1. Who we are
UNITIX Soft is operated by Unitix Agency LLC and provides a customer relationship management and scheduling service (the “Service”). This policy explains how we process personal information when you use our CRM, public booking pages, and integrations. Questions may be sent to support@unitixsoft.pro.
2. Information we collect
We collect account information such as name, business email, role, company details, profile photo, authentication records, and preferences. CRM users may add lead and customer details, tasks, notes, booking information, messages, and files. Public booking visitors may provide their name, email, phone number, timezone, meeting answers, and preferred time.
We also collect limited technical data, including IP address, browser and device information, timestamps, security logs, cookie identifiers, and usage events needed to operate, protect, and improve the Service.
3. Zoom and Google integrations
When a user connects Zoom, UNITIX Soft CRM receives encrypted OAuth tokens, the authorized Zoom user ID and account ID, email, granted scopes, token expiry, and information necessary to create, update, or delete that user's meetings. Meeting records may include topic, start time, duration, timezone, participant join URL, meeting ID, and status. We do not store Zoom host start_url values or ZAK tokens and do not access meeting audio, video, chat, or recordings.
When a user connects Google Calendar or Google Meet, we access the connected account email, Free/Busy availability, and events owned by that user only as needed to create, read, update, or delete CRM-linked events, manage recurrence and attendee invitations, and create Google Meet conference details. We store the connected email, calendar identifier, granted scopes, encrypted OAuth tokens, token expiry, Google event identifiers and links, Meet links, and synchronization status.
Google OAuth permissions
https://www.googleapis.com/auth/calendar.events.owned— create, read, update, and delete Google Calendar events owned by the authorizing user, including CRM-linked recurrence, attendee invitations, and Google Meet conference details.https://www.googleapis.com/auth/calendar.freebusy— retrieve busy time ranges needed to determine booking availability without disclosing unrelated event titles, descriptions, participants, or Google event metadata.https://www.googleapis.com/auth/userinfo.email— identify and display the connected Google account and associate the authorization with the correct UNITIX Soft CRM user.
We do not request Gmail, Drive, Contacts, People, or full Calendar access. Each Google connection belongs exclusively to the CRM user who authorized it. Server-side ownership checks prevent administrators and other CRM users from implicitly accessing or operating Google Calendar through another user's OAuth credentials.
Zoom and Google OAuth access and refresh tokens are encrypted at rest and securely stored. They are never sent to the browser. Access is restricted to authorized server processes and personnel with a legitimate operational need. Tokens are transmitted only over encrypted HTTPS connections.
4. Google API Services User Data Policy and Limited Use
UNITIX Soft CRM's use and transfer to any other application of information received from Google APIs will comply with the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is used only to provide or improve user-facing Google Calendar, Google Meet, scheduling, and availability features that are visible in UNITIX Soft CRM. Google user data is not sold, transferred to data brokers or advertising platforms, used for advertising, retargeting, personalized or interest-based advertising, creditworthiness, or lending decisions, or used to train generalized AI or machine-learning models.
UNITIX Soft CRM does not allow humans to read Google user data unless the user has given affirmative consent for specific support access, access is necessary to investigate abuse or a security incident, access is required by applicable law, or the data has been aggregated and anonymized for permitted internal operations.
5. How we use information
- Provide CRM, scheduling, notifications, support, and account administration.
- Synchronize availability and automatically create or manage Zoom and Google meetings.
- Authenticate users, prevent abuse, investigate incidents, and maintain audit records.
- Improve reliability and understand aggregate product usage.
- Comply with law and enforce our Terms of Service.
Where applicable, our legal bases include performance of a contract, legitimate interests in operating and securing the Service, consent for optional integrations or cookies, and compliance with legal obligations.
6. Cookies and analytics
We use essential cookies for sessions, authentication, security, and preferences. We may use privacy-conscious analytics to measure product performance. Optional analytics cookies, where used, are subject to consent requirements. You can control cookies through your browser, although blocking essential cookies may prevent the Service from working.
7. Sharing and third-party services
We share information only as needed with infrastructure, hosting, email, security, and support providers acting on our instructions, and with integrations you choose to connect. Relevant third parties may include Zoom Video Communications, Inc. and Google LLC. Their processing is governed by their own privacy terms. We may also disclose information when required by law, to protect rights or safety, or in connection with a corporate transaction. We do not sell personal information or Google user data.
8. Retention and deletion
Google OAuth credentials are retained only while the Google integration remains connected. When a user selects Disconnect, UNITIX Soft CRM first sends a revocation request to Google. After successful revocation, or when Google confirms that the grant is already expired or revoked, UNITIX Soft CRM immediately removes the local encrypted access token, refresh token, expiry, and granted scopes. If Google is temporarily unavailable and revocation cannot be confirmed, the encrypted credentials are retained so the user can safely retry Disconnect; they are not silently deleted before revocation.
Zoom Disconnect follows the same safe order: UNITIX Soft CRM first asks Zoom to revoke the authorization and removes the matching local encrypted connection only after success or an already-revoked response. A temporary Zoom or network failure preserves the connection for retry. A verified Zoom Marketplace deauthorization notification removes only the matching user's local Zoom authorization.
Google event identifiers, Meet links, Zoom meeting identifiers, participant join URLs, and synchronization status associated with CRM records remain until the corresponding CRM record or account is deleted, unless longer retention is required for contractual, security, tax, legal, or dispute purposes. Disconnect alone does not delete existing provider events or meetings.
Web access logs are rotated daily with 14 archived rotations. Database backups are retained for no more than 14 days, and full and release recovery backups are retained for no more than 30 days. Backup copies are access-restricted, are not used for ordinary processing, and expire when the applicable backup is removed.
To request account or personal data deletion, email support@unitixsoft.pro with the subject “Data deletion request.” We may verify your identity and authority before completing the request. See Google Data Deletion and Zoom Integration.
9. Security
We use administrative, technical, and organizational safeguards including HTTPS in transit, encryption of OAuth tokens at rest, access controls, session protection, least-privilege permissions, audit logging, backups, and security monitoring. No system is completely secure; users must also protect their credentials and promptly report suspected misuse.
10. Your rights
Depending on your location, you may request access, correction, deletion, restriction, portability, or objection to certain processing, and may withdraw consent without affecting earlier lawful processing. You may also complain to your local data protection authority.
GDPR and UK GDPR
Residents of the EEA, Switzerland, and United Kingdom may exercise the rights listed above and ask about applicable legal bases, international transfers, and safeguards.
California privacy rights (CCPA/CPRA)
California residents may request to know, correct, or delete covered personal information and receive a portable copy. UNITIX Soft does not sell or share personal information for cross-context behavioral advertising and will not discriminate against you for exercising privacy rights. An authorized agent may submit a verified request on your behalf.
11. International transfers and children
Information may be processed in countries other than yours. Where required, we use appropriate contractual or legal safeguards. The Service is intended for business users and is not directed to children under 16.
12. Changes and contact
We may update this policy and will post the revised date on this page. For privacy questions or rights requests, contact support@unitixsoft.pro or hello@unitixsoft.pro.
