Your data, your control.
Legal data is confidential. Unomia is built with privacy and compliance as its foundation — not as an afterthought.
Our hosting infrastructure (Odoo.sh) is ISO 27001 certified. This internationally recognized standard confirms that information security is managed systematically and demonstrably — from risk assessment to incident handling.
Odoo.sh complies with SOC 2 Type II, the US standard for cloud service providers. This report confirms that security controls have been operating effectively over an observation period — critical for enterprise and compliance-sensitive environments.
All personal data is processed in compliance with the General Data Protection Regulation (GDPR). Servers are located in the EU, each client has their own isolated database, and a Data Processing Agreement (DPA) is available on request.
Security foundations
Dedicated database
Every Unomia client has their own fully isolated database. Your data is never stored in a shared system or combined with data from other firms. This is a hard requirement for attorney-client privilege.
EU hosting · GDPR-compliant
All servers are located in Europe. Unomia is fully compliant with the GDPR. A Data Processing Agreement (DPA) is available on request. Data transfers outside the EEA do not occur without appropriate safeguards (Standard Contractual Clauses).
2FA & role-based access
Two-factor authentication (TOTP) is available by default. Role-based access control ensures staff only see what is relevant to their role. SSO integration via Outlook/Microsoft Entra is available.
Audit log & encryption
Every user action is logged. Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Regular backups to three geographic EU locations are included.
How we integrate securely
Unomia integrates with external services using a privacy-by-design approach. Here's how.
Emails and calendar items sync via Microsoft Graph API. OAuth 2.0 authentication. No passwords stored. SSO via Microsoft Entra ID available.
Gmail integrates via Google OAuth 2.0. Minimal scope: only required email permissions. No Google passwords stored. Data stays in your own Odoo database.
Via the official WhatsApp Business API (Meta). Messages are processed and stored directly in your matter file. End-to-end encryption on the WhatsApp channel. DPA with Meta available.
Casey uses OpenAI's API. Prompts do not contain direct personal data without explicit consent. Data is not used by OpenAI for training (API mode). Privacy agreement with OpenAI is in place.
Client identity is verified via Veriff's eIDAS-compliant verification service. Biometric data is processed by Veriff and not stored in Unomia. ISO 27001 certified. GDPR-compliant processing.
Unomia runs on Odoo.sh — ISO 27001 and SOC 2 Type II certified cloud infrastructure. EU servers, daily backups, isolated database per client, and continuous security monitoring.
Security overview
-
✓
ISO 27001 certifiedVia Odoo.sh hosting infrastructure · Odoo S.A.
-
✓
SOC 2 Type II compliantSecurity, Availability & Confidentiality · via Odoo.sh
-
✓
GDPR complianceData Processing Agreement available on request
-
✓
EU data hostingServers in the Netherlands / Europe
-
✓
Dedicated isolated database per clientNo shared multi-tenant storage
-
✓
Two-factor authentication (TOTP)Available by default for all users
-
✓
Role-based access controlConfigurable per user
-
✓
SSO via Outlook / Microsoft EntraOptionally available
-
✓
Audit logEvery action logged per user
-
✓
TLS 1.3 encryption in transitAll data traffic encrypted
-
✓
AES-256 encryption at restStored data encrypted
-
✓
Automated backupsDaily backups to 3 EU locations included
-
✓
Official WhatsApp Business APIMeta DPA available
-
✓
OpenAI API — no training dataPrompts are not used for AI training
-
✓
Veriff ID verificationeIDAS-compliant · ISO 27001 certified
Questions about security or a Data Processing Agreement?
We are happy to answer your questions — including for your IT manager or compliance officer.
Contact us