Privacy policy

UNA Watch: Privacy Policy

Last Updated: August 2026

UNA Watch Ltd (“UNA”, “we”, “us”, “our”) is committed to protecting the privacy of everyone who visits our website, uses our Products, or otherwise interacts with us. This Privacy Policy explains how we collect, use, store, and protect your personal data, including through cookies and similar technologies, in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).

Who We Are

UNA Watch Ltd is a company registered in Scotland under company number SC793931, with our registered office at CBC House, 24 Canning Street, Edinburgh, EH3 8EG. We are the data controller responsible for your personal data. For any questions, contact us at hello@unawatch.com.

Data We Collect

  • Personal identifiers: name, email address, phone number, and delivery address.

  • Technical data: IP address, browser type, device ID, operating system, time zone settings.

  • Usage data: interactions with our website and app, referring URLs.

  • Health and fitness data: heart rate and activity metrics, collected via your UNA Watch.

  • Precise GPS location data (latitude, longitude, and altitude) from your mobile device, collected while the app is in use and, periodically, in the background while your UNA Watch is connected.

  • Cookies and similar technologies (see Section 4 below).

We use your device’s location to calculate a reference location that is sent to your UNA Watch. The watch uses this to speed up GPS positioning and calibrate altitude measurements for greater accuracy during activities. So that your watch remains accurate without needing the app open, we may collect and update this reference periodically in the background while your watch is connected. We do not use your location for advertising, tracking, or profiling, and we do not sell your location data.

How We Use Your Data

  • To fulfil Product orders and manage your account.

  • To provide product support and customer service.

  • To provide fitness and wellness insights based on your health and activity data.

  • To improve our website, Products, and Services.

  • To personalise your experience.

  • For marketing communications, where you have consented.

  • To comply with our legal obligations.

Cookies

What Are Cookies

Cookies are small text files placed on your device (computer, smartphone, or tablet) when you visit our website. They help our website function and give us information about how it is used.

Types of Cookies We Use

  • Strictly Necessary Cookies: essential for security, network management, and accessibility. These cannot be switched off.

  • Performance Cookies: collect aggregated, anonymous information about how visitors use our site, such as which pages are visited most often.

  • Functionality Cookies: remember your preferences, such as your region, to give you a more personalised experience.

  • Marketing Cookies: used, only with your consent, to show you more relevant advertising. These may be set by our advertising partners.

Third-Party Cookies

We use third-party service providers, including Google Analytics, to help us understand website traffic and usage. These providers may place cookies on your device as part of this service.

Managing Your Cookie Preferences

When you first visit our website, you will see a cookie banner that lets you accept or manage your cookie preferences. Non-essential cookies (performance, functionality, and marketing) are only set once you have given your consent. You can change your preferences at any time using the “Cookie Settings” link at the bottom of our website, or through your browser settings. Note that blocking all cookies may affect how our website functions.

Cookie Retention

Session cookies are deleted when you close your browser. Persistent cookies remain on your device until they expire or you delete them.

Legal Basis for Processing

  • Contractual necessity: for order fulfilment and account management.

  • Explicit consent: for processing health and fitness data as required for special category data under Article 9 of the UK GDPR.

  • Consent: for marketing communications and non-essential cookies.

  • Legitimate interests: to improve and secure our Products and Services.

  • Legal obligation: to comply with legal and tax requirements.

Data Sharing and Transfers

Your data may be shared with trusted third parties, such as payment processors, logistics providers, and analytics services. Where we transfer data outside the UK, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses.

When calculating your reference location, we send your latitude and longitude to a third-party elevation and weather data provider solely to retrieve the ground elevation for that point. This data is used only to provide this feature and is not used by the provider to identify you.

Data Retention

  • Order and account data: 6 years post-purchase.

  • Marketing data: until you withdraw your consent.

  • Health and activity data: until you withdraw your consent.

  • Cookie data: for the duration described above.

Your Rights Under UK GDPR

You have the right to:

  • Access your personal data.

  • Rectify incorrect or outdated data.

  • Request erasure (the “right to be forgotten”).

  • Object to processing, or request that it be restricted.

  • Data portability.

  • Withdraw your consent at any time.

To exercise these rights, contact us at hello@unawatch.com

Data Security & Processing

We implement appropriate security measures, including encryption, secure servers, and regular audits, to protect your data from unauthorised access, alteration, or loss.

Where is user data stored?

User data is stored on secure infrastructure provided by Amazon Web Services (AWS) in the London (UK) region.

In addition, limited customer communication and messaging data is processed by trusted third-party providers, including Klaviyo (email and marketing communications) and Twilio (SMS delivery). These providers process only the data necessary to deliver their respective services and operate under GDPR-compliant data processing agreements.

Is the data stored in the EU, UK, US, or another country?

Primary data storage is located in the United Kingdom (AWS London region).

When third-party services such as Klaviyo and Twilio are used, certain data may be processed in other regions, including the European Union and the United States, in accordance with applicable data protection laws. 

Is my data secure?

Yes. We apply multiple layers of technical and organisational security measures to protect user data.

Encryption at rest:

All data stored in AWS is encrypted at rest using industry-standard encryption mechanisms (e.g., AES-256).

Encryption in transit:

Data transmitted between systems is encrypted using TLS (HTTPS) to protect against interception or unauthorised access.

Access control:

Access to production systems and user data is strictly limited to authorised personnel only, following the principle of least privilege.

Role-based access control (RBAC) and strong authentication mechanisms are used.

Infrastructure security:

AWS provides a highly secure and compliant infrastructure, including network isolation, firewalls, monitoring, and regular security audits.

Third-party compliance:

Klaviyo applies comparable security standards and contractual safeguards to ensure the secure processing of personal data.

Your Health Data & Product Disclaimer

UNA Watch and its companion app are designed for general fitness and wellness purposes only. Metrics such as heart rate are provided for informational purposes and are not intended to diagnose, treat, or monitor any medical condition, and should not be relied upon as medical advice. If you have concerns about your health, please consult a qualified healthcare professional.

Children’s Privacy

Our Products and Services are not designed for children under the age of 13, and we do not knowingly collect personal data from children below this age. Where our Products and Services are used by 13 to 17 year olds, we recommend that a parent or guardian supervise use, given that our Products collect location and health data. Parents or guardians who believe a child has provided us with personal data without appropriate consent should contact us at hello@unawatch.com, and we will take reasonable steps to delete that data promptly.

Changes to This Policy

We may update this Privacy Policy at any time. We will communicate any material changes via our website.

Contact Us

For questions, data requests, or concerns, please contact us at hello@unawatch.com