1. Controller
No company has yet been incorporated under the UniXpanse name. Pending incorporation, the controller for personal-data processing carried out for the public Site (including contact and intake forms) is the natural person operating the Site, reachable at:
- Name used: UniXpanse
- Legal status: unincorporated project (no company yet registered)
- Email: legal@unixpanse.com
Data Protection Officer: Not appointed. UniXpanse has not designated a DPO. Data-protection requests should be sent to legal@unixpanse.com.
Pending incorporation, the natural person operating the Site determines the applicable role for each processing activity. Following incorporation, the entity operating under the UniXpanse name may act as:
- data controller;
- processor acting on documented instructions from a professional customer;
- or another role determined under applicable data-protection law.
2. Data covered
Depending on how the Service is used, UniXpanse may process:
- name;
- professional email;
- company;
- role;
- account information;
- authentication and security information;
- IP address;
- browser/device information;
- timestamps;
- contact-form information;
- professional requirements;
- uploaded files;
- egocentric video recordings;
- transcripts;
- metadata;
- annotations;
- licence and rights information;
- delivery information;
- payment and accounting information;
- technical logs;
- public display name;
- account reputation and contribution scores;
- hashed anti-fraud signals (IP address, user-agent, and similar technical identifiers);
- network-risk attributes derived from the connecting IP (estimated country/region, ASN/organisation, VPN/proxy/Tor/datacenter/hosting flags, and a risk score);
- hashed network-risk decisions;
- referral codes and first-touch referral relationships.
Egocentric video recordings may contain personal data relating to identifiable individuals.
3. Purposes and legal bases
| Processing | Purpose | Legal basis |
|---|
| Contact requests | Respond to requests | Pre-contractual steps / legitimate interest |
| Professional enquiries | Evaluate business requests | Pre-contractual steps / legitimate interest |
| Account management | Create and operate accounts | Contract |
| Authentication/security | Secure accounts and prevent abuse | Legitimate interest / legal obligation where applicable |
| Egocentric video collection | Ingest, qualify, and package recorded video against a written brief | Contract |
| Dataset licensing | Perform contractual licensing services for AI laboratories | Contract |
| Billing/accounting | Billing and accounting obligations | Legal obligation / contract |
| Referral program | Attribute first-touch contributor referrals and calculate commissions set by UniXpanse | Contract / legitimate interest |
| Fraud/security | Protect the Service | Legitimate interest |
| Anti-fraud signals | Detect clustered multi-account behaviour from hashed technical identifiers. A shared IP is not treated as identity on its own. | Legitimate interest |
| Network risk / anti-abuse | Use network-classification signals (for example VPN, proxy, Tor, datacenter or hosting flags, ASN, coarse location and a risk score) to decide whether a sensitive action may proceed, be monitored, or require extra verification. A VPN is not a permanent ban. A risk score is a security signal, not an automated finding that a person is fraudulent. | Legitimate interest |
| Account reputation | Compute an internal score from qualification, rejection and duplicate rates with volume weighting. The score may map to an account tier that affects upload quotas and rate limits. It does not by itself determine payout of accepted hours. It is not a public ranking and is not treated as an automated finding of fraud. | Legitimate interest / contract |
| Public ranking | Where enabled, publish opted-in display names and contribution scores for contributors. Email and other account identifiers stay private. | Legitimate interest / consent via ranking setting |
| Legal claims | Establish, exercise or defend legal claims | Legitimate interest / legal obligation |
| Optional analytics | Measure audience/performance | Consent where required |
| Technical cookies | Provide requested functionality | Article 82 exemption where applicable |
UniXpanse does not use customer or contact-form data to train public AI models unless this is expressly agreed under a separate lawful arrangement.
4. Intake forms
The public Site is intended for AI companies and laboratories. It may provide forms for:
- AI companies and laboratories;
- companies contributing egocentric footage;
- general contact.
Contributor accounts are created by UniXpanse and operated as authenticated platform relationships, not as a public recruitment offering.
Providing information marked as necessary may be required to respond to the request.
Optional fields are not required unless indicated.
Each public form includes a short privacy notice. Required fields are marked with an asterisk (*).
When an intake form is submitted, the server receives the submitter's IP address from the hosting infrastructure. UniXpanse records this address with the intake submission for security, abuse prevention and follow-up, and may include it in the internal email notification or optional webhook configured for that form. It is not used for advertising or audience profiling. Hosting and infrastructure logs may separately process IP addresses under the applicable provider's retention rules.
5. Uploaded content and third-party personal data
A user must not submit egocentric video or other content containing personal data or third-party material unless the user has an appropriate legal basis and the rights necessary for the intended processing and licensing.
Egocentric video may capture people, workplaces, and confidential information. The submitting party must ensure that the intended processing and licensing are lawful.
UniXpanse may process such data for the purposes expressly agreed in the applicable service or licensing arrangement.
Where UniXpanse acts as a processor, processing is performed only under documented instructions and the applicable Data Processing Agreement.
Those contractual warranties from a submitting party do not replace UniXpanse’s own assessment of its role (controller, processor, or otherwise) for each actual processing activity.
6. AI processing
UniXpanse may use AI and automated processing to assist with:
- duration and task metadata extraction;
- metadata generation;
- quality analysis;
- duplicate detection;
- classification;
- enrichment.
AI-generated outputs are treated as potentially inaccurate and are subject to validation appropriate to their use.
AI output does not by itself determine:
- ownership;
- legal rights;
- licence entitlement;
- payout entitlement;
- access permissions.
AI-assisted processing runs only when the relevant provider is configured. Depending on configuration, UniXpanse may send audio (for transcription) or derived text/metadata (for classification or enrichment) to Groq and/or OpenAI. UniXpanse does not send full dataset catalogues to those providers as a matter of course.
Retention at the provider is governed by that provider’s terms and UniXpanse’s configuration. UniXpanse does not use those providers to train UniXpanse’s own public models, and does not authorise provider training on UniXpanse inputs where the applicable provider contract allows UniXpanse to opt out. Processing may take place outside the EEA; see International transfers.
7. Recipients
Depending on the processing actually enabled, data may be processed by:
- authorised UniXpanse personnel;
- hosting providers;
- database providers;
- object-storage providers;
- email providers;
- payment providers;
- transcription/AI providers;
- security or malware-scanning providers;
- IP intelligence / anti-abuse providers, when that processing is enabled;
- infrastructure providers.
The current providers actually activated by UniXpanse should be listed in an up-to-date internal subprocessor register and, where required, communicated to customers.
8. Subprocessors
Where UniXpanse acts as a processor, subprocessors are used only within the framework required by Article 28 GDPR.
The applicable DPA governs:
- authorised subprocessors;
- notification of changes;
- confidentiality;
- security;
- assistance;
- deletion/return;
- audits.
A public Privacy Policy does not replace the Article 28 DPA where one is required.
9. International transfers
Some service providers may process data outside the European Economic Area.
Where such a transfer occurs, UniXpanse uses a transfer mechanism permitted under Chapter V GDPR, such as:
- an adequacy decision where applicable;
- Standard Contractual Clauses;
- another lawful transfer mechanism.
The applicable mechanism depends on the provider, destination and configuration actually used.
UniXpanse does not claim that a provider is covered by a particular certification unless that status has been verified.
10. Retention
Personal data is retained only for as long as necessary for the purpose for which it was collected, subject to legal obligations and the establishment, exercise or defence of legal claims.
Indicative retention rules are:
Contact and professional enquiries
Up to 24 months after the last meaningful interaction, unless a contractual relationship or legal claim requires longer retention.
Accounts
For the duration of the account relationship, followed by deletion or restricted archival where necessary.
Contract and licence records
For the period required to manage the contractual relationship and for applicable legal/accounting requirements.
Accounting records
For the legally required retention period.
Security and technical logs
Application audit and technical logs are retained for security, debugging and accountability, then reviewed at least annually and deleted or anonymised when they are no longer required for those purposes. Hosting-provider logs follow the host’s own retention policy.
Network risk and IP intelligence
The connecting IP is read from the hosting reverse proxy, not from a client-supplied header. UniXpanse may query a maintained IP-intelligence service with that address to classify the network (for example VPN, proxy, Tor, datacenter, hosting, or residential) and to obtain ASN and coarse location. Cache entries are keyed by a hashed IP, store classification flags without the raw address, and expire within 6 hours by default (never more than 24 hours). Decision logs keep a hashed IP, action category, score band, decision, country and ASN for 30 days, then are deleted. The `Accept-Language` header may be compared with estimated country as a coarse consistency signal and is not stored. Manual allow/block rules are kept until revoked. UniXpanse does not use invasive device fingerprinting for this control.
Egocentric video and licensed datasets
According to the applicable contract, licence, rights documentation and operational retention policy. Where a dataset is licensed, the Dataset Licence Agreement or equivalent contract must specify a retention period or a mechanism for determining it (including deletion or return at the end of the licence).
Personal data contained in licensed datasets
According to the applicable dataset agreement, DPA where applicable, legal requirements and the defined purpose of the processing.
Retention periods may differ where a legal obligation or litigation requires preservation. The CNIL requires organisations to determine retention according to the purpose and not retain personal data indefinitely.
11. Your rights
Subject to the conditions provided by applicable law, you may have the right to:
- access your personal data;
- correct inaccurate data;
- request erasure;
- request restriction;
- object to processing based on legitimate interests;
- request portability where applicable;
- withdraw consent where processing is based on consent;
- define directives concerning the fate of your data after death where applicable under French law.
Requests should be sent to:
legal@unixpanse.com
UniXpanse may request reasonable information necessary to verify the identity of the requester.
You may also write to the same address to contest a network-risk restriction or an account-tier restriction that significantly affects access to an authenticated account. Where such a restriction has a significant effect, UniXpanse will review it with human involvement.
12. Right to lodge a complaint
You may lodge a complaint with the Commission nationale de l'informatique et des libertés (CNIL) if you believe that your personal-data rights have not been respected.
CNIL: https://www.cnil.fr
13. Cookies and trackers
UniXpanse uses several categories of cookies and similar technologies.
Strictly necessary cookies
These may be used without prior consent when they are strictly necessary for a service expressly requested by the user or otherwise fall within an applicable exemption.
Examples may include:
- authentication/session cookies;
- security cookies;
- upload-session cookies;
- cookie-consent preference storage.
Referral cookie (`ux_ref`)
If a referral code is present in the URL (`ref=`), UniXpanse may set a first-party cookie `ux_ref` (90 days, SameSite=Lax, Secure on HTTPS) so that a later contributor account can be attributed to that code. It is not used for advertising and is not a cross-site tracker.
This cookie is not classified as strictly necessary for browsing the public Site. It is used for the contributor referral programme. It may be set before the visitor has an account. It is not treated as an Article 82 exemption merely because it relates to affiliation or attribution.
Analytics and performance measurement
UniXpanse may use Vercel Web Analytics and Vercel Speed Insights.
These tools will be treated as exempt from consent only if their actual configuration satisfies the conditions established by the CNIL.
Otherwise, they will be activated only after valid consent.
The CNIL requires exempt audience-measurement tools to remain strictly limited to the relevant audience/performance purposes, produce anonymous statistical data under the applicable conditions, avoid cross-site tracking and avoid reuse for other purposes.
Therefore, UniXpanse does not state categorically that these services are exempt from consent merely because they are analytics or performance tools.
Until an exemption is demonstrated for the configuration actually deployed, Vercel Analytics and Speed Insights are loaded only after the user chooses Accept on the cookie banner. Choosing Refuse prevents them from loading. If they were already loaded, Refuse unloads them and reloads the page.
14. Cookie choices
Where consent is required, users must be able to:
- accept;
- refuse;
- manage their choices.
Refusal must be as easy as acceptance.
Consent choices must be recorded so UniXpanse can demonstrate the user's choice where required.
On this Site, choices are stored in browser localStorage (key `unixpanse.audience`) and a first-party cookie `ux_audience` (values `accepted` or `refused`, 180 days, SameSite=Lax, Secure on HTTPS). Each Accept or Refuse is also recorded in UniXpanse's server-side event log (`cookie_consent_recorded`) so the choice can be demonstrated. You can reopen the banner via Manage cookies in the footer on public pages, or via Manage cookies on platform pages.
15. Security
UniXpanse implements technical and organisational measures appropriate to the risks associated with its processing activities. Depending on the functionality concerned, these measures may include:
- access controls;
- authentication controls;
- server-side authorisation;
- encryption and secure transport;
- isolated object storage;
- temporary signed URLs;
- job ownership controls;
- rate limiting;
- network-risk signals for sensitive actions;
- monitoring;
- logging.
No security measure guarantees absolute protection.
16. Data breaches
Where a personal-data breach occurs, UniXpanse will assess the incident and comply with the notification obligations applicable under the GDPR, including notification to the CNIL where legally required and communication to affected persons where required.
17. International users
The public Site is intended for AI companies and laboratories. Authenticated platform areas are intended for professional contributors, buyers, and operations.
Where users are located outside France or the EEA, additional local rules may apply depending on the circumstances.
18. Children
The Service is intended for professional use and is not directed at children.
Users must not submit children's personal data unless they have an appropriate legal basis and the processing is lawful.
19. Changes to this policy
This Privacy Policy may be updated to reflect:
- changes to the Service;
- changes to providers;
- changes to processing;
- changes in applicable law;
- security improvements.
The current version and update date are displayed on this page.
20. Voluntary contributions
Where UniXpanse accepts a voluntary financial contribution, it processes the name, email, company details, and optional branding submitted in order to confirm payment, keep internal records, operate any public recognition the contributor consented to, and prevent abuse. A contribution does not confer equity or any investment interest.
Legal bases typically include performance of the contribution request and UniXpanse's legitimate interest in recording the transaction. Card data is processed by Stripe, not stored by UniXpanse.
Last updated: 9 September 2026.