Legal

Privacy Policy

Last updated 23 August 2026

This Privacy Policy explains how Symfor (“Symfor”, “we”, “us”), operating the Unimatix product at unimatix.io, collects, uses, stores, and shares personal data. It applies to the website, the Unimatix workspace, and related services.

1. Who we are

Unimatix is operated by Symfor, 703, Block-B, Asian Suncity, Kondapur, Hyderabad, Telangana 500084, India.

For privacy requests, email hello@unimatix.io. We are the data fiduciary for account and website data. When you store client or project content in a workspace, you control that content; we process it to provide the service.

2. Data we collect

Account data: name, email address, password hash or sign-in tokens (Google / GitHub / Microsoft / Firebase), profile photo if you upload one, and workspace membership.

Workspace data you create: projects, tasks, clients, proposals, planner items, invoices, comments, files, and client-portal content.

Connected services, if you enable them: Google Calendar event metadata needed to sync tasks; WhatsApp group messages you choose to connect for classification into tasks, feedback, or approvals; OAuth tokens stored encrypted.

Billing data: plan, subscription status, trial dates, and payment references from Razorpay. We do not store full card numbers. Razorpay processes UPI, cards, and netbanking.

Usage and device data: pages viewed, buttons clicked, browser type, approximate location from IP, and diagnostic logs needed to keep the product running.

Marketing and ads data: cookies and first-party storage for analytics and attribution, including Google Analytics 4, Google Tag Manager, and click identifiers such as gclid plus UTM parameters when you arrive from an ad or campaign.

Support data: messages you send to hello@unimatix.io or through the contact form.

3. How we use data

To create and secure your account, operate workspaces, and show you projects, proposals, planner, and client portals.

To process subscriptions, trials, invoices, and plan changes through Razorpay.

To sync calendar events or classify WhatsApp messages only when you connect those integrations.

To understand product usage, fix errors, and measure marketing — including whether a visit from Google Ads led to a signup — using GA4, GTM, and stored attribution fields.

To send transactional email (sign-in, invites, billing). We send product updates only if you asked for them.

To comply with law, prevent abuse, and respond to lawful requests.

4. Legal bases (India)

We process personal data under the Digital Personal Data Protection Act, 2023, on the basis of your consent (account creation, cookies that are not strictly necessary, optional integrations) and for legitimate uses needed to perform the contract (providing Unimatix, billing, security).

You may withdraw consent for optional processing by disconnecting an integration, changing cookie settings in your browser, or emailing hello@unimatix.io. Withdrawing consent does not affect processing already completed.

5. Cookies and similar technologies

Strictly necessary: session and authentication cookies so you can stay signed in and use the app.

Analytics and ads: Google Tag Manager (GTM-PDXKBDJC) and Google Analytics 4 (G-43664NSG1K) on unimatix.io. We also store last-touch attribution (gclid, UTM fields, landing page) in a first-party cookie named _unx_attr and in localStorage for up to 90 days so we can attribute signups to campaigns.

You can block or delete cookies in your browser. The site may still work; ads measurement will be less accurate. We do not sell personal data or run a cross-site data marketplace.

6. Sharing and processors

We do not sell personal data.

We share data with processors who help us run Unimatix, only as needed: hosting (Vercel for the website, Railway for the API and database), Firebase Authentication, Google (sign-in and Calendar if you connect it), GitHub or Microsoft if you use those sign-in methods, Razorpay for payments, email delivery (transactional mail), and Google Analytics / Google Ads / Google Tag Manager for measurement.

Client portal links share the project status you choose to publish with anyone who has the link. You are responsible for what you share with clients.

We may disclose data if required by Indian law or to protect users, the service, or the public from harm.

7. International transfers

Servers and processors may be located outside India (for example, Vercel, Railway, Google, and Firebase). Where data is transferred, we do so to provide the service you requested and with appropriate contractual and security measures.

8. Retention

Account and workspace data is kept while your account is active. You may delete content in the product or ask us to close the account.

Billing records are kept as required for tax and accounting (typically seven years in India).

Attribution cookies last up to 90 days. Analytics data follows Google Analytics retention settings.

Backups and logs are rotated on a limited schedule. After account deletion, residual copies may remain in backups until those expire.

9. Security

We use HTTPS, hashed passwords, encrypted OAuth tokens, and access controls on production systems. No method of transmission or storage is completely secure. You must keep your password and workspace invites confidential.

10. Children

Unimatix is for people 18 years or older. We do not knowingly collect personal data from children. If you believe a minor has created an account, email hello@unimatix.io and we will delete it.

11. Your rights

You may request access, correction, or deletion of your personal data, or a copy of data you provided, by emailing hello@unimatix.io from the address on the account.

You may disconnect Google Calendar or WhatsApp, change your profile, or leave a workspace in the product.

You may object to marketing emails by using the unsubscribe link or emailing us.

If you are not satisfied with our response, you may raise a complaint with the Data Protection Board of India once the Board is accepting complaints under the DPDP Act.

12. Third-party links and client data

The site and workspace may link to third-party sites (for example Razorpay checkout or Google). Their privacy practices apply when you leave Unimatix.

If you put personal data of your clients into Unimatix, you must have a lawful basis to do so. You are the data fiduciary for that client data; we process it on your instructions to provide the workspace.

13. Changes

We may update this policy. The “Last updated” date at the top will change. Material changes will be posted on this page. Continued use after an update means you accept the revised policy.

14. Contact

Privacy and grievance contact: hello@unimatix.io

Postal: Symfor, 703, Block-B, Asian Suncity, Kondapur, Hyderabad, Telangana 500084, India.

Website: https://unimatix.io