Privacy
Privacy Notice
This notice explains who is responsible for personal information handled through the Unisen website and demonstration, what we collect, why we use it, and the rights available to you.
Effective and last updated: 20 August 2026
1. Who is responsible for your information
Unisen is a pre-incorporation venture jointly operated by Hanad Ali (CEO), Husaam Ateeq (CFO), and Mikhail Wijanarko (Founding Engineer and CTO). The three co-founders jointly decide why and how personal information is processed and are joint data controllers for the processing described in this notice.
Our service address is 1-2 Paris Garden, London SE1 8ND, United Kingdom. Our central contact for privacy questions and rights requests is enquiries@unisen.uk. You may address a request to any of the joint controllers through this contact.
The co-founders share responsibility for privacy information, rights requests, security and service-provider oversight. The central contact coordinates responses on their behalf. This arrangement does not affect your right to exercise your data-protection rights against any joint controller.
2. Scope
This notice applies when you:
- Visit unisen.uk, www.unisen.uk, or app.unisen.uk
- Submit an enquiry or request a walkthrough
- Create or use an account
- Use a fictional school or family demonstration workspace
- Receive or respond to a workspace invitation or access request
The current service is a prototype for fictional demonstration data. It is not approved for live SEND casework and this notice is not a privacy notice for live pupil or family case processing.
3. Information we collect and where it comes from
Information you provide
- Name, email address, telephone number, organisation and role
- Enquiry messages and correspondence
- Access requests, invitation responses and workspace selections
- Content entered into fictional demonstration workspaces
Account and access information
- Authentication identifier and verified email status
- Workspace membership, role, relationship and access status
- Invitation and account-administration records
- Security and audit events associated with your account
Technical information
Our hosting, authentication and security providers may process IP address, browser and device information, session identifiers, timestamps, request data, and signals used to detect spam, misuse or security threats.
Sources of information
We receive information directly from you, from Clerk or a sign-in provider you choose, from an authorised person who invites you to a workspace, and from the systems that record access, security and demonstration activity.
Demonstration workspace content
Signed-in edits are stored as account-linked cloud snapshots. Depending on the workspace, these may include fictional school profiles, provision and staffing notes, consultation drafts, evidence labels, templates, plan notes, document metadata, placement preferences, support-network details and private notes.
4. Why we use information and our lawful bases
We process personal information only where we have a lawful basis:
- Enquiries and walkthroughs. To respond, arrange a demonstration and keep relevant correspondence. We rely on steps you ask us to take before a possible contract and, where that basis does not apply, our legitimate interests in answering enquiries and developing business relationships.
- Accounts and demonstration access. To authenticate users, administer memberships and invitations, restore saved demonstration work, and provide requested prototype features. We rely on performance of these terms for individual users and our legitimate interests in operating and evaluating a controlled demonstration.
- Security and service integrity. To prevent spam, investigate misuse, enforce access controls, keep audit records, troubleshoot and protect the service and its users. We rely on our legitimate interests in maintaining a secure and reliable service.
- Legal and regulatory matters. To respond to rights requests, complaints, lawful demands and disputes. We rely on legal obligations and, where applicable, our legitimate interests in establishing, exercising or defending legal claims.
Where we rely on legitimate interests, we consider whether the processing is necessary and whether your rights and reasonable expectations override those interests. We do not use enquiry or account information for email marketing without a separate lawful basis and any consent required by law.
5. Special category data and children
We do not intentionally collect special category data or provide the prototype directly to children. If you believe prohibited live case data has been entered, contact us promptly so that we can investigate and delete or restrict it as appropriate.
6. Who receives information
We use the following service providers and recipient categories:
- Convex for application database and demonstration snapshot storage
- Clerk for authentication and account sessions
- Cloudflare for website hosting, delivery, security and Turnstile spam protection
- Resend for enquiry notifications and confirmation emails
- Google for the team email inbox that receives and stores enquiry correspondence
- Professional advisers, regulators, courts, law enforcement or public authorities where disclosure is necessary and lawful
We do not sell personal information. We may disclose information if the Unisen venture or its assets are reorganised, incorporated, financed or transferred, subject to appropriate confidentiality and data-protection safeguards.
7. International processing
Some providers operate internationally, so personal information may be processed outside the United Kingdom. The applicable location and transfer mechanism depend on the provider, service and subprocessor involved.
Our review of provider processing locations, contracts and UK international transfer safeguards is not yet complete. We will update this notice with the applicable mechanisms and how to obtain further information when that review is complete. Until then, the demonstration remains restricted to fictional data and must not be used for live SEND case information.
8. How long we keep information
- Website enquiry records in Convex are normally deleted after 30 days. Related email correspondence is kept only while needed to answer the enquiry, manage an active business relationship, maintain necessary records or resolve a dispute.
- Account, membership and invitation information is kept while needed to provide and secure demonstration access. Removed or expired records may be retained where needed for access integrity, security, audit or dispute handling.
- Demonstration snapshots are kept while the prototype workspace remains active, until the prototype is withdrawn, or until an applicable deletion request is completed. Editing or resetting a workspace may overwrite snapshot content.
- Provider security and delivery logs are retained under the provider's applicable retention settings and contractual terms.
When no fixed period applies, we consider the amount, nature and sensitivity of the information, the purpose for which it is held, security and legal risks, and whether the purpose can be achieved in another way.
9. Your data-protection rights
Depending on the processing and lawful basis, you may have the right to:
- Request access to and a copy of your personal information
- Ask us to correct inaccurate or incomplete information
- Ask us to erase information in certain circumstances
- Ask us to restrict processing in certain circumstances
- Object to processing based on legitimate interests
- Receive certain information in a portable format
- Withdraw consent at any time where processing relies on consent
These rights are not absolute. We may need information to verify your identity and will normally respond within one month. We do not charge a fee unless a request is manifestly unfounded or excessive, or the law otherwise permits a fee.
You have the right to object at any time to processing based on our legitimate interests. Tell us what you object to and why. We will stop unless we demonstrate compelling legitimate grounds or need the information for legal claims.
To exercise a right, email enquiries@unisen.uk.
10. Security
We use access controls, authenticated sessions, role-based authorisation, service security controls and operational safeguards intended to protect information from unauthorised access, alteration, disclosure or loss. No internet service can be guaranteed completely secure. You are responsible for protecting your sign-in credentials and notifying us if you suspect unauthorised account use.
12. Automated decisions
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. Turnstile automatically assesses technical signals to identify suspected spam or misuse, but it does not make a legally significant decision about you.
13. Complaints
Please contact us first so that we can investigate your concern. You may also complain to the UK Information Commissioner's Office. Guidance and contact details are available on the ICO website. Your right to complain is not affected by contacting us first.
14. Changes and contact
We may update this notice when the service, operators, providers or legal requirements change. Material changes will be brought to users' attention where appropriate. The date at the top identifies the current version.
Privacy questions and requests can be sent to enquiries@unisen.uk or by post to Unisen, 1-2 Paris Garden, London SE1 8ND, United Kingdom.