Unframe Data Processing
Privacy Statement

Effective Date: July 28, 2026

1. Purpose

This Data Processing Privacy Statement  ("Statement") explains how Unframe ("Company", "we", "our", or "us") collects, processes, stores, protects, and discloses information processed through Unframe’s AI-powered software products, cloud services, APIs, applications, and related services, on behalf of our customers (collectively, the "Products").

This Statement applies solely to personal information processed through the Products. Personal information collected through our corporate website, including marketing activities, recruitment, newsletters, cookies, and contact forms, is governed by our separate Website Privacy Policy available here: https://www.unframe.ai/.

This Statement should be read together with our AI Usage Policy, Data Processing Agreement ("DPA"), and any applicable customer agreements.

2. Definitions

For purposes of this Statement:

  • Authorized User means an employee, contractor, consultant, agent, or other individual authorized by a Customer to access or use the Products.
  • California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”).
  • Customer means a legal entity or organization that licenses or subscribes to the Products.
  • Customer Data means all information, content, data, records, documents, communications, and materials submitted, transmitted, uploaded, stored, generated, or otherwise made available by or on behalf of a Customer, or its Authorized Users, through the Products, regardless of format or source.
  • EU General Data Protection Regulation (“GDPR”).
  • Health Insurance Portability and Accountability Act of 1996 (“HIPAA”).
  • Israeli Protection of Privacy Law and applicable regulations (“PPL”).
  • Swiss Federal Act on Data Protection (“FADP”).

UK GDPR and the UK Data Protection Act 2018 (“UK GDPR”). 

Customer is the responsible party to determine the categories of Customer Data to be shared with Unframe and Customer is and remains the owner of Customer Data.

3. Our Role

For Customer Data processed through the Products:

  • Customers act as the Data Controller (or equivalent under applicable privacy laws).
  • We act as the Data Processor under the GDPR, UK GDPR, FADP and PPL and as a Service Provider under the CCPA/CPRA, processing Customer Data solely on behalf of and in accordance with our customers' documented instructions.
  • To the extent that Customer is considered a covered entity under HIPAA, we act as a Business Associate. 

Our Products are designed to support Customers in meeting their privacy obligations; however, each Customer remains responsible for ensuring that its own collection, submission, and use of Customer Data complies with applicable laws, regulations, and contractual obligations.

For information relating to our own business operations (including website, account administration, billing, support, compliance, and security), we act as the data Controller. You can find further information in our Privacy Policy.

4. Information We Process

Depending on the Products and Customer configuration, we process the following categories of information. Depending on customer usage, this information may contain personal information, confidential business information, regulated information, or other sensitive data. 

  • Identification Data: Name, email address, or other contact information of the end users.
  • Professional Information: Job titles, company names, and department names, if relevant for user profiling and platform access.
  • Usage Data: Information about how users interact with the platform, such as login timestamps, page views, and actions taken.
  • AI Inputs and Outputs: Our Products process prompts; questions; uploaded documents; contextual information; conversation history where enabled; AI-generated responses; summaries; recommendations; and workflow outputs.
  • Content Data: Any data inputted by users, such as text entered into forms or documents uploaded, depending on the platform’s purpose.
  • Communication Data: Information from communications through the platform, such as chat messages or emails, if applicable.
  • System and Security Information: We automatically collect technical information required to operate and secure the Products, including: IP addresses; browser information; device information; operating system information; authentication logs; API request metadata; timestamps; audit logs; error reports; and security events.
  • Other Data: Categories of Personal Data that the Customer decides to provide to Unframe and/or the Products.

Customer Business Data

Customers may submit Customer Data through:

  • APIs;
  • software integrations;
  • uploaded files;
  • connected business applications;
  • workflow automation;
  • enterprise systems;
  • databases.

5. How We Use Customer Data

We process Customer Data only for legitimate business purposes in accordance with our customers' documented instructions and contractual obligations, and as necessary to provide the Products, including:

  • providing the Products (i.e., AI-powered services);
  • administer customer accounts;
  • processing customer requests;
  • generating AI responses;
  • authenticating users;
  • operating APIs and integrations;
  • maintaining service availability;
  • maintaining security;
  • securing our infrastructure;
  • monitoring system performance;
  • detecting fraud and security incidents;
  • troubleshooting technical issues;
  • complying with legal obligations;
  • providing customer support;
  • improve reliability;
  • communicate regarding the Products;
  • maintaining product quality and reliability.

For the avoidance of doubt, the information processed by Unframe will be used to generate the requested AI functionality and not for purposes of training underlying AI models. 

Where product testing, diagnostics, quality assurance, or service improvements are performed, these activities use data that has been appropriately de-identified, aggregated, or otherwise expressly authorized by the Customer, or as otherwise permitted by applicable law.

Our Products utilize artificial intelligence to:

  • analyse information;
  • answer user questions;
  • summarize information;
  • classify information;
  • extract insights;
  • automate workflows;
  • generate recommendations; and/or
  • support business processes.

AI-generated outputs should be reviewed by appropriately qualified Customer personnel before being relied upon for decisions, including decisions involving healthcare, financial services, insurance, employment, legal matters, public services, or other high-impact activities. 

Important note: We do not use Customer Data for:

  • advertising;
  • behavioural marketing;
  • unrelated commercial purposes;
  • employee monitoring;
  • unrelated profiling; or
  • training underlying AI models. For the avoidance of doubt, our AI models and products may learn patterns and be fine-tuned for your own and sole purpose. In these cases, the models are not re-used for the benefit of any other customer or party. 

6. Third-Party AI Services

To provide AI-powered functionality, our Products may use approved third-party AI service providers, including providers of large language models (LLMs) (“AI providers”).

Our AI providers process Customer Data under contractual obligations requiring:

  • confidentiality;
  • appropriate technical and organizational security measures;
  • compliance with applicable privacy and data protection laws;
  • restrictions on the use of Customer Data;
  • processing only for authorized purposes.

We conduct due diligence and ongoing assessments of our AI providers as part of our vendor risk management program.

Please note that the terms, usage policies, and other applicable requirements of the AI providers apply to your use of the Products, and your use of the Products must comply with such terms, policies, and requirements. 

7. Security

We implement technical and organizational measures designed to protect Customer Data.

These measures include:

  • AES-256 encryption for Customer Data at rest;
  • TLS 1.2 or TLS 1.3 encryption for all Customer Data transmitted over public networks;
  • role-based access controls;
  • least-privilege access principles;
  • authentication and authorization controls;
  • audit logging;
  • continuous monitoring;
  • vulnerability management;
  • backup and disaster recovery procedures;
  • employee confidentiality obligations.

Although no system can guarantee absolute security, we maintain safeguards appropriate to the sensitivity of the information we process.

8. Subprocessors and Third-Party Service Providers

We engage carefully selected Subprocessors to support the operation and delivery of the Products.

These may include providers of:

  • cloud infrastructure and hosting;
  • artificial intelligence services;
  • managed databases;
  • storage services;
  • networking;
  • monitoring;
  • identity management;
  • communications;
  • backup services;
  • disaster recovery;
  • cybersecurity.

Subprocessors may process Customer Data only to the extent necessary to perform the contracted services.

All Subprocessors are contractually required to:

  • process Customer Data only on documented instructions;
  • maintain confidentiality;
  • implement appropriate security measures;
  • comply with applicable privacy laws;
  • notify us of security incidents where required;
  • support our compliance obligations.

A current list of approved Subprocessors is available upon request or through customer documentation.

9. International Data Transfers

Customer Data may be processed in jurisdictions where we, our affiliates, or approved Subprocessors operate.

Where international transfers occur, we implement appropriate safeguards, including where applicable:

  • Standard Contractual Clauses;
  • UK International Data Transfer Addendum;
  • Swiss transfer mechanisms;
  • adequacy decisions;
  • Data Privacy Framework certification;
  • other legally recognized safeguards.

10. Data Retention

We retain Customer Data only as necessary to provide the Products, maintain security, comply with legal obligations, resolve disputes, and fulfil our contractual obligations.

Specific retention periods are established in the applicable customer agreement, Data Processing Agreement (DPA), Statement of Work, or other contractual documentation and may vary depending on the Products and services provided.

Where Customers configure retention settings within the Products, those settings will apply unless otherwise required by law or agreed contractually.

Upon termination of the applicable agreement, Customer Data will be returned, deleted, or securely disposed of in accordance with the applicable agreement, the DPA, documented customer instructions, and applicable law.

11. Privacy Rights

Where applicable, individuals may have rights to:

  • access personal information;
  • correct inaccurate information;
  • request deletion;
  • restrict processing;
  • object to processing;
  • receive a copy of their personal information;
  • withdraw consent where applicable;
  • lodge complaints with an appropriate supervisory authority.

Where we act as a Data Processor, data subject requests relating to Customer Data should normally be directed to the relevant Customer acting as Data Controller. Unframe will reasonably assist Customer with handling any received data subject request. 

12. Changes to this Statement

We may update this Statement from time to time to reflect changes in our Products, legal requirements, security practices, or business operations. For updates, please check the most current version of this Statement. We will publish the latest version together with its updated date.  

13. Contact

Questions regarding this Product Privacy Statement or our privacy practices may be directed to: privacy@unframe.ai

Privacy Officer: Yossi Bronshtein