How we handle your data
Last updated 22 August 2026
1. Who this applies to
This policy covers everyone who uses Univo: the business (“tenant”) that signs up for a workspace, the admins and employees that tenant invites into it, and visitors to our marketing site. Each tenant is a separate customer with its own isolated workspace — see “Data isolation” below for what that means technically.
2. What we collect
When you sign up or use Univo, we collect:
- Account data — name, email, and password (stored as a salted hash, never in plain text) for anyone who logs in, plus Google account identifiers if you sign in with Google.
- Workspace data — whatever your organization enters into the product: employee records, attendance, payroll, salary and statutory details (e.g. PAN, bank account), leave and recruitment data, and any documents your admins upload.
- Usage data — request logs, IP address, browser/device information, and audit-log entries for sensitive actions (role changes, salary edits, permission grants).
- Branding data — logo, colors, and display preferences a tenant admin configures for their workspace.
3. How we use it
We use this data to:
- Provide and operate the product you’ve signed up for (authentication, payroll runs, attendance tracking, and every other module you use).
- Send account, security, and transactional email (e.g. password resets, generated login credentials).
- Maintain an audit trail of sensitive changes for your own workspace’s security review.
- Diagnose and fix bugs, and keep the service secure and available.
We do not sell your data, and we do not use workspace data (employee records, payroll, etc.) to train any models.
4. Data isolation
Each tenant’s workspace data lives in its own database schema, not a shared table with a tenant column — one tenant’s data is never queryable from another’s connection, by construction. Uploaded documents are stored per-tenant in a dedicated bucket.
5. Where data is stored
Application data is stored in a managed Postgres database. Uploaded files and documents are stored in Cloudflare R2. All traffic to Univo is encrypted in transit via TLS. Sub-processors we use to run the service include our hosting provider (Vercel), our database provider, and Cloudflare (object storage), plus an email provider for transactional email.
6. How long we keep it
We keep workspace data for as long as your workspace is active. If a workspace is closed, we retain data only as long as needed for legal, tax, or dispute-resolution purposes, then delete it. Signup drafts that are never completed are deleted automatically once the associated account is provisioned or abandoned.
7. Your rights
If you’re an employee whose data a tenant has entered into Univo, requests to access, correct, or delete your data should go to your employer (the tenant), since they control that data. If you’re a tenant admin, you can request an export or deletion of your workspace’s data by contacting us directly.
8. Cookies
The product uses a browser storage token to keep you signed in; it isn’t used for cross-site tracking or advertising. Our marketing site may use minimal analytics cookies to understand aggregate traffic.
9. Children’s privacy
Univo is a business product and isn’t directed at, or knowingly used by, children under 16.
10. Changes to this policy
If we make material changes to this policy, we’ll update the date at the top of this page and, where required, notify tenant admins directly.
11. Contact
Questions about this policy or a data request? Reach us via the contact page.