Privacy policy
Last updated: 2026-06-20
Note: This is an interim summary describing current practice. The full privacy policy is being prepared with our legal counsel and will replace this page before our first paying customer engagement. If you need to confirm specific practices before that — for example as part of supplier due-diligence — contact the address at the bottom.
Uno Sales Engine (“Uno”, “we”) helps sales teams score, prioritise, enrich and act on B2B leads. This page explains what personal data we collect, why we collect it, how long we keep it, who we share it with, and what choices you have.
1. Who is the controller?
For data about people who hold an Uno account (the “Account Holder”) we are the data controller. That covers your email address, hashed password and authentication sessions managed by Supabase Auth.
For data about a customer’s leads (company contacts the Account Holder’s organisation uploads or enriches inside Uno) we act as data processor on the customer’s behalf. The customer remains the controller for that lead data. The customer may instruct us to delete, export, or correct lead data via the contact address at the bottom of this page.
2. What personal data we process
For Account Holders:
- Email address used to sign in.
- Hashed password and session tokens (Supabase Auth).
- Limited usage telemetry described in our cookies policy.
For leads stored in a customer’s workspace (where the customer is the controller and we are the processor):
- Lead identifiers and contact data: company name, contact name, job title, email address, phone number, website, location, company size, industry.
- Sales workflow data: status, assigned rep, last contact date, next follow-up, pain point, buying signal, lead source, free- text notes.
- Generated outputs: scoring band, rationale text, suggested next-step text, enrichment suggestions returned by upstream providers.
We do not deliberately collect special-category data (race, health, religious belief, etc.). If a customer’s notes include such data the customer is the controller and should obtain a lawful basis themselves.
3. Why we process it (purpose + lawful basis)
- To deliver the service. Lawful basis under UK GDPR: performance of a contract (Art. 6(1)(b)) with the customer organisation. Under POPIA: section 11(1)(b) (necessary to carry out actions for the conclusion or performance of a contract) and section 11(1)(d) (legitimate interests of the data subject, responsible party or third party).
- To secure the service. Lawful basis under UK GDPR: legitimate interests (Art. 6(1)(f)) in operating a secure platform. Under POPIA: section 11(1)(d) and section 11(1)(f) (legitimate interests of a third party to whom the information is supplied).
- To meet legal obligations. Lawful basis under UK GDPR: Art. 6(1)(c) where applicable (e.g. tax records). Under POPIA: section 11(1)(c) (compliance with an obligation imposed by law).
POPIA additionally requires compliance with eight conditions for lawful processing (sections 8 to 25). Our processing is designed around these conditions, with particular attention to condition 3 (purpose specification), condition 4 (further processing limitation) and condition 7 (security safeguards).
4. Who we share data with (subprocessors)
Our current list of subprocessors and what each one processes is on the subprocessors page. Customers under a signed Data Processing Agreement are notified of material changes to that list.
5. International transfers
Some of our subprocessors process data outside the UK and EEA. The most relevant one is Anthropic (United States) for scoring generation. Transfers are made under the appropriate safeguards (UK International Data Transfer Addendum to the EU SCCs, where required). The full list and the per-subprocessor transfer mechanism is on the subprocessors page.
6. Retention
We retain personal data for the periods set out in our internal retention policy. Headline rules for the most common categories:
- Customer-uploaded lead data: up to 24 months active plus 12 months archive from last modification, unless the customer shortens or extends in writing.
- Enrichment runs, scoring runs and lead actions tied to a lead row: same lifetime as the underlying lead row (cascade deletion).
- Provider usage logs (cost / billing audit): 7 years for accounting purposes.
- Account credentials and sessions: lifetime of the account plus a 30-day restore window after closure, then permanent deletion.
- Suppression entries: retained while the organisation is active, because their purpose is to prevent re-enrichment of previously-suppressed identifiers.
A more granular breakdown by data category is available on request to the contact at the bottom of this page.
7. Your rights
Under UK GDPR and POPIA you have the right to:
- Access the personal data we hold about you.
- Have inaccurate data corrected.
- Have data erased in some circumstances.
- Restrict or object to processing.
- Receive your data in a structured machine-readable format (portability), where the processing is automated and based on contract or consent.
- Withdraw any consent you have given.
- Lodge a complaint with the supervisory authority (Information Commissioner’s Office in the UK; the Information Regulator in South Africa).
To exercise any of these rights, contact us at the address below. We respond within one month under UK GDPR. We do not charge a fee unless the request is manifestly unfounded or excessive.
8. Cookies
Our use of cookies and equivalent client-side storage is described on the cookies policy page.
9. Security
We apply technical and organisational measures appropriate to the risk, including: per-organisation row-level isolation in our database (Supabase RLS), service-role keys held only in our deployment platform’s encrypted environment, application- level PII redaction in error reports and observability tooling, a documented service-role key rotation procedure, and a strict content-security policy on our web surfaces.
Application-level PII redaction uses pattern matching and cannot guarantee removal of every form of personal data. Customers processing sensitive lead data should review our subprocessor list and their own lawful basis.
10. Changes to this policy
We may update this policy from time to time. Material changes are flagged at the top of the page and communicated to customers under a signed Data Processing Agreement. The “last updated” date at the top of this page reflects the most recent change.
11. Contact
For privacy questions, subject-access or erasure requests, or to ask about a specific subprocessor: arshad.sabat+privacy@gmail.com.
You can also lodge a complaint with the UK Information Commissioner’s Office (ico.org.uk/concerns) or, for South African data subjects, with the Information Regulator (inforegulator.org.za).