Aurora LogoAurora
Home Privacy Terms

Data Processing Agreement

Auftragsverarbeitungsvertrag (AVV) gemäß Art. 28 DSGVO — Last updated: 21 July 2026 · Deutsche Fassung

Language versions. This DPA exists in English and German. For customers seated in Germany the German version prevails; otherwise the English version, unless the Offer states differently. A signed AVV for an engagement prevails over either web version.

1. Parties & Scope

Processor: Aurora AI Solutions Studio UG (haftungsbeschränkt)

Friedhofstr. 10, 70191 Stuttgart, Germany · Amtsgericht Stuttgart HRB 805284

E-Mail: info@helloaurora.ai

Data Protection Contact: Sasa Stanojevic — privacy@helloaurora.ai

This Data Processing Agreement ("DPA") is Aurora's standard agreement under Art. 28 GDPR between the customer of Aurora CapacityOS (the "Customer" — the controller) and Aurora AI Solutions Studio UG (haftungsbeschränkt) ("Aurora" — the processor). It governs the personal data Aurora processes on the Customer's behalf when operating the contracted workflows.

It applies together with the Terms and the Customer's engagement Offer. Where the parties sign an individual AVV for an engagement, the signed AVV prevails over this page for that engagement. For personal data Aurora processes for its own purposes — contracting, billing, security, and the website — Aurora acts as an independent controller as described in the Privacy Policy.

2. Subject Matter, Nature & Purpose of Processing

Aurora builds and operates AI-agent workflows that perform defined routine operations for the Customer. The processing consists of:

  • receiving and reading incoming emails and attachments addressed to the agreed workflow mailboxes (or reachable under access the Customer grants);
  • extracting the relevant case facts from those messages and documents;
  • checking them against the Customer's own reference material (documents the Customer provides, indexed for retrieval), with named, cited checks;
  • preparing reply drafts and internal notes for the Customer's review;
  • presenting each prepared action at a human approval gate and — only upon approval by the Customer's designated reviewer — sending the approved reply to the named recipient;
  • recording step-by-step run logs, approval decisions, and the standing rules learned from the Customer's corrections, as the service's audit trail.

Duration: the term of the engagement (Terms, Section 10). Purpose: performance of the contracted operations — no other use. Aurora does not use the Customer's data, documents, or learned rules to provide services to any other customer, and does not permit its model providers to train on this data (see Section 6).

3. Categories of Data Subjects & Personal Data

Data subjects

  • the Customer's staff and designated reviewers;
  • the Customer's own clients ("end-clients") and other correspondents whose emails and documents flow through the agreed workflows;
  • persons mentioned in submitted documents (e.g. parties named in a claim, an invoice, or a financing file).

Categories of personal data

  • communication data: sender/recipient addresses, subject lines, message bodies, timestamps;
  • document content submitted by correspondents: e.g. claim descriptions and photos, invoices and receipts, financing and income documents — depending on the contracted workflow;
  • the Customer's reference material (policy documents, checklists, house rules) to the extent it contains personal data;
  • prepared drafts, run logs with cited sources, approval decisions (which reviewer decided what, when), and learned rules;
  • reviewer account data for the approval surface (name, email, authentication data).

Special categories (Art. 9 GDPR)

Incoming correspondence may incidentally contain special-category data (for example, health-related details in an insurance claim). Such data is processed only as an unavoidable part of the mandated workflow, under the same safeguards as all workflow data. The Customer must not mandate a workflow whose primary purpose is the systematic processing of special-category data without a prior written agreement with Aurora covering the additional safeguards.

4. Aurora's Obligations as Processor

  • Documented instructions (Art. 28(3)(a)): Aurora processes personal data only on the Customer's documented instructions — constituted by the engagement Offer, the agreed workflow configuration, and each approval given at the gate (each approval is the Customer's instruction to send). Aurora informs the Customer if it considers an instruction to violate data protection law.
  • Confidentiality (Art. 28(3)(b)): all persons authorised to process the data are bound to confidentiality.
  • Security (Art. 28(3)(c), Art. 32): see Section 5.
  • Sub-processors (Art. 28(3)(d)): see Section 6.
  • Data subject rights (Art. 28(3)(e)): Aurora supports the Customer with appropriate technical and organisational measures in answering data-subject requests (access, rectification, erasure, restriction, portability, objection). Requests reaching Aurora directly are forwarded to the Customer without undue delay.
  • Assistance (Art. 28(3)(f)): Aurora assists the Customer, taking into account the nature of the processing and the information available to it, with security, breach notification (Art. 33/34), data protection impact assessments (Art. 35), and prior consultation (Art. 36).
  • Deletion/return (Art. 28(3)(g)): see Section 8.
  • Audit (Art. 28(3)(h)): see Section 9.

5. Technical & Organisational Measures (Art. 32)

  • EU hosting by design: the workflow engine runs on Hetzner Online GmbH servers in Germany; databases (including the retrieval index) are hosted by Supabase in the EU (Frankfurt); where the engagement uses Aurora-provided workflow mailboxes, these run on Google Workspace (Google Ireland Ltd.) — engagements on the Customer's own systems use the Customer's platform under the Customer's grant. Only model API calls (Section 6) leave the EU by design.
  • Encryption: TLS 1.3 in transit; encryption at rest at the hosting providers (AES-256).
  • Separation: strict per-customer (per-firm) isolation in the engine and databases; row-level security on database access; isolation verified by automated tests.
  • Access control: least-privilege access; approval-surface access limited to the Customer's designated reviewers; administrative access secured by key-based authentication; secrets in encrypted environment configuration, never in source code.
  • Traceability: every workflow run is logged step by step; every outward action requires a recorded human approval naming the recipient; the audit trail is part of the delivered service.
  • Reliability: continuous automated monitoring with alerting (including an independent dead-man's watchdog on the production engine); documented restore procedures; timeouts and recovery paths on all external connections so a failure surfaces visibly instead of losing a case silently.
  • Input handling: incoming attachments are validated before processing; content of incoming mail is treated as case data, never as instructions to the system (prompt-injection resistance is explicitly tested).

6. Sub-processors

The Customer authorises the following sub-processors for Aurora CapacityOS. The canonical, always-current list — including links to each provider's own DPA — is published at helloaurora.ai/sub-processors.

Sub-processor Location Purpose
Hetzner Online GmbH Germany (EU) Hosting of the workflow engine (compute; processes workflow emails, documents, and run data)
Supabase, Inc. EU (AWS eu-central-1, Frankfurt) Databases: run records, approval items, learned rules, document retrieval index; reviewer authentication
Google Ireland Ltd. (Google Workspace) EU/EEA; possible transfers to Google LLC (USA) under DPF/SCCs Aurora-provided workflow mailboxes — engaged only where the engagement routes workflow email through Aurora-provided addresses; not used where workflows run on the Customer's own mail system or involve no email
Vercel Inc. Compute: Frankfurt (fra1); global CDN; USA entity under DPF/SCCs Hosting of the approval surface (cockpit) web application
Anthropic PBC (Claude API) USA (DPF/SCCs) Primary model provider: reading, extraction, checks, and drafting within workflow runs. No training on API data per Anthropic's commercial terms.
OpenAI, L.L.C. USA (DPF/SCCs) Text embeddings for document retrieval; configured fallback model provider. No training on API data per OpenAI's API terms.
Stripe (Stripe Payments Europe Ltd. / Stripe, Inc.) Ireland (EU) / USA (DPF/SCCs) Payment processing for subscription billing (billing contact and payment status only — no workflow content)

Changes: Aurora notifies the Customer at least 30 days before a new sub-processor begins processing Customer personal data. The Customer may object on reasonable data-protection grounds within 14 days of the notice; if no workable alternative exists, either party may terminate the affected engagement as of the change date.

Not sub-processors: systems the Customer or its end-clients grant access to (their own mailboxes and platforms) remain the granting party's own controller relationships; Aurora processes only the data reachable under the grant. Banking institutions (Qonto, Wise) act as independent controllers. Aurora's uptime monitoring receives no personal data.

7. International Transfers

Processing is EU-based except for model API calls and the US-entity services listed in Section 6. Transfers to the United States rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR), with supplementary measures (encryption in transit and at rest, data minimisation — model calls carry the case content needed for the step, not the Customer's full data store).

8. Deletion & Return

During the engagement, the Customer can request deletion of individual cases or documents at any time. After the end of the engagement, Aurora — at the Customer's choice — returns the Customer's workflow data in a common machine-readable format and/or deletes it, within 30 days of the request, unless statutory retention duties require longer storage. Deletion is propagated to sub-processors. Aurora confirms completed deletion in text form on request.

9. Audits & Information Rights

Aurora provides the Customer, on request, with the information necessary to demonstrate compliance with Art. 28 GDPR — including its current technical and organisational measures, sub-processor agreements' relevant assurances, and run-level audit trails for the Customer's own workflows. Audits (including inspections) by the Customer or a mandated auditor are possible with reasonable notice, during business hours, without disrupting other customers' operations; Aurora may satisfy audit requests through meaningful documentation, certifications of its infrastructure providers, or a remote review session.

10. Personal Data Breaches

Aurora notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, with the information required by Art. 33(3) GDPR as it becomes available (nature of the breach, categories and approximate numbers affected, likely consequences, measures taken). The notification duty toward the supervisory authority and data subjects (Art. 33/34) lies with the Customer as controller; Aurora supports the Customer in meeting it.

11. Liability, Term & Governing Law

  • Liability follows Art. 82 GDPR and the liability provisions of the Terms (Section 13).
  • This DPA applies for the duration of the engagement and, for the obligations in Sections 8–10, beyond its end as long as Aurora holds Customer personal data.
  • This DPA is governed by German law. Place of jurisdiction: Stuttgart, Germany (for merchants).

Contact. For questions about this DPA, to conclude a signed AVV for an engagement, or to exercise data-subject rights, write to privacy@helloaurora.ai.

Aurora LogoAurora
Home Impressum Privacy Terms DPA Sub-processors Refund Policy Contact
© 2026 Aurora AI Solutions Studio UG (haftungsbeschränkt) · Stuttgart, Germany · Amtsgericht Stuttgart HRB 805284 · USt-IdNr. DE463430205