UltiSuite privacy

Privacy policy

Data processing, owned infrastructure and external subprocessors enabled on this instance.

Last updated: 29 June 2026

Data controller

This policy explains how UltiSuite processes personal data in connection with its services.

UltiSuite is created by Eliott Guillaumin. Copyright Eliott Guillaumin. All rights reserved.

Depending on context, the data controller may be Eliott Guillaumin or the organization that provides UltiSuite to its users. Your organization administrator can clarify this point.

Data processed

UltiSuite may process account, authentication, preference, email, file, document, event, meeting, contact, administration, AI prompt and technical log data.

Data processed depends on tools used, enabled settings and content voluntarily provided by the user or organization.

UltiSuite does not request more data than necessary for operation, security, administration and reasonable service improvement.

Purposes

Data is used to provide UltiSuite tools, authenticate users, synchronize content, personalize the experience, secure access, prevent abuse and diagnose incidents.

It may also be used to apply organization policies, maintain audit logs, ensure service continuity and meet legal obligations.

User content is not sold, rented or used for targeted advertising.

Hosting and infrastructure

UltiSuite is deployed on the organization's infrastructure or that of its host (OVH by default). Suite software components (Authentik, Nextcloud, database, storage, etc.) run on this dedicated infrastructure.

These components are not external subprocessors: they are part of the UltiSuite deployment under the control of the instance operator.

Only third-party services actually configured and enabled on the instance may receive data outside this perimeter. They are listed dynamically below and on the dedicated page.

Legal bases

Depending on the case, processing relies on performance of the requested service, legitimate interest in security and administration, compliance with legal obligations or consent where required.

For accounts provided by an organization, some processing may depend on that organization's own instructions and obligations.

Users may contact the publisher or their administrator to learn the applicable basis for a specific processing activity.

Retention

Account and content data are retained as long as the account, workspace or organization maintains them, unless deletion is requested or law requires otherwise.

Technical and security logs are retained for a period proportionate to diagnostic, security, audit and compliance needs.

When an account is deleted, some data may temporarily remain in backups or strictly necessary logs before purge according to applicable technical cycles.

Security

UltiSuite applies technical and organizational measures intended to protect access, limit incidents and reduce the risk of loss, alteration or unauthorized viewing.

However, no method of transmission or storage can be guaranteed as absolutely secure.

The user must keep credentials confidential, enable available protections and report any suspicious access.

Individual rights

Under applicable law, you may request access, rectification, erasure, restriction, objection, portability or withdrawal of consent where processing is based on it.

Some requests may be handled by your organization administrator when your account depends on it.

A request may be refused or limited when a legal obligation, third-party right, security need or need to prove an incident requires retaining certain information.

Cookies, analytics and local storage

UltiSuite uses strictly necessary technical cookies: OIDC session (httpOnly), temporary OAuth PKCE tokens, and possibly sidebar state (`sidebar_state`).

Preferences, drafts and local state may be stored in localStorage or IndexedDB (cache, offline queue, encrypted zero-trust keys).

Usage statistics may be measured via self-hosted Matomo in cookieless mode, without a consent banner when this configuration is active.

These mechanisms are not used to sell data or for advertising targeting.

Browser-side storage

In addition to technical cookies, the client may locally store blocked or trusted addresses, scheduled sends/snoozes, contacts deleted to trash, calendar or video keys, and an API query cache.

You can clear this data from your account privacy settings or by clearing browser storage.

Blocking certain technical storage may degrade or prevent normal service operation.

Transfers

By default, UltiSuite aims for processing on infrastructure configured by the instance operator.

Enabling external integrations (AI providers, OAuth, payments, etc.) may result in transfers to those providers, listed on the subprocessors page.

The responsible organization must inform its users and, where applicable, implement appropriate safeguards.

Contact

For any question or request about personal data, contact the publisher or your UltiSuite organization administrator.

For organization-managed accounts, the administrator may be the primary contact for exercising your rights.

GDPR compliance

UltiSuite is fully GDPR-compliant in day-to-day operations: export, erasure, consents, processing restriction and subprocessors transparency.

See compliance details and your rights

Enabled external subprocessors

List generated from integrations configured on this instance. UltiSuite components on your infrastructure are not listed here.

Loading subprocessors list…

Full subprocessors page · Data processing agreement (DPA)

Suite apps

Each app has its own section via URL anchor, for example #ultidocs.

Ultimail

mail, composition, attachments, linked contacts and mail search.

  • Ultimail processes emails, headers, recipients, drafts, attachments and preferences necessary for the service.
  • Message content is not used for advertising or sold to third parties.
  • Mail data is hosted on OVH infrastructure used by UltiSuite.

UltiDrive

storage, organization, sharing and file preview.

  • UltiDrive processes files, file names, metadata, sharing rights and technical histories useful to the service.
  • Files are retained as long as the account, workspace or organization maintains them, unless law requires otherwise.
  • Access and sensitive operations may be logged for security and audit.

UltiDocs

collaborative documents, rich editing, comments and writing aids.

  • UltiDocs processes document content, technical collaboration history, selections, comments and editing preferences.
  • Personal dictionaries and editing settings remain linked to the account or browser depending on user configuration.
  • Writing-aid processing runs in the UltiSuite environment hosted at OVH, without a third-party service provider.

UltiCal

calendar, invitations, availability and shared events.

  • UltiCal processes titles, locations, times, participants, responses, event notes and reminders.
  • Availability may be visible according to account or organization settings.
  • Calendar data is hosted at OVH with the rest of the suite.

UltiMeet

meetings, rooms, invitation links and video conferencing.

  • UltiMeet processes meeting information, participants, room settings and connection technical data.
  • Audio/video streams are used to provide communication and are not exploited for advertising.
  • Technical logs may be retained for security, diagnosis and service quality.

UltiCards

contacts, address books, records and correspondent discovery.

  • UltiCards processes names, email addresses, phones, organizations, notes and relationship metadata.
  • Contacts support addressing, search, suggestions and address book management.
  • Contact data is not resold or used for advertising targeting.

UltiAI

assistant, completion, writing aid and intelligent automations.

  • UltiAI processes prompts, provided contexts and results necessary for the user's request.
  • UltiSuite does not use an external service provider for UltiAI; declared infrastructure is OVH.
  • Data is not used to train an advertising or third-party model.

Administration

organization console, accounts, policies, security and global settings.

  • The console processes identities, roles, organization settings, security policies and administration logs.
  • Audit logs help protect accounts, prove certain actions and diagnose incidents.
  • Administrators may access certain metadata according to their rights and organization settings.

UltiSuite account

profile, authentication, preferences, sessions and personal settings.

  • The account processes identity, email, preferences, sessions, security settings and sign-in logs.
  • This data is used to authenticate the user, maintain security and personalize the experience.
  • The user may request access, rectification, deletion or export under applicable conditions.