Legal

Privacy Policy

Effective: 1 July 2026 · Last updated: 10 July 2026

The short version.

We only collect what we need to run UniMate: your account details, your checklist progress, and any files you choose to upload. We never sell your data, never run ads, and never share your data with immigration authorities. You can export or delete everything at any time.

1. Data controller

The data controller responsible for the processing of your personal data is [UniMate operating entity — legal name, NIF/CIF], with registered office at [registered address], Barcelona, Spain ("UniMate", "we", "us").

For any question about this Policy, to exercise your rights, or to contact us on any privacy matter, email info@unimate.im.

2. Scope of this Policy

This Policy explains how we collect and process personal data when you visit our website, create an account, upload documents, subscribe to our newsletter, or contact us. It applies to processing carried out under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights ("LOPDGDD").

3. Categories of personal data we collect

We only collect what we need to run the Service:

  • Account data: full name, email address, university, country of origin, and the hashed password you set (or the identifier of the Google account you signed in with). We record the date your account was created and last sign-in timestamp.
  • Verification data: 6-digit codes sent to your email during sign-up. Stored hashed and deleted immediately after successful use or after 10 minutes.
  • Checklist and profile data: which flow steps you marked as done, your arrival date, your visa or TIE expiry dates, and other information you enter to receive deadline reminders.
  • Uploaded documents: files you choose to upload to your personal document hub. Stored encrypted at rest in Firebase Storage. We do not scan or manually review the content of your uploads unless required by law or to investigate a security incident.
  • Contact and feedback data: name, email, subject, message body, and any topic tag when you write in through the contact form or submit "Was this helpful?" feedback.
  • Newsletter data: email address, subscription source (which page you subscribed from), and subscription date.
  • Server and technical logs: IP address, user agent, timestamps, and URL paths, retained for a maximum of 30 days for security, fraud prevention, and debugging.

We do not collect special categories of personal data (health, political opinions, religion, sexual orientation, etc.). Please do not upload documents that reveal such data unless strictly necessary — we cannot guarantee they are needed for the Service.

4. Sources of the data

All personal data is collected either (a) directly from you when you use the Service, or (b) from your identity provider (Google) if you choose to sign in with Google. We do not buy personal data from third parties and we do not enrich your profile with data purchased from data brokers.

5. Purposes and legal bases

We only process your personal data for the purposes and on the legal bases set out below (GDPR art. 6):

  • Providing the Service (account authentication, saving checklist progress, storing documents). Legal basis: performance of a contract with you (art. 6(1)(b)).
  • Sending appointment and deadline reminders (transactional emails triggered by dates you enter). Legal basis: performance of the contract when you opt in during onboarding; you can turn reminders off at any time in your profile.
  • Sending the newsletter. Legal basis: your consent(art. 6(1)(a)), given when you subscribe. You can withdraw consent by clicking the "unsubscribe" link included in every email.
  • Responding to your enquiries submitted through the contact form or by email. Legal basis: our legitimate interest in providing customer support (art. 6(1)(f)) and, where you initiate a pre-contractual request, art. 6(1)(b).
  • Security, abuse detection, and fraud prevention (server logs, rate-limiting, honeypot verification). Legal basis: our legitimate interest in operating a secure service (art. 6(1)(f)).
  • Complying with legal obligations (responding to valid legal requests, tax and accounting record keeping). Legal basis: legal obligation (art. 6(1)(c)).

6. Automated decision-making and profiling

We do not make decisions about you based solely on automated processing that produces legal or similarly significant effects. Deadline reminders are automated but purely informational and do not affect your rights.

7. Sub-processors and international transfers

We share the minimum personal data necessary with the following sub-processors, each bound by a Data Processing Agreement (GDPR art. 28):

  • Google Ireland Ltd — Firebase (Authentication, Firestore, Storage). Data is processed in EU regions.
  • Vercel Inc.(application hosting). Where a Vercel edge region outside the EEA processes data in transit, the transfer is covered by Standard Contractual Clauses (Commission Decision 2021/914) and Vercel's DPA.
  • Our SMTP provider (transactional emails such as verification codes, appointment reminders, and receipts). See the current provider name in the DPA table available on request.
  • ActiveCampaign LLC(newsletter delivery, marketing-email campaigns, and customer-relationship management). ActiveCampaign is a US-based processor. Transfers are covered by Standard Contractual Clauses and ActiveCampaign's DPA.
  • Stripe Payments Europe Ltd (payment processing for paid tiers). Card data is handled directly by Stripe as an independent controller under PCI DSS; UniMate does not receive or store full card details.

Where a sub-processor is located outside the European Economic Area, the transfer relies on an adequacy decision of the European Commission or on Standard Contractual Clauses. A copy of the safeguards is available on request at info@unimate.im.

We do not share your personal data with immigration authorities, universities, employers, or any other third party for their own commercial purposes. We may disclose data if compelled by a valid court order or by a specific legal obligation, and will notify you where the law allows.

8. Retention

We retain personal data only for as long as necessary for the purposes described above:

  • Account data: until you delete your account. On deletion, we remove or irreversibly anonymise your data within 30 days, except where retention is required by law (see below).
  • Verification codes: up to 10 minutes, then permanently deleted.
  • Uploaded documents: until you delete them or close your account.
  • Contact messages: up to 24 months after the last interaction, then archived or deleted.
  • Newsletter subscription: until you unsubscribe.
  • Server logs: 30 days.
  • Records required by tax or accounting law: retained for the periods required by the applicable Spanish law (typically 4–6 years).

9. Your rights under the GDPR

You have the following rights, subject to the conditions of the GDPR:

  • Right of access (art. 15) — obtain confirmation of processing and a copy of your data.
  • Right to rectification (art. 16) — correct inaccurate or incomplete data.
  • Right to erasure(art. 17, "right to be forgotten") — delete your account and personal data.
  • Right to restrict processing (art. 18).
  • Right to data portability (art. 20) — receive your data in a structured, machine-readable format.
  • Right to object (art. 21) to processing based on our legitimate interest, including profiling.
  • Right to withdraw consent at any time (art. 7(3)) without affecting the lawfulness of processing based on consent before its withdrawal.
  • Right not to be subject to automated decision-making with legal or similarly significant effects (art. 22) — as explained in Section 6, we do not carry out such decisions.

You can exercise most of these rights yourself from your profile, or by writing to us at info@unimate.im. To protect your account we may ask you to verify your identity before acting on the request. We will respond within one month of receipt (extendable to two additional months for complex requests, in which case we will explain the reasons).

If you consider that we have processed your data in breach of the GDPR, you have the right to lodge a complaint with the Spanish data protection authority — the Agencia Española de Protección de Datos (AEPD) — via www.aepd.es, or with the supervisory authority of your habitual residence.

10. Cookies and similar technologies

When you first visit UniMate you will see a cookie consent banner asking you to accept, reject, or customize non-essential cookies. We group cookies and similar technologies (local storage, session storage) into three categories. Essential cookies are always active because the site cannot function without them; all other categories are off by defaultand only activate if you switch them on. You can change your choice at any time from the "Cookie preferences" link in the footer.

10.1 Essential (always active)

Strictly necessary for authentication, security, and remembering your consent choice. Under ePrivacy art. 5(3), consent is not required for these.

  • vs_session — first-party, HTTP-only, Secure session cookie that keeps you signed in. Expires after one hour of inactivity.
  • um_consent — first-party cookie storing your cookie-preferences decision, the categories you accepted, and the timestamp of the decision. Lifetime 12 months. Also mirrored to localStorage key unimate.consent.
  • Local-storage flags used to remember your sidebar collapsed state and dismissed notices.

10.2 Analytics (opt-in)

First-party measurement of page views and feature use, so we can understand which parts of the guidance students actually use and improve them. No advertising, no cross-site tracking, no sharing with third parties for their own purposes. Nothing in this category is loaded or stored until you switch it on.

  • unimate.aid — a random anonymous identifier stored in localStorage so we can join events from the same browser. Not linked to your account unless you sign in.
  • unimate.sid, unimate.sid_ts — short-lived session identifiers in localStorage, reset after 30 minutes of inactivity.
  • Plausible Analytics — if enabled, a cookie-less, EU-hosted analytics script that records aggregate page views. No cookies are set by Plausible itself.

10.3 Marketing (opt-in)

Reserved for future email attribution and campaign measurement (for example, tying a newsletter click to a signup). We do not use advertising cookies, retargeting pixels, or cross-site trackers, and we do not plan to. This category is included in the banner so we can offer a granular choice as our tooling evolves; at the time of writing no marketing cookies are set regardless of your choice.

10.4 Changing or withdrawing your choice

You can change your cookie preferences at any time using the Cookie preferences link in the footer. Withdrawing consent is as simple as giving it — one click reopens the banner and you can toggle any category off. When you withdraw analytics consent, the associated local-storage keys are no longer written and any Plausible script is removed from subsequent page loads.

11. Security

We apply technical and organisational measures appropriate to the risk (GDPR art. 32), including HTTPS by default, hashed passwords, hashed verification codes, encryption of uploads at rest, restricted admin access, audit logging, and dependency monitoring. No system is perfectly secure, however; if we detect a personal-data breach that is likely to result in a high risk to your rights, we will notify you and the AEPD as required by GDPR arts. 33–34.

12. Children

The Service is intended for university-age adults and requires users to be at least 18 years old. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please email info@unimate.im and we will delete it.

13. Third-party links

The Service links to Spanish government portals and to third-party resources. Once you leave UniMate, this Policy no longer applies — the target site's privacy policy governs any data you provide there. We recommend you read those policies before submitting information.

14. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will (a) update the "Last updated" date at the top of this page, and (b) notify registered users by email at least fifteen (15) days before the change takes effect. Where required by law, we will seek your renewed consent.

15. Contact

To exercise any of the rights above, to raise a concern, or to request a copy of the sub-processor DPA safeguards, contact us at info@unimate.im. See also our Terms of Service.