Privacy policy

Last updated: 2026-06-20

Note: This is an interim summary describing current practice. The full privacy policy is being prepared with our legal counsel and will replace this page before our first paying customer engagement. If you need to confirm specific practices before that — for example as part of supplier due-diligence — contact the address at the bottom.

Uno Sales Engine (“Uno”, “we”) helps sales teams score, prioritise, enrich and act on B2B leads. This page explains what personal data we collect, why we collect it, how long we keep it, who we share it with, and what choices you have.

1. Who is the controller?

For data about people who hold an Uno account (the “Account Holder”) we are the data controller. That covers your email address, hashed password and authentication sessions managed by Supabase Auth.

For data about a customer’s leads (company contacts the Account Holder’s organisation uploads or enriches inside Uno) we act as data processor on the customer’s behalf. The customer remains the controller for that lead data. The customer may instruct us to delete, export, or correct lead data via the contact address at the bottom of this page.

2. What personal data we process

For Account Holders:

For leads stored in a customer’s workspace (where the customer is the controller and we are the processor):

We do not deliberately collect special-category data (race, health, religious belief, etc.). If a customer’s notes include such data the customer is the controller and should obtain a lawful basis themselves.

3. Why we process it (purpose + lawful basis)

POPIA additionally requires compliance with eight conditions for lawful processing (sections 8 to 25). Our processing is designed around these conditions, with particular attention to condition 3 (purpose specification), condition 4 (further processing limitation) and condition 7 (security safeguards).

4. Who we share data with (subprocessors)

Our current list of subprocessors and what each one processes is on the subprocessors page. Customers under a signed Data Processing Agreement are notified of material changes to that list.

5. International transfers

Some of our subprocessors process data outside the UK and EEA. The most relevant one is Anthropic (United States) for scoring generation. Transfers are made under the appropriate safeguards (UK International Data Transfer Addendum to the EU SCCs, where required). The full list and the per-subprocessor transfer mechanism is on the subprocessors page.

6. Retention

We retain personal data for the periods set out in our internal retention policy. Headline rules for the most common categories:

A more granular breakdown by data category is available on request to the contact at the bottom of this page.

7. Your rights

Under UK GDPR and POPIA you have the right to:

To exercise any of these rights, contact us at the address below. We respond within one month under UK GDPR. We do not charge a fee unless the request is manifestly unfounded or excessive.

8. Cookies

Our use of cookies and equivalent client-side storage is described on the cookies policy page.

9. Security

We apply technical and organisational measures appropriate to the risk, including: per-organisation row-level isolation in our database (Supabase RLS), service-role keys held only in our deployment platform’s encrypted environment, application- level PII redaction in error reports and observability tooling, a documented service-role key rotation procedure, and a strict content-security policy on our web surfaces.

Application-level PII redaction uses pattern matching and cannot guarantee removal of every form of personal data. Customers processing sensitive lead data should review our subprocessor list and their own lawful basis.

10. Changes to this policy

We may update this policy from time to time. Material changes are flagged at the top of the page and communicated to customers under a signed Data Processing Agreement. The “last updated” date at the top of this page reflects the most recent change.

11. Contact

For privacy questions, subject-access or erasure requests, or to ask about a specific subprocessor: arshad.sabat+privacy@gmail.com.

You can also lodge a complaint with the UK Information Commissioner’s Office (ico.org.uk/concerns) or, for South African data subjects, with the Information Regulator (inforegulator.org.za).