Skip to main content
🔒 Transparency & GDPR

Privacy
policy

We are committed to protecting your personal data with seriousness and transparency. This page explains clearly what we collect, why, and your rights.

📅 Last updated: 🇪🇺 GDPR-compliant

Data controller

The controller of the data collected through the UnlimitedMessaging site is the company operating this service.

UnlimitedMessaging

Website: unlimitedmessaging.app

Contact: [email protected]


Data collected

Through our forms (demo and waitlist) and app usage, we collect the following data:

DataDescriptionRequired
Phone numberCountry code + local number, stored on our servers to send your WhatsApp demo messageYes (demo)
Email addressCollected via the waitlist form - used to keep you informed about the serviceYes (waitlist)
IP addressCollected automatically for security and abuse prevention purposesAutomatic
User-AgentBrowser and OS information, for technical purposesAutomatic
TimestampDate and time of submissionAutomatic
Message contentText of WhatsApp messages sent and received through our service, stored in our database to display your messaging historyYes (app)
Interlocutor phone numberPhone number or WhatsApp identifier of the message recipient or senderYes (app)
WhatsApp session dataSession credentials used to maintain your SIM's connection to the WhatsApp network, stored encryptedYes (app)
Message content: message texts are stored in our database and encrypted at rest. For shared (system) SIMs, replies received in response to your messages are accessible to UnlimitedMessaging administrators only (see §05).

Processing purposes

Your data is collected for the following reasons:

  • Provide the WhatsApp messaging service: sending and receiving messages through SIMs connected to your account
  • Keep you informed about UnlimitedMessaging offers and updates (our own service only - never third parties)
  • Abuse and spam prevention (IP-based rate limiting)
  • Service improvement and anonymised statistical analysis
  • Compliance with legal obligations

The legal basis of the processing is your explicit consent, expressed when submitting the form (Article 6.1.a of the GDPR).

Your personal data is never sold, rented, or shared with third parties. It may be used to contact you at launch and keep you informed of our own offers and services. You can withdraw your consent at any time by writing to [email protected].


Retention period

Your data is kept for a limited period proportionate to the purpose of the processing:

  • Phone number: 12 months maximum from collection
  • IP address and technical data: 6 months for security purposes

After this period, your data is automatically deleted from our systems or irreversibly anonymized.


Data sharing

Your personal data is never sold nor shared with third parties for commercial purposes.

It may only be shared in the following cases:

  • To our technical service providers strictly necessary for the service (hosting, notifications), bound by GDPR-compliant data processing agreements
  • Upon judicial request or legal obligation
  • To UnlimitedMessaging administrators, for messages received on shared (system) SIMs: when you send a message via a system SIM, any replies from your contact are visible to the UM team - not to you. This behaviour is inherent to how shared SIMs work and you are informed of it at the time of sending.
Our servers and databases are hosted in the European Union. No data transfer outside the EU is performed without appropriate safeguards.

Your rights

In accordance with the General Data Protection Regulation (GDPR), you have the following rights over your personal data:

  • Right of access - obtain a copy of the data concerning you
  • Right to rectification - correct inaccurate or incomplete data
  • Right to erasure - request deletion of your data
  • Right to object - object to certain processing
  • Right to restriction - temporarily restrict processing
  • Right to portability - receive your data in a readable format
  • Right to withdraw consent - at any time, without justification

To exercise these rights, contact us at [email protected]. We will respond within a maximum of 30 days.

You also have the right to lodge a complaint with your national data protection authority (e.g. CNIL in France): www.cnil.fr.


Data security

We implement appropriate technical and organizational measures to protect your data:

  • Encrypted connections via HTTPS (TLS)
  • Restricted and authenticated database access
  • Protection against SQL injection via prepared statements (PDO)
  • Rate limiting per IP and session
  • CSRF tokens to secure forms

In the event of a data breach likely to cause a risk to your rights and freedoms, we commit to informing you within the timeframes set by the GDPR.

Need help?

Our team is here to answer your questions.

Go to contact page

Response within 1 business day