1. Controller
The data controller is Evosolve Korlátolt Felelősségű Társaság (Evosolve Kft.), trading as Auro AI. Registered seat: 6722 Szeged, Kálvária sugárút 19., Hungary. Company registration number (cégjegyzékszám): 06-09-024422 (registering court: Szegedi Törvényszék Cégbírósága). Tax number (adószám): 26344465-2-06. EU VAT: HU26344465. Managing director: Van Der Walt Johannes Lodewicus. Contact: [email protected]. For data-protection requests you can also use auroai.eu/privacy/request.
2. Data We Collect
We collect name, email address, company name, phone number, and website domain. You provide these voluntarily through our contact form or client portal. We also collect service usage data through server logs. On our public marketing website, we also collect anonymous, aggregate visit statistics for every visitor (page, language, referrer domain, campaign tags, device type — never tied to an identifiable person), and, only if you accept our cookie banner, more detailed on-site usage analytics (clicks, scrolling, and similar interaction patterns) linked to a random, anonymous browser identifier — never your name or anything you type into a form. See the retention table below for how long this is kept; consent for the detailed tier is withdrawable at any time via the cookie banner. If you are a paying client, we also process customer conversations that go through our AI (chat widget messages, WhatsApp messages, email bodies) and any third-party data you explicitly connect (see Section 8).
3. Purpose & Legal Basis
Data is processed for the purpose of providing B2B services. Legal basis: contract performance (Art. 6(1)(b) GDPR) and legitimate interest (Art. 6(1)(f) GDPR).
4. Data Retention
We keep personal data only for as long as we need it. Specific retention periods by data type:
- Client account data (name, email, company, billing info): retained for the duration of the contract. Deleted within 30 days of account closure or cancellation, except where the law requires longer retention (see billing records below).
- Billing & invoice records: retained for 8 years, as required by the Hungarian Accounting Act (Act C of 2000, §169). This applies to invoices, receipts, payment records, and VAT documentation. This is a legal requirement, not something we can adjust.
- Customer conversation records (chat transcripts, WhatsApp messages, email bodies): retained for the life of the client's subscription plus 90 days for dispute resolution. After that, they are permanently deleted.
- Customer contact data captured via AI conversations (names, emails, phone numbers of end-customers): follows the same window as conversation records above, unless an end-customer requests earlier deletion via auroai.eu/privacy/request.
- Leads (entries created from "hot-lead" detection): retained for 3 years from last activity, then deleted.
- AI-generated content (posts, newsletter drafts, summaries): retained until the client deletes it, or until 90 days after the subscription ends.
- Knowledge base docs uploaded by a client: retained until the client deletes them from their dashboard. Chunks and embeddings expire at the same time.
- OAuth tokens & third-party integration data (Google Calendar, Outlook, Zoom, Meta, LinkedIn, Slack, etc.): cached data and tokens are deleted within 30 days of disconnecting the integration.
- Server logs & usage metrics (API call records, error logs, rate-limit counters): retained for 12 months, then deleted on a rolling basis.
- Marketing website analytics (aggregate visit statistics, and, only for visitors who accept our cookie banner, detailed on-site interaction data): retained for 12 months, then deleted on a rolling basis, same as the server logs above. You can withdraw consent for the detailed tier at any time via the cookie banner; the aggregate statistics contain no identifier to withdraw from.
- Erasure audit trail: when we delete data at your request, we keep a minimal non-PII record (hashed email, timestamp, row count) indefinitely. This is regulatory proof that the erasure happened, and it is itself required by Article 5(2) of the GDPR (accountability principle). It contains no personal data, only a one-way hash.
Retention is enforced by an automated daily sweep. Once a period expires, data is permanently deleted. It cannot be recovered.
5. Your Rights
Under GDPR you have the right to access, rectify, erase, restrict, or port your data. Contact [email protected] to exercise these rights.
6. Data Location
All primary data is stored on servers within the European Union (Hetzner, Germany/Finland). Some AI processing is carried out by sub-processors outside the EU (see Section 9) under appropriate safeguards (EU-US Data Privacy Framework and/or Standard Contractual Clauses).
7. AI Disclosure
In compliance with EU AI Act 2024/1689, we disclose that some of our services use AI systems. AI assistants deployed by Auro AI will identify themselves as AI to end users.
8. Third-Party Integrations You Connect
Our clients can optionally connect third-party accounts (such as their Google Calendar) to Auro AI so that our AI assistant can perform tasks on their behalf. When you authorise such an integration, we store an encrypted access token and use it only to deliver the specific feature you connected it for. Below are the integrations we currently support and exactly what data we access:
8.1 Google Calendar
When a client of ours connects their Google Calendar to Auro AI, we request the following OAuth scopes:
- View events on all your calendars (
https://www.googleapis.com/auth/calendar.readonly): so our AI can read your availability the moment a customer tries to book with you, and only offer slots that are actually free. - View and edit events on all your calendars (
https://www.googleapis.com/auth/calendar.events): so when a customer completes a booking, we create the appointment as a real event in your Google Calendar and add the customer as an attendee so they get a native Google invite. We also delete the event if the customer later cancels. - Your email and basic profile (
userinfo.email,userinfo.profile): used only once, at connect time, to label the connection in your dashboard.
How we use Google user data, per the Google API Services User Data Policy Limited Use requirements:
- Google user data we obtain through the Google APIs is used only to provide the features described above: showing real availability to your customers, and creating and deleting bookings in your calendar.
- We do not transfer Google user data to third parties, except when necessary to provide these features, to comply with applicable law, or as part of a merger or acquisition with prior notice to users.
- We do not use Google user data for advertising, of any kind.
- We do not let staff read your Google user data, unless you have given explicit consent for a specific case, it is necessary for security reasons (such as investigating abuse), or we are legally required to.
- We do not use Google user data to develop, improve, or train general AI or machine learning models. The AI works per conversation, on live retrieval, and never feeds calendar contents into any training pipeline.
- We access calendar contents only during active customer booking conversations. We do not store or index them in our database. We keep only the resulting booking records (start time, end time, customer name and contact), so we can show you your upcoming bookings in the dashboard.
- OAuth access tokens and refresh tokens are stored encrypted at rest (AES-256-GCM) on our EU-based infrastructure. On disconnect, all tokens and cached data are deleted within 30 days.
- You can revoke Auro AI's access at any time. Disconnect inside your Auro AI dashboard, or go directly to your Google account at myaccount.google.com/permissions.
Auro AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
9. Sub-Processors
Auro AI uses the following sub-processors to deliver the service. We have a Data Processing Agreement (DPA) with each. Transfers to US-based providers rely on the EU-US Data Privacy Framework (DPF) where the provider is certified, and on Standard Contractual Clauses (SCCs) otherwise; the specific mechanism in force for each provider is available on request.
| Provider | Purpose | Location | Transfer basis |
|---|---|---|---|
| Anthropic (Claude) | AI conversation + content generation | USA | SCCs |
| Google Cloud (Gemini, Imagen, Places, Calendar, Drive) | AI embeddings + image generation + maps + calendar + file sync | EU (Gemini) / USA (Imagen, Places) | EU-US DPF and/or SCCs |
| Microsoft (Graph, Azure AD) | Outlook / Teams / M365 integration | EU (tenant-bound) | EU-US DPF and/or SCCs |
| Meta (WhatsApp, FB, IG) | Messaging + social publishing | USA / Ireland | EU-US DPF and/or SCCs |
| Social publishing | Ireland / USA | EU-US DPF and/or SCCs | |
| Zoom | Video meeting creation | EU (Frankfurt) | EU |
| Revolut | AI meeting notetaker bot | EU (Frankfurt) | EU |
| Hetzner Online | Payment processing | Lithuania / Ireland | EU |
| Slack, Notion, HubSpot, Jira, Stripe, Shopify, Zapier | Server hosting + DB + email delivery infrastructure | Germany / Finland | EU-US DPF and/or SCCs |
We update this list when we add or remove sub-processors. We notify active clients of material changes by email, with at least 30 days notice. If you have specific residency requirements (for example healthcare or legal), contact [email protected]. We can discuss an EU-only deployment.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email to active clients. The "Last updated" date at the top of this page always reflects the latest revision.