Skip to content

Legal

Privacy Policy

Effective date

1. Purpose and scope

This Privacy Policy explains how MBI processes personal data when people visit mbi.unigrate.com, create or use an MBI account, communicate with MBI, or use the Service.

MBI is a business intelligence service operated under the Unigrate brand.

The legal entity responsible for the Service and its contact details are identified in the MBI website footer, checkout, account area, and customer invoices.

This Policy applies to personal data for which MBI determines the purposes and means of processing.

When a business Customer uses MBI to process personal data in Customer Content, MBI generally acts as a processor on behalf of that Customer. That processing is governed by the Data Processing Agreement, and the Customer is responsible for the relevant controller obligations.

2. Personal data we process

Depending on how the Service is used, MBI may process the following categories.

Account and contact data

  • name;
  • business email address;
  • organization;
  • role or job title;
  • account settings;
  • authentication and account identifiers; and
  • communications with MBI.

Subscription and billing data

  • subscription and plan information;
  • billing contact information;
  • transaction status;
  • invoice information; and
  • limited payment metadata received from payment providers.

MBI does not need to store full payment-card details where payment is handled by an external payment provider.

Customer Content

Customer Content may contain:

  • prompts and instructions;
  • monitored companies, people, topics, keywords, products, and markets;
  • source URLs and source selections;
  • uploaded or integrated information;
  • notes and configuration;
  • generated reports and summaries; and
  • personal data contained in information Customer asks MBI to monitor or analyze.

Where Customer Content is processed on behalf of a Customer, the Customer determines the purpose of that processing.

Public-source information

The Service may retrieve business information from publicly available sources. This can include personal data that appears in business-related material, such as:

  • names;
  • business roles and employers;
  • professional contact information;
  • public statements;
  • articles, posts, interviews, event appearances, or publications; and
  • other professional information made available through the selected source.

MBI processes this information to provide configured business-intelligence functionality, not to create consumer advertising profiles.

Usage, device, and security data

MBI may process:

  • IP address;
  • browser and device information;
  • login and authentication events;
  • timestamps;
  • feature usage;
  • API activity;
  • diagnostic information;
  • error logs;
  • security logs; and
  • cookie or similar identifiers.

Support and communication data

If you contact MBI, we process the content of the communication and any information required to respond.

3. How we obtain data

We obtain personal data:

  • directly from Customers and users;
  • automatically through use of the Service;
  • from public sources selected, configured, or monitored through the Service;
  • through integrations enabled by Customer;
  • from payment, authentication, infrastructure, communication, security, analytics, and other service providers; and
  • from business contacts who communicate with MBI.

4. Why we process personal data

MBI processes personal data for the following purposes.

Purpose Typical legal basis
Create and manage accounts Performance of contract
Provide subscribed Service features Performance of contract
Process Customer Content on Customer instructions Processor activity under the DPA
Billing, invoices, and subscription administration Performance of contract and legal obligations
Security, fraud prevention, abuse detection, and access control Legitimate interests and legal obligations
Service diagnostics, performance, and improvement Legitimate interests
Respond to support and business inquiries Performance of contract or legitimate interests
Maintain records and comply with law Legal obligations and legitimate interests
Send service communications Performance of contract and legitimate interests
Send marketing communications Consent where required, or another lawful basis where permitted
Use non-essential cookies or similar technologies Consent

Where MBI relies on legitimate interests, those interests include operating and securing a B2B software service, preventing misuse, improving performance, supporting customers, and managing business relationships.

5. AI processing

MBI uses third-party AI and machine-learning providers to provide parts of the Service.

Providers may include Anthropic, OpenAI, and other AI providers selected by MBI. MBI may change or add AI providers as the Service evolves.

Customer Content may be sent to one or more AI providers where necessary to perform a requested feature. Provider selection may vary by feature, model capability, availability, performance, cost, geography, or technical requirements.

Where an AI provider processes personal data on MBI's behalf, MBI treats that provider as a subprocessor and applies the DPA and applicable transfer safeguards.

MBI does not guarantee that any specific request will be processed by a particular AI provider unless separately agreed.

MBI does not use Customer Content to train general-purpose AI models unless Customer expressly agrees to that use.

6. Service providers and subprocessors

MBI uses service providers for functions such as:

  • application and database infrastructure;
  • AI inference and machine learning;
  • authentication;
  • payment processing;
  • email and communications;
  • security and monitoring;
  • analytics;
  • support; and
  • operational tooling.

The specific providers may change over time.

Where MBI acts as a processor for Customer Personal Data, the current providers that process that data are identified in the Subprocessor Register governed by the DPA.

Some providers act as independent controllers for limited processing they determine themselves, such as certain payment or fraud-prevention functions. Their own privacy terms apply to that independent processing.

7. Data location and international transfers

Persistent Customer Content and primary application data are hosted in the European Union.

Some service providers, including AI providers, may process or access limited data outside the European Economic Area.

Where personal data is transferred internationally, MBI uses a lawful transfer mechanism as required by applicable data-protection law. This may include:

  • an adequacy decision;
  • the European Commission's Standard Contractual Clauses;
  • other legally recognized transfer safeguards; and
  • supplementary technical or organizational measures where appropriate.

8. Data retention

MBI retains personal data only for as long as reasonably necessary for the purpose for which it is processed, including providing the Service, maintaining security, resolving disputes, and meeting legal, tax, accounting, and contractual requirements.

In general:

  • account data is retained while the account is active and for a reasonable period afterwards where required for legal or operational purposes;
  • billing and transaction records are retained for the period required by applicable accounting and tax law;
  • support communications are retained for as long as reasonably necessary to resolve and document the matter;
  • security and technical logs are retained for a limited period based on security and operational need; and
  • Customer Content is deleted or returned after termination in accordance with the DPA and MBI's deletion processes.

Backup copies may remain for a limited period until they are overwritten through normal backup rotation. They remain protected and are not restored except for continuity, recovery, or security purposes.

9. Security

MBI maintains technical and organizational measures appropriate to the nature and risk of the processing.

Measures include, as appropriate:

  • access controls and least-privilege principles;
  • authentication controls;
  • encryption in transit;
  • encryption of stored data where appropriate;
  • logical separation of customer environments and data;
  • logging and security monitoring;
  • backup and recovery processes;
  • vulnerability and dependency management;
  • incident-response procedures; and
  • confidentiality obligations for personnel with access to personal data.

No method of storage or transmission is completely secure.

10. Cookies and similar technologies

MBI uses cookies and similar technologies for necessary functions and, where enabled, preferences, analytics, or other optional purposes.

Non-essential cookies are not used until the required consent has been obtained.

Details are provided in the Cookie Policy and the cookie settings interface.

11. Marketing

MBI may send product or business communications to business contacts where permitted by law.

Where consent is required, MBI sends marketing only after obtaining that consent.

You can unsubscribe from marketing communications at any time using the unsubscribe mechanism in the message or the contact method shown in the MBI website footer.

Service, billing, security, and account communications are not marketing and may continue while necessary to administer the Service.

12. Your rights

Subject to applicable law, you may have the right to:

  • access personal data MBI holds about you;
  • correct inaccurate data;
  • request deletion;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • receive certain data in a portable format;
  • withdraw consent at any time where processing is based on consent; and
  • lodge a complaint with a supervisory authority.

If MBI processes the relevant data only on behalf of a Customer, MBI may refer the request to that Customer or assist the Customer in responding.

For processing where MBI is controller, requests can be submitted using the contact details shown in the MBI website footer or account area.

If you are in Denmark, you may lodge a complaint with the Danish Data Protection Agency, Datatilsynet. You may also have the right to complain to the supervisory authority in the EU/EEA country where you live or work.

13. Automated decision-making

MBI uses automation and AI to create business intelligence, summaries, classifications, and recommendations.

MBI does not use website, account, or billing personal data to make solely automated decisions about individuals that produce legal or similarly significant effects.

Customers remain responsible for how they use Output and for ensuring appropriate human review where decisions may affect individuals.

14. Children

The Service is designed for business and professional use and is not directed to children.

MBI does not knowingly offer accounts to children.

15. Sale of personal data

MBI does not sell personal data for money.

MBI does not use Customer Content for third-party behavioral advertising.

16. Changes to this Privacy Policy

MBI may update this Privacy Policy to reflect changes to the Service, law, providers, or processing activities.

The current version and effective date are published on this page.

A change of an individual AI provider or other service provider does not necessarily require a separate Privacy Policy notice where the nature and purpose of processing remain materially the same. Where data-protection law or the DPA requires subprocessor notice, MBI provides that notice as required.

17. Contact

Questions about this Privacy Policy or MBI's processing of personal data can be submitted using the legal or privacy contact details shown in the MBI website footer, checkout, account area, order documentation, or invoice.

---