Privacy Policy
Version: 2.0
Effective Date: June 16, 2026
Previous Version: v1.0 — June 13, 2026
1. Introduction
Unistack Software Services - FZCO («Unistack», «we», «us», or «our»), a company registered in the United Arab Emirates (IFZA), License No. 79050, with its registered office at IFZA Business Park, DDP, PO Box 342001, Dubai, UAE, is committed to protecting the privacy and security of your personal data.
This Privacy Policy explains how we collect, use, disclose, and protect personal data when you:
- Visit our website at https://getunistack.com (the «Website»);
- Engage us to provide software development, IT, AI/ML, and related services (the «Services»);
- Communicate with us via email, phone, or other channels.
This policy is issued jointly by Unistack in its capacity as a Data Controller (for Website visitors and marketing contacts) and as a Data Processor (when processing personal data on behalf of our B2B clients).
In limited circumstances, we may process identity verification data, including government-issued identification documents and biometric verification data, strictly for corporate due diligence, fraud prevention, sanctions screening, client onboarding, or project-risk assessment purposes, where permitted by applicable law and subject to appropriate safeguards.
Please read this Privacy Policy carefully. By using our Website or Services, you acknowledge that you have read and understood this Privacy Policy.
2. Definitions
- «Personal Data» means any information relating to an identified or identifiable natural person.
- «Processing» means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
- «Data Subject» means the natural person to whom Personal Data relates.
- «Controller» means the entity that determines the purposes and means of processing Personal Data.
- «Processor» means the entity that processes Personal Data on behalf of the Controller.
- «Applicable Data Protection Law» means all applicable laws relating to the processing of Personal Data, including the UAE Federal Decree-Law No. 45 of 2021 (UAE PDPL), the EU General Data Protection Regulation (GDPR), and the UK GDPR.
3. Our Roles: Controller vs. Processor
It is important to understand the different roles we play in relation to your Personal Data:
3.1 Unistack as Data Controller
We act as a Data Controller when we collect and process your Personal Data for the following purposes:
- Operating our Website and responding to general inquiries;
- Marketing our Services (where you have consented or where permitted by law);
- Managing our own business operations and compliance obligations.
In these cases, we determine the purposes and means of processing, and this Privacy Policy applies in full.
3.2 Unistack as Data Processor
We act as a Data Processor when we process Personal Data on behalf of our B2B clients (who act as Data Controllers) in connection with the provision of our Services (e.g., software development, hosting, AI/ML workflows).
In these cases:
- Our client (the Controller) determines the purposes and means of processing;
- Our processing is governed by a separate Data Processing Agreement (DPA) between us and the client;
- Our standard DPA is available at: https://getunistack.com/legal/dpa;
- If you are an employee, contractor, or end-user of one of our clients, please direct any data protection requests to your organization (the Controller), as we can only act on instructions from them.
4. Information We Collect
We collect the following categories of Personal Data:
4.1 Business Contact Information
- Full name, job title, company name;
- Email address, phone number, business address;
- Communication preferences.
4.2 Contractual and Financial Data
- Details of contracts, statements of work, and invoices;
- Payment information (processed through secure third-party payment processors);
- Correspondence and meeting notes.
4.3 Technical and Website Data
- IP address, browser type and version, device identifiers;
- Pages visited, time spent on pages, referral URLs;
- Cookies and similar technologies (see our Cookie Policy).
4.4 Project-Related Data (as Processor)
When acting as a Processor, we may process Personal Data provided by our clients in connection with their projects. This may include:
- Names and contact details of client employees or end-users;
- Technical identifiers and logs;
- Content uploaded to applications we develop or maintain.
Note: We do not knowingly collect Special Categories of Personal Data (e.g., health, biometric, religious, or political data) unless explicitly authorized in writing for a specific project.
5. How We Use Your Information
We use your Personal Data for the following purposes, each supported by a specific legal basis:
| Purpose | Legal Basis |
|---|---|
| To respond to your inquiries and provide customer support | Performance of a contract / Legitimate interest |
| To negotiate, enter into, and manage contracts with you | Performance of a contract |
| To provide, maintain, and improve our Services | Performance of a contract / Legitimate interest |
| To develop and deliver software, AI/ML, and IT solutions on behalf of our clients | Performance of a contract (as Processor) |
| To ensure the security of our Website, systems, and networks | Legitimate interest / Legal obligation |
| To comply with legal, tax, and regulatory obligations | Legal obligation |
| To send marketing communications about our Services | Consent (where required) / Legitimate interest |
| To analyze Website usage and improve user experience | Legitimate interest |
| To prevent fraud, abuse, and unauthorized access | Legitimate interest / Legal obligation |
6. Legal Basis for Processing (GDPR Art. 6)
Where Applicable Data Protection Law requires a legal basis for processing, we rely on the following:
6.1 Contractual Necessity
Processing is necessary for the performance of a contract with you, or to take steps at your request prior to entering into a contract.
6.2 Legitimate Interests
Processing is necessary for the purposes of our legitimate interests, provided these are not overridden by your rights and freedoms. Our legitimate interests include:
- Providing and improving our Services;
- Ensuring the security of our systems and networks;
- Preventing fraud and abuse;
- Marketing our Services (where you have not opted out);
- Administering our business and internal operations.
Legitimate Interests Assessment (LIA): Where we rely on legitimate interests, we have conducted a balancing test to ensure that our interests are not overridden by your rights and freedoms. You may request a copy of our LIA by contacting us at privacy@getunistack.com.
6.3 Legal Obligation
Processing is necessary for compliance with a legal obligation to which we are subject (e.g., tax, accounting, and anti-money laundering laws).
6.4 Consent
Where required by law (e.g., for certain marketing communications), we will obtain your explicit consent before processing your Personal Data. You may withdraw your consent at any time.
7. Data Retention
We retain Personal Data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
| Category of Data | Retention Period |
|---|---|
| Business contact information | Duration of the business relationship + 3 years |
| Contractual and financial records | 7 years (to comply with tax and legal requirements) |
| Website logs and technical data | 12 months |
| Cookies (strictly necessary) | Session or up to 12 months |
| Marketing communications preferences | Until consent is withdrawn |
| Project-related data (as Processor) | As instructed by the Controller, or as required by the DPA |
Upon expiration of the retention period, Personal Data is securely deleted or anonymized.
8. International Data Transfers
As a UAE-based company with international clients and service providers, we may transfer Personal Data to countries outside the European Economic Area (EEA), UK, or Switzerland, including the United Arab Emirates and the United States.
Where the European Commission or UK authorities have not issued an adequacy decision for the recipient country, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs): We have implemented the EU SCCs (Commission Implementing Decision (EU) 2021/914) for transfers from the EEA.
- UK International Data Transfer Addendum (IDTA): For transfers from the UK.
- Transfer Impact Assessments (TIAs): Conducted where necessary to assess the legal framework of the recipient country.
- UAE PDPL Compliance: We comply with the cross-border transfer requirements of the UAE Federal Decree-Law No. 45 of 2021.
A copy of the safeguards in place may be obtained by contacting us at privacy@getunistack.com.
9. Sub-processors
We engage trusted third-party service providers («Sub-processors») to assist in providing our Services. These may include cloud hosting providers, development tools, and communication platforms.
- Current List: A complete and up-to-date list of our authorized Sub-processors, including their location and purpose, is available at: https://getunistack.com/legal/sub-processors.
- Notification: We will provide at least thirty (30) days' notice before adding or replacing any Sub-processor.
- Right to Object: You may object to such changes on reasonable data protection grounds.
- Flow-down Obligations: All Sub-processors are contractually obligated to maintain data protection standards no less protective than those in this Privacy Policy and our DPA.
10. Data Processing Agreement (DPA)
When we process Personal Data on behalf of our B2B clients as a Data Processor, our processing is governed by a Data Processing Agreement (DPA). Our standard DPA is available at: https://getunistack.com/legal/dpa.
Clients may request a mutually executed copy of the DPA by contacting us at privacy@getunistack.com.
11. Automated Decision-Making and Profiling
We do not use Personal Data for solely automated decision-making (including profiling) that produces legal effects or similarly significantly affects you, unless you have given explicit consent or it is necessary for a contract.
If we implement AI/ML-assisted workflows that involve automated decision-making on behalf of a client (as Processor), we will:
- Inform the client in advance;
- Provide meaningful information about the logic involved;
- Explain the significance and envisaged consequences;
- Support the client in fulfilling its obligations under GDPR Art. 22 (or equivalent), including the right to obtain human intervention, express a point of view, and contest the decision.
12. Your Rights
Under Applicable Data Protection Law, you have the following rights in relation to your Personal Data:
- Right of Access: To request a copy of the Personal Data we hold about you.
- Right to Rectification: To request correction of inaccurate or incomplete data.
- Right to Erasure («Right to be Forgotten»): To request deletion of your data, subject to legal exceptions.
- Right to Restriction: To request limitation of processing in certain circumstances.
- Right to Data Portability: To receive your data in a structured, machine-readable format.
- Right to Object: To object to processing based on legitimate interests or for direct marketing.
- Right to Withdraw Consent: Where processing is based on consent, to withdraw it at any time.
How to Exercise Your Rights
To exercise any of your rights, please contact us at privacy@getunistack.com.
Response Timeline:
- We will respond to your request without undue delay, and in any event within thirty (30) days of receipt (in accordance with GDPR Art. 12(3) and UAE PDPL).
- In complex cases, this period may be extended by up to sixty (60) days, with prior notification to you.
- Responses are provided free of charge, unless requests are manifestly unfounded or excessive, in which case a reasonable fee may be charged.
Important Note for Processor-Related Requests: If we are processing your Personal Data as a Processor on behalf of a client, please direct your request to your organization (the Controller). We will assist the Controller in fulfilling your request in accordance with our DPA.
Right to Lodge a Complaint
If you are not satisfied with our response, you have the right to lodge a complaint with a supervisory authority:
- In the EU: List of EU Data Protection Authorities
- In the UK: Information Commissioner's Office (ICO)
- In the UAE: The competent authority under the UAE PDPL (once formally established)
13. Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, Personal Data may be transferred to the acquiring entity or a third party. We will:
- Notify you of any such change;
- Ensure that the acquiring entity is bound by equivalent data protection obligations;
- Inform you of any choices you may have regarding your data.
14. Security
We implement appropriate Technical and Organizational Measures (TOMs) to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures are proportionate to the risks and include:
- Encryption in transit (TLS 1.2+) and at rest (AES-256);
- Role-Based Access Control (RBAC) and mandatory Multi-Factor Authentication (MFA);
- Secure software development lifecycle (SDLC) with code reviews and dependency scanning;
- Separation of development, staging, and production environments;
- Incident response procedures with 48-hour breach notification.
A detailed description of our security practices is available on our Trust & Security page.
15. EU Representative (GDPR Art. 27)
In accordance with Article 27 of the General Data Protection Regulation, Unistack Software Services - FZCO has appointed a representative in the European Union for data protection matters:
Email: eu_rep@getunistack.com
You may address any data protection-related requests directly to our EU representative, without prejudice to any communications with Unistack itself.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. We will:
- Post the updated version on this page;
- Update the «Last Updated» date at the top;
- Notify clients and registered contacts of material changes via email.
We encourage you to review this Privacy Policy periodically.
17. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact us:
Data Protection Contact: privacy@getunistack.com
EU Representative: eu_rep@getunistack.com
Security Issues: security@getunistack.com
General Inquiries: hello@getunistack.com
Postal Address:
Unistack Software Services - FZCO
IFZA Business Park, DDP
PO Box 342001
Dubai, United Arab Emirates