Effective Date: July 28, 2026
1. Purpose
This Data Processing Privacy Statement ("Statement") explains how Unframe ("Company", "we", "our", or "us") collects, processes, stores, protects, and discloses information processed through Unframe’s AI-powered software products, cloud services, APIs, applications, and related services, on behalf of our customers (collectively, the "Products").
This Statement applies solely to personal information processed through the Products. Personal information collected through our corporate website, including marketing activities, recruitment, newsletters, cookies, and contact forms, is governed by our separate Website Privacy Policy available here: https://www.unframe.ai/.
This Statement should be read together with our AI Usage Policy, Data Processing Agreement ("DPA"), and any applicable customer agreements.
2. Definitions
For purposes of this Statement:
UK GDPR and the UK Data Protection Act 2018 (“UK GDPR”).
Customer is the responsible party to determine the categories of Customer Data to be shared with Unframe and Customer is and remains the owner of Customer Data.
3. Our Role
For Customer Data processed through the Products:
Our Products are designed to support Customers in meeting their privacy obligations; however, each Customer remains responsible for ensuring that its own collection, submission, and use of Customer Data complies with applicable laws, regulations, and contractual obligations.
For information relating to our own business operations (including website, account administration, billing, support, compliance, and security), we act as the data Controller. You can find further information in our Privacy Policy.
4. Information We Process
Depending on the Products and Customer configuration, we process the following categories of information. Depending on customer usage, this information may contain personal information, confidential business information, regulated information, or other sensitive data.
Customer Business Data
Customers may submit Customer Data through:
5. How We Use Customer Data
We process Customer Data only for legitimate business purposes in accordance with our customers' documented instructions and contractual obligations, and as necessary to provide the Products, including:
For the avoidance of doubt, the information processed by Unframe will be used to generate the requested AI functionality and not for purposes of training underlying AI models.
Where product testing, diagnostics, quality assurance, or service improvements are performed, these activities use data that has been appropriately de-identified, aggregated, or otherwise expressly authorized by the Customer, or as otherwise permitted by applicable law.
Our Products utilize artificial intelligence to:
AI-generated outputs should be reviewed by appropriately qualified Customer personnel before being relied upon for decisions, including decisions involving healthcare, financial services, insurance, employment, legal matters, public services, or other high-impact activities.
Important note: We do not use Customer Data for:
6. Third-Party AI Services
To provide AI-powered functionality, our Products may use approved third-party AI service providers, including providers of large language models (LLMs) (“AI providers”).
Our AI providers process Customer Data under contractual obligations requiring:
We conduct due diligence and ongoing assessments of our AI providers as part of our vendor risk management program.
Please note that the terms, usage policies, and other applicable requirements of the AI providers apply to your use of the Products, and your use of the Products must comply with such terms, policies, and requirements.
7. Security
We implement technical and organizational measures designed to protect Customer Data.
These measures include:
Although no system can guarantee absolute security, we maintain safeguards appropriate to the sensitivity of the information we process.
8. Subprocessors and Third-Party Service Providers
We engage carefully selected Subprocessors to support the operation and delivery of the Products.
These may include providers of:
Subprocessors may process Customer Data only to the extent necessary to perform the contracted services.
All Subprocessors are contractually required to:
A current list of approved Subprocessors is available upon request or through customer documentation.
9. International Data Transfers
Customer Data may be processed in jurisdictions where we, our affiliates, or approved Subprocessors operate.
Where international transfers occur, we implement appropriate safeguards, including where applicable:
10. Data Retention
We retain Customer Data only as necessary to provide the Products, maintain security, comply with legal obligations, resolve disputes, and fulfil our contractual obligations.
Specific retention periods are established in the applicable customer agreement, Data Processing Agreement (DPA), Statement of Work, or other contractual documentation and may vary depending on the Products and services provided.
Where Customers configure retention settings within the Products, those settings will apply unless otherwise required by law or agreed contractually.
Upon termination of the applicable agreement, Customer Data will be returned, deleted, or securely disposed of in accordance with the applicable agreement, the DPA, documented customer instructions, and applicable law.
11. Privacy Rights
Where applicable, individuals may have rights to:
Where we act as a Data Processor, data subject requests relating to Customer Data should normally be directed to the relevant Customer acting as Data Controller. Unframe will reasonably assist Customer with handling any received data subject request.
12. Changes to this Statement
We may update this Statement from time to time to reflect changes in our Products, legal requirements, security practices, or business operations. For updates, please check the most current version of this Statement. We will publish the latest version together with its updated date.
13. Contact
Questions regarding this Product Privacy Statement or our privacy practices may be directed to: privacy@unframe.ai
Privacy Officer: Yossi Bronshtein