Aurora LogoAurora
Home Impressum Terms

Privacy Policy

Datenschutzerklärung — Last updated: 24 July 2026

1. Controller / Verantwortlicher

Aurora AI Solutions Studio UG (haftungsbeschränkt)

Friedhofstr. 10, 70191 Stuttgart, Germany

E-Mail: info@helloaurora.ai

Telefon: +49 172 9557922

Data Protection Contact: Sasa Stanojevic — privacy@helloaurora.ai

2. Overview

Aurora AI Solutions Studio UG ("Aurora," "we," "us") operates Aurora CapacityOS — a managed service in which AI-agent workflows perform defined routine operations for service firms (reading incoming emails and documents, checking them against the customer's own records with cited sources, and preparing reply drafts), always with explicit human approval before anything is sent. This policy covers:

  • the website helloaurora.ai (Section 3),
  • business contact, contracting, and billing (Section 4), and
  • the operation of Aurora CapacityOS for our customers (Section 5).

We process personal data in compliance with the EU General Data Protection Regulation (GDPR/DSGVO), the German Federal Data Protection Act (BDSG), the German Digital Services Act (DDG), and the Telecommunications Digital Services Data Protection Act (TDDDG).

3. Visiting helloaurora.ai

3.1 Hosting & server logs

The website is hosted by Vercel Inc. (compute in Frankfurt, Germany region; global content delivery network for static assets). When you visit, the hosting infrastructure processes the technical data your browser transmits (IP address, browser type, requested page, timestamp) to deliver the site and protect it against abuse. These logs are short-lived and used for security and operations only. Legal basis: Art. 6(1)(f) GDPR — legitimate interest in operating a secure website.

On the start page we additionally use Vercel Web Analytics, a cookie-free page-view measurement by the same hosting provider. It counts visits, page paths, and referrer sources in aggregated form only: no cookies, no cross-site tracking, and no persistent visitor identifier (an anonymised session hash is discarded within 24 hours). We use these aggregate numbers to understand which pages are read. Legal basis: Art. 6(1)(f) GDPR — legitimate interest in measuring aggregate site usage without tracking individuals.

3.2 Fonts

Legal pages use fonts self-hosted on our own domain. The start page additionally loads fonts from Bunny Fonts (BunnyWay d.o.o., Slovenia/EU) — an EU-based, GDPR-focused font service that does not set cookies or store identifiable visitor logs according to its provider. Legal basis: Art. 6(1)(f) GDPR.

3.3 Cookies & consent

The website itself sets no third-party tracking cookies and uses no cookie-based analytics — page-view measurement happens cookie-free via our hosting provider (see 3.1). Your language choice and your cookie-consent decision are stored locally in your browser (localStorage). The consent banner lets you accept or reject optional categories; essential storage (consent state, language) works without consent (§ 25(2) TDDDG).

3.4 Demo videos (YouTube, click-to-load)

Demo recordings on the start page are embedded via YouTube's extended privacy mode (youtube-nocookie.com) and load only after you press play. Until you click, no request is sent to YouTube/Google. When you press play, YouTube (Google Ireland Ltd. / Google LLC) receives your IP address and device information under Google's own privacy policy, and may transfer data to the United States (EU-US Data Privacy Framework). Legal basis: Art. 6(1)(a) GDPR — consent expressed by starting the player.

3.5 Booking a demo (Calendly)

The "Book a demo" buttons link to our scheduling page at Calendly LLC (USA; EU-US Data Privacy Framework and SCCs). If you book there, Calendly processes the name, email address, and time slot you enter, and shares them with us to hold the meeting. You may alternatively email info@helloaurora.ai to schedule without Calendly. Legal basis: Art. 6(1)(b) GDPR — pre-contractual steps at your request.

3.6 KI-Check

The self-assessment at /ki-check runs entirely in your browser. Your answers are not transmitted to Aurora or any third party.

3.7 Contact by email

If you email us, we process your address and message content to answer you. Legal basis: Art. 6(1)(b) GDPR (pre-)contractual communication, or Art. 6(1)(f) GDPR for general enquiries.

4. Contracting & Billing

  • Offers and contracts. For enquiries, offers, and engagements we process business contact data (name, role, company, email, phone) and contract data (scope, fees, correspondence). Legal basis: Art. 6(1)(b) GDPR.
  • Payments via Stripe. Recurring fees are processed by Stripe (Stripe Payments Europe Ltd., Ireland, and Stripe Inc., USA — EU-US Data Privacy Framework and SCCs). Aurora does not store credit-card or bank-account numbers; we receive billing status, customer reference, and payment timestamps.
  • Invoicing and banking. Invoices and quotes are issued via our business-banking provider Qonto (Olinda SAS, France/EU); funds are held with Qonto and, for non-EUR currencies, Wise (EU). These institutions act under their own regulatory responsibilities.
  • Retention. Billing and contract records are retained for the statutory periods of German commercial and tax law (up to 10 years, § 147 AO, § 257 HGB). Legal basis: Art. 6(1)(c) GDPR.

5. Operating Aurora CapacityOS

When Aurora operates workflows for a customer, Aurora processes personal data on that customer's behalf as a processor under a data processing agreement (Auftragsverarbeitung, Art. 28 GDPR) — see our Data Processing Agreement. In brief:

  • What is processed: incoming emails and attachments addressed to the agreed workflow mailboxes (e.g. a claims or document-intake address), the customer's reference documents indexed for retrieval, the drafts the workflow prepares, the step-by-step run logs with cited sources, approval decisions, and the standing rules learned from the customer's corrections.
  • Who the data concerns: the customer's staff (reviewers) and the customer's own clients and correspondents whose messages and documents flow through the agreed workflow.
  • AI processing: message and document content is processed by our model providers — Anthropic (primary) and OpenAI (text embeddings for document retrieval; configured fallback) — under our own agreements with them. Per their API terms, neither provider uses our API data to train their models. See the sub-processor list for details and transfer safeguards.
  • Where it runs: the workflow engine runs on servers of Hetzner Online GmbH in Germany; databases (including the document index) are hosted by Supabase in the EU (Frankfurt). Where the engagement uses Aurora-provided workflow mailboxes, these run on Google Workspace (Google Ireland Ltd.); where workflows operate on the customer's own systems (e.g. the customer's Microsoft 365 tenant) or involve no email, they run under the customer's own access grant instead. Model API calls to Anthropic/OpenAI are the only processing step that leaves the EU by design.
  • Human approval (Art. 22 GDPR): no client-facing message is sent without explicit approval by a human reviewer designated by the customer. The workflows prepare drafts; they make no solely automated decisions with legal or similarly significant effect.
  • AI transparency (EU AI Act Art. 50): messages sent through the workflows carry machine-readable markers identifying them as AI-assisted and human-reviewed.

For data subjects whose messages are processed inside a customer's workflow, the customer is the controller; please direct rights requests to the firm you corresponded with — we support our customers in answering them (Art. 28(3)(e) GDPR).

6. Recipients & Sub-processors

The complete, canonical list of Aurora's sub-processors — including purpose, location, and transfer safeguards for each — is published at helloaurora.ai/sub-processors and forms part of this policy. We disclose personal data to authorities only where legally required.

7. International Data Transfers

Aurora's infrastructure is EU-based by design (Hetzner Germany, Supabase Frankfurt, Vercel Frankfurt compute, Google Ireland). Transfers to providers in the United States (Anthropic, OpenAI, Stripe, Calendly, YouTube on click, Vercel's global CDN) are safeguarded by the EU-US Data Privacy Framework where the provider is certified, and by the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) with supplementary measures (TLS 1.3 in transit, encryption at rest, data minimisation).

8. Your Rights Under GDPR

  • Access (Art. 15): request a copy of the personal data we hold about you.
  • Rectification (Art. 16): request correction of inaccurate data.
  • Erasure (Art. 17): request deletion, subject to statutory retention duties.
  • Restriction (Art. 18): request restricted processing.
  • Data portability (Art. 20): receive your data in a structured, machine-readable format.
  • Objection (Art. 21): object to processing based on legitimate interest.
  • No solely automated decisions (Art. 22): the human approval gate is the operative safeguard — no outbound action is taken without human approval.
  • Withdraw consent (Art. 7(3)): withdraw any consent (e.g. the video-player consent) at any time with effect for the future.

To exercise these rights, email privacy@helloaurora.ai. We respond within 30 days; if we need longer, we tell you within that period. If your data was processed inside one of our customers' workflows, we will route or support your request as described in Section 5.

9. Retention

  • Enquiries: kept as long as needed to handle the matter, then deleted in regular reviews.
  • Contract, billing, and tax records: statutory periods (up to 10 years, § 147 AO / § 257 HGB).
  • Customer workflow data (emails, documents, drafts, run logs, learned rules): retained for the duration of the engagement as part of the contracted service record; on termination, returned or deleted per the DPA (within 30 days of the request, subject to statutory retention duties).
  • Hosting logs: short-lived, per the hosting providers' security-log cycles.

10. Security

  • All data in transit is encrypted (HTTPS / TLS 1.3); data at rest is encrypted by our hosting providers (AES-256).
  • Strict per-customer separation in the workflow engine and databases (row-level security; per-firm isolation verified by automated tests).
  • Access on a least-privilege basis; secrets kept in encrypted environment configuration, never in source code.
  • Every workflow run is logged step by step; approval decisions are recorded — the audit trail is part of the service itself.
  • Continuous automated monitoring and alerting on the production system.

11. Children's Privacy

Our services are directed at businesses and not intended for individuals under 16. We do not knowingly collect personal data from children; if we become aware of such data, we delete it promptly.

12. Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority. The competent authority for Aurora is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg

Königstraße 10a, 70173 Stuttgart

Website: www.baden-wuerttemberg.datenschutz.de

13. Changes to This Policy

We update this policy when our services or legal requirements change. Material changes are communicated to active customers by email. The "Last updated" date above reflects the most recent revision.

Aurora LogoAurora
Home Impressum Privacy Terms DPA Sub-processors Refund Policy Contact
© 2026 Aurora AI Solutions Studio UG (haftungsbeschränkt) · Stuttgart, Germany · Amtsgericht Stuttgart HRB 805284 · USt-IdNr. DE463430205