Privacy Policy
1. Data Controller
The data controller responsible for your personal data in connection with this campaign is:
- Name: Unime Labs Ltd
- Website: unimelabs.com
- Campaign site: exxysmartpen.unimelabs.com
- Contact: privacy@unimelabs.com
2. Personal Data We Collect
2.1 Data you provide directly
| Data field | Collected for | Required? |
|---|---|---|
| Full name | Reservation / Expression of Interest | Yes |
| Email address | Reservation / Expression of Interest | Yes |
| Country | Shipping logistics, tax compliance | No |
| Phone / WhatsApp number | Reservation fulfilment communications | No |
| Shipping address | Delivery planning | No |
| Quantity of pens reserved | Production planning | Yes (default: 1) |
2.2 Payment data
Payments are processed by PayPal (PayPal Holdings, Inc.) and Wise (Wise Payments Ltd). We do not receive or store full card numbers, bank account numbers, or PayPal login credentials. We receive and store:
- A transaction/order ID from the payment provider.
- Payment status (confirmed / pending / refunded).
- The amount and currency paid.
2.3 Technical data collected automatically
Our servers and third-party services may automatically collect:
- IP address (used for geolocation to pre-select country, then discarded).
- Browser type, device type, and operating system (for analytics and compatibility).
- Referring URL.
- Timestamp of submission.
3. Legal Basis for Processing (UK/EU GDPR)
| Processing activity | Legal basis |
|---|---|
| Fulfilling your reservation or expression of interest | Contract performance (Art. 6(1)(b) GDPR) |
| Sending confirmation and reminder emails | Contract performance (Art. 6(1)(b) GDPR) |
| Processing refunds where applicable | Contract performance (Art. 6(1)(b) GDPR) |
| Fraud prevention and compliance | Legitimate interest (Art. 6(1)(f) GDPR) |
| Campaign analytics and improvement | Legitimate interest (Art. 6(1)(f) GDPR) |
| Marketing updates about the Indiegogo launch | Legitimate interest (Art. 6(1)(f) GDPR) / Consent |
4. How We Use Your Personal Data
- To issue your reservation or expression of interest confirmation.
- To send reminder emails before the Cutoff Date.
- To notify you when the Indiegogo campaign launches.
- To notify Expression of Interest backers when a Super Early Bird spot becomes available.
- To process refunds where applicable.
- To plan production quantities and shipping logistics.
- To comply with applicable financial and tax regulations.
- To prevent fraud and abuse.
5. Marketing Communications
We will send you transactional emails related to your reservation or expression of interest. We may also send campaign updates, launch notifications, and related product announcements based on your participation. These communications are sent under legitimate interest where directly related to your reservation or expression of interest. You may opt out at any time by clicking the unsubscribe link in any email or by emailing privacy@unimelabs.com.
We will not sell, rent, or trade your email address or personal data to third-party marketing companies.
6. Data Sharing and Third Parties
6.1 Payment processors
Your payment data is processed by PayPal and/or Wise. Each processor has its own privacy policy:
6.2 Cloud infrastructure
Our platform is hosted on Microsoft Azure (EU/East US 2 region). All data is stored within Azure-managed infrastructure subject to Microsoft's data protection agreements. We have a Data Processing Agreement in place with Microsoft.
6.3 Analytics
We may use Microsoft Application Insights for performance monitoring. Aggregated analytics data does not contain personally identifiable information.
6.4 No sale of data
We do not sell, rent, or trade your personal data to any third party.
6.5 Legal disclosure
We may disclose personal data if required by law, court order, or regulatory authority.
7. Data Retention
| Data | Retention period |
|---|---|
| Reservation records (confirmed + refunded) | 7 years from pledge date (financial record-keeping) |
| Expression of Interest records | 2 years from payment date, or until the campaign ends |
| Email address (for launch notifications) | Until you unsubscribe or the campaign concludes |
| Payment transaction references | 7 years (legal / tax compliance) |
| Technical/server logs | 90 days |
After the applicable retention period, data is securely deleted or anonymised.
8. Your Rights
Depending on your location, you may have the following rights under GDPR (EU/UK) or equivalent privacy law:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Ask us to correct inaccurate data.
- Erasure: Ask us to delete your personal data, subject to legal retention obligations.
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interest.
- Restriction: Ask us to restrict processing of your data in certain circumstances.
- Withdraw consent: Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
To exercise any of these rights, email privacy@unimelabs.com. We will respond within 30 days. You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or your relevant national supervisory authority.
9. Cookies and Tracking
This campaign page does not use advertising cookies or cross-site tracking cookies. Strictly necessary session cookies may be set by the browser or payment provider iframes. No consent banner is required for these.
If you interact with the PayPal button, PayPal may set its own cookies subject to their policy.
10. Data Security
We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful loss, destruction, alteration, or unauthorised access. These include:
- HTTPS / TLS encryption for all data in transit.
- AES-256 encryption for data at rest in Azure SQL.
- Role-based access controls limiting staff access to personal data.
- Automated retention and deletion policies.
If a data breach occurs that is likely to result in risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by law.
11. International Data Transfers
Your personal data is primarily stored in Microsoft Azure (East US 2 region). If data is transferred to countries outside the UK or European Economic Area, we ensure appropriate safeguards are in place (such as Standard Contractual Clauses with the data processor).
12. Children's Privacy
This campaign is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has submitted personal data, please contact us immediately at privacy@unimelabs.com.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email to all Reservists and Interested Backers. The "Last updated" date at the top of this page indicates when the policy was last revised. Continued participation after notice of changes constitutes acceptance.
14. Contact Us
For any questions about this Privacy Policy or your personal data:
- Email: privacy@unimelabs.com
- General enquiries: hello@unimelabs.com
- Website: exxysmartpen.unimelabs.com