Auftragsverarbeitungsvertrag (AVV) gemäß Art. 28 DSGVO — Last updated: 21 July 2026 · Deutsche Fassung
Language versions. This DPA exists in English and German. For customers seated in Germany the German version prevails; otherwise the English version, unless the Offer states differently. A signed AVV for an engagement prevails over either web version.
Processor: Aurora AI Solutions Studio UG (haftungsbeschränkt)
Friedhofstr. 10, 70191 Stuttgart, Germany · Amtsgericht Stuttgart HRB 805284
E-Mail: info@helloaurora.ai
Data Protection Contact: Sasa Stanojevic — privacy@helloaurora.ai
This Data Processing Agreement ("DPA") is Aurora's standard agreement under Art. 28 GDPR between the customer of Aurora CapacityOS (the "Customer" — the controller) and Aurora AI Solutions Studio UG (haftungsbeschränkt) ("Aurora" — the processor). It governs the personal data Aurora processes on the Customer's behalf when operating the contracted workflows.
It applies together with the Terms and the Customer's engagement Offer. Where the parties sign an individual AVV for an engagement, the signed AVV prevails over this page for that engagement. For personal data Aurora processes for its own purposes — contracting, billing, security, and the website — Aurora acts as an independent controller as described in the Privacy Policy.
Aurora builds and operates AI-agent workflows that perform defined routine operations for the Customer. The processing consists of:
Duration: the term of the engagement (Terms, Section 10). Purpose: performance of the contracted operations — no other use. Aurora does not use the Customer's data, documents, or learned rules to provide services to any other customer, and does not permit its model providers to train on this data (see Section 6).
Incoming correspondence may incidentally contain special-category data (for example, health-related details in an insurance claim). Such data is processed only as an unavoidable part of the mandated workflow, under the same safeguards as all workflow data. The Customer must not mandate a workflow whose primary purpose is the systematic processing of special-category data without a prior written agreement with Aurora covering the additional safeguards.
The Customer authorises the following sub-processors for Aurora CapacityOS. The canonical, always-current list — including links to each provider's own DPA — is published at helloaurora.ai/sub-processors.
| Sub-processor | Location | Purpose |
|---|---|---|
| Hetzner Online GmbH | Germany (EU) | Hosting of the workflow engine (compute; processes workflow emails, documents, and run data) |
| Supabase, Inc. | EU (AWS eu-central-1, Frankfurt) | Databases: run records, approval items, learned rules, document retrieval index; reviewer authentication |
| Google Ireland Ltd. (Google Workspace) | EU/EEA; possible transfers to Google LLC (USA) under DPF/SCCs | Aurora-provided workflow mailboxes — engaged only where the engagement routes workflow email through Aurora-provided addresses; not used where workflows run on the Customer's own mail system or involve no email |
| Vercel Inc. | Compute: Frankfurt (fra1); global CDN; USA entity under DPF/SCCs | Hosting of the approval surface (cockpit) web application |
| Anthropic PBC (Claude API) | USA (DPF/SCCs) | Primary model provider: reading, extraction, checks, and drafting within workflow runs. No training on API data per Anthropic's commercial terms. |
| OpenAI, L.L.C. | USA (DPF/SCCs) | Text embeddings for document retrieval; configured fallback model provider. No training on API data per OpenAI's API terms. |
| Stripe (Stripe Payments Europe Ltd. / Stripe, Inc.) | Ireland (EU) / USA (DPF/SCCs) | Payment processing for subscription billing (billing contact and payment status only — no workflow content) |
Changes: Aurora notifies the Customer at least 30 days before a new sub-processor begins processing Customer personal data. The Customer may object on reasonable data-protection grounds within 14 days of the notice; if no workable alternative exists, either party may terminate the affected engagement as of the change date.
Not sub-processors: systems the Customer or its end-clients grant access to (their own mailboxes and platforms) remain the granting party's own controller relationships; Aurora processes only the data reachable under the grant. Banking institutions (Qonto, Wise) act as independent controllers. Aurora's uptime monitoring receives no personal data.
Processing is EU-based except for model API calls and the US-entity services listed in Section 6. Transfers to the United States rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR), with supplementary measures (encryption in transit and at rest, data minimisation — model calls carry the case content needed for the step, not the Customer's full data store).
During the engagement, the Customer can request deletion of individual cases or documents at any time. After the end of the engagement, Aurora — at the Customer's choice — returns the Customer's workflow data in a common machine-readable format and/or deletes it, within 30 days of the request, unless statutory retention duties require longer storage. Deletion is propagated to sub-processors. Aurora confirms completed deletion in text form on request.
Aurora provides the Customer, on request, with the information necessary to demonstrate compliance with Art. 28 GDPR — including its current technical and organisational measures, sub-processor agreements' relevant assurances, and run-level audit trails for the Customer's own workflows. Audits (including inspections) by the Customer or a mandated auditor are possible with reasonable notice, during business hours, without disrupting other customers' operations; Aurora may satisfy audit requests through meaningful documentation, certifications of its infrastructure providers, or a remote review session.
Aurora notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, with the information required by Art. 33(3) GDPR as it becomes available (nature of the breach, categories and approximate numbers affected, likely consequences, measures taken). The notification duty toward the supervisory authority and data subjects (Art. 33/34) lies with the Customer as controller; Aurora supports the Customer in meeting it.
Contact. For questions about this DPA, to conclude a signed AVV for an engagement, or to exercise data-subject rights, write to privacy@helloaurora.ai.