Privacy Policy
Last updated: August 26, 2026 · Effective September 25, 2026 for accounts existing on the last updated date, and immediately for new accounts.
In short
- We do not sell or share your personal information, and we do not use it for advertising.
- We do not use your data to develop our own models, and no training data set exists. If that ever changes we will ask you first — opt in, never by default. Our AI providers may never use your data to train theirs.
- No decision that significantly affects a student is made by AI alone. A person always decides.
- Your counseling organization controls your student record. We process it on their instructions.
This Privacy Policy explains how [UnisPath registered legal name] ("UnisPath", "we", "us", "our") collects, uses, stores, and shares information when you and your organization use our student counseling and application management platform (the "Service"), and when you visit our website.
1. Who we are and how to contact us
| Legal entity | [UnisPath registered legal name] |
| Registration number | [commercial licence / registration number] |
| Registered address | [registered address, Dubai, United Arab Emirates] |
| Privacy contact | privacy@unispath.com |
| Security incidents | security@unispath.com |
| EU representative (GDPR Art. 27) | [EU Article 27 representative — name and address] |
| UK representative (UK GDPR Art. 27) | [UK Article 27 representative — name and address] |
If you have a question about this policy or want to exercise a right, contact us at privacy@unispath.com or through our contact page.
2. Our role: controller or processor
Which of your rights apply, and who you exercise them against, depends on our role for the data in question.
| Data | Who decides how it is used | Our role |
|---|---|---|
| Student profiles, applications, uploaded documents, messages, and status history entered by or on behalf of a counseling organization | The counseling organization that onboarded the student | Processor (service provider). We act only on the organization's documented instructions. |
| Account registration, authentication, billing, security logs, abuse prevention, and platform operations | UnisPath | Controller |
| Website visitors, the public website chatbot, and contact form submissions | UnisPath | Controller |
| Webinar registrations, attendance, recordings, and AI-generated summaries | UnisPath | Controller |
| Developing UnisPath's own AI and statistical models (Section 8) — not currently carried out | Would be UnisPath, with the organization's authorisation and your consent | Would be controller. This would be our own purpose, not your organization's, which is why we would ask you for consent directly rather than relying on your organization. |
If you are a student and want to access, correct, or delete your record, start with your counseling organization. If they do not respond, contact us and we will help — see Section 16. The one exception is model development (Section 8): because that is our own purpose and we are the controller for it, come to us directly to withdraw consent or ask what we hold.
3. Who uses UnisPath
- Students — invited by a counseling organization. Students cannot self-register.
- Organization members— belong to a counseling organization with management access to that organization's students, applications, documents, and messages. The founding member registers the organization; after our review and approval, they manage students and invite additional members.
- UnisPath superadministrators — UnisPath personnel who approve new organizations, manage webinars, and provide support.
4. Information we collect
Account information. Email address, full name (optional), phone number (optional), WhatsApp number (optional), role, organization affiliation, and a flag indicating whether you must change your password on next sign-in. You may sign in with a password (the hash is stored by Firebase Authentication / Google Identity Platform) or, where enabled, by connecting a Google or Microsoft account — in that case Firebase, Google, and (for Microsoft sign-in) Microsoft each confirm your identity, and we receive only your verified email address and name. UnisPath never has access to your Google or Microsoft password.
Student profile and application data.Through the profile setup flow: country of residence, preferred destination countries and cities, intended majors, grade level, course system and score (for example IB or A-Levels), individual subject grades, standardized test scores (SAT/ACT), English proficiency scores (IELTS/TOEFL), extracurricular activities, awards and honours, a personal statement summary, tuition budget, and campus preferences. We store the universities you shortlist and every application you create, with each application's status as it moves through the pipeline.
Uploaded documents. Documents required by target universities, as PDFs or images (JPEG, PNG, or WebP) of up to 10 MB each, including academic transcripts, English-test score reports, personal statements, CVs, and reference letters. An organization may define additional custom document types for its own students.
Messages. Messages exchanged between students and their counseling team within the platform.
Status history.Each application's status transitions, logged with a timestamp and the user who made the change, for audit and notification purposes.
Contact form. If you submit our public contact form: your name, email, organization name, and message.
AI assistant conversations. Messages you send to the in-app AI assistant and to the public website chatbot are transmitted to our AI provider to generate a response (see Section 7). We do not store chat transcripts on our servers; we log only usage metadata (feature used, timing, and token counts).
Webinar data. Registration details, attendance, and — where a session is recorded — the recording and any Google Meet-generated summary. See Section 14.
Usage and device information. Server logs, IP address, browser user-agent, and request paths, used for security, debugging, and abuse prevention.
5. Sensitive and special category information
Documents uploaded to the Service — transcripts, personal statements, reference letters, and identity pages — can contain information that data protection law treats as sensitive or "special category": date of birth, nationality and national identification numbers, and sometimes information revealing health or disability (for example, an accommodation request or a medical explanation for absence), religious or philosophical belief (for example, a faith-school transcript), or racial or ethnic origin.
We do not ask for this information and we do not use it for profiling. Where it appears in a document, we process it only as part of storing and displaying that document and running the automated validation described in Section 7, on the basis of the explicit consent obtained by your counseling organization (or, where relevant, because you have manifestly made it public by including it in an application document). Counseling organizations are responsible for obtaining that explicit consent before uploading.
Note that automated document validation reads the whole of every document you upload, including anything sensitive it happens to contain. We do not currently operate a filter that detects or removes special category information, which is why the request above matters. Should we ever begin developing our own models (Section 8), such a filter would be a precondition.
Please do not upload more than is needed. Redact information a university has not asked for. If you believe a document containing sensitive information was uploaded without a proper basis, contact privacy@unispath.com and we will work with your organization to remove it.
6. How we use information, and our legal bases
Where UnisPath acts as controller, we rely on the legal bases below. Where we act as processor, the counseling organization is responsible for establishing the legal basis and we process on its instructions.
| Purpose | Information used | Legal basis |
|---|---|---|
| Authenticate users, enforce role-based access, and operate the Service | Account information, usage and device information | Performance of a contract; legitimate interests in securing the Service |
| Allow organizations to manage students, members, and applications | Student profile and application data, documents, messages | Processing on the organization's instructions as its processor |
| University search and comparison using curated third-party data | Profile preferences, shortlists | Performance of a contract |
| Automated AI document validation and optional AI document coaching | Uploaded document content | Processing on the organization's instructions; explicit consent for any special category content (Section 5) |
| In-app AI assistant and public website chatbot | Your messages plus relevant account context | Performance of a contract; consent for the public chatbot |
| Transactional and operational email notifications | Account information, application and document events | Performance of a contract |
| Security monitoring, abuse prevention, and debugging | Server logs, IP address, user-agent, AI usage metadata | Legitimate interests in protecting the Service and its users |
| Billing and account administration | Account and organization information | Performance of a contract; legal obligation |
| Developing UnisPath's own AI and statistical models (Section 8) | Uploaded documents, profile and application data, and counselor feedback — opted-in records only | Your consent (Art. 6(1)(a)), and explicit consent (Art. 9(2)(a)) for any special category content, given separately from your use of the Service and withdrawable at any time |
| Webinars, including recording and summaries | Registration, attendance, recording | Consent, which you may withdraw by leaving the session |
| Complying with legal obligations and responding to lawful requests | As required | Legal obligation |
Where we rely on legitimate interests, we have assessed that our interest in operating and securing the Service is not overridden by your rights and freedoms. You can ask for a summary of that assessment at privacy@unispath.com. Where we rely on consent, you may withdraw it at any time; this does not affect processing carried out before withdrawal.
7. AI processing
The Service currently uses Google Vertex AI (Gemini), processed within UnisPath's own Google Cloud project, for the features below. We may use additional or different AI providers or models as the Service evolves; we will give organizations at least 30 days' notice before doing so, as described in Section 10.
- Automated document validation — when a student uploads a document, its content is sent to the AI provider to check document type, legibility, completeness, and potential fraud indicators. The result is a status of valid, needs review, or invalid, plus notes for the organization team.
- Document coaching — students may optionally request AI feedback on an uploaded document, which returns quality ratings, strengths, suggested improvements, and a readiness assessment.
- Student and counselor AI assistant — to answer your questions, context from your account is included in prompts sent to the AI provider along with your messages. For students that context includes your name, email address, phone number, and WhatsApp number, together with your profile, shortlists, applications, document statuses, tasks, and assigned counselor. For counselors it includes the names and email addresses of the students in their caseload, with application counts, intake status, tasks, recent uploads, and team workload figures.
- Superadmin AI assistant — UnisPath superadministrators have an assistant that helps with platform management. Only organization-level and aggregate operational data is included in these prompts.
- Public website chatbot — answers general questions about UnisPath. Do not enter personal information about yourself or anyone else into it.
Our AI providers never train on your data. Our contracts with them prohibit using anything you send through the Service to train or improve their own general-purpose models, and prompts are not retained by the provider for that purpose. This is unconditional and is not affected by anything in Section 8.
We log the type, timing, and token count of AI requests for monitoring, cost management, and abuse prevention. AI outputs are not guaranteed to be accurate or complete; verify university requirements, deadlines, and document acceptance directly with each university.
8. Developing our own models — opt-in only
We are not doing this today.
UnisPath does not currently use any student information to develop its own models, and no training data set exists. This section describes the conditions that would have to be met first. We are publishing them in advance so you can see the rules before anything changes, and so that nothing can start quietly. If we begin, we will tell you and ask you directly — it will never happen through an update to this policy.
We would like to develop our own AI and statistical models to make document review, university matching, and application guidance work better, and doing that well requires real examples. If we do, we will only use your information with your agreement.
Nothing would enter our training data unless all of these are true:
- Your organization has opted in through a signed data processing agreement. This is never a default and never happens because we updated this policy.
- You have separately said yes using a clearly labelled control in the Service, after being told what would be used and why. Where your local law requires a parent or guardian to agree as well, we require that too.
- You were 16 or older when you agreed. We never use the data of anyone under 16 to develop models, on any basis, even with parental consent.
- Your organization is eligible. Institutions for which we act as a school official under FERPA, and organizations covered by student privacy laws that prohibit this use, are excluded entirely.
- The content passed our sensitivity filter. Documents flagged as containing special category information (Section 5) are excluded unless you gave explicit consent covering that information.
Saying no would cost you nothing. Consent here would be genuinely optional and entirely separate from your use of the Service. If you declined, or withdrew later, you would keep every feature, your documents would be reviewed exactly the same way, and neither UnisPath nor your counseling organization would treat your application differently. We would not ask again after you declined, other than through a setting you could change yourself at any time.
What we would do with it. Where you had opted in, we would use your uploaded documents, profile and application data, and counselor feedback on our automated review to train, fine-tune, and evaluate models that UnisPath owns and uses in the Service.
What we would never do. We would not sell the training data or make it available to any third party, we would not use it to build models for anyone other than UnisPath, and we would not deploy a model in a form that reproduces identifiable information from documents. We would test models for memorisation before releasing them.
Withdrawing. You would be able to withdraw at any time from your account settings or by emailing privacy@unispath.com. We would remove your records from the training data promptly and exclude them from every future training run. We want to be straightforward about one limit: a model that has already been trained cannot have an individual's contribution surgically removed, so withdrawal would apply going forward rather than retroactively to models already built.
Safeguards. The training data would be held separately from the live Service, access restricted to named personnel and logged, and every record would carry a record of the organization opt-in and the individual consent that permitted it. Because this processing would involve people under 18, we would carry out and keep under review a data protection impact assessment addressing the best interests of the child, in line with the UK Age Appropriate Design Code and equivalent guidance, before starting.
9. Automated decision-making and human review
UnisPath does not make decisions producing legal or similarly significant effects about any student by automated means alone. The document validation status is a flag surfaced to your counseling organization for a person to review; it does not by itself reject a document, block an application, or affect any admission decision. Every consequential decision is taken by a human at your organization.
You may ask for human review of any automated flag, express your point of view, and contest the result — through your counseling organization, or by writing to privacy@unispath.com. We monitor validation outputs for accuracy and unintended bias, and we do not use AI to score, rank, or profile students.
10. Subprocessors
We use the third-party providers below. Each is bound by a written contract limiting its use of the data to providing its service to us.
| Provider | What it does | Data involved |
|---|---|---|
| Google Cloud Platform | Hosting (Cloud Run), database (Cloud SQL for PostgreSQL, private IP), document storage (Cloud Storage, private bucket with signed URLs), and operational logging | All Customer Data and server logs |
| Google Vertex AI (Gemini) | AI document validation, coaching, and assistants, processed inside UnisPath's Google Cloud project | Document content, chat messages, account context |
| Firebase Authentication (Google Identity Platform) | Authentication, password management, session tokens, and password reset emails. Password hashes are held entirely by Firebase; UnisPath never has plaintext passwords. Where you sign in with Google or Microsoft, Firebase brokers the sign-in and Google or Microsoft (Microsoft Entra ID) confirms your identity under its own terms. | Email address, name, authentication metadata |
| Resend | Transactional and operational email — invitations, status updates, webinar notifications, and announcements | Email address, name, notification content |
| Google Meet (Google Workspace) | Hosting webinars, including recording and Google's built-in AI meeting summaries where enabled | Name, email, audio/video where you participate |
We will give organizations at least 30 days' notice before adding or replacing a subprocessor that processes Customer Data. To receive those notices, email privacy@unispath.com. An organization may object on reasonable data protection grounds, as described in the Terms.
11. How we share data
- Within your organization.A student's applications, documents, and messages are visible to members of the organization that onboarded them. Each student is assigned a primary counselor by an automatic least-loaded algorithm, but other members of the same organization may access the records as part of normal team operations.
- Between organizations: never.We do not share student data with any other counseling organization, no organization can see another's students, documents, or messages, and we do not maintain any combined data set drawn from more than one organization. Were the model development described in Section 8 ever to begin, the resulting training data would be the sole exception — it would contain only records that both the organization and the individual had opted in, would never be visible to any customer, and would never be disclosed to anyone outside UnisPath.
- Service providers. The subprocessors listed in Section 10, strictly for the purposes described.
- Legal and safety. Where required by law or valid legal process, or to protect the rights, property, or safety of UnisPath, our users, or others. Where we are legally permitted to do so, we will notify the affected organization before disclosing.
- Corporate transactions. In connection with a merger, acquisition, financing, or sale of assets, subject to the recipient being bound by protections at least as protective as this policy. We will notify affected organizations before their data is transferred.
We do not sell or share personal information, and we do not use it for advertising. We have not sold or shared personal information — including the personal information of anyone we know to be under 16 — in the preceding 12 months, as those terms are defined by the California Consumer Privacy Act and comparable laws. We do not run third-party advertising or social-tracking technologies in the Service, and there is therefore no opt-out for you to exercise. We honour Global Privacy Control and similar browser signals.
12. Children and minors
Many of our users are between 16 and 18 and applying to universities. The Service is intended for students aged 16 and over, or aged 13 to 15 where their counseling organization has obtained verifiable parental or guardian consent and local law permits. We do not knowingly collect personal information from anyone under 13.
Counseling organizations are contractually responsible for obtaining and retaining evidence of every parental, guardian, or school consent required by local law — including the consent required under Article 8 of the EU and UK GDPR, which sets the digital consent age between 13 and 16 depending on the country — before submitting any data about a minor to the Service.
If you believe a child's information has been provided to us without proper consent, contact privacy@unispath.com and we will delete it promptly.
13. Student records and education privacy laws
Our customers are principally independent counseling organizations and agencies rather than schools. Where UnisPath is engaged by an educational institution and processes education records on its behalf, we act solely as a school official with a legitimate educational interest, under the institution's direct control, in accordance with 34 CFR § 99.31(a)(1)(i)(B) of the US Family Educational Rights and Privacy Act (FERPA). In that role we will:
- use education records only for the purposes the institution authorises;
- not redisclose them to any third party without the institution's authorisation or as permitted by FERPA;
- not use them to create a student profile for any purpose other than delivering the Service; and
- return or destroy them at the institution's direction on termination.
Depending on your jurisdiction, our processing may also engage US state student privacy laws (such as California's SOPIPA), the EU and UK GDPR, the UK Data Protection Act 2018, the DIFC Data Protection Law No. 5 of 2020, UAE Federal Decree-Law No. 45 of 2021, or equivalent regimes. Consistent with those laws, we do not sell student data, do not use it for targeted advertising, and do not build advertising profiles.
14. Webinars and recordings
Webinars run on Google Meet. Where a session will be recorded, we tell you at registration and again at the start of the session. You may attend with your camera and microphone off, or leave, and your participation is entirely voluntary. Google Meet's built-in AI features may generate summaries or notes; these are processed by Google under its own terms.
Recordings and summaries may be shared with registered attendees. We retain them for 12 months unless you ask us to remove your contribution sooner, which you can do at privacy@unispath.com.
15. Data retention
| Data | Retention period |
|---|---|
| Account, profile, application, document, and message data | For as long as the student or organization account is active. On deletion, the account is immediately deactivated and hidden from all rosters, then held in a recoverable state for 60 days before permanent erasure. |
| Backups | Automated daily database backups with point-in-time recovery, retained on a rolling 7-day cycle. Deleted data persists in backups until the cycle completes, after which it is purged. |
| Server and security logs | 12 months, then deleted or aggregated. |
| AI usage metadata (feature, timing, token counts) | 24 months for cost and abuse monitoring. No prompt or response content is retained. |
| AI chat transcripts | Not stored on our servers. |
| Contact form submissions | 24 months from your last correspondence with us. |
| Webinar recordings, summaries, and attendance | 12 months from the session date. |
| Billing and tax records | As required by applicable law, typically 5 to 7 years. |
| Model training data (Section 8) | None held — we do not currently develop our own models. Were we to begin, opted-in records would be retained for as long as we maintained the models trained on them, reviewed every 24 months, and removed promptly on withdrawal. |
| Consent records for model development | None held today. Any future consent record would be retained for the life of the training data plus 6 years, as evidence that consent was validly obtained. |
| Aggregated, de-identified analytics that cannot be linked to any individual | Retained without a fixed period for product improvement. |
During the 60-day recovery window, an organization admin or UnisPath can restore an account with its data intact. An organization or student may request immediate permanent deletion instead — see Section 16. We may retain information longer where we are legally required to, or where it is necessary to establish, exercise, or defend legal claims; in that case we isolate it and stop using it for any other purpose.
16. Your rights
Depending on where you live, you may have the right to: access a copy of your personal information; correct inaccurate information; delete it; obtain it in a portable format; restrict or object to certain processing, including processing based on legitimate interests; withdraw consent at any time; limit the use of sensitive personal information; not be discriminated against for exercising a right; and not be subject to a solely automated decision with legal or similarly significant effects (see Section 9).
Model development consent. We do not currently ask for this consent, because we do not develop our own models. If we ever do, you will be able to change your decision at any time from your account settings — a single toggle, as easy to turn off as on — withdrawal will take effect immediately for all future use, and nothing else about your account will change. See Section 8.
Students.You may delete your own account directly from the platform. This immediately disables sign-in, hides the account, and starts the 60-day period described in Section 15, after which the data is permanently erased. Because your record may also be your counseling organization's business record, we will notify your organization of the deletion, and they may need to retain limited information where they have an independent legal obligation to do so. You may also ask your organization for assistance, including immediate permanent deletion.
Everyone else. Contact privacy@unispath.com or use our contact page. We will verify your identity through your registered email address before acting, and we respond within 30 days (extendable by a further 30 or 45 days for complex requests, where the law permits and with notice to you). Exercising a right is free unless a request is manifestly unfounded or excessive. You may use an authorised agent where the law allows; we will ask for proof of their authority.
Complaints.If you are unhappy with our response, you have the right to lodge a complaint with your data protection supervisory authority — in the EU, the authority in your country of residence or workplace; in the UK, the Information Commissioner's Office (ico.org.uk); in the DIFC, the DIFC Commissioner of Data Protection; and in the UAE, the UAE Data Office. We would appreciate the chance to address your concern first.
17. International transfers
UnisPath is established in the United Arab Emirates. The Service runs on Google Cloud Platform in a single region in the United States: your account data, your uploaded documents, and our database backups are all stored there. There is no per-account or per-country choice of region. Our personnel and providers access that data from the United Arab Emirates.
AI processing is carried out by Google Vertex AI. Depending on the model, inference may run on Google's global endpoint, which means the content of a request may be processed in Google infrastructure outside the United States. Nothing is retained by the provider for its own purposes.
For transfers of personal data out of the European Economic Area, the United Kingdom, Switzerland, or the DIFC, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, the Swiss addendum, and the equivalent mechanisms under DIFC Data Protection Law, together with supplementary technical measures including encryption in transit and at rest and access controls. You can request a copy of the relevant transfer mechanism, with commercial terms redacted, from privacy@unispath.com.
18. Security
- Encryption in transit (TLS 1.2 or higher) for all client traffic.
- Encryption at rest for the database (Cloud SQL), document storage (Cloud Storage), and secrets (Secret Manager).
- The database is reachable only over a private IP from inside our Google Cloud VPC.
- Documents are served via time-limited V4 signed URLs; the storage bucket is not publicly accessible.
- Authentication is delegated to Firebase Authentication (Google Identity Platform), with a required password change on first invited sign-in.
- Role-based access control and organization-scoped queries enforced server-side on every authenticated request.
- Automated daily database backups with point-in-time recovery, and object versioning on document storage.
- Administrative and infrastructure access is logged via Google Cloud Audit Logs.
Read more on our security page. No security programme is perfect, and no method of transmission or storage is completely secure.
19. If something goes wrong
If we confirm a personal data breach, we will notify the affected counseling organization, as controller, without undue delay and in any event within 48 hours of confirming it, with the information the organization needs to meet its own notification duties. Where we act as controller, we will notify the competent supervisory authority within 72 hours where required, and will notify affected individuals directly without undue delay where the breach is likely to result in a high risk to their rights and freedoms, or where any applicable law requires individual notice. We will follow up with a written post-incident summary.
To report a suspected vulnerability or incident, contact security@unispath.com. We aim to acknowledge reports within 48 hours.
20. Cookies and similar technologies
We use only cookies that are strictly necessary to operate the Service. We do not run advertising, analytics, social-tracking, or session-recording technologies, and we therefore do not display a consent banner — strictly necessary cookies do not require consent.
| Cookie | Purpose | Duration |
|---|---|---|
| Session cookie | Keeps you signed in after authentication. HttpOnly, Secure, SameSite. | Expires on sign-out or when the session expires |
| Functional preferences | Remembers basic interface state, such as a collapsed sidebar | Up to 12 months |
Blocking the session cookie will prevent you from signing in. If we ever introduce analytics or any non-essential technology, we will update this section and ask for your consent first.
21. Communications
We send transactional and operational messages — invitations, application status updates, document review alerts, direct-message notifications, webinar invitations, and service announcements — which are necessary to provide the Service and cannot be turned off while your account is active, though you can adjust notification preferences where the Service offers them. Any purely promotional email will include an unsubscribe link and will be sent only where we have a lawful basis to do so.
22. Changes
We may update this policy. We will update the "last updated" date above and, for material changes, notify organizations and account holders through the Service or by email at least 30 days before they take effect. We will never apply a materially different use of previously collected personal information without a lawful basis and, where required, your consent. Previous versions are available on request from privacy@unispath.com.
23. Contact
Questions about this policy, or requests to exercise your rights, can be sent to privacy@unispath.com, or through our contact page. Our postal address is [UnisPath registered legal name], [registered address, Dubai, United Arab Emirates]. Our Terms of Service are available here.