This GDPR Notice explains how UNLIPARSE ("we", "us", or "our") complies with the European Union's General Data Protection Regulation ("GDPR"), the UK General Data Protection Regulation ("UK GDPR"), and the Swiss Federal Act on Data Protection ("FADP") when we process the personal data of individuals located in the European Economic Area ("EEA"), the United Kingdom, or Switzerland. It supplements, and should be read together with, our Privacy Policy, Terms of Service, and Cookie Policy. In the event of any conflict between this Notice and our Privacy Policy on a GDPR-specific point, this Notice prevails for individuals to whom the GDPR applies.
On this page
- 1. Introduction and Scope
- 2. Data Controller
- 3. Personal Data We Process
- 4. Lawful Bases for Processing
- 5. Data Protection Principles
- 6. Your Rights as a Data Subject
- 7. How to Exercise Your Rights
- 8. International Data Transfers
- 9. Data Retention
- 10. Security and Confidentiality
- 11. Personal Data Breaches
- 12. Automated Decision-Making and Profiling
- 13. Children's Data
- 14. Right to Lodge a Complaint
- 15. Changes to This Notice
- 16. Contact Us
1. Introduction and Scope
The GDPR is a European data protection law that gives individuals located in the EEA, the UK, and Switzerland a set of rights over their personal data and imposes obligations on organisations that process that data. UNLIPARSE is committed to handling personal data in accordance with these laws.
This Notice applies whenever UNLIPARSE processes "personal data" — that is, any information relating to an identified or identifiable natural person — about a user located in the EEA, the UK, or Switzerland. It applies regardless of where our servers or service providers are located.
Because UNLIPARSE is designed to be used without an account, the personal data we handle about most visitors is very limited. The most sensitive data we process is the content of the documents and images that you choose to upload for extraction, which may itself contain personal data.
2. Data Controller
For the purposes of the GDPR, the data controller responsible for the personal data processed through the Service is:
- Controller: UNLIPARSE
- Contact email: info@unliparse.com
- EU/UK representative: Not currently appointed. The Service consists of transient, on-demand document processing, does not require accounts, does not profile users, and is not specifically targeted at individuals in the EEA or UK. We therefore rely on the limited-scope exemption in Article 27(2) GDPR. If you are located in the EEA or UK, please contact the controller directly at the email address above.
UNLIPARSE is operated online and does not maintain a public physical office; all correspondence relating to this Notice should be sent to the email address above. If you are uncertain which entity is responsible for a particular processing activity, you may contact us using the details above and we will direct your enquiry appropriately. Where a third-party service provider acts as an independent controller of your personal data (for example, when you follow an external link), that third party is responsible under its own privacy notice.
3. Personal Data We Process
We process the following categories of personal data:
- Document and image content you upload — files in PNG, JPG, PDF, TIFF, SVG, WebP, GIF, or BMP format, which may contain personal data visible in the document (names, addresses, ID numbers, financial details, etc., depending on what you choose to upload).
- Extraction templates that you create or upload, including any field names, descriptions, or examples you provide.
- Technical and connection data — IP address, browser type and version, device type, operating system, language, referring URL, pages visited, and timestamps. Used for security, abuse prevention, and aggregate analytics.
- Cookie and local storage data — language preference, locally saved templates, session identifiers, and security tokens (CSRF, CAPTCHA). See our Cookie Policy.
- Correspondence — when you contact us, the content of your message and any contact details you provide (typically your email address).
4. Lawful Bases for Processing
Under Article 6 of the GDPR, we may only process your personal data if we have a lawful basis to do so. We rely on the following lawful bases:
- Performance of a contract (Art. 6(1)(b)) — to deliver the Service you request, including processing the documents you upload and returning the extracted output to you.
- Legitimate interests (Art. 6(1)(f)) — to operate, secure, and improve the Service, prevent fraud and abuse (including CAPTCHA verification), maintain technical logs, and understand aggregate usage. We have balanced these interests against your rights and freedoms and consider them not to be overridden, but you may object as described in section 6 below.
- Consent (Art. 6(1)(a)) — where you have given us specific, freely given, informed consent (for example, for non-essential analytics cookies). You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- Legal obligation (Art. 6(1)(c)) — to comply with applicable laws, regulations, court orders, or lawful requests from public authorities.
- Vital interests (Art. 6(1)(d)) — in rare cases, to protect the vital interests of you or another natural person.
- Public interest (Art. 6(1)(e)) — we do not currently rely on this basis, but reserve it for situations where applicable law specifically requires it.
We do not knowingly process special categories of personal data (such as health, biometric, or political data) under Article 9 unless you choose to include such data in a document you upload. If you do, you should be aware that the lawful basis for our handling of that content remains your decision to submit it to the Service for extraction.
5. Data Protection Principles
Article 5 of the GDPR sets out seven principles that govern how personal data must be processed. We apply these principles to every personal data activity at UNLIPARSE:
- Lawfulness, fairness, and transparency — we process personal data only on a lawful basis, in ways you would reasonably expect, and we tell you what we do in this Notice and our Privacy Policy.
- Purpose limitation — we collect personal data for the specific purposes described in this Notice and do not reuse it for incompatible new purposes without a lawful basis.
- Data minimisation — we collect only what is necessary to provide the Service. Because the Service does not require an account, we deliberately collect very little about most visitors.
- Accuracy — we take reasonable steps to keep personal data accurate and, where necessary, up to date, and we provide a right to rectification.
- Storage limitation — uploaded documents are processed transiently and are not retained after extraction; technical logs and other limited data are kept only as long as necessary.
- Integrity and confidentiality — we use appropriate technical and organisational measures (HTTPS, access controls, abuse-prevention mechanisms) to protect personal data.
- Accountability — we maintain internal records of our processing activities and review this Notice as our practices evolve.
6. Your Rights as a Data Subject
If the GDPR or UK GDPR applies to you, you have the following rights in relation to the personal data we hold about you. These rights are not absolute and may be subject to legal limitations.
- Right of access (Art. 15) — to obtain confirmation of whether we process your personal data and, if so, a copy of that data along with information about how we process it.
- Right to rectification (Art. 16) — to have inaccurate personal data corrected and incomplete personal data completed.
- Right to erasure / "right to be forgotten" (Art. 17) — to have your personal data deleted in certain circumstances, for example when it is no longer needed for the purposes for which it was collected.
- Right to restriction of processing (Art. 18) — to limit how we use your personal data in certain circumstances, for example while we verify a rectification request.
- Right to data portability (Art. 20) — to receive personal data you provided to us in a structured, commonly used, machine-readable format, and to transmit it to another controller, where processing is based on consent or contract and carried out by automated means.
- Right to object (Art. 21) — to object, on grounds relating to your particular situation, to processing based on our legitimate interests. You may also object at any time to processing for direct marketing (we do not currently engage in direct marketing).
- Right to withdraw consent (Art. 7(3)) — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right not to be subject to solely automated decisions (Art. 22) — see section 12 below for how this applies to the Service.
- Right to lodge a complaint (Art. 77) — see section 14 below.
7. How to Exercise Your Rights
You can exercise any of the rights described in section 6 by emailing us at info@unliparse.com. To help us respond accurately, please include:
- A clear description of the right you are exercising (for example, "request for access" or "request for erasure").
- Enough information for us to identify the personal data you are asking about. Because UNLIPARSE does not require an account, we may need additional context — such as the approximate date and time of your interaction with the Service, the IP address you used, or the email address from which you contacted us — to locate any data we may hold.
- A means of contacting you (typically a reply email address) so we can respond.
Identity verification. Where we have reasonable doubts about the identity of the person making the request, we may ask for additional information to verify your identity before we act, in line with Article 12(6) of the GDPR.
Response time. We aim to respond to data subject requests without undue delay and in any event within one month of receipt, in line with Article 12(3). Where a request is particularly complex or where we receive a high volume of requests, we may extend that period by up to two further months and will tell you why.
Cost. Exercising your rights is free of charge. We may charge a reasonable administrative fee — or refuse to act — only where a request is manifestly unfounded or excessive, in line with Article 12(5).
If we cannot fulfil your request. If we are unable to act on your request, we will explain why and inform you of your right to lodge a complaint with a supervisory authority and to seek a judicial remedy.
8. International Data Transfers
Because the Service and the providers that support it (including our hosting provider, content-delivery network, and the third-party AI processing provider that performs the document extraction) may be based outside the EEA, the UK, or Switzerland, your personal data may be transferred to and processed in countries that the European Commission has not formally recognised as providing an adequate level of data protection.
Where this is the case, we rely on appropriate safeguards under Chapter V of the GDPR, in particular:
- European Commission adequacy decisions — where the destination country (or specific framework, such as the EU-US Data Privacy Framework) has been recognised as providing an adequate level of protection.
- Standard Contractual Clauses ("SCCs") — the European Commission's and UK Information Commissioner's standard contractual clauses, supplemented by additional technical and organisational measures where required by the Schrems II ruling and subsequent guidance.
- UK International Data Transfer Agreement / UK Addendum — for transfers from the UK.
- Derogations under Article 49 — only in limited, occasional cases (for example, with your explicit consent or where the transfer is necessary for the performance of a contract you have requested).
You may request a copy of the safeguards we rely on for a specific transfer by contacting us at info@unliparse.com. We may redact commercially confidential information from any copy we provide.
9. Data Retention
We keep personal data only for as long as is necessary for the purposes described in this Notice, after which it is deleted or anonymised. Specifically:
- Uploaded documents and images are processed transiently. We do not retain them on our servers once the extraction request is fulfilled.
- Extraction output is delivered to your browser and is not retained on our servers after delivery.
- Extraction templates and preferences saved to your browser's local storage remain on your device until you clear them. We do not have access to them.
- Technical and security logs (which may contain IP addresses and timestamps) are retained for a limited period — typically no longer than is necessary to operate, secure, and audit the Service — and then deleted or aggregated.
- Correspondence you send us is retained for as long as is necessary to handle your enquiry and to keep a reasonable record of how it was resolved, and is then deleted.
We may retain personal data for a longer period where we are required to do so by law, or where retention is necessary to establish, exercise, or defend legal claims.
10. Security and Confidentiality
In line with Article 32 of the GDPR, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk presented by our processing. These measures include, where relevant:
- Encrypted transport of all data between your browser and our servers (HTTPS / TLS).
- Access controls and the principle of least privilege for any personnel or systems that may handle personal data.
- CAPTCHA and other abuse-prevention mechanisms to protect the Service from automated abuse and credential-stuffing-style attacks.
- Vetting of service providers and contractual data protection obligations on those providers.
- Transient processing of uploaded documents so that personal data does not persist on our servers after extraction.
- Periodic review of our security posture and of this Notice.
No method of transmission or storage over the internet is completely secure, and we cannot guarantee absolute security. You should not upload documents containing personal data that you are not authorised to share, or that you would not be comfortable having processed by a third-party AI provider.
11. Personal Data Breaches
A "personal data breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
In the event of a personal data breach affecting your personal data:
- Where the breach is likely to result in a risk to the rights and freedoms of natural persons, we will notify the relevant supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of it, in line with Article 33.
- Where the breach is likely to result in a high risk to the rights and freedoms of natural persons, we will also communicate the breach to affected individuals without undue delay, in clear and plain language, in line with Article 34. This communication may be made by a prominent notice on the Service where individual contact is not feasible.
- We maintain an internal record of all personal data breaches, including the facts, effects, and remedial action taken, in line with Article 33(5).
12. Automated Decision-Making and Profiling
The UNLIPARSE extraction tools use automated processing — including artificial intelligence and computer-vision techniques — to read your uploaded document and return extracted key-value data. This processing is requested by you for the specific purpose of producing the output you are asking for, and the output is delivered back to you rather than used to make a decision about you.
Accordingly, we do not consider this processing to be a "solely automated decision … which produces legal effects concerning [you] or similarly significantly affects [you]" within the meaning of Article 22 of the GDPR. We do not use the Service to profile users for advertising, credit scoring, employment decisions, or similar purposes.
If you have concerns about how an automated extraction has handled personal data in a document, you may contact us at info@unliparse.com and we will assist you, including by considering any objection you may raise.
13. Children's Data
The Service is not directed to children, and we do not knowingly collect personal data from children under the age of 16 (or the lower minimum age set by local law in your country, where applicable, in line with Article 8 of the GDPR).
If you are a parent or guardian and you believe that a child has provided us with personal data — for example, by uploading a document that identifies them — please contact us at info@unliparse.com and we will take appropriate steps to delete that data.
15. Changes to This Notice
We may update this GDPR Notice from time to time to reflect changes in the law, in supervisory-authority guidance, or in how the Service operates. When we do, we will revise the "Effective Date" at the top of this page.
If the changes are material, we will take reasonable steps to provide additional notice — for example, by posting a prominent notice on the Service. Your continued use of the Service after the updated Notice takes effect constitutes your acknowledgement of the changes, to the extent permitted by applicable law.
16. Contact Us
For any question, concern, or request relating to this GDPR Notice or to how UNLIPARSE processes your personal data, please contact us by email at info@unliparse.com.
Please mark GDPR-related correspondence as "GDPR Request" in the subject line so we can route it appropriately.
Have a GDPR request or question?
Submit a data subject request or ask us anything about how we handle your personal data. We respond promptly and free of charge. For general questions, you can also visit our Contact Us page.
Contact us