Datenschutzerklärung — Last updated: 24 July 2026
Aurora AI Solutions Studio UG (haftungsbeschränkt)
Friedhofstr. 10, 70191 Stuttgart, Germany
E-Mail: info@helloaurora.ai
Telefon: +49 172 9557922
Data Protection Contact: Sasa Stanojevic — privacy@helloaurora.ai
Aurora AI Solutions Studio UG ("Aurora," "we," "us") operates Aurora CapacityOS — a managed service in which AI-agent workflows perform defined routine operations for service firms (reading incoming emails and documents, checking them against the customer's own records with cited sources, and preparing reply drafts), always with explicit human approval before anything is sent. This policy covers:
We process personal data in compliance with the EU General Data Protection Regulation (GDPR/DSGVO), the German Federal Data Protection Act (BDSG), the German Digital Services Act (DDG), and the Telecommunications Digital Services Data Protection Act (TDDDG).
The website is hosted by Vercel Inc. (compute in Frankfurt, Germany region; global content delivery network for static assets). When you visit, the hosting infrastructure processes the technical data your browser transmits (IP address, browser type, requested page, timestamp) to deliver the site and protect it against abuse. These logs are short-lived and used for security and operations only. Legal basis: Art. 6(1)(f) GDPR — legitimate interest in operating a secure website.
On the start page we additionally use Vercel Web Analytics, a cookie-free page-view measurement by the same hosting provider. It counts visits, page paths, and referrer sources in aggregated form only: no cookies, no cross-site tracking, and no persistent visitor identifier (an anonymised session hash is discarded within 24 hours). We use these aggregate numbers to understand which pages are read. Legal basis: Art. 6(1)(f) GDPR — legitimate interest in measuring aggregate site usage without tracking individuals.
Legal pages use fonts self-hosted on our own domain. The start page additionally loads fonts from Bunny Fonts (BunnyWay d.o.o., Slovenia/EU) — an EU-based, GDPR-focused font service that does not set cookies or store identifiable visitor logs according to its provider. Legal basis: Art. 6(1)(f) GDPR.
The website itself sets no third-party tracking cookies and uses no cookie-based analytics — page-view measurement happens cookie-free via our hosting provider (see 3.1). Your language choice and your cookie-consent decision are stored locally in your browser (localStorage). The consent banner lets you accept or reject optional categories; essential storage (consent state, language) works without consent (§ 25(2) TDDDG).
Demo recordings on the start page are embedded via YouTube's extended privacy mode (youtube-nocookie.com) and load only after you press play. Until you click, no request is sent to YouTube/Google. When you press play, YouTube (Google Ireland Ltd. / Google LLC) receives your IP address and device information under Google's own privacy policy, and may transfer data to the United States (EU-US Data Privacy Framework). Legal basis: Art. 6(1)(a) GDPR — consent expressed by starting the player.
The "Book a demo" buttons link to our scheduling page at Calendly LLC (USA; EU-US Data Privacy Framework and SCCs). If you book there, Calendly processes the name, email address, and time slot you enter, and shares them with us to hold the meeting. You may alternatively email info@helloaurora.ai to schedule without Calendly. Legal basis: Art. 6(1)(b) GDPR — pre-contractual steps at your request.
The self-assessment at /ki-check runs entirely in your browser. Your answers are not transmitted to Aurora or any third party.
If you email us, we process your address and message content to answer you. Legal basis: Art. 6(1)(b) GDPR (pre-)contractual communication, or Art. 6(1)(f) GDPR for general enquiries.
When Aurora operates workflows for a customer, Aurora processes personal data on that customer's behalf as a processor under a data processing agreement (Auftragsverarbeitung, Art. 28 GDPR) — see our Data Processing Agreement. In brief:
For data subjects whose messages are processed inside a customer's workflow, the customer is the controller; please direct rights requests to the firm you corresponded with — we support our customers in answering them (Art. 28(3)(e) GDPR).
The complete, canonical list of Aurora's sub-processors — including purpose, location, and transfer safeguards for each — is published at helloaurora.ai/sub-processors and forms part of this policy. We disclose personal data to authorities only where legally required.
Aurora's infrastructure is EU-based by design (Hetzner Germany, Supabase Frankfurt, Vercel Frankfurt compute, Google Ireland). Transfers to providers in the United States (Anthropic, OpenAI, Stripe, Calendly, YouTube on click, Vercel's global CDN) are safeguarded by the EU-US Data Privacy Framework where the provider is certified, and by the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) with supplementary measures (TLS 1.3 in transit, encryption at rest, data minimisation).
To exercise these rights, email privacy@helloaurora.ai. We respond within 30 days; if we need longer, we tell you within that period. If your data was processed inside one of our customers' workflows, we will route or support your request as described in Section 5.
Our services are directed at businesses and not intended for individuals under 16. We do not knowingly collect personal data from children; if we become aware of such data, we delete it promptly.
You have the right to lodge a complaint with a supervisory authority. The competent authority for Aurora is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Königstraße 10a, 70173 Stuttgart
We update this policy when our services or legal requirements change. Material changes are communicated to active customers by email. The "Last updated" date above reflects the most recent revision.