Unlistix · Legal

Privacy Policy

Last updated: August 28, 2026

Thank you for being part of Unlistix. ROTAMA COMPANY LTD, doing business as Unlistix ("Unlistix", "we", "us"), is committed to protecting your personal information and your right to privacy. This policy explains what data we collect, how we use it and what rights you have. If you have any questions, write to support@unlistix.com.

1. Data controller

ROTAMA COMPANY LTD is the controller of your personal data. This policy applies to unlistix.com, all our services and any communication with us.

2. What information we collect

  • Data you provide: name and surname, email, language, password (always bcrypt-hashed), stage names, identity verification data and rights-ownership documentation where applicable.
  • Billing and subscription data: plan, coupons, renewal status and cancellations. We do not store card numbers or security codes: payments are processed by our authorised payment provider.
  • Automatic data: IP address, browser and device type, and security logs, needed to operate and protect the service.

3. How we use your information and legal bases

  • Creating and managing your account, authenticating you and providing the contracted service (contract performance, art. 6.1.b GDPR).
  • Locating, documenting and requesting removal of unauthorised content on your behalf (contract performance and, for sensitive data, your explicit consent).
  • Processing payments, managing renewals, issuing invoices and preventing fraud (contract performance and legal obligation).
  • Sending service and security communications: access codes, account notices, a renewal reminder 7 days before each charge (contract performance).
  • Preventing fraud and abuse (legitimate interest, art. 6.1.f GDPR): at sign-up and at contracting we store your IP address and technical device data to detect duplicate accounts, protect the referral programme and document the contracting against payment disputes (chargebacks).
  • Sending you commercial communications about our own services only if you accepted via the optional checkbox at registration or enable them from your panel (consent, art. 6.1.a GDPR), with free, immediate opt-out in every email or from Security → Communication preferences.
  • Keeping the service secure, preventing abuse and complying with legal obligations (legitimate interest and legal obligation).

4. Special category and biometric data

To provide the service we may process special category data: stage names linked to intimate content, reference content and, where applicable, biometric data for facial recognition. We process it solely to locate and remove unauthorised content, with your explicit consent (art. 9.2.a GDPR). This consent is collected via a specific checkbox at the moment you create a protected identity or upload reference material — never at sign-up or checkout — and you can withdraw it at any time from your account (by deleting the identity) or by writing to us. We also use the facial signature, in an automated way and entirely on our own servers, to prevent the same person from being protected in more than one account (duplicate and fraud prevention).

Important: if your subscription becomes inactive, we permanently delete your protected identities and all associated sensitive and biometric data 7 days after suspension, and notify you by email. If you reactivate, you will need to recreate your identities and re-upload your references.

5. Where your data lives

Our servers are in the European Union (Hetzner Online GmbH, Germany). The database resides on our own server, with no third-party storage.

6. Who we share data with and international transfers

  • Hetzner Online GmbH (Germany, EU) — hosting. Data Processing Agreement (DPA) in place.
  • Resend, Inc. (USA) — transactional and, if consented, promotional email delivery. Transfer covered by the EU-U.S. Data Privacy Framework and Standard Contractual Clauses (SCCs).
  • Third-party platforms, search engines and hosting providers: only the data strictly necessary to process each removal request on your behalf.
  • Authorities: where a law, court order or valid legal request requires it.
  • We never sell your data or share it with third parties for advertising purposes.

7. How long we keep your data

  • Account data: while the account exists and up to 12 months after deletion for legal obligations.
  • Sensitive and biometric data: while the subscription is active; permanently deleted 7 days after suspension or upon consent withdrawal.
  • Billing: periods required by applicable tax law.
  • Consent and unsubscribe records: 3 years as proof of compliance.

8. Security

We apply appropriate technical and organisational measures: TLS encryption in transit, bcrypt-hashed passwords, two-step verification, hardened servers (firewall, fail2ban, key-only access), role-restricted access and scheduled deletion of sensitive data. No Internet transmission is 100% secure, but if we detect a breach affecting you we will act in accordance with applicable law.

9. Your rights (EEA/UK)

You can exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to support@unlistix.com. You can delete your account and data directly from Security → Delete my account. If you believe we process your data unlawfully, you may complain to your supervisory authority (in Cyprus, the Office of the Commissioner for Personal Data Protection).

10. US residents (California)

If you are a California resident, you may have additional rights under the CCPA/CPRA: to request access, correction or deletion of your personal information and to know which categories we process. Categories we process: identifiers, commercial information (subscription and billing), service activity data and, only with your explicit consent, biometric data. We do not sell or share personal information for targeted advertising. Exercising your rights never results in discrimination or loss of service. To exercise them, write to support@unlistix.com.

11. Minors

The service is intended solely for people over 18. We do not knowingly collect data from minors. If we detect a minor's account, we will suspend it and delete its data. If you know of a case, tell us at support@unlistix.com.

12. AI-assisted technologies

We use automated technologies, including AI-assisted reverse image search and matching, to locate potentially unauthorised uses of your content. These technologies may produce false positives or negatives and their results are used as part of a broader review process; they are not the sole basis for determining infringement.

13. Changes to this policy

We may update this policy; the current version is indicated by the "last updated" date. For material changes we will notify you prominently or by email where required by law.

14. Contact

ROTAMA COMPANY LTD · Griva Digeni Avenue 51, Athineon Court, Office 202, 8047, Paphos, Cyprus · support@unlistix.com

In case of discrepancy between language versions, the English version prevails.