Privacy Policy

Effective: 14 May 2026 · Last updated: 29 July 2026

Unitelia ("we", "us", "the Service") is a B2B SaaS operated by ФОП Мазур Назарій Ярославович (Lviv, Ukraine; sole proprietor / individual entrepreneur). This policy explains how we handle personal data when a business customer ("Operator") uses the Service to communicate with their own customers ("End-customers").

1. Roles

  • Operator is the data controller for End-customer data they bring into the Service (Instagram conversations, KeyCRM orders, etc.).
  • We are the data processor, acting on the Operator's documented instructions.

2. What data we process

For each Operator account:

  • Operator profile: email, name, organization name, billing details.
  • Connector credentials: API tokens and OAuth tokens (Instagram, KeyCRM, Nova Poshta). Stored encrypted at rest with per-organization keys (pgsodium).
  • Conversation content: incoming and outgoing messages (text, attachments metadata), conversation status, channel identifiers (Instagram-scoped user id, phone, etc.).
  • Order and product metadata imported from connected CRMs solely for the purpose of replying to End-customers (order id, status, total, line items).
  • AI-generated drafts and decisions, with cost and latency metadata for each LLM call.
  • Audit log of message lifecycle events (delivered, read, edited, deleted) preserved per message_events table.

3. Why we process it

  • To operate the Service for the Operator (contractual basis).
  • To generate, queue, and deliver AI-drafted replies on the Operator's behalf, with Operator-configured Trust Mode (Manual / Semi / Auto).
  • To run analytics that help the Operator optimize their store performance.
  • To comply with legal obligations (e.g., tax records).

4. Where data is stored

Primary database: Supabase Postgres, EU (Frankfurt) region. Operator credentials are encrypted at rest via pgsodium with per-organization keys; ciphertext is bound to the organization id (AAD).

Backups are retained for 30 days. After backup expiry, deleted data is unrecoverable.

5. Sharing with third parties

The Service relies on the following subprocessors:

  • Anthropic (LLM provider, US) — message text is sent to Claude for draft generation. Anthropic does not train on this data per their commercial terms.
  • Google (Gemini, US) — message text is sent for embedding generation (semantic search over past conversations). Gemini API does not train on data sent via paid or free tier per their commercial terms.
  • Supabase (Postgres + Auth, EU/Frankfurt) — primary storage.
  • Vercel (frontend hosting, EU/Frankfurt) — serves apps/web.
  • Fly.io (orchestrator hosting, EU/Frankfurt) — runs the orchestrator service.
  • Inngest (durable workflow runtime, US) — orchestrates background jobs. Payloads are encrypted in transit; persistence is short-lived for replay/retry.
  • Meta (Instagram Graph API) — message exchange with End-customers when the Operator has connected Instagram.
  • Sentry (error tracking, US) — receives stack traces and error metadata when something fails in our application. We scrub message content from breadcrumbs (a beforeSend sanitizer drops fields named content, text, message, body, draft). Sentry does NOT receive message text.
  • Helicone (LLM observability proxy, US — EU region for EU customers) — transparently routes our LLM calls so we can measure per-call cost and latency. The LLM provider key still terminates at the LLM provider; Helicone observes traffic in passing. Helicone DOES see prompt and completion text. We sign a Data Processing Agreement with Helicone before any paying customer's data flows through.

We do not sell personal data. We do not use End-customer data for marketing or training.

6. Retention

  • Conversations and messages: kept while the Operator's account is active. On Operator deletion: removed within 30 days (after backup expiry).
  • End-customer right-to-deletion: on request via the Operator, we null the content column of every matching message and preserve only the audit log (the factual record that a communication occurred). See Data Deletion Instructions.
  • Credentials: deleted on connector revocation.
  • Logs: 30 days.

7. End-customer rights (GDPR-style)

End-customers can exercise their rights — access, rectification, erasure, restriction, portability — through the Operator who controls their data. If the Operator does not respond, End-customers may contact us at m.nazar77@gmail.com and we will route the request to the Operator with a 30-day SLA.

Personal data is processed under the Law of Ukraine "On Personal Data Protection" and, for data subjects in the EU, the General Data Protection Regulation (GDPR).

8. Security

  • TLS in transit; encryption at rest for credentials.
  • Row-Level Security in Postgres scopes every read/write to one organization, enforced by a per-request session GUC.
  • 2FA available on Operator accounts via Supabase Auth.
  • Audit log immutable from application code (operators cannot delete events).
  • SOC 2 Type II audit planned (ADR-025); status published at trust.unitelia.com when active.

9. Changes

We will notify Operators via in-app banner and email at least 14 days before material changes to this policy. Continued use after the effective date constitutes acceptance.

10. Contact

Private Entrepreneur Mazur Nazarii Yaroslavovych · Lviv, Ukraine · m.nazar77@gmail.com

The Ukrainian version of this policy is the authoritative one. This English text is a convenience translation; if the two diverge, the Ukrainian text prevails.

Політика конфіденційності / Privacy Policy — Unitelia · Unitelia