Legal and compliance overview
Introduction
This compliance center brings together every legal, privacy, and governance document in one place. Whether you are a visitor checking how we handle cookies, a customer reviewing our data processing terms, or a procurement team running due diligence, you will find the relevant document in the sidebar.
Frequently asked questions
What does the legal section cover?
The legal section is where you find everything procurement, security, and compliance teams ask for. It holds our terms and conditions, privacy policies, the data processing addendum, our sub-processor list, the security overview, our code of conduct, and supporting guidance on EU residency, cookies, and audit trails. Anything a customer or auditor needs to evaluate Unless on paper should be here.
Where is customer data hosted?
All personal data on the Unless platform is hosted inside the European Union. Our core infrastructure runs on AWS in Ireland, with auxiliary cloud workloads in EU regions of Microsoft Azure and Google Cloud. Only our financial administration uses tools that may partially be hosted outside the EU, and these contain no end-user personal data.
Does Unless transfer personal data outside the EU?
No. Personal data processed by the Unless platform stays within the EU/EEA by design. We do not rely on adequacy decisions or transfer impact assessments for platform data, because we do not move it abroad.
Who are the sub-processors?
The full sub-processor list is published in our data processing addendum. The platform sub-processors are EU entities of AWS, Microsoft Azure, and Google Cloud, all processing data inside the EU. A few business tools used for our own administration sit outside the EU, but they never touch end-user personal data from the platform.
Is Unless ISO 27001 certified?
Unless does not hold its own ISO 27001 certificate as a legal entity. Our cloud infrastructure is certified through our providers: AWS is ISO/IEC 27001, 27017, and 27018 certified, and our authentication and supporting services run on providers with the same level of certification. We operate an information security management system modeled after ISO 27001 and 27002:2022, and we are working towards ISO 42001 for AI management systems.
Which standards and regulations does Unless follow?
Unless is built for GDPR, DORA, and the EU AI Act, with an ISMS modeled after ISO 27001 and 27002:2022. We monitor ISO/IEC TR 24028 on AI trustworthiness and are preparing for ISO/IEC 42001 certification. Customers in regulated sectors can use Unless under their own supervisory regimes, including entities supervised by BaFin and AFM.
What is the role of Unless under the EU AI Act?
Unless is the Provider of the AI system. We build, configure, and operate the platform, including the RAG layer, Privacy Vault, agentic framework, and integrations with foundation models. The foundation models themselves come from upstream providers like AWS Bedrock and Azure OpenAI, hosted in EU regions. Customers act as Deployers within their own context.
Does Unless train AI models on customer data?
No. We do not train models on customer content, end-user conversations, or any other customer data. Living Knowledge improves through approved content and team feedback, never by feeding raw conversations into model training.
How does Unless protect personal data inside the AI pipeline?
Personal data is filtered at ingestion and at runtime, so identifiers are removed or masked before they enter the model. Where personal context is required, it is tokenized through our Privacy Vault and the model only sees tokens, not the underlying identifiers. De-tokenization happens inside our controlled environment, so raw personal data never reaches the foundation model provider.
Has Unless had any data breaches or government access requests?
No. Unless has not experienced any significant personal data breach in the last three years, and no security incident has resulted in material exposure of customer data. We have also not received any data access requests from non-EU government authorities. If we ever receive a lawful request, our policy is to limit disclosure to what is strictly required and to notify the affected customer where the law allows it.
Does Unless carry liability insurance?
Yes. Unless holds liability insurance that covers liability arising from our customer contracts, with insured amounts proportional to the contractual liability caps in our agreements.
Are Unless operations subject to any EU sanctions?
No. Unless is not based in a sanctioned country, and we are not a sanctioned entity. Our supply chain, including subcontractors and partners, is screened for the same.
Does Unless have its own code of conduct?
Yes. Our code of conduct covers legal compliance, non-discrimination, fair compensation, employee wellbeing, ethical sourcing, environmental responsibility, and the standards we expect from our suppliers. It is published in the legal section.
How does Unless approach sustainability?
We have set emission reduction targets aligned with the 1.5°C pathway and committed them to the Science Based Targets initiative. The largest part of our footprint sits in our cloud usage, so we minimize model calls and run on EU regions where providers publish carbon-aware reporting. As a small company, we are not yet required to publish a standalone sustainability report under the EU CSRD.
How long are audit logs retained?
Our standard retention for security-relevant logs is one year, unless the customer contract sets a shorter period. Logs are protected against tampering, monitored continuously, and queryable for investigations or audits.
Who is responsible for data protection at Unless?
Our CEO acts as the designated contact for personal data matters and our CTO owns technical operation and security of the platform. Senior management oversees the ISMS and AI governance.
How can customers exercise data subject rights?
Customers handle access, rectification, erasure, and portability requests for their end users through our dashboard. The controller initiates the request, and our team verifies it with a human in the loop. For any personal data that has been tokenized through the Privacy Vault, tokens orphan automatically when the underlying value changes or is deleted, so old references cannot be hijacked.