Privacy Policy

Last updated: August 26, 2026 · Effective September 25, 2026 for accounts existing on the last updated date, and immediately for new accounts.

In short

  • We do not sell or share your personal information, and we do not use it for advertising.
  • We do not use your data to develop our own models, and no training data set exists. If that ever changes we will ask you first — opt in, never by default. Our AI providers may never use your data to train theirs.
  • No decision that significantly affects a student is made by AI alone. A person always decides.
  • Your counseling organization controls your student record. We process it on their instructions.

This Privacy Policy explains how [UnisPath registered legal name] ("UnisPath", "we", "us", "our") collects, uses, stores, and shares information when you and your organization use our student counseling and application management platform (the "Service"), and when you visit our website.

1. Who we are and how to contact us

Legal entity[UnisPath registered legal name]
Registration number[commercial licence / registration number]
Registered address[registered address, Dubai, United Arab Emirates]
Privacy contactprivacy@unispath.com
Security incidentssecurity@unispath.com
EU representative (GDPR Art. 27)[EU Article 27 representative — name and address]
UK representative (UK GDPR Art. 27)[UK Article 27 representative — name and address]

If you have a question about this policy or want to exercise a right, contact us at privacy@unispath.com or through our contact page.

2. Our role: controller or processor

Which of your rights apply, and who you exercise them against, depends on our role for the data in question.

DataWho decides how it is usedOur role
Student profiles, applications, uploaded documents, messages, and status history entered by or on behalf of a counseling organizationThe counseling organization that onboarded the studentProcessor (service provider). We act only on the organization's documented instructions.
Account registration, authentication, billing, security logs, abuse prevention, and platform operationsUnisPathController
Website visitors, the public website chatbot, and contact form submissionsUnisPathController
Webinar registrations, attendance, recordings, and AI-generated summariesUnisPathController
Developing UnisPath's own AI and statistical models (Section 8) — not currently carried outWould be UnisPath, with the organization's authorisation and your consentWould be controller. This would be our own purpose, not your organization's, which is why we would ask you for consent directly rather than relying on your organization.

If you are a student and want to access, correct, or delete your record, start with your counseling organization. If they do not respond, contact us and we will help — see Section 16. The one exception is model development (Section 8): because that is our own purpose and we are the controller for it, come to us directly to withdraw consent or ask what we hold.

3. Who uses UnisPath

  • Students — invited by a counseling organization. Students cannot self-register.
  • Organization members— belong to a counseling organization with management access to that organization's students, applications, documents, and messages. The founding member registers the organization; after our review and approval, they manage students and invite additional members.
  • UnisPath superadministrators — UnisPath personnel who approve new organizations, manage webinars, and provide support.

4. Information we collect

Account information. Email address, full name (optional), phone number (optional), WhatsApp number (optional), role, organization affiliation, and a flag indicating whether you must change your password on next sign-in. You may sign in with a password (the hash is stored by Firebase Authentication / Google Identity Platform) or, where enabled, by connecting a Google or Microsoft account — in that case Firebase, Google, and (for Microsoft sign-in) Microsoft each confirm your identity, and we receive only your verified email address and name. UnisPath never has access to your Google or Microsoft password.

Student profile and application data.Through the profile setup flow: country of residence, preferred destination countries and cities, intended majors, grade level, course system and score (for example IB or A-Levels), individual subject grades, standardized test scores (SAT/ACT), English proficiency scores (IELTS/TOEFL), extracurricular activities, awards and honours, a personal statement summary, tuition budget, and campus preferences. We store the universities you shortlist and every application you create, with each application's status as it moves through the pipeline.

Uploaded documents. Documents required by target universities, as PDFs or images (JPEG, PNG, or WebP) of up to 10 MB each, including academic transcripts, English-test score reports, personal statements, CVs, and reference letters. An organization may define additional custom document types for its own students.

Messages. Messages exchanged between students and their counseling team within the platform.

Status history.Each application's status transitions, logged with a timestamp and the user who made the change, for audit and notification purposes.

Contact form. If you submit our public contact form: your name, email, organization name, and message.

AI assistant conversations. Messages you send to the in-app AI assistant and to the public website chatbot are transmitted to our AI provider to generate a response (see Section 7). We do not store chat transcripts on our servers; we log only usage metadata (feature used, timing, and token counts).

Webinar data. Registration details, attendance, and — where a session is recorded — the recording and any Google Meet-generated summary. See Section 14.

Usage and device information. Server logs, IP address, browser user-agent, and request paths, used for security, debugging, and abuse prevention.

5. Sensitive and special category information

Documents uploaded to the Service — transcripts, personal statements, reference letters, and identity pages — can contain information that data protection law treats as sensitive or "special category": date of birth, nationality and national identification numbers, and sometimes information revealing health or disability (for example, an accommodation request or a medical explanation for absence), religious or philosophical belief (for example, a faith-school transcript), or racial or ethnic origin.

We do not ask for this information and we do not use it for profiling. Where it appears in a document, we process it only as part of storing and displaying that document and running the automated validation described in Section 7, on the basis of the explicit consent obtained by your counseling organization (or, where relevant, because you have manifestly made it public by including it in an application document). Counseling organizations are responsible for obtaining that explicit consent before uploading.

Note that automated document validation reads the whole of every document you upload, including anything sensitive it happens to contain. We do not currently operate a filter that detects or removes special category information, which is why the request above matters. Should we ever begin developing our own models (Section 8), such a filter would be a precondition.

Please do not upload more than is needed. Redact information a university has not asked for. If you believe a document containing sensitive information was uploaded without a proper basis, contact privacy@unispath.com and we will work with your organization to remove it.

6. How we use information, and our legal bases

Where UnisPath acts as controller, we rely on the legal bases below. Where we act as processor, the counseling organization is responsible for establishing the legal basis and we process on its instructions.

PurposeInformation usedLegal basis
Authenticate users, enforce role-based access, and operate the ServiceAccount information, usage and device informationPerformance of a contract; legitimate interests in securing the Service
Allow organizations to manage students, members, and applicationsStudent profile and application data, documents, messagesProcessing on the organization's instructions as its processor
University search and comparison using curated third-party dataProfile preferences, shortlistsPerformance of a contract
Automated AI document validation and optional AI document coachingUploaded document contentProcessing on the organization's instructions; explicit consent for any special category content (Section 5)
In-app AI assistant and public website chatbotYour messages plus relevant account contextPerformance of a contract; consent for the public chatbot
Transactional and operational email notificationsAccount information, application and document eventsPerformance of a contract
Security monitoring, abuse prevention, and debuggingServer logs, IP address, user-agent, AI usage metadataLegitimate interests in protecting the Service and its users
Billing and account administrationAccount and organization informationPerformance of a contract; legal obligation
Developing UnisPath's own AI and statistical models (Section 8)Uploaded documents, profile and application data, and counselor feedback — opted-in records onlyYour consent (Art. 6(1)(a)), and explicit consent (Art. 9(2)(a)) for any special category content, given separately from your use of the Service and withdrawable at any time
Webinars, including recording and summariesRegistration, attendance, recordingConsent, which you may withdraw by leaving the session
Complying with legal obligations and responding to lawful requestsAs requiredLegal obligation

Where we rely on legitimate interests, we have assessed that our interest in operating and securing the Service is not overridden by your rights and freedoms. You can ask for a summary of that assessment at privacy@unispath.com. Where we rely on consent, you may withdraw it at any time; this does not affect processing carried out before withdrawal.

7. AI processing

The Service currently uses Google Vertex AI (Gemini), processed within UnisPath's own Google Cloud project, for the features below. We may use additional or different AI providers or models as the Service evolves; we will give organizations at least 30 days' notice before doing so, as described in Section 10.

  • Automated document validation — when a student uploads a document, its content is sent to the AI provider to check document type, legibility, completeness, and potential fraud indicators. The result is a status of valid, needs review, or invalid, plus notes for the organization team.
  • Document coaching — students may optionally request AI feedback on an uploaded document, which returns quality ratings, strengths, suggested improvements, and a readiness assessment.
  • Student and counselor AI assistant — to answer your questions, context from your account is included in prompts sent to the AI provider along with your messages. For students that context includes your name, email address, phone number, and WhatsApp number, together with your profile, shortlists, applications, document statuses, tasks, and assigned counselor. For counselors it includes the names and email addresses of the students in their caseload, with application counts, intake status, tasks, recent uploads, and team workload figures.
  • Superadmin AI assistant — UnisPath superadministrators have an assistant that helps with platform management. Only organization-level and aggregate operational data is included in these prompts.
  • Public website chatbot — answers general questions about UnisPath. Do not enter personal information about yourself or anyone else into it.

Our AI providers never train on your data. Our contracts with them prohibit using anything you send through the Service to train or improve their own general-purpose models, and prompts are not retained by the provider for that purpose. This is unconditional and is not affected by anything in Section 8.

We log the type, timing, and token count of AI requests for monitoring, cost management, and abuse prevention. AI outputs are not guaranteed to be accurate or complete; verify university requirements, deadlines, and document acceptance directly with each university.

8. Developing our own models — opt-in only

We are not doing this today.

UnisPath does not currently use any student information to develop its own models, and no training data set exists. This section describes the conditions that would have to be met first. We are publishing them in advance so you can see the rules before anything changes, and so that nothing can start quietly. If we begin, we will tell you and ask you directly — it will never happen through an update to this policy.

We would like to develop our own AI and statistical models to make document review, university matching, and application guidance work better, and doing that well requires real examples. If we do, we will only use your information with your agreement.

Nothing would enter our training data unless all of these are true:

  • Your organization has opted in through a signed data processing agreement. This is never a default and never happens because we updated this policy.
  • You have separately said yes using a clearly labelled control in the Service, after being told what would be used and why. Where your local law requires a parent or guardian to agree as well, we require that too.
  • You were 16 or older when you agreed. We never use the data of anyone under 16 to develop models, on any basis, even with parental consent.
  • Your organization is eligible. Institutions for which we act as a school official under FERPA, and organizations covered by student privacy laws that prohibit this use, are excluded entirely.
  • The content passed our sensitivity filter. Documents flagged as containing special category information (Section 5) are excluded unless you gave explicit consent covering that information.

Saying no would cost you nothing. Consent here would be genuinely optional and entirely separate from your use of the Service. If you declined, or withdrew later, you would keep every feature, your documents would be reviewed exactly the same way, and neither UnisPath nor your counseling organization would treat your application differently. We would not ask again after you declined, other than through a setting you could change yourself at any time.

What we would do with it. Where you had opted in, we would use your uploaded documents, profile and application data, and counselor feedback on our automated review to train, fine-tune, and evaluate models that UnisPath owns and uses in the Service.

What we would never do. We would not sell the training data or make it available to any third party, we would not use it to build models for anyone other than UnisPath, and we would not deploy a model in a form that reproduces identifiable information from documents. We would test models for memorisation before releasing them.

Withdrawing. You would be able to withdraw at any time from your account settings or by emailing privacy@unispath.com. We would remove your records from the training data promptly and exclude them from every future training run. We want to be straightforward about one limit: a model that has already been trained cannot have an individual's contribution surgically removed, so withdrawal would apply going forward rather than retroactively to models already built.

Safeguards. The training data would be held separately from the live Service, access restricted to named personnel and logged, and every record would carry a record of the organization opt-in and the individual consent that permitted it. Because this processing would involve people under 18, we would carry out and keep under review a data protection impact assessment addressing the best interests of the child, in line with the UK Age Appropriate Design Code and equivalent guidance, before starting.

9. Automated decision-making and human review

UnisPath does not make decisions producing legal or similarly significant effects about any student by automated means alone. The document validation status is a flag surfaced to your counseling organization for a person to review; it does not by itself reject a document, block an application, or affect any admission decision. Every consequential decision is taken by a human at your organization.

You may ask for human review of any automated flag, express your point of view, and contest the result — through your counseling organization, or by writing to privacy@unispath.com. We monitor validation outputs for accuracy and unintended bias, and we do not use AI to score, rank, or profile students.

10. Subprocessors

We use the third-party providers below. Each is bound by a written contract limiting its use of the data to providing its service to us.

ProviderWhat it doesData involved
Google Cloud PlatformHosting (Cloud Run), database (Cloud SQL for PostgreSQL, private IP), document storage (Cloud Storage, private bucket with signed URLs), and operational loggingAll Customer Data and server logs
Google Vertex AI (Gemini)AI document validation, coaching, and assistants, processed inside UnisPath's Google Cloud projectDocument content, chat messages, account context
Firebase Authentication (Google Identity Platform)Authentication, password management, session tokens, and password reset emails. Password hashes are held entirely by Firebase; UnisPath never has plaintext passwords. Where you sign in with Google or Microsoft, Firebase brokers the sign-in and Google or Microsoft (Microsoft Entra ID) confirms your identity under its own terms.Email address, name, authentication metadata
ResendTransactional and operational email — invitations, status updates, webinar notifications, and announcementsEmail address, name, notification content
Google Meet (Google Workspace)Hosting webinars, including recording and Google's built-in AI meeting summaries where enabledName, email, audio/video where you participate

We will give organizations at least 30 days' notice before adding or replacing a subprocessor that processes Customer Data. To receive those notices, email privacy@unispath.com. An organization may object on reasonable data protection grounds, as described in the Terms.

11. How we share data

  • Within your organization.A student's applications, documents, and messages are visible to members of the organization that onboarded them. Each student is assigned a primary counselor by an automatic least-loaded algorithm, but other members of the same organization may access the records as part of normal team operations.
  • Between organizations: never.We do not share student data with any other counseling organization, no organization can see another's students, documents, or messages, and we do not maintain any combined data set drawn from more than one organization. Were the model development described in Section 8 ever to begin, the resulting training data would be the sole exception — it would contain only records that both the organization and the individual had opted in, would never be visible to any customer, and would never be disclosed to anyone outside UnisPath.
  • Service providers. The subprocessors listed in Section 10, strictly for the purposes described.
  • Legal and safety. Where required by law or valid legal process, or to protect the rights, property, or safety of UnisPath, our users, or others. Where we are legally permitted to do so, we will notify the affected organization before disclosing.
  • Corporate transactions. In connection with a merger, acquisition, financing, or sale of assets, subject to the recipient being bound by protections at least as protective as this policy. We will notify affected organizations before their data is transferred.

We do not sell or share personal information, and we do not use it for advertising. We have not sold or shared personal information — including the personal information of anyone we know to be under 16 — in the preceding 12 months, as those terms are defined by the California Consumer Privacy Act and comparable laws. We do not run third-party advertising or social-tracking technologies in the Service, and there is therefore no opt-out for you to exercise. We honour Global Privacy Control and similar browser signals.

12. Children and minors

Many of our users are between 16 and 18 and applying to universities. The Service is intended for students aged 16 and over, or aged 13 to 15 where their counseling organization has obtained verifiable parental or guardian consent and local law permits. We do not knowingly collect personal information from anyone under 13.

Counseling organizations are contractually responsible for obtaining and retaining evidence of every parental, guardian, or school consent required by local law — including the consent required under Article 8 of the EU and UK GDPR, which sets the digital consent age between 13 and 16 depending on the country — before submitting any data about a minor to the Service.

If you believe a child's information has been provided to us without proper consent, contact privacy@unispath.com and we will delete it promptly.

13. Student records and education privacy laws

Our customers are principally independent counseling organizations and agencies rather than schools. Where UnisPath is engaged by an educational institution and processes education records on its behalf, we act solely as a school official with a legitimate educational interest, under the institution's direct control, in accordance with 34 CFR § 99.31(a)(1)(i)(B) of the US Family Educational Rights and Privacy Act (FERPA). In that role we will:

  • use education records only for the purposes the institution authorises;
  • not redisclose them to any third party without the institution's authorisation or as permitted by FERPA;
  • not use them to create a student profile for any purpose other than delivering the Service; and
  • return or destroy them at the institution's direction on termination.

Depending on your jurisdiction, our processing may also engage US state student privacy laws (such as California's SOPIPA), the EU and UK GDPR, the UK Data Protection Act 2018, the DIFC Data Protection Law No. 5 of 2020, UAE Federal Decree-Law No. 45 of 2021, or equivalent regimes. Consistent with those laws, we do not sell student data, do not use it for targeted advertising, and do not build advertising profiles.

14. Webinars and recordings

Webinars run on Google Meet. Where a session will be recorded, we tell you at registration and again at the start of the session. You may attend with your camera and microphone off, or leave, and your participation is entirely voluntary. Google Meet's built-in AI features may generate summaries or notes; these are processed by Google under its own terms.

Recordings and summaries may be shared with registered attendees. We retain them for 12 months unless you ask us to remove your contribution sooner, which you can do at privacy@unispath.com.

15. Data retention

DataRetention period
Account, profile, application, document, and message dataFor as long as the student or organization account is active. On deletion, the account is immediately deactivated and hidden from all rosters, then held in a recoverable state for 60 days before permanent erasure.
BackupsAutomated daily database backups with point-in-time recovery, retained on a rolling 7-day cycle. Deleted data persists in backups until the cycle completes, after which it is purged.
Server and security logs12 months, then deleted or aggregated.
AI usage metadata (feature, timing, token counts)24 months for cost and abuse monitoring. No prompt or response content is retained.
AI chat transcriptsNot stored on our servers.
Contact form submissions24 months from your last correspondence with us.
Webinar recordings, summaries, and attendance12 months from the session date.
Billing and tax recordsAs required by applicable law, typically 5 to 7 years.
Model training data (Section 8)None held — we do not currently develop our own models. Were we to begin, opted-in records would be retained for as long as we maintained the models trained on them, reviewed every 24 months, and removed promptly on withdrawal.
Consent records for model developmentNone held today. Any future consent record would be retained for the life of the training data plus 6 years, as evidence that consent was validly obtained.
Aggregated, de-identified analytics that cannot be linked to any individualRetained without a fixed period for product improvement.

During the 60-day recovery window, an organization admin or UnisPath can restore an account with its data intact. An organization or student may request immediate permanent deletion instead — see Section 16. We may retain information longer where we are legally required to, or where it is necessary to establish, exercise, or defend legal claims; in that case we isolate it and stop using it for any other purpose.

16. Your rights

Depending on where you live, you may have the right to: access a copy of your personal information; correct inaccurate information; delete it; obtain it in a portable format; restrict or object to certain processing, including processing based on legitimate interests; withdraw consent at any time; limit the use of sensitive personal information; not be discriminated against for exercising a right; and not be subject to a solely automated decision with legal or similarly significant effects (see Section 9).

Model development consent. We do not currently ask for this consent, because we do not develop our own models. If we ever do, you will be able to change your decision at any time from your account settings — a single toggle, as easy to turn off as on — withdrawal will take effect immediately for all future use, and nothing else about your account will change. See Section 8.

Students.You may delete your own account directly from the platform. This immediately disables sign-in, hides the account, and starts the 60-day period described in Section 15, after which the data is permanently erased. Because your record may also be your counseling organization's business record, we will notify your organization of the deletion, and they may need to retain limited information where they have an independent legal obligation to do so. You may also ask your organization for assistance, including immediate permanent deletion.

Everyone else. Contact privacy@unispath.com or use our contact page. We will verify your identity through your registered email address before acting, and we respond within 30 days (extendable by a further 30 or 45 days for complex requests, where the law permits and with notice to you). Exercising a right is free unless a request is manifestly unfounded or excessive. You may use an authorised agent where the law allows; we will ask for proof of their authority.

Complaints.If you are unhappy with our response, you have the right to lodge a complaint with your data protection supervisory authority — in the EU, the authority in your country of residence or workplace; in the UK, the Information Commissioner's Office (ico.org.uk); in the DIFC, the DIFC Commissioner of Data Protection; and in the UAE, the UAE Data Office. We would appreciate the chance to address your concern first.

17. International transfers

UnisPath is established in the United Arab Emirates. The Service runs on Google Cloud Platform in a single region in the United States: your account data, your uploaded documents, and our database backups are all stored there. There is no per-account or per-country choice of region. Our personnel and providers access that data from the United Arab Emirates.

AI processing is carried out by Google Vertex AI. Depending on the model, inference may run on Google's global endpoint, which means the content of a request may be processed in Google infrastructure outside the United States. Nothing is retained by the provider for its own purposes.

For transfers of personal data out of the European Economic Area, the United Kingdom, Switzerland, or the DIFC, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, the Swiss addendum, and the equivalent mechanisms under DIFC Data Protection Law, together with supplementary technical measures including encryption in transit and at rest and access controls. You can request a copy of the relevant transfer mechanism, with commercial terms redacted, from privacy@unispath.com.

18. Security

  • Encryption in transit (TLS 1.2 or higher) for all client traffic.
  • Encryption at rest for the database (Cloud SQL), document storage (Cloud Storage), and secrets (Secret Manager).
  • The database is reachable only over a private IP from inside our Google Cloud VPC.
  • Documents are served via time-limited V4 signed URLs; the storage bucket is not publicly accessible.
  • Authentication is delegated to Firebase Authentication (Google Identity Platform), with a required password change on first invited sign-in.
  • Role-based access control and organization-scoped queries enforced server-side on every authenticated request.
  • Automated daily database backups with point-in-time recovery, and object versioning on document storage.
  • Administrative and infrastructure access is logged via Google Cloud Audit Logs.

Read more on our security page. No security programme is perfect, and no method of transmission or storage is completely secure.

19. If something goes wrong

If we confirm a personal data breach, we will notify the affected counseling organization, as controller, without undue delay and in any event within 48 hours of confirming it, with the information the organization needs to meet its own notification duties. Where we act as controller, we will notify the competent supervisory authority within 72 hours where required, and will notify affected individuals directly without undue delay where the breach is likely to result in a high risk to their rights and freedoms, or where any applicable law requires individual notice. We will follow up with a written post-incident summary.

To report a suspected vulnerability or incident, contact security@unispath.com. We aim to acknowledge reports within 48 hours.

20. Cookies and similar technologies

We use only cookies that are strictly necessary to operate the Service. We do not run advertising, analytics, social-tracking, or session-recording technologies, and we therefore do not display a consent banner — strictly necessary cookies do not require consent.

CookiePurposeDuration
Session cookieKeeps you signed in after authentication. HttpOnly, Secure, SameSite.Expires on sign-out or when the session expires
Functional preferencesRemembers basic interface state, such as a collapsed sidebarUp to 12 months

Blocking the session cookie will prevent you from signing in. If we ever introduce analytics or any non-essential technology, we will update this section and ask for your consent first.

21. Communications

We send transactional and operational messages — invitations, application status updates, document review alerts, direct-message notifications, webinar invitations, and service announcements — which are necessary to provide the Service and cannot be turned off while your account is active, though you can adjust notification preferences where the Service offers them. Any purely promotional email will include an unsubscribe link and will be sent only where we have a lawful basis to do so.

22. Changes

We may update this policy. We will update the "last updated" date above and, for material changes, notify organizations and account holders through the Service or by email at least 30 days before they take effect. We will never apply a materially different use of previously collected personal information without a lawful basis and, where required, your consent. Previous versions are available on request from privacy@unispath.com.

23. Contact

Questions about this policy, or requests to exercise your rights, can be sent to privacy@unispath.com, or through our contact page. Our postal address is [UnisPath registered legal name], [registered address, Dubai, United Arab Emirates]. Our Terms of Service are available here.