Legal and compliance overview
Introduction
This compliance center brings together every legal, privacy, and governance document in one place. Whether you are a visitor checking how we handle cookies, a customer reviewing our data processing terms, or a procurement team running due diligence, you will find the relevant document in the sidebar.
Key concepts
Before diving into individual documents, here are the principles that shape how Unless handles data and privacy.
- Cookieless by default. By default, our system does not use cookies. However, for audience segmentation, personalization, and A/B testing, cookies may be required. In that case, you should connect your consent mechanism to our Consent API.
- Separation of personal data and system data. By default, Unless filters all Personally Identifiable Data from user input and AI training data. However, after consent or with legitimate interest, some customers may submit third-party data. We store this data in Europe only, in a protected "privacy vault".
- Privacy vault. Our data privacy vault technology isolates, protects, and governs sensitive customer data. Tokenization replaces sensitive data with tokens, providing an extra layer of security. Sensitive data is stored in the vault, while de-identified data is used in other cloud storage and downstream services like the AI models.
For website visitors
Plain-language policies for anyone browsing unless.com.
For customers
The contractual core. Subscription terms, data processing, SLAs, and AI-specific addenda for regulated buyers.
- Terms and conditions
- Data Processing Addendum
- Sub-processors
- Security addendum
- Third party usage policies
Company policies
Organizational governance for stakeholders, partners, and procurement teams doing due diligence.