1. Scope and our role
This Privacy Policy applies to the Union Software marketing website, trial and sales interactions, support communications, and the Union Software platform. Union Software is a business of Union Global. In this policy, “Union Software,” “we,” “us,” and “our” refer to Union Global operating the Union Software business.
Our privacy role depends on the context. For website, sales, account, billing, and business-contact information, we generally decide why and how the information is handled. For personal information that a union or other customer enters into the platform, the customer controls the purposes and access permissions, and we process that information to provide the service under the customer’s instructions and agreement.
2. Information we collect
| Category | Examples | How we receive it |
|---|---|---|
| Contact and business information | Name, work email, phone number, role, union or organization, and correspondence | Forms, email, meetings, support, and customer administration |
| Account and transaction information | Account identifiers, permissions, subscription, invoices, and payment status | Account setup, order forms, the platform, and payment providers |
| Website and device information | IP address, browser, device type, approximate location, referring page, pages viewed, and timestamps | Server logs and consented analytics |
| Preference information | Region, language, appearance, and cookie choices | Your browser and our local storage or cookies |
| Customer content | Member records, casework, communications, files, forms, financial records, and other data a customer chooses to use in enabled modules | Customers, authorized users, integrations, and people responding to customer communications |
| Support and security information | Support requests, diagnostic data, audit events, authentication events, and suspected misuse | You, authorized administrators, and platform systems |
We do not ask website visitors to provide sensitive member or casework information. Customers decide what information is appropriate to place in their workspace and must configure access according to their legal, constitutional, collective-agreement, and governance obligations.
3. Why we use information
- Provide, secure, maintain, troubleshoot, and improve the website and platform.
- Create and administer accounts, subscriptions, regional hosting choices, permissions, support, and customer relationships.
- Process requested whitepapers, trial inquiries, transactions, communications, and service notices.
- Measure website performance and understand product interest when analytics consent has been given.
- Detect, investigate, and prevent fraud, misuse, security incidents, and violations of our terms.
- Meet legal, tax, accounting, regulatory, and dispute-resolution obligations.
- Send marketing messages where permitted by law and by your choices. You may unsubscribe at any time.
We do not use customer content for targeted advertising. We do not sell personal information. We do not use customer content to train general-purpose artificial intelligence models unless a customer gives separate, explicit written authorization for a specific program.
4. Consent and other authority
We collect, use, and disclose personal information with consent or as otherwise permitted or required by applicable law. Depending on the context, our authority may also arise from performing a contract, providing a requested service, protecting the service and its users, meeting a legal obligation, or another recognized business purpose.
You may withdraw consent for future optional uses, subject to legal or contractual restrictions and reasonable notice. Withdrawing consent does not affect processing already lawfully completed and may limit an optional feature. Essential processing needed to secure an account or provide a contracted service cannot always be disabled while the account remains active.
5. When we disclose information
- To the customer and its authorized users according to permissions the customer manages.
- To service providers that support hosting, databases, communications, payments, mapping, analytics, support, security, and other enabled functions, under appropriate contractual restrictions.
- To Union Global affiliates and personnel who need the information to operate, support, secure, or administer the service.
- To authorities, courts, regulators, or other parties when reasonably necessary to comply with law, protect rights or safety, investigate misuse, or establish and defend legal claims.
- In connection with a financing, reorganization, merger, acquisition, sale, or transfer of all or part of a business, subject to confidentiality and applicable law.
- With your direction or consent.
Our current platform service providers, their purposes, and relevant location notes are listed on the Subprocessors page. A provider may apply only to customers that enable the related module or integration.
6. Data location and international processing
Customer Data in the core hosted platform is assigned to a supported residency region during signup or in the order form. Canadian customer workspaces use a Canadian regional deployment, US customer workspaces use a US regional deployment, and customers in another supported market use the corresponding regional deployment. We do not use a different country as a fallback when the required region is unavailable.
Within that regional deployment, we configure managed production database services and core cloud application, storage, backup, logging, queue, and security services in the same supported region. Core Customer Data, in-region database replicas, backups, application processing, and private service-to-service traffic remain within that regional boundary and are not ordinarily moved, replicated, or routed through another regional environment. A customer-authorized correction of an incorrectly selected setup region or a binding legal requirement may require different handling.
This regional commitment applies to the core hosted platform, not every transmission over the public internet. If a customer enables email, SMS, voice, payments, maps, support, or another customer-directed integration, the limited information needed for that feature may be processed by the approved provider outside the primary hosting region. Website inquiries, billing and account-administration information, consent records, and provider account or diagnostic metadata may also be processed where Union Software or the disclosed provider operates. The Subprocessors page and Data Processing Addendum describe these exceptions. Laws in those places may permit lawful access by courts, law-enforcement agencies, or national-security authorities.
We use contractual, organizational, and technical measures appropriate to the information and transfer. For Québec personal information, we support the customer’s required privacy impact assessment and written transfer arrangements where applicable. The order form and Data Processing Addendum control if they identify a different supported region or contain a more specific commitment.
7. Retention and deletion
We retain personal information only as long as reasonably necessary for the stated purposes, the customer’s documented instructions, and legal, security, accounting, backup, and dispute-resolution requirements. Retention depends on the type and sensitivity of the information, the customer’s configuration, the length of the relationship, and applicable law.
When a customer account ends, return and deletion of customer content are handled under the customer agreement and data processing addendum. Backups and security logs may remain for a limited period under controlled access until overwritten or securely deleted. We may retain minimal suppression records to respect an unsubscribe request and records required to demonstrate compliance.
For a free trial that does not become a paid subscription, workspace access is suspended when the trial expires. The customer may request a standard export during the trial or within 30 days after it ends. We delete trial Customer Data from active systems within 90 days after the trial ends, unless the customer subscribes or law requires retention. Trial administrator and business-contact records may be kept for up to 24 months after the last interaction for relationship administration, fraud prevention, and support history, unless a shorter period is required or a verified deletion request applies. Consent, suppression, security, agreement, and legal records may be retained longer where reasonably necessary for those purposes.
8. Safeguards
We maintain administrative, technical, and physical safeguards designed for the sensitivity and volume of information we handle. Measures include role-based access, authentication controls, encryption in transit, encryption at rest where supported by the service architecture, logging, backups, vulnerability and incident processes, personnel confidentiality duties, and service-provider review.
No system is completely secure. Customers are responsible for managing their users, roles, exports, connected services, and devices. If you believe information may have been compromised, contact us promptly.
9. Rights in Canada
Subject to applicable exceptions, people in Canada may ask to access personal information we control, understand how it has been used or disclosed, correct inaccurate information, withdraw consent, or challenge our compliance. Québec residents may also have rights relating to portability, de-indexation, re-indexation, and information about automated decisions where the statutory conditions apply.
We may need to verify identity and authority before acting. If the information is controlled by a customer, we will direct the request to that customer or assist it as required. You may complain to the Office of the Privacy Commissioner of Canada or the applicable provincial privacy regulator after first giving us an opportunity to address the concern.
10. Rights in the United States
Residents of certain U.S. states may have rights to know or access personal information, receive a portable copy, correct inaccuracies, delete information, opt out of sale, targeted advertising, or certain profiling, limit specified uses of sensitive information, and appeal a denied request. These rights apply only where the relevant law covers us and the requested information.
Union Software does not sell personal information and does not share it for cross-context behavioural advertising. We do not discriminate against a person for exercising an applicable privacy right. An authorized agent may submit a request where permitted, but we may verify the agent’s authority and the individual’s identity.
12. Email, SMS, and marketing preferences
We send promotional email or text messages only where we have the permission or other legal authority required for the recipient and region. Canadian commercial electronic messages identify the sender and include a working unsubscribe method as required by Canada’s Anti-Spam Legislation. Service, security, billing, and requested-response messages may still be sent when necessary.
Starting or using a free trial does not require consent to marketing and does not by itself enrol a person in promotional messages. Where offered, marketing consent is a separate, optional, unchecked choice covering product news, educational content, events, discounts, promotions, and subscription or upgrade offers. If selected, that consent applies during and after the trial until withdrawn; the end of the trial does not itself cancel the marketing choice. We record the consent statement, date, time, source, and account or address associated with the choice. Declining or withdrawing marketing consent does not affect the trial. We may still send account verification, security, requested support, neutral days-remaining reminders, expiry, export, and deletion notices that are necessary to provide or close the requested service. A message whose primary purpose is to persuade the recipient to subscribe, upgrade, or claim an offer is treated as marketing.
13. Children and minors
Our public website and direct trial or account signup are intended for organizations and their authorized representatives, not for children or minors acting on their own. We do not knowingly invite a child or minor to submit personal information directly through a public website form or create an organization account. If a customer has a lawful reason to maintain dependent or youth-member information in its workspace, the customer is responsible for the required authority, notices, access controls, and safeguards.
14. Privacy Officer and requests
Contact the Privacy Officer at legal@unionsoftware.com with “Privacy Request” in the subject line, or write to: Union Software, Attention: Privacy Officer, 190 Norseman St., Suite 100, Etobicoke, Ontario, Canada M8Z 2R4. Describe the request, your jurisdiction, and whether the information relates to the website or a customer workspace. Do not email sensitive member, medical, financial, or casework records.
We may update this policy as our services or legal obligations change. We will post the revised policy with a new effective date and provide additional notice when required.