Security and data

Most of the questions a buyer asks before giving an automation supplier access to their systems are answered on this page. If yours is not, write to us and we will answer it directly.

Where your data lives

By default, it stays with you. Production systems are deployed inside your own cloud environment, or in a region you choose, and we work through named accounts in your systems. We do not take a copy of your database.

Pilot work is done on anonymised or synthetic data wherever the acceptance criteria allow, so that a trial does not require a transfer of personal data at all.

What we sign before access

  • Data Processing Agreement. You are the controller, we are the processor. It sets out what we process, where, which sub-processors are involved, how long data is kept and how it is deleted.
  • Transfer safeguards. Our company is established in Uzbekistan, which is not covered by a UK or EU adequacy decision. Where personal data subject to UK or EU law is involved, we sign the ICO's International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum, and provide the information you need for your own transfer risk assessment.
  • Confidentiality. Mutual, and it survives the end of the engagement.

Automated actions require a human

Anything our software does that reaches your customer — a message, a status change, a published post — waits for approval by a named person on your side. This is not a setting or a policy document. It is enforced in the architecture of the system, and switching it off requires an explicit written agreement.

We learned the value of that distinction from our own mistake. In July 2026 one component of our internal outreach automation bypassed its approval step and sent 42 unapproved messages over three days. The rule existed and the gate existed; the component simply did not consult it. We rebuilt the control so that sending is impossible without a physical arming file that only the owner creates. Every client system we build now carries that lesson.

Access and controls

  • Individual named accounts with multi-factor authentication. No shared logins.
  • Least privilege: the narrowest scope that lets the work happen.
  • Access is revoked within three business days of anyone leaving your account.
  • Encryption in transit everywhere; storage encryption where we control storage.
  • Separate environment and credentials per client. No shared production databases.
  • Application logs are scrubbed of personal data.

AI models

Where the solution uses third-party language models, we configure them so that your content is not retained by the provider for training, and we name every provider in the Data Processing Agreement before processing starts. We do not use your data to train models of our own.

If something goes wrong

We notify you of any personal data breach affecting your data within 24 hours of becoming aware of it, with what happened, what is affected, what we have done and a named contact. Not a form letter, and not a week later.

Leaving

On request we return or delete your data and confirm deletion in writing. Deliverables built for you are yours on full payment, and you keep working systems rather than a dependency on us.

Questions before a call

Security questionnaires are welcome — send yours and we will complete it. For anything on this page, or a copy of our DPA in advance, contact contact@unika-digital.com.

Security and Data — How We Handle Your Information | UNIKA