This agreement applies whenever a wholesale or API client, or a customer of a hosted copy of this website, sends us personal data about its own customers. It is part of the Terms of Service and the Master Service Agreement; no signature is needed, and a signed copy is available on request.
“Controller” is the client — a wholesale account, an API account, or a customer of a hosted copy of this website — that decides why and how its customers’ data is used. “Processor” is UnlockMyIMEI, Florida, United States, which processes that data on the Controller’s behalf to perform the ordered services. Where we act for our own retail customers we are the controller and the Privacy Policy applies instead.
We process Controller Data only on the Controller’s documented instructions. The instructions are: the orders and requests submitted through the portal, the API or the admin of a hosted copy; the settings the Controller chooses there; this agreement; and any further written instruction we accept. We may also process Controller Data where EU, UK or US law requires us to, in which case we tell the Controller first unless the law forbids it.
The Controller also instructs us to run blacklist, lost/stolen, repeat-order and payment-risk checks on every order and to hold or refuse orders that fail them. For the following we act as an independent controller, not as the Controller’s processor: our own security and sign-in records, fraud and abuse prevention across the platform, accounting and tax records, and disclosures to carriers, manufacturers or law enforcement about a device reported lost, stolen or obtained by fraud. Those uses are described in our Privacy Policy.
We tell the Controller at once if, in our opinion, an instruction breaks data-protection law. The details of what is processed are in Annex 1.
Only staff who need Controller Data to do their job have access to it, under a duty of confidentiality, and only through role-based permissions in the admin. We do not use Controller Data for our own purposes, do not sell it, and do not combine it with other customers’ data except for the platform-wide blacklist and fraud checks described in section 2 and for aggregate, anonymous statistics.
We apply the technical and organizational measures in Annex 2, review them when the service changes, and keep them appropriate to the risk, the state of the art and the nature of the data. The Controller is responsible for the security of its own systems, accounts, passwords and API keys, and for what its staff submit.
Each sub-processor that acts for us (hosting, network, email, AI) is bound by written data-protection terms consistent with this agreement, and we remain responsible for its performance. The Controller gives general authorization for the sub-processors in Annex 3. We publish changes to that list on this page at least 14 days before a new sub-processor of that kind handles Controller Data; the Controller may object in writing within that time on reasonable data-protection grounds, and if we cannot resolve the objection the Controller may stop using the affected service and close its account without penalty.
The suppliers that perform a particular unlock, check or remote service are authorized as a category, because we choose the supplier per order and per service and the list changes often. For them the 14-day notice does not apply; instead, on request we give the Controller the current named list (names, locations, contact details) under a confidentiality undertaking, update it on request, and the Controller may object to a named supplier within 14 days of receiving the list; if we cannot resolve the objection, the Controller may stop using the affected service. Each supplier receives only the identifier and the service needed. The payment providers and Telegram are independent services engaged under their own terms; the Controller instructs us to use them for its orders and accepts that they keep the data they receive under those terms.
If a person contacts us directly about data the Controller submitted, we refer them to the Controller unless the law requires us to answer. We help the Controller answer access, correction, deletion, portability, restriction and objection requests within the legal deadlines, using the portal’s own tools where they exist (orders, statements, exports) and by email otherwise.
When the services end or the account closes, we return Controller Data first if asked — by export from the portal or admin during the 14-day export window in the Master Service Agreement, or by email in a common format — and delete it within 30 days after that window or after the Controller’s request, except for records we must keep under accounting, tax or other law (kept only for that purpose and for that time). A supplier that has performed a completed service keeps the identifier under the terms of its contract with us; we instruct deletion on the Controller’s request and tell the Controller if a supplier does not confirm it.
On request, we give the Controller the information needed to show compliance with this agreement — this page, Annexes 1–3, our security description and answers to a reasonable questionnaire. Where that is not enough for a legal requirement, the Controller (or an independent auditor bound by confidentiality) may audit the relevant parts of our processing once in any 12 months, on 30 days’ notice, during business hours, without disrupting the service, at the Controller’s cost; the parties agree the scope in advance and the Controller receives the findings.
We process data in the United States and our sub-processors may be elsewhere. For Controller Data that is subject to the GDPR, the UK GDPR or the Swiss FADP, the EU Standard Contractual Clauses (Decision 2021/914) are incorporated into this agreement between the Controller as data exporter and UnlockMyIMEI as data importer: Module Two (controller to processor), or Module Three (processor to processor) where the Controller itself acts as a processor for its own business customers; with the Docking Clause, option 2 of clause 9 (general authorization, 14 days), Irish law and courts, and the UK International Data Transfer Addendum and Swiss adjustments as applicable. Annexes 1 and 2 serve as the Clauses’ Annex I and II; Annex 3 and the named supplier list provided under section 5 serve as Annex III.
The Clauses are concluded on the date we approve the Controller’s account (or, for a hosted copy, the date of the order confirmation). For the Controller, the business name, address and contact email entered in the account form Annex I.A, with the role “data exporter”; for us, UnlockMyIMEI, Florida, United States, with the contact address below, role “data importer”. The competent supervisory authority under Clause 13 is the authority of the EU Member State where the Controller is established or, for a Controller outside the EU, the Irish Data Protection Commission. On request we give the Controller the information it needs for its transfer assessment under Clause 14. Where another lawful transfer mechanism applies, it takes precedence.
Each party is liable for its own breach of data-protection law and of this agreement, subject to the limitation of liability in the Terms of Service or the Master Service Agreement, whichever governs the account — except that nothing limits liability that the law does not allow to be limited. This agreement lasts as long as we process Controller Data and ends when section 8 has been completed.
If this agreement conflicts with the Terms or the MSA on a data-protection matter, this agreement wins; the Standard Contractual Clauses win over everything where they apply.
| Subject matter | Phone unlocking, IMEI/serial checks and remote device services ordered by the Controller for its customers; account, balance and statement management; the hosted operation of a copy of this website where the Controller bought one. |
|---|---|
| Duration | For as long as the Controller has an account or hosted service, plus the retention periods in section 8. |
| Nature and purpose | Receiving device identifiers and service requests; sending them to the supplier or carrier process that performs the service; receiving and delivering results; verification of reported results; invoicing and statements; support; the checks in section 2. |
| Categories of data | Device identifiers (IMEI, serial number, model, carrier, country, lock and blacklist status); order details and results; the Controller’s staff contact details (names, emails, phone numbers, usernames, sign-in records); where the Controller submits them, its customers’ email addresses or names for result delivery; payment references. No special categories of data are intended; the Controller must not submit any. |
| Data subjects | The Controller’s customers (device owners) and the Controller’s own staff and representatives. |
| Frequency | Continuous, as orders are placed. |
| Retention | As in section 8 of this agreement and section 6 of the Privacy Policy. |
| Transfers to sub-processors | As listed in Annex 3, for the purpose in each row, for the duration of the service. |
| Sub-processor | Purpose | Location |
|---|---|---|
| Hosting provider (virtual private server) | Runs the application and database | United States (Boston) |
| Cloudflare, Inc. | DNS, network security and performance in front of the server | United States (global network) |
| Email delivery provider | Sends transactional emails (results, statements, alerts) | United States |
| Anthropic, PBC | Generates the assistant’s replies from the chat text | United States |
| Unlock, IMEI-data and remote-service suppliers (engaged per service) | Perform the ordered service with the device identifier | Named list provided to the Controller on request under confidentiality; that list is part of Annex III of the Standard Contractual Clauses |
Independent services the Controller instructs us to use, under their own terms (not sub-processors acting for us): PayPal, Inc. and the payment rails the Controller chooses (independent controllers of payment data); Telegram FZ-LLC for the updates a client links; the public blockchains a crypto payment is written to.
Data-protection matters for wholesale, API and hosted-copy clients: support@unlockmyimei.com (write “DPA” in the subject). A countersigned copy of this agreement or of the Standard Contractual Clauses, or the named supplier list under confidentiality: sales@unlockmyimei.com. All legal documents are on the Legal page.
Ask us in the chat — the assistant answers 24/7 and the team replies within 1 business day.