(1)(c) GDPR --- compliance with tax and accounting obligations.
3.13 Roles in Team Processing. Where an Organization determines the purposes and means of using Team functionality for its workforce, contractors, invitations, membership, and offboarding, the Organization is generally the controller and Unabyss processes the relevant personal data on the Organization's documented instructions as a processor under the applicable data processing agreement. This includes administrator-ordered Account deactivation and full Content purge. Unabyss acts as an independent controller for data processed for Account registration and authentication, security and abuse prevention, its own billing relationship, tax and accounting compliance, legal claims, and compliance with law. Team Members may import or create Content on their User-scoped Accounts, but the Service does not provide a separate technical mode for "business" and "personal" Content. The Organization is responsible for providing required workforce notices, establishing a lawful basis, and ensuring that Team administration and offboarding instructions comply with applicable law.
3.14 Sanctions and Restricted Jurisdiction Screening. Unabyss processes the data described in Section 2.10 in order to verify that Users are eligible to use the Service under Section 3.9 of the Terms and Conditions, to comply with restrictive measures adopted by the European Union and the United Nations and applied in Poland, and, where relevant to a given transaction, with the sanctions regimes of the United States and the United Kingdom. A potential match is reviewed by a member of Unabyss's staff before any decision to refuse registration or to suspend or terminate an Account is taken; such decisions are not taken solely by automated means. A User affected by such a decision may contest it and request human re-examination by contacting legal@unabyss.com. Legal basis: Article 6(1)(c) GDPR --- compliance with a legal obligation to which Unabyss is subject; Article 6(1)(f) GDPR --- legitimate interest in preventing unlawful use of the Service and in protecting Unabyss against regulatory and financial risk, in respect of any screening going beyond a strict legal obligation.
4. Data Sharing and Subprocessors
4.1 General Rules. Unabyss does not sell or rent personal data. Data may be shared only with trusted partners and subprocessors where necessary to operate the Service, fulfill contractual obligations, or comply with legal requirements. Each subprocessor is bound by a written data processing agreement ensuring confidentiality, security, and GDPR compliance.
4.2 Categories of Recipients. Personal data may be shared with the following categories of recipients:
(a) Technical service providers supporting hosting, infrastructure, or storage.
(b) Payment processors and financial institutions.
(c) Analytics and advertising partners.
(d) Communication and email delivery platforms.
(e) AI technology providers used for content generation, transcription, or analysis.
(f) Data import and integration infrastructure providers used to retrieve data from third-party services connected by the User.
(g) Public authorities when required by law.
Additional recipients may include: (a) Team Administrators acting on behalf of the Organization paying for a Team, limited to identification, membership, role, invitation, Seat, subscription, invoice, and billing information, without access to Members' private Context Data, AI Output, memory, Integrations, or other Content solely by reason of the Team relationship; (b) payment processors, invoicing, accounting, and archive providers used for Personal and Organization-attributed billing; and (c) external destinations and their operators selected by the User for MCP distribution, mirroring, synchronization, tunneling, or storage.
4.3 Core Subprocessors and Providers. To deliver the Service, Unabyss currently engages the following subprocessors and technology partners:
Hosting and Infrastructure:
Contabo --- VPS hosting, S3-compatible cloud storage, and application infrastructure.
Neon Inc. --- managed PostgreSQL database hosting for the Service's production database.
Cloudflare, Inc. --- edge delivery, CDN, and Workers for signed URL proxy.
Payments and Billing:
Stripe, Inc. --- payment processing, subscription management, and pre-authorization holds.
Invoicing, accounting, and document-archive providers --- issuing, delivering, reporting, and retaining Personal and Organization-attributed invoices and billing records, where used by Unabyss.
Analytics and Advertising:
Google LLC (Google Analytics, Google Tag Manager) --- analytics and performance tracking.
Meta Platforms Ireland Ltd. (Meta Pixel) --- conversion tracking and campaign optimization.
LinkedIn Ireland Unlimited Company (LinkedIn Insight Tag) --- conversion tracking and retargeting.
X Corp. (X / Twitter Pixel) --- conversion tracking and advertising performance measurement.
Microsoft Corporation (Microsoft Clarity) --- session analytics, heatmaps, and session replay.
Artificial Intelligence and Content Generation:
OpenAI, L.L.C. --- text generation and analysis.
Anthropic PBC (Claude) --- reasoning and text generation.
Google LLC (Gemini) --- natural language processing.
Speech-to-Text:
- ElevenLabs, Inc. (Scribe) --- real-time speech-to-text transcription.
Email and Communication:
Resend --- transactional and marketing email delivery.
Slack Technologies, LLC --- internal organization and operational notifications.
Customer Support:
- Chatwoot Inc. --- in-product support and messaging, including the content of support conversations.
Data Import and Integration Infrastructure:
Apify Technologies s.r.o. --- retrieval of data from third-party services connected by the User.
Pipedream, Inc. --- integration and workflow infrastructure supporting connections to third-party services.
Meta Platforms Ireland Ltd.:
- Import of advertising performance data from the Meta Marketing API, at the User's direction.
All subprocessors are contractually obliged to handle data securely, process it only on documented instructions, and comply with the GDPR or equivalent safeguards.
4.4 International Transfers. Some subprocessors may process data outside the European Economic Area (EEA), particularly in the United States. In such cases, Unabyss ensures adequate protection by relying on an adequacy decision of the European Commission (including the EU--US Data Privacy Framework, where the recipient is certified under it), Standard Contractual Clauses (SCCs) approved by the European Commission, or another transfer mechanism permitted under Chapter V of the GDPR.
4.5 Access Control. Access to personal data within Unabyss is strictly limited to authorized employees and contractors who require access for the performance of their duties. All individuals with access are bound by confidentiality agreements and receive training in data protection principles.
4.6 Updates to the List of Subprocessors. The list of subprocessors may change from time to time to reflect operational needs. An updated list will be maintained by Unabyss and made available to Users upon request. In the event of a material change affecting personal data, Users will be notified prior to the new subprocessor's engagement.
5. International Transfers and Data Storage
5.1 Data Storage Locations. Personal data collected and processed by Unabyss is stored on application and object-storage infrastructure operated by Contabo on servers located within the European Economic Area (EEA), and in a managed PostgreSQL database operated by Neon Inc., which may be provisioned in a region outside the EEA. Transfers arising from the location of the database are protected by the safeguards described in Section 5.2. Depending on the User's selected settings or plan, Context Data may instead be transferred to a User-configured external destination and may not be persistently stored on Unabyss infrastructure. The location and operator of such destination are determined by the User and may include a local instance or a destination outside the EEA. However, some data may be transferred or temporarily processed outside the EEA by subprocessors located in countries that do not provide an equivalent level of data protection.
5.2 Legal Safeguards for Transfers. When personal data is transferred outside the EEA, Unabyss ensures that such transfers are protected by appropriate legal safeguards, including:
(a) Standard Contractual Clauses (SCCs) adopted by the European Commission.
(b) Adequacy decisions issued by the European Commission for certain jurisdictions.
(c) Other mechanisms permitted under Articles 45--49 of the GDPR.
5.3 Countries of Transfer. Certain subprocessors, such as OpenAI, Anthropic, ElevenLabs, Stripe, Neon, Pipedream, Chatwoot, and Google (for Gemini AI processing), may process data in the United States or other non-EEA jurisdictions. In all such cases, Unabyss requires that these entities apply GDPR-equivalent security and privacy measures and enters into a binding data processing agreement which relies, as applicable to the recipient, on an adequacy decision of the European Commission (including the EU--US Data Privacy Framework, where the recipient is certified under it), Standard Contractual Clauses, or another transfer mechanism permitted under Chapter V of the GDPR.
5.4 Backups and Recovery. Regular backups of data stored within Unabyss are performed to ensure continuity and resilience. Backup data is stored securely on S3-compatible storage and subject to the same protection measures as production data.
5.5 Security of Transfers. All international data transfers and remote accesses are protected by encryption and secure communication protocols (TLS/HTTPS). Access to data by subprocessors is limited to specific, documented processing tasks and is monitored through contractual and technical controls.
6. Data Security Measures
6.1 General Commitment. Unabyss applies appropriate technical and organizational measures to ensure a level of security appropriate to the risk associated with the processing of personal data. These measures are designed to prevent unauthorized access, alteration, disclosure, or destruction of information.
6.2 Technical Measures. The following technical safeguards are implemented:
(a) Encryption of data in transit (TLS/HTTPS) and at rest.
(b) Secure server configuration, firewalls, and Nginx reverse proxy to prevent unauthorized access.
(c) JWT-based authentication with short-lived access tokens (60 minutes) and rotating refresh tokens.
(d) Regular software updates and patch management.
(e) Anonymization or pseudonymization of data where appropriate.
(f) Secure deletion and overwriting of data when no longer needed.
(g) Automated database backups to S3-compatible cloud storage.
(h) Continuous monitoring of infrastructure and detection of potential threats.
6.3 Organizational Measures. Organizational controls applied by Unabyss include:
(a) Restricted access to data based on role and necessity.
(b) Confidentiality agreements for employees and contractors.
(c) Mandatory data protection and cybersecurity training.
(d) Clear internal procedures for handling data breaches.
(e) Regular security audits and compliance reviews.
6.4 Incident Management and Data Breach Response. In the event of a personal data breach, Unabyss will:
(a) Assess the scope and impact of the incident.
(b) Take immediate steps to mitigate harm.
(c) Notify the competent supervisory authority (President of the Personal Data Protection Office in Poland) within 72 hours if required under Article 33 of the GDPR.
(d) Inform affected Users when the breach is likely to result in a high risk to their rights and freedoms.
6.5 Subprocessor Security. All subprocessors used by Unabyss are required to implement comparable security measures and to comply with GDPR standards. Their compliance is verified through contractual guarantees and, where possible, security documentation or audits.
6.6 Data Integrity and Confidentiality. Unabyss ensures that personal data remains accurate, complete, and confidential throughout its lifecycle. Regular reviews are carried out to maintain the integrity of stored information.
6.7 Physical Security. Data centers hosting the Service are maintained by professional providers (Contabo) that ensure physical security, including restricted access, 24/7 monitoring, and environmental controls.
7. User Rights under GDPR
7.1 General Information. Users whose personal data is processed by Unabyss have the rights described in this section. Unabyss respects and facilitates the exercise of these rights in accordance with Articles 12--23 of the GDPR.
7.2 Right of Access. Users have the right to obtain confirmation as to whether or not their personal data is being processed, and, where that is the case, to access such data and receive information about its source, purpose, and recipients.
7.3 Right to Rectification. Users have the right to request correction of any inaccurate or incomplete personal data concerning them.
7.4 Right to Erasure ("Right to be Forgotten"). Users have the right to request the deletion of their personal data when:
(a) The data is no longer necessary for the purposes for which it was collected.
(b) The User withdraws consent (where consent was the legal basis).
(c) The User objects to processing and there are no overriding legitimate grounds.
(d) The processing is unlawful.
(e) Deletion is required by law.
This right may not apply where data retention is required for compliance with legal obligations or for the establishment, exercise, or defense of legal claims.
7.5 Right to Restriction of Processing. Users may request restriction of processing where:
(a) The accuracy of personal data is contested.
(b) The processing is unlawful but the User opposes deletion.
(c) Unabyss no longer needs the data but the User requires it for legal claims.
(d) The User has objected to processing pending verification of legitimate grounds.
7.6 Right to Data Portability. Users have the right to receive their personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible. This includes Context Data, context files, and conversation histories. Where an Account is deactivated and scheduled for purge following removal from a Team or Team dissolution, this right may be exercised during the grace period described in Section 11.8.
7.7 Right to Object. Users have the right to object at any time to the processing of their personal data based on legitimate interests or for direct marketing purposes. If the objection concerns direct marketing, Unabyss will stop the processing for that purpose without further balancing. For other processing based on legitimate interests, Unabyss may continue only if it demonstrates compelling legitimate grounds that override the User's interests, rights, and freedoms, or if the processing is required for legal claims.
7.8 Right to Withdraw Consent. Where processing is based on consent, the User may withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
7.9 Right to Lodge a Complaint. Users have the right to lodge a complaint with the competent supervisory authority if they believe that the processing of their personal data infringes applicable data protection laws. In Poland, the supervisory authority is the Personal Data Protection Office (UODO), ul. Stanisława Moniuszki 1A, 00-014 Warszawa, Poland. Website: https://uodo.gov.pl.
7.10 Exercising Rights. Requests regarding any of the above rights can be submitted by email to privacy@unabyss.com. Unabyss will respond to verified requests within one month of receipt, or within three months in complex cases, in accordance with Article 12(3) of the GDPR.
8. Cookies and Tracking Technologies
8.1 Use of Cookies. Unabyss's websites and web applications use cookies and similar tracking technologies to ensure proper functionality, analyze performance, and improve the User experience. Cookies are small text files stored on the User's device by their browser.
8.2 Types of Cookies Used. The following types of cookies may be used:
(a) Essential cookies --- required for the basic operation of the website, including login (JWT token management), navigation, and session management.
(b) Functional cookies --- enable enhanced functionality, such as remembering preferences and improving usability.
(c) Analytics cookies --- collect information on how Users interact with the website to help improve performance and content (Google Analytics, Google Tag Manager, Microsoft Clarity).
(d) Marketing cookies --- track User interactions for advertising and remarketing purposes (Meta Pixel, LinkedIn Insight Tag, X (Twitter) Pixel).
8.3 Cookie Consent. On the first visit to the Unabyss website, Users are presented with a cookie banner allowing them to accept or reject non-essential cookies. Consent is recorded and can be modified or withdrawn at any time through the cookie settings interface or browser preferences.
8.4 Third-Party Cookies. Some cookies may be placed by third-party service providers integrated with the website. These providers include:
(a) Google LLC --- for analytics (Google Analytics), tag management (Google Tag Manager), and marketing.
(b) Meta Platforms Ireland Ltd. --- for marketing and conversion tracking (Meta Pixel).
(c) LinkedIn Ireland Unlimited Company --- for conversion tracking and retargeting (LinkedIn Insight Tag).
(d) X Corp. --- for conversion tracking and advertising performance measurement (X / Twitter Pixel).
(e) Microsoft Corporation --- for session analytics, heatmaps, and session replay (Microsoft Clarity).
Each third party is responsible for its own privacy practices. Users are encouraged to review their privacy policies at: Google: https://policies.google.com/privacy; Meta: https://www.facebook.com/privacy/policy; LinkedIn: https://www.linkedin.com/legal/privacy-policy.
8.5 Managing Cookies. Most browsers allow Users to control cookies through settings that block, delete, or alert them about cookie use. However, disabling certain cookies may affect the functionality or performance of the website.
8.6 Retention of Cookie Data. Cookies are stored for varying durations depending on their type: session cookies are deleted automatically when the browser is closed; persistent cookies remain stored for a defined period or until manually deleted.
8.7 Analytics and Anonymization. Data collected through analytics tools is processed in an aggregated and anonymized form whenever possible. IP anonymization is enabled for Google Analytics to comply with GDPR requirements.
8.8 Withdrawal of Consent. Users can withdraw consent to non-essential cookies at any time by updating their cookie preferences on the website or through their browser settings.
9. Marketing Communication and Newsletters
9.1 Product and Marketing Communications. When a User provides or maintains an email address in connection with an Account and accepts the Terms and Conditions, the User makes that address available for the purposes specified in Section 4.11 of the Terms, including receiving commercial information concerning Unabyss's own Services. Such communications may include newsletters, onboarding guidance, product tips, feature updates, plans, offers, events, surveys, and educational content. Individuals who do not have an Account may voluntarily subscribe through a form clearly designated for marketing communications. Essential service communications described in Section 3.6 are not affected by a marketing opt-out.
9.2 Legal Basis. Personal data used for direct marketing of Unabyss's own Services is processed on the basis of Unabyss's legitimate interest under Article 6(1)(f) GDPR. The use of email or another electronic communication channel is based on the recipient's consent required under applicable electronic communications laws, including consent expressed by making an electronic address available for marketing purposes in the manner described in the Terms and Conditions. For individuals who are not Users and subscribe through a dedicated form, personal data is processed on the basis of consent under Article 6(1)(a) GDPR.
9.3 Making the Address Available for Marketing. A User's consent to receiving commercial information by email may be expressed by providing or maintaining an email address in connection with an Account and accepting the Terms and Conditions, which state that the address is also made available for marketing purposes. Unabyss may use a double opt-in procedure as an additional verification measure. Individuals who do not have an Account provide consent through a form clearly designated for marketing communications.
9.4 Content of Communication. Marketing communication may include:
(a) Information about new features, updates, or product releases.
(b) Educational content related to AI, context management, and professional workflows.
(c) Invitations to events, beta programs, or surveys.
(d) Limited promotional offers or discounts.
9.5 Email Platform. Email communication is managed using Resend for both transactional and marketing email delivery. Resend is bound by a GDPR-compliant data processing agreement.
9.6 Unsubscribing and Objection. Users may withdraw consent to the use of the electronic communication channel, object to the processing of personal data for direct marketing, or unsubscribe at any time by changing the relevant Account setting, clicking the "unsubscribe" link included in each marketing email, or contacting privacy@unabyss.com. Unsubscribing or objecting will not affect transactional or essential service-related messages (for example, billing or system notifications).
9.7 Frequency of Messages. Unabyss limits the frequency of marketing messages to a reasonable level to prevent spam and ensure relevance.
9.8 Data Retention. Personal data processed for marketing purposes will be retained until the User objects to direct marketing, withdraws consent to the electronic communication channel, or unsubscribes, after which it will be deleted or anonymized within thirty (30) days, unless a longer period is necessary to establish, exercise, or defend legal claims. Unabyss may retain limited information necessary to demonstrate the circumstances in which the address was made available for marketing and to maintain a suppression record preventing further marketing messages.
9.9 Analytics of Engagement. Unabyss may analyze anonymized engagement metrics such as open rates, click rates, and unsubscribe statistics to improve the relevance and quality of its communication. This data is never used for profiling or automated decision-making that produces legal effects.
10. Automated Decision-Making and Profiling
10.1 No Automated Decisions with Legal Effects. Unabyss does not engage in automated decision-making that produces legal effects or similarly significant consequences for Users within the meaning of Article 22 of the GDPR. The sanctions and eligibility screening described in Section 3.14 includes human review of any potential match before a decision is taken, and is therefore not a decision based solely on automated processing.
10.2 AI-Driven Processing. The Unabyss platform uses artificial intelligence technologies to assist Users in managing context, generating content, and conducting research. Such processing is always initiated by the User and serves only to deliver requested functionality. AI systems do not make autonomous decisions about Users, nor do they evaluate or score individuals.
10.3 Limited Personalization. Some personalization may occur within the Service to improve User experience, such as recommending context file organization. This personalization is rule-based and does not involve behavioral profiling or automated evaluation of personality, preferences, or performance.
10.4 Human Oversight. All AI-based operations performed within the Service are subject to human oversight. Users maintain full control over their AI Output and must review and approve all generated content.
10.5 Transparency of AI Providers. AI processing is performed using trusted third-party providers (OpenAI, Anthropic/Claude, Google/Gemini, and ElevenLabs). Each provider operates under contractual terms that ensure GDPR compliance, confidentiality, and limited data use. Context Data and conversation data are not used to train or improve external AI models.
10.6 User Control. Users can manage their Context Data or delete their data through the account settings or by contacting privacy@unabyss.com.
10.7 Marketing Analytics and Profiling. Unabyss does not carry out automated decision-making producing legal effects or similarly significant consequences for marketing purposes. Subject to cookie consent, analytics and advertising partners may process online identifiers and interaction data to measure campaign performance and, where enabled, support retargeting as described in Sections 2.5 and 8. Unabyss does not use Context Data or AI Output to create advertising profiles.
11. Data Retention and Deletion
11.1 General Principle. Personal data is retained only for as long as necessary to achieve the purposes for which it was collected or to comply with legal, accounting, or reporting obligations. After this period, data is securely deleted or anonymized.
11.2 Retention Periods by Category. The following retention rules apply unless a longer period is required by law:
(a) Account data --- retained for the duration of the User's Account. On deletion or deactivation followed by purge, Account data is removed from production systems without undue delay, and residual copies are removed from encrypted backups as those backups age out, in any event within ninety (90) days. Limited identifiers, Organization association, billing records, tax invoices, security logs, and audit events may be retained for longer where required by law or necessary for claims.
(b) Context Data, context files, and AI Output --- retained for the duration of the User's Account and deleted upon account closure or earlier at the User's request.
(c) Conversation logs --- retained for the duration of the User's Account.
(d) Payment, credit transaction, Personal and Team Subscription, Seat-proration, Organization billing, invoice, and payment-dispute information --- retained for the period required by Polish tax and accounting regulations and for the duration necessary to establish, exercise, or defend legal claims.
(e) Customer support communications --- retained for up to two (2) years to ensure service quality and resolve potential disputes.
(f) Newsletter and marketing data --- retained until the User objects to direct marketing, withdraws consent to the electronic communication channel, or unsubscribes, after which data is deleted or anonymized within thirty (30) days, subject to the retention of a limited suppression record.
(g) Backups --- retained for a limited period (up to ninety (90) days) for system recovery and continuity purposes.
(h) Sanctions and eligibility screening records, including records of potential matches and review decisions --- retained for five (5) years from the end of the relationship with the User, or for such longer period as is necessary to demonstrate compliance with applicable restrictive-measures legislation or to establish, exercise, or defend legal claims.
Additional retention rules. Team membership and role data is retained during the Team relationship and thereafter as necessary to document access, offboarding, billing, security, or claims. Pending invitation tokens expire after seven (7) days unless a different period is displayed; invitation email addresses and event logs may be retained until acceptance, decline, revocation, expiry, or Team dissolution and for up to ninety (90) days thereafter for security, dispute handling, or audit purposes. Team activation, Seat changes, role changes, removals, payment failures, cancellation, and dissolution events may be retained in alignment with Organization billing records and legal-hold periods. In an external-destination-only mode, Unabyss does not retain a persistent copy of Context Data after transfer, subject to transient processing, security logs, and backup cycles. Limited records documenting the making available of an electronic address for marketing, withdrawal, objection, and suppression may be retained for the period necessary to demonstrate compliance and honor a marketing opt-out.
11.3 Criteria for Retention. Retention periods are determined based on the duration of the contractual relationship, applicable legal requirements, the nature and sensitivity of the data, and the potential risk of unauthorized use or disclosure.
11.4 Secure Deletion. Once data reaches the end of its retention period, it is securely deleted or irreversibly anonymized using appropriate technical measures to prevent recovery.
11.5 User-Initiated Deletion. Users may request deletion of their Account and associated data through Account settings or by contacting privacy@unabyss.com. Before deleting an Account, the User may export their Context Data and AI Output through the Service. Deleting a personal Account deactivates login, immediately cancels the Personal Subscription, and triggers an irreversible full purge of Context Data and AI Output from production systems, with residual copies removed from backups as described in Section 11.2(g). A separate context-purge function, where available, keeps the Account active. Deleting a Team Member Account ends Team membership, may automatically reduce the Organization's purchased Seat quantity, and does not restore a previous Personal Subscription. A sole Team Administrator cannot delete the Account while other Team Members remain unless another Administrator is appointed or the Team is cancelled. If the last person in an Organization deletes the Account, the Team Subscription is cancelled and the Organization is dissolved. Deletion from Unabyss does not remove copies previously delivered to User-configured external destinations. Limited identifiers, Organization association, billing history, tax invoices, payment records, security logs, and audit events may remain where required by law, necessary for claims, or processed under a lawful Organization instruction.
11.6 Exceptions. Certain data may be retained for a longer period if necessary for compliance with legal or regulatory requirements, establishment, exercise, or defense of legal claims, or prevention of fraud, abuse, or misuse of the Service.
11.7 Anonymization for Statistical Use. Unabyss may retain anonymized and aggregated data after Account deletion for statistical analysis, service improvement, or research purposes. Such data cannot be linked to any identifiable User.
11.8 Team Offboarding, Grace Period, and Organization Dissolution. When a Team Administrator removes a Member, the Member's Team access ends and the Member Account is deactivated and enters a grace period of thirty (30) days. Unabyss notifies the Member by email at the start of the grace period. During the grace period the Member may sign in for the sole purpose of exporting their User-scoped Context Data and AI Output, and may exercise the rights described in Section 7, including the right to data portability under Section 7.6. At the end of the grace period, or earlier if the Member confirms that the export is complete, the Member's User-scoped Context Data and AI Output are irreversibly purged. Where a portability or access request is outstanding at the end of the grace period, the purge is deferred until that request has been fulfilled. The export is available to the Member only: the Service does not provide an Organization export, transfer to another User, or partial deletion limited to work-related data.
When a Team is cancelled at the end of a billing period, the offboarding process begins when the Team Subscription ends; where immediate cancellation is selected, it begins immediately. Team dissolution invalidates pending invitations and deactivates all Member Accounts, each of which enters the thirty (30) day grace period described above before the corresponding purge takes place. Organization status, invoices, tax records, payment records, and necessary audit events may be retained after dissolution for statutory, security, dispute, and legal-hold purposes.
12. Children's Data
12.1 Age Restriction. The Unabyss Service is intended exclusively for individuals who are at least eighteen (18) years old. Unabyss does not knowingly collect or process personal data from children under this age.
12.2 Parental Consent. If it becomes apparent that personal data has been collected from a minor without verifiable parental consent, Unabyss will take immediate steps to delete such data and, where applicable, to disable the associated Account.
12.3 Responsibility of Users. Users creating an Account on behalf of an organization are responsible for ensuring that all individuals who access the Service under their authorization meet the minimum age requirement.
12.4 Reporting. Parents or guardians who believe that their child has provided personal data to Unabyss without consent are encouraged to contact privacy@unabyss.com. Unabyss will investigate and act promptly to remove the data in accordance with applicable law.
13. Changes to the Privacy Policy
13.1 Right to Update. Unabyss reserves the right to modify or update this Privacy Policy at any time to reflect changes in legal requirements, technology, or the operation of the Service.
13.2 Notification of Changes. In the event of material changes affecting the way personal data is processed, Unabyss will notify Users by email or by displaying a notice within the Service prior to the effective date of the updated Privacy Policy.
13.3 Effect of Changes. The updated Privacy Policy applies from its effective date, but continued use of the Service does not constitute consent to any processing for which applicable law requires consent. Where consent is required, Unabyss will obtain it in the manner described in the Terms and Conditions or separately where applicable. Users who do not agree to the modifications may discontinue use of the Service and request deletion of their data.
13.4 Historical Versions. Previous versions of this Privacy Policy will be archived and made available upon request.
13.5 Effective Date. This Privacy Policy enters into force on the date of publication on the Unabyss website and remains valid until replaced by a new version.
14. Contact Information and Supervisory Authority
14.1 Data Controller Contact. For any questions, requests, or concerns related to this Privacy Policy or the processing of personal data, Users may contact Unabyss at: OneType Prosta Spółka Akcyjna, ul. Fabryczna 4A/11, 00-446 Warszawa, Poland. KRS: 0001224271; NIP: 7011299839. Email: privacy@unabyss.com. Website: unabyss.com.
14.2 Data Protection Officer. Unabyss has not designated a Data Protection Officer (DPO), as it is not required to do so under Article 37 of the GDPR, and has made no corresponding notification to the President of the Personal Data Protection Office. All data protection inquiries should be directed to privacy@unabyss.com. If Unabyss designates a DPO in the future, the DPO's contact details will be published on the Unabyss website and notified to the supervisory authority, and this Privacy Policy will be updated accordingly.
14.3 Supervisory Authority. Users have the right to lodge a complaint with the competent supervisory authority if they believe that their personal data is being processed in violation of applicable law. The competent authority in Poland is the Personal Data Protection Office (UODO), ul. Stanisława Moniuszki 1A, 00-014 Warszawa, Poland. Website: https://uodo.gov.pl.
14.4 Language of Communication. Communication regarding privacy and data protection matters may be conducted in English or Polish.
14.5 Final Provision. This Privacy Policy applies to all services provided by Unabyss under the domains unabyss.com and app.unabyss.com and their subdomains.