Privacy Policy
Last updated July 17, 2026
How Auroranexis AI Solutions processes personal data when you use the Auroranexis B2B SaaS platform.
Last updated July 17, 2026
How Auroranexis AI Solutions processes personal data when you use the Auroranexis B2B SaaS platform.
This Privacy Policy applies to workspace users, invited team members, and authorized client portal users of the Auroranexis platform. Our services are offered exclusively to business customers (entrepreneurs within the meaning of § 14 BGB). This policy describes processing under the GDPR and applicable German data protection law.
We process: account and profile data (name, email, role, organization); operational data you enter (clients, reports, risks, incidents, knowledge, automation configurations); usage, audit, and security logs; billing and subscription identifiers processed via FastSpring, our current Merchant of Record (historical subscriptions purchased before our FastSpring transition were processed via Paddle); connector and integration tokens (stored encrypted); support communications; and, where enabled, inputs/outputs for AI-assisted features.
Processing occurs to provide the SaaS contract (Art. 6(1)(b) GDPR), for billing and account administration (Art. 6(1)(b) and (1)(f) GDPR), for security and fraud prevention (Art. 6(1)(f) GDPR), for compliance with legal obligations (Art. 6(1)(c) GDPR), and — where applicable — based on your consent for optional analytics or marketing (Art. 6(1)(a) GDPR). Where you act as controller for your clients' data, we process on your instructions as processor (see our DPA).
We retain personal data for the duration of the subscription and as required for support, billing records, security logs, and legal retention obligations. Deletion or return of customer data follows contract termination and your offboarding instructions, subject to statutory retention periods.
We use sub-processors listed on our Sub-processors page (including Supabase, Vercel, FastSpring, Resend, and optional AI providers when enabled; Paddle processed historical transactions predating our FastSpring transition). Transfers outside the EEA, if any, rely on appropriate safeguards such as Standard Contractual Clauses. Material sub-processor changes are communicated to workspace administrators with reasonable notice.
Data subjects may have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority. Workspace administrators can manage GDPR requests in the Compliance center where available. Contact us at legal@auroranexis.com. We respond within statutory timeframes.
On the public website, optional analytics tools (such as Plausible, Microsoft Clarity, or PostHog where configured) load only if you grant analytics consent. Marketing conversion tools (such as GA4 where explicitly enabled) load only if you grant marketing consent. You can change preferences via the cookie banner or footer link. Inside the authenticated application, operational logging and security monitoring may occur separately as described in this policy and our Security Policy.
We implement technical and organizational measures described in our Security Policy, including encryption in transit, access controls, tenant isolation, and audit logging.
Data protection inquiries: legal@auroranexis.com. Product support: support@auroranexis.com. Security reports: security@auroranexis.com.