Unnoodle · Privacy Policy

Privacy Policy

We collect the minimum data needed to run the product. We do not sell it, profile you with it, or share it beyond what is necessary to deliver the service.

Last updated: July 2025 · Effective date: July 2025

At a glance

Minimal data collection

We collect account identifiers, product usage, and support communications — nothing beyond what the service requires.

3-year retention limit

Account data is retained for up to 3 years after inactivity or account closure, then deleted.

GDPR rights honoured

You may export your data (Art. 20), request erasure (Art. 17), and withdraw consent at any time.

No selling, no profiling

We do not sell personal data. We do not build advertising profiles. Third-party tools are strictly limited to operating the service.

Subprocessors disclosed

We use a small set of subprocessors for infrastructure and communications. All are bound by data processing agreements.

privacy@unnoodle.com

Send any privacy question, access request, or deletion request directly to our privacy contact.

01 — Scope

Who this policy covers

This policy applies to personal data processed by Unnoodle ("Unnoodle", "we", "us") when you visit our marketing website, sign up for the product, or contact us. It covers all personal data we hold as a data controller under the EU General Data Protection Regulation (GDPR).

Data processed inside your organisation's Unnoodle workspace (for example, meeting notes, action items, and team comments) is processed by us as a data processor on behalf of your organisation, which acts as the data controller. Your organisation's own privacy policy governs that data.

02 — Data collection

What we collect and why

Account data

  • Name and work email address — to create and manage your account
  • Organisation name and domain — to provision your workspace
  • Password hash (bcrypt, never the plaintext password) — for authentication
  • Two-factor authentication secret (AES-256-GCM encrypted at rest) — for account security

Usage data

  • Feature interaction events (e.g. meeting created, action item resolved) — to understand how the product is used and improve it
  • Session metadata (IP address, browser, device type) — for security monitoring and abuse prevention
  • Error and performance telemetry — to diagnose bugs and maintain reliability

Communications data

  • Emails and messages you send us — to respond to enquiries and provide support
  • In-product feedback submissions — to inform the product roadmap

Payment data

We use Stripe to process payments. Card numbers and payment details are never stored on our systems. We retain billing history (plan, amount, date) for legal and audit purposes.

04 — Retention

How long we keep your data

We retain personal data only as long as necessary for the purpose it was collected, subject to the following defaults:

  • Active account data — held while your account is active
  • Inactive or closed account data — deleted within 3 years of last activity or closure
  • Support communications — deleted within 3 years of the last exchange
  • Security audit logs — retained for 12 months, then deleted
  • Billing records — retained for 7 years to meet statutory accounting obligations

You can request earlier deletion of your account data at any time (see Your rights below).

05 — Sharing

Who we share data with

We do not sell personal data. We share data only with subprocessors that help us deliver the service, each bound by a data processing agreement:

  • Cloud infrastructure provider — for hosting, storage, and database services
  • Stripe — for payment processing
  • Transactional email provider — to send account and system notifications
  • Error monitoring service — to capture and diagnose application errors

We may disclose personal data if required by law, court order, or to protect the rights, property, or safety of Unnoodle, its users, or the public.

We do not transfer personal data outside the EEA without ensuring an adequate level of protection, either through an EU adequacy decision or Standard Contractual Clauses.

06 — Your rights

What you can ask us to do

Under the EU GDPR you have the following rights. To exercise any of them, email privacy@unnoodle.com. We will respond within one month.

  • Access (Art. 15) — receive a copy of the personal data we hold about you
  • Portability (Art. 20) — receive your account data in a structured, machine-readable format
  • Rectification (Art. 16) — correct inaccurate data
  • Erasure (Art. 17) — request deletion of your personal data where no overriding legal obligation requires us to retain it
  • Restriction (Art. 18) — ask us to pause processing while a dispute is resolved
  • Objection (Art. 21) — object to processing based on legitimate interests
  • Withdraw consent — opt out of marketing emails at any time with no effect on service access

You also have the right to lodge a complaint with the data protection authority in your country of residence.

07 — Cookies

Cookies and local storage

We use a small number of strictly necessary cookies and local storage entries to operate the product:

  • Session token — keeps you authenticated; expires when you sign out or after 30 days of inactivity
  • CSRF token — protects form submissions from cross-site request forgery
  • UI preference keys (e.g. sidebar state) — stored in localStorage, never sent to our servers

We do not use advertising cookies, cross-site tracking, or third-party analytics cookies that send data to external advertising networks.

08 — Contact

How to reach us

For any privacy question, data subject request, or concern:

  • Email: privacy@unnoodle.com
  • Response time: within 5 business days for general enquiries; within 1 month for formal data subject requests

We will update this policy when our practices change materially. Registered users will be notified by email for significant changes. The effective date at the top of this page shows when the current version took effect.

Privacy Policy – Unnoodle