Home/Knowledge Base/Security & Compliance/Data Privacy in UniAsset
Back to Security & Compliance

Data Privacy in UniAsset

4 minBeginnerLast updated: January 2, 2026

Data privacy in UniAsset

Who controls your data

Your organization is the data controller. UniAsset is the data processor.

You decide what goes into UniAsset and what happens to it. UniAsset processes it on your behalf.

What personal data is held

  • User names and email addresses
  • Person records — name, phone, employee ID, designation
  • Login logs — IP address and a coarse derived location
  • Whatever you put in free-text fields

That last one is worth thinking about. Descriptions, notes, and custom fields hold whatever your team types into them.

The Data Processing Agreement

Acceptance is recorded immutably: a new record per acceptance, capturing the agreement version, the accepting person by name and email, IP address, user agent, and timestamp.

Names and emails are captured by value, so the record survives even if that account is later deleted.

A published subprocessor list is maintained.

Cookies and consent

UniAsset uses a first-party consent implementation — not a third-party banner.

No non-essential cookie or tracking script loads before you grant consent.

CategoryBehaviour
EssentialAlways on — the product cannot work without it
AnalyticsOnly after consent
PreferencesOnly after consent
MarketingOnly after consent

Your consent record carries the policy version in force at the time, a timestamp, and your per-category decisions. A policy change re-prompts rather than silently inheriting an old decision.

Withdrawing consent is available at any time from the footer, with per-category toggles. Withdrawing clears the cookies in that category.

The published cookie policy is generated from the same registry that drives the consent logic, so the list cannot drift from what the application actually sets.

Your rights

Right to erasure. Delete your organization and everything in it is permanently erased. There is a 30-day recoverable grace period, or immediate anonymization. See How to delete your organization.

Data portability. Assets, reports, and the Fixed Asset Register export to CSV, Excel, and PDF. You are never locked in.

Anonymization scrubs user identifiers and detaches connected sign-in accounts, available immediately without waiting for the grace period.

Isolation

Every organization's data is isolated. Queries always filter by an organization identifier that came from the server, never from client input, and every file is stored under a per-organization prefix.

What is not done with your data

Your operational data is yours. The AI Command Bar answers questions from your own records — the model plans the question and narrates the answer, but every figure on screen came out of your database.

Good practice for your team

  • Do not put personal data in asset descriptions unless you need it there
  • Archive leavers rather than deleting them, so history stays attributable while access is revoked
  • Review who has which role — access control is the practical side of privacy
  • Export before deleting anything you may need later

Related articles

Need Help?

If you have questions not covered in this article, our support team is here to help.

Contact Support