Skip to Content
Security & Privacy

Your data, your control.

Legal data is confidential. Unomia is built with privacy and compliance as its foundation — not as an afterthought.

ISO 27001
Information Security · via Odoo.sh
SOC 2 Type II
Security & Availability · via Odoo.sh
🇪🇺
GDPR
Fully compliant · EU servers
ISO 27001
Information Security Management

Our hosting infrastructure (Odoo.sh) is ISO 27001 certified. This internationally recognized standard confirms that information security is managed systematically and demonstrably — from risk assessment to incident handling.

Certificate number via Odoo S.A.
SOC 2 Type II
Security, Availability & Confidentiality

Odoo.sh complies with SOC 2 Type II, the US standard for cloud service providers. This report confirms that security controls have been operating effectively over an observation period — critical for enterprise and compliance-sensitive environments.

AICPA Trust Services Criteria
🇪🇺
GDPR
European Data Protection Regulation

All personal data is processed in compliance with the General Data Protection Regulation (GDPR). Servers are located in the EU, each client has their own isolated database, and a Data Processing Agreement (DPA) is available on request.

Data Processing Agreement available
Technical security

Security foundations

🗄️

Dedicated database

Every Unomia client has their own fully isolated database. Your data is never stored in a shared system or combined with data from other firms. This is a hard requirement for attorney-client privilege.

☁️

EU hosting · GDPR-compliant

All servers are located in Europe. Unomia is fully compliant with the GDPR. A Data Processing Agreement (DPA) is available on request. Data transfers outside the EEA do not occur without appropriate safeguards (Standard Contractual Clauses).

🔐

2FA & role-based access

Two-factor authentication (TOTP) is available by default. Role-based access control ensures staff only see what is relevant to their role. SSO integration via Outlook/Microsoft Entra is available.

📋

Audit log & encryption

Every user action is logged. Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Regular backups to three geographic EU locations are included.

Integrations & data security

How we integrate securely

Unomia integrates with external services using a privacy-by-design approach. Here's how.

Microsoft Outlook
Email & calendar integration

Emails and calendar items sync via Microsoft Graph API. OAuth 2.0 authentication. No passwords stored. SSO via Microsoft Entra ID available.

Gmail (Google Workspace)
Email integration

Gmail integrates via Google OAuth 2.0. Minimal scope: only required email permissions. No Google passwords stored. Data stays in your own Odoo database.

WhatsApp Business
Client communication

Via the official WhatsApp Business API (Meta). Messages are processed and stored directly in your matter file. End-to-end encryption on the WhatsApp channel. DPA with Meta available.

ChatGPT / OpenAI
Casey AI support

Casey uses OpenAI's API. Prompts do not contain direct personal data without explicit consent. Data is not used by OpenAI for training (API mode). Privacy agreement with OpenAI is in place.

Veriff
Digital identity verification

Client identity is verified via Veriff's eIDAS-compliant verification service. Biometric data is processed by Veriff and not stored in Unomia. ISO 27001 certified. GDPR-compliant processing.

Odoo.sh
Hosting & infrastructure

Unomia runs on Odoo.sh — ISO 27001 and SOC 2 Type II certified cloud infrastructure. EU servers, daily backups, isolated database per client, and continuous security monitoring.

Security overview

  • ISO 27001 certified
    Via Odoo.sh hosting infrastructure · Odoo S.A.
  • SOC 2 Type II compliant
    Security, Availability & Confidentiality · via Odoo.sh
  • GDPR compliance
    Data Processing Agreement available on request
  • EU data hosting
    Servers in the Netherlands / Europe
  • Dedicated isolated database per client
    No shared multi-tenant storage
  • Two-factor authentication (TOTP)
    Available by default for all users
  • Role-based access control
    Configurable per user
  • SSO via Outlook / Microsoft Entra
    Optionally available
  • Audit log
    Every action logged per user
  • TLS 1.3 encryption in transit
    All data traffic encrypted
  • AES-256 encryption at rest
    Stored data encrypted
  • Automated backups
    Daily backups to 3 EU locations included
  • Official WhatsApp Business API
    Meta DPA available
  • OpenAI API — no training data
    Prompts are not used for AI training
  • Veriff ID verification
    eIDAS-compliant · ISO 27001 certified

Questions about security or a Data Processing Agreement?

We are happy to answer your questions — including for your IT manager or compliance officer.

Contact us