Quick summary for the busy reader. This DPA is the contract between you (the data controller — e.g. a business owner using Auro AI) and us (the data processor, Evosolve Kft.). By signing up to, or continuing to use, Auro AI, this DPA forms part of our service agreement. A counter-signed PDF copy is available on request: email [email protected].
1. Parties
Processor: Evosolve Korlátolt Felelősségű Társaság (Evosolve Kft.), a limited liability company registered in Hungary, trading as Auro AI ("Auro AI", "we", "us").
- Registered seat
- 6722 Szeged, Kálvária sugárút 19., Hungary
- Company reg. no.
- 06-09-024422 (cégjegyzékszám)
- Registering court
- Szegedi Törvényszék Cégbírósága
- Tax number
- 26344465-2-06 (adószám)
- EU VAT number
- HU26344465
- Managing director
- Van Der Walt Johannes Lodewicus
- Contact
- [email protected]
Controller: the natural or legal person identified by the email address registered with their Auro AI customer account ("Customer", "you").
2. Subject matter, duration, nature & purpose
Subject: the processing of personal data on behalf of the Customer in connection with the Customer’s use of the Auro AI software-as-a-service (the "Service").
Duration: from account creation until the deletion / return obligations in Section 10 have been completed after termination.
Nature: automated electronic processing on Hetzner infrastructure (Germany / Finland, EU), plus the sub-processors listed at auroai.eu/subprocessors.php.
Purpose: to deliver Auro AI features — CRM, Finance & Accounting, HR, communications inbox, and the AI staff member — to the Customer.
3. Categories of data subjects & types of personal data
Categories of data subjects: the Customer’s employees; the Customer’s end-customers (B2B contacts); the Customer’s suppliers; visitors to the Customer’s web properties when an Auro AI widget is embedded; job applicants where the Customer uses the recruitment module.
Types of personal data:
- Identification: first name, last name, employee/customer ID, email address, phone number, business address, LinkedIn URL.
- Hungarian statutory employment data (HR module only): TAJ-szám, adóazonosító jel, bank account number, marital status, number of dependants, date of birth, home address. Encrypted at rest with AES-256.
- Communications content: chat messages, WhatsApp messages, email bodies, and attachments routed through the inbox module.
- Financial transaction data: invoices, payments, bank statement lines, supplier payment records.
- System usage: session logs, IP address (Cloudflare-resolved), user agent, timestamps, audit-log entries.
We do not process special-category data (Art. 9 GDPR) by default. Sick-leave records (a medical category) are stored only as start/end dates with the leave-type label "sick"; no diagnosis and no clinical detail.
4. Processor’s obligations (Art. 28(3) GDPR)
We undertake to:
- Process only on documented instructions. The instructions consist of (a) this DPA, (b) the Customer’s configuration of the Service via the dashboard, and (c) any individual instruction sent to [email protected]. We will not process for our own purposes; we will not sell Customer data or use it to train AI models. This includes instructions on transfers to a third country unless we are required to transfer by EU or Member State law (in which case we inform the Customer first, unless the law prohibits it).
- Ensure confidentiality. All Auro AI personnel and contractors with access to personal data are bound by written confidentiality obligations.
- Implement appropriate security measures (Art. 32 GDPR). See Annex II below.
- Engage sub-processors only on the same data-protection terms and remain fully liable for them. See Section 6 and /subprocessors.php.
- Assist the Controller with data-subject requests (access, rectification, erasure, restriction, portability, objection), and with obligations under Art. 32–36 (security, breach notification, impact assessments), taking into account the nature of the processing. We will respond within 7 working days of a request from the Customer.
- Notify personal data breaches per Section 8.
- Delete or return data at the end of processing, per Section 10.
- Make available all information needed to demonstrate compliance with Art. 28, and allow for and contribute to audits per Section 9.
5. Customer’s (Controller’s) responsibilities
- Establish a lawful basis under Art. 6 GDPR for processing each category of personal data.
- Obtain valid consent from data subjects where consent is the lawful basis.
- Provide data subjects with the privacy information required by Art. 13/14 GDPR.
- Keep your Auro AI account credentials secure, and use two-factor authentication where offered.
- Not upload special-category (Art. 9) or criminal-conviction (Art. 10) data unless agreed with us in writing beforehand.
6. Sub-processors
The Customer hereby grants general written authorisation for the engagement of sub-processors. The current list is published at auroai.eu/subprocessors.php, and we update it before adding or replacing a sub-processor. You will receive at least 30 days’ notice of changes via the email on file. You may object on reasonable data-protection grounds within that window; if we cannot accommodate your objection, you may terminate the affected part of the contract with a pro-rata refund of pre-paid fees. We remain fully liable to the Customer for the performance of each sub-processor’s obligations.
7. International transfers
EU/EEA storage is the default: all primary data is hosted with Hetzner in Germany / Finland. Where a sub-processor processes personal data outside the EEA (for example Anthropic, Google or NVIDIA in the United States for AI inference), the transfer is governed by an appropriate Chapter V safeguard — the recipient’s certification under the EU–US Data Privacy Framework where it is certified, and/or the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 2 or 3 as applicable) executed between Evosolve Kft. and the sub-processor, together with supplementary measures where needed. The safeguards in force for a given sub-processor are listed at /subprocessors.php and are available on request.
8. Personal data breach notification
We will notify the Customer without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the Customer’s data. The notification will describe: the nature of the breach; the categories and approximate number of data subjects and records concerned; the likely consequences; and the measures taken or proposed. Channel: email to the registered Customer email address, plus a status-page entry at status.auroai.eu. This assists the Customer, as controller, in meeting its own Art. 33/34 obligations.
9. Audits & inspections
We will respond to a Customer audit request once per calendar year by providing (a) our latest internal security review, (b) the most recent penetration-test summary, and (c) responses to a written audit questionnaire. On-site audits are available on 30 days’ written notice, at the Customer’s expense, subject to reasonable confidentiality and scheduling constraints. Audits triggered by a documented breach are not subject to the once-per-year limit.
10. Return / deletion of data at end of processing
On termination of the service contract, the Customer may within 30 days request a full data export (CSV + JSON). After 30 days — or immediately on Customer instruction — we delete all personal data from active systems within 7 days, and from backups within 90 days. Records that we are required by Hungarian law to retain (in particular accounting and invoice records, kept 8 years under the Accounting Act, Act C of 2000, §169) are moved to a restricted, sealed archive for the statutory period and are not processed for any other purpose.
11. Liability
Liability under this DPA is limited as set out in the main service agreement (see our Terms of Service). Each party indemnifies the other for damages arising from its own breach of its GDPR obligations. Nothing in this DPA limits either party’s liability where such a limitation is prohibited by Art. 82 GDPR (a data subject’s right to compensation) or by applicable law.
12. Governing law & jurisdiction
This DPA is governed by Hungarian law and, in respect of the processing, by the GDPR. Disputes are subject to the exclusive jurisdiction of the competent Hungarian courts.
Annex I — Description of processing (summary)
| Subject matter | Provision of the Auro AI SaaS platform. |
| Duration | Term of the service agreement, plus the return/deletion window in Section 10. |
| Nature & purpose | Automated electronic processing for CRM, Finance & Accounting, HR, communications, and AI assistance. |
| Categories of data subjects | See Section 3. |
| Types of personal data | See Section 3. |
Annex II — Technical & organisational measures (Art. 32)
- Encryption in transit: TLS 1.2+ on all public endpoints; HSTS enabled.
- Encryption at rest: AES-256 for sensitive PII columns (TAJ, adóazonosító, bank account, OAuth tokens); database backups encrypted at the storage layer.
- Access control: role-based access at the application layer; SSH to production gated by per-engineer key plus IP allowlist; database password rotation; no shared credentials.
- Network: Cloudflare WAF in front of all customer-facing surfaces; the origin accepts connections only from Cloudflare.
- Audit logging: per-row create/edit/delete logging on PII-bearing tables; 12 months active plus cold retention.
- Backups: nightly encrypted off-site database dumps; periodic restore tests; rolling retention with monthly snapshots.
- Personnel: all staff and contractors with production access sign written confidentiality agreements and complete GDPR refresher training.
- Sub-processor governance: public list at /subprocessors.php; an appropriate transfer safeguard (DPF and/or SCCs) in place for every non-EEA sub-processor.
- Incident response: documented breach-notification runbook; 48-hour notification target; status page at status.auroai.eu.
- Data deletion: automated daily retention sweep with verification that deletion completed.