Unipile acts as controller for registration, identity, authentication, subscriptions, support, service communications, security, fraud prevention and legal compliance.
Privacy Policy
How Unipile SAS processes personal data when you use Nilyo, connect communication accounts or authorize an agent or ATS/CRM connector.
Effective and last updated: 15 September 2026
1. Scope
This policy applies to Nilyo on https://nilyo.com, its account area, OAuth and MCP authorization flows, billing, support and connected-account services. Nilyo is a commercial service name operated by Unipile SAS; it is not a separate legal entities.
We process personal data under Regulation (EU) 2016/679 (GDPR), the amended French Data Protection Act and other applicable data-protection laws.
2. Who we are
Unipile SAS, RCS Roanne 885 265 595, with registered office at 168 rue de la Rotonde, 42153 Riorges, France, is responsible for the processing described below when it determines why and how data is used. General questions may be sent to start@unipile.com. Privacy requests may be sent to our Data Protection Officer at dpo@unipile.com.
3. Our roles
When a user or customer chooses the purpose of a search, read, send, synchronization or CRM/ATS action, Unipile provides the technical service and processes the relevant data on that user’s or customer’s instructions.
A business customer remains responsible for having a lawful basis, informing its employees, candidates, prospects, customers and correspondents, respecting electronic-communications rules and answering their requests. A Data Processing Agreement is available from dpo@unipile.com.
4. Who this concerns
- Visitors, prospects, subscribers and support contacts.
- Account holders, Team owners, administrators, members and invited members.
- People whose provider accounts are connected to the service.
- Correspondents, contacts, candidates, prospects or customers whose data is processed through a connected account or an ATS/CRM workflow.
5. Data we process
6. Purposes and legal bases
Where consent is the appropriate basis, it may be withdrawn at any time without affecting earlier lawful processing.
7. Connected providers and agents
The service accesses provider data only to perform an action requested through the account, an authorized agent or an installed ATS/CRM connector. It does not sell provider data or use private communications for advertising.
Under the current Unipile V2 architecture, most channel content is processed transiently. V2 WhatsApp message and conversation data is stored encrypted until the connected account is deleted; V2 calendar data may be cached for up to one hour by default. Connection tokens or session identifiers are encrypted and retained while the account remains connected. Exact behavior may differ by provider and selected configuration.
When you authorize ChatGPT, Claude, another agent runtime, an ATS or a CRM, requested results may be sent to that service. Its own privacy terms then apply. Connected platforms such as LinkedIn, Google, Microsoft, Meta, Telegram and Apple also process data under their own terms.
8. Retention
- Account and subscription data is kept for the contractual relationship and normally for 30 days after account deletion, except records retained for statutory accounting, legal claims or security.
- Connected accounts are scheduled for deletion seven days after an unresolved trial expiry or payment failure. Recovery before deletion cancels that schedule.
- Provider content follows the V2 periods described above and is removed when the connected account is deleted, subject to a provider’s own systems and legal requirements.
- The provider type, stable provider account identifier and account name used for trial-abuse prevention are retained until six months after the trial ends, then deleted unless a longer period is required for a documented dispute, fraud or legal obligation.
- OAuth access tokens expire after one hour and refresh authorization after no more than 90 days unless revoked earlier. Verification and reset secrets are kept only until use or expiry.
- Billing and accounting records are retained for the period required by French law.
9. Recipients and service providers
Access is limited to authorized Unipile personnel and providers that need the data to supply the service. These include Unipile’s hosting and API infrastructure providers, Stripe for payment processing, Brevo for transactional email and, when chosen by the user, Google, Microsoft or Apple for sign-in. The current infrastructure sub-processor list and transfer safeguards are maintained in the Unipile Privacy Policy.
If a transfer outside the European Economic Area is necessary, Unipile relies on a recognized safeguard such as an adequacy decision, the EU Standard Contractual Clauses with supplementary measures where required, or an applicable Data Privacy Framework certification.
10. Cookies
Nilyo currently uses only cookies strictly necessary for login, account security and OAuth flows. It does not load advertising, audience-measurement or personalization trackers, so no consent banner is displayed. If non-essential tracking is introduced later, it will remain disabled until valid consent is collected and this policy is updated.
11. Security
Unipile applies technical and organizational safeguards proportionate to the risk, including encryption, least-privilege access, MFA for sensitive access, monitoring and account isolation. See the Security & Compliance page for product-specific controls.
12. Your rights
Subject to applicable conditions, you may request access, correction, deletion, restriction, objection or portability, withdraw consent, and object to qualifying solely automated decisions. Write to dpo@unipile.com. We may request reasonable proof of identity and normally answer within one month. If Unipile processes data only on behalf of a business customer, contact that customer first; Unipile will assist it.
You may lodge a complaint with the CNIL or your local supervisory authority.
13. Changes and contact
We may update this policy when the services, providers or law change. Material changes will be communicated through an appropriate channel. Contact: Data Protection Officer, Unipile SAS, 168 rue de la Rotonde, 42153 Riorges, France, dpo@unipile.com.
The English version is authoritative; translations may be provided for convenience.