UNIPIA
Features Universities
Download
On This Page
1. Data Controller 2. Personal Data We Collect 3. Legal Bases 4. How We Use Your Data 5. Disclosure 6. International Transfers 7. Data Retention 8. Your Rights (UK GDPR) 9. Cookies 10. Children's Privacy 11. Security 12. Third-Party Links 13. Changes 14. Contact Us
← Back to UNIPIA
Legal

Privacy Policy

Effective: 9 September 2026
ICO Registration: ZC131686

This Privacy Policy explains how UNIPIA Ltd ("UNIPIA", "we", "us", "our") collects, uses, discloses, and protects your personal data when you use the UNIPIA application — a study planner, timetable, anonymous department community and record for UK university students — and related services (the "Service").

We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).

ICO Registration Number: ZC131686
We are registered with the UK Information Commissioner's Office as a data controller.

1. Data Controller

UNIPIA Ltd is the data controller responsible for your personal data.
Contact: info@unipia.business

2. Personal Data We Collect

We collect the following categories of personal data:

2.1 Account Information

Name, email address (including your university email used for verification), date of birth (to confirm you are 18 or over), profile photo (optional), university and department. We verify your university by sending a code to your university email address; we do not store the code after verification.

2.2 Study Data

The modules you add, your class times and rooms, deadlines and assignments you record, their status (to do, in progress, done, completed on time or late), and any links or notes you attach to them. This data builds your personal Record, which only you can see unless you choose to export or share it.

You can export your Record at any time. An export contains only your own study data: the modules you added, each deadline with its date, status and whether it was completed on time, and any links or notes you attached. Exports are produced at your request and are yours to share or keep.

2.3 Community and Chat Data

Posts, replies, votes and event sign-ups in the community, and messages you send in your department chat or focus room. Community posts show your university name, not your personal name. Department chat and focus-room messages are shown without your name and are deleted automatically at midnight (UK time) on the day they are sent; notices that classmates confirm may be kept pinned until they expire.

Anonymous to other students, accountable to us. Anonymity applies to what other users see. Behind the scenes, every post, reply and chat message stays linked to the verified account that sent it. We use that link only to investigate reports, enforce our Terms and Community Guidelines, and respond to lawful requests. If a message is reported, we keep that message and its link to your account long enough to review the report and to deal with any appeal — no longer than 30 days, which covers the 24-hour review and the 14-day appeal window set out in our Community Guidelines. Messages that are not reported are deleted on the normal schedule, and the link to your account goes with them.

2.4 Presence Data ("Live")

If you choose to set a status (in class, library, focusing, free), we store that status and show it to your department only as an aggregated count. We do not show who set which status, and we hide counts for departments with fewer than 10 active members. Your status is cleared automatically each day. We do not use your device location.

2.5 Usage Data

Device identifiers (IDFA, AAID), IP address, app version, operating system, time zone, language, in-app activity, crash reports, and analytics data.

2.6 Communication Data

Push notification tokens (Firebase Cloud Messaging), email correspondence with our support team.

2.7 Payment Data

In-app purchase records (we do not collect or store payment card details — these are handled by Google Play and Apple App Store).

3. Legal Bases for Processing

We process your personal data on the following legal bases:

  • Contract — to provide the Service you have requested;
  • Legitimate Interest — to operate, secure, improve, and personalise the Service, prevent fraud, and enforce our Terms. In practice this covers: keeping the Service running and backed up; investigating reports and removing content that breaches our Guidelines; blocking spam, bots and duplicate accounts; measuring which features are used so we can improve them; and defending legal claims. We balance these against your rights and you can object at any time (see section 8);
  • Consent — for optional features such as push notifications, sharing your Live status, and marketing communications (you may withdraw consent at any time);
  • Legal Obligation — to comply with applicable laws and regulations.

4. How We Use Your Personal Data

  • To create and manage your account and verify your university affiliation.
  • To provide, maintain, and improve the Service.
  • To provide your timetable, deadlines and Record, and to let you share a deadline with a classmate by link when you choose to.
  • To enable community features (posting, replies, department chat, focus rooms, and aggregated Live status).
  • To send push notifications, transactional emails, and service announcements.
  • To detect, prevent, and respond to fraud, abuse, and security incidents.
  • To enforce our Terms of Service and Community Guidelines.
  • To comply with legal obligations and respond to lawful requests from authorities.
  • To deliver advertisements (we use Google AdMob; you can opt out of personalised ads in your device settings).

5. Disclosure of Personal Data

We do NOT sell your personal data. We may share your data with:

5.1 Service Providers

Cloud hosting (AWS), authentication (Firebase Auth), analytics (Google Analytics, Firebase), advertising (AdMob), push notifications (FCM), payment processing (Google Play, Apple).

5.2 Legal Authorities

When required by law, court order, or to protect our rights, property, or safety.

5.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity.

5.4 Your Record

We do not share your Record, your modules, your deadlines or any export of them with employers, universities, recruiters, advertisers or any other third party. If we ever offer a feature that sends your Record to someone else, it will be entirely optional and will ask for your explicit consent first, naming who receives it and what it contains. You will be able to withdraw that consent at any time.

5.5 Other Users

Community posts and replies are visible to other verified users with your university name (not your personal name). Department chat and focus-room messages are visible to members of the same department without your name. Your study data and Record are private to you unless you share a deadline by link or export your Record.

6. International Data Transfers

Some of our service providers are based outside the United Kingdom. When transferring data internationally, we use appropriate safeguards such as Standard Contractual Clauses and adequacy decisions to ensure your data remains protected.

7. Data Retention

7.1 Account data is retained for as long as your account is active.

7.2 If you delete your account, your personal data will be deleted within 30 days, except where retention is required by law (e.g. financial records up to 7 years). Where we keep aggregate figures — for example how many people were active in a department — we strip out every identifier first, so the remaining data cannot be linked back to you by us or by anyone else, and cannot be reversed.

7.3 We keep automated database backups for 7 days on a rolling basis, so a copy of your data may remain in a backup for up to 7 days after you delete it. Backups are encrypted and are only ever used to restore the Service after a failure.

7.4 Department chat and focus-room messages are deleted at midnight (UK time) on the day they are sent. Live status is cleared daily.

7.5 If we update these terms or this policy in a way that requires your renewed agreement and you do not agree within 30 days of being asked, your account will be paused and then deleted in line with section 7.2.

8. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

  • Right of Access — request a copy of your data;
  • Right to Rectification — correct inaccurate data;
  • Right to Erasure — request deletion of your data;
  • Right to Restriction — limit how we process your data;
  • Right to Data Portability — receive your data in a structured, machine-readable format;
  • Right to Object — object to processing based on legitimate interest or for marketing;
  • Right to Withdraw Consent — for any consent-based processing;
  • Right to Lodge a Complaint — with the Information Commissioner's Office (ICO) at https://ico.org.uk/.

To exercise your rights, contact info@unipia.business. We will respond within one calendar month.

9. Cookies and Similar Technologies

The Service uses minimal device-level identifiers required for core functionality. We do not use browser cookies in the mobile app. Web-based admin interfaces may use functional cookies only.

10. Children's Privacy

The Service is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If we discover such data, we will delete it promptly.

11. Security

We implement appropriate technical and organisational measures including encryption in transit (TLS), access controls, role-based permissions, and regular security audits. However, no system is completely secure; you use the Service at your own risk.

If a personal data breach occurs, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it where the law requires, and we will tell affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms. Our notice will describe what happened, what data was involved, what we are doing about it, and what you can do.

12. Third-Party Links and Services

The Service may contain links to third-party websites or integrate with third-party services. This Privacy Policy does not apply to those third parties; please review their respective privacy policies.

13. Changes to This Policy

We may update this Privacy Policy from time to time. The updated version will be posted within the app with a new "Effective Date". Material changes will be notified via in-app notification or email.

14. Contact Us

If you have questions or concerns about this Privacy Policy or your personal data:

UNIPIA Ltd
ICO Registration: ZC131686
Email: info@unipia.business
Web: https://unipia.co.uk

To make a complaint to the supervisory authority:

Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Tel: 0303 123 1113
Web: https://ico.org.uk

UNIPIA

Deadlines, sorted by module.
Built for UK university students.

Product
Features Universities Download
Company
Contact Delete your data
Legal
Privacy Policy Terms of Service Community Guidelines
© 2026 UNIPIA Ltd. All rights reserved. Made for UK students