AuroAI
HomePricingFounding
  • Magyar HU
  • English EN
  • Deutsch DE
Log in Get started →
HomePricingFounding Log in Get started →
HU EN DE
Legal

Privacy Policy

Last updated: 18 September 2026

On this page

  1. 1. Controller
  2. 2. Data We Collect
  3. 3. Purpose & Legal Basis
  4. 4. Data Retention
  5. 5. Your Rights
  6. 6. Data Location
  7. 7. AI Disclosure
  8. 8. Third-Party Integrations
  9. 9. Sub-Processors
  10. 10. Changes to This Policy

1. Controller

The data controller is Evosolve Korlátolt Felelősségű Társaság (Evosolve Kft.), trading as Auro AI. Registered seat: 6722 Szeged, Kálvária sugárút 19., Hungary. Company registration number (cégjegyzékszám): 06-09-024422 (registering court: Szegedi Törvényszék Cégbírósága). Tax number (adószám): 26344465-2-06. EU VAT: HU26344465. Managing director: Van Der Walt Johannes Lodewicus. Contact: [email protected]. For data-protection requests you can also use auroai.eu/privacy/request.

2. Data We Collect

We collect name, email address, company name, phone number, and website domain. You provide these voluntarily through our contact form or client portal. We also collect service usage data through server logs. On our public marketing website, we also collect anonymous, aggregate visit statistics for every visitor (page, language, referrer domain, campaign tags, device type — never tied to an identifiable person), and, only if you accept our cookie banner, more detailed on-site usage analytics (clicks, scrolling, and similar interaction patterns) linked to a random, anonymous browser identifier — never your name or anything you type into a form. See the retention table below for how long this is kept; consent for the detailed tier is withdrawable at any time via the cookie banner. If you are a paying client, we also process customer conversations that go through our AI (chat widget messages, WhatsApp messages, email bodies) and any third-party data you explicitly connect (see Section 8).

3. Purpose & Legal Basis

Data is processed for the purpose of providing B2B services. Legal basis: contract performance (Art. 6(1)(b) GDPR) and legitimate interest (Art. 6(1)(f) GDPR).

4. Data Retention

We keep personal data only for as long as we need it. Specific retention periods by data type:

  • Client account data (name, email, company, billing info): retained for the duration of the contract. Deleted within 30 days of account closure or cancellation, except where the law requires longer retention (see billing records below).
  • Billing & invoice records: retained for 8 years, as required by the Hungarian Accounting Act (Act C of 2000, §169). This applies to invoices, receipts, payment records, and VAT documentation. This is a legal requirement, not something we can adjust.
  • Customer conversation records (chat transcripts, WhatsApp messages, email bodies): retained for the life of the client's subscription plus 90 days for dispute resolution. After that, they are permanently deleted.
  • Customer contact data captured via AI conversations (names, emails, phone numbers of end-customers): follows the same window as conversation records above, unless an end-customer requests earlier deletion via auroai.eu/privacy/request.
  • Leads (entries created from "hot-lead" detection): retained for 3 years from last activity, then deleted.
  • AI-generated content (posts, newsletter drafts, summaries): retained until the client deletes it, or until 90 days after the subscription ends.
  • Knowledge base docs uploaded by a client: retained until the client deletes them from their dashboard. Chunks and embeddings expire at the same time.
  • OAuth tokens & third-party integration data (Google Calendar, Outlook, Zoom, Meta, LinkedIn, Slack, etc.): cached data and tokens are deleted within 30 days of disconnecting the integration.
  • Server logs & usage metrics (API call records, error logs, rate-limit counters): retained for 12 months, then deleted on a rolling basis.
  • Marketing website analytics (aggregate visit statistics, and, only for visitors who accept our cookie banner, detailed on-site interaction data): retained for 12 months, then deleted on a rolling basis, same as the server logs above. You can withdraw consent for the detailed tier at any time via the cookie banner; the aggregate statistics contain no identifier to withdraw from.
  • Erasure audit trail: when we delete data at your request, we keep a minimal non-PII record (hashed email, timestamp, row count) indefinitely. This is regulatory proof that the erasure happened, and it is itself required by Article 5(2) of the GDPR (accountability principle). It contains no personal data, only a one-way hash.

Retention is enforced by an automated daily sweep. Once a period expires, data is permanently deleted. It cannot be recovered.

5. Your Rights

Under GDPR you have the right to access, rectify, erase, restrict, or port your data. Contact [email protected] to exercise these rights.

6. Data Location

All primary data is stored on servers within the European Union (Hetzner, Germany/Finland). Some AI processing is carried out by sub-processors outside the EU (see Section 9) under appropriate safeguards (EU-US Data Privacy Framework and/or Standard Contractual Clauses).

7. AI Disclosure

In compliance with EU AI Act 2024/1689, we disclose that some of our services use AI systems. AI assistants deployed by Auro AI will identify themselves as AI to end users.

8. Third-Party Integrations You Connect

Our clients can optionally connect third-party accounts (such as their Google Calendar) to Auro AI so that our AI assistant can perform tasks on their behalf. When you authorise such an integration, we store an encrypted access token and use it only to deliver the specific feature you connected it for. Below are the integrations we currently support and exactly what data we access:

8.1 Google Calendar

When a client of ours connects their Google Calendar to Auro AI, we request the following OAuth scopes:

  • View events on all your calendars (https://www.googleapis.com/auth/calendar.readonly): so our AI can read your availability the moment a customer tries to book with you, and only offer slots that are actually free.
  • View and edit events on all your calendars (https://www.googleapis.com/auth/calendar.events): so when a customer completes a booking, we create the appointment as a real event in your Google Calendar and add the customer as an attendee so they get a native Google invite. We also delete the event if the customer later cancels.
  • Your email and basic profile (userinfo.email, userinfo.profile): used only once, at connect time, to label the connection in your dashboard.

How we use Google user data, per the Google API Services User Data Policy Limited Use requirements:

  • Google user data we obtain through the Google APIs is used only to provide the features described above: showing real availability to your customers, and creating and deleting bookings in your calendar.
  • We do not transfer Google user data to third parties, except when necessary to provide these features, to comply with applicable law, or as part of a merger or acquisition with prior notice to users.
  • We do not use Google user data for advertising, of any kind.
  • We do not let staff read your Google user data, unless you have given explicit consent for a specific case, it is necessary for security reasons (such as investigating abuse), or we are legally required to.
  • We do not use Google user data to develop, improve, or train general AI or machine learning models. The AI works per conversation, on live retrieval, and never feeds calendar contents into any training pipeline.
  • We access calendar contents only during active customer booking conversations. We do not store or index them in our database. We keep only the resulting booking records (start time, end time, customer name and contact), so we can show you your upcoming bookings in the dashboard.
  • OAuth access tokens and refresh tokens are stored encrypted at rest (AES-256-GCM) on our EU-based infrastructure. On disconnect, all tokens and cached data are deleted within 30 days.
  • You can revoke Auro AI's access at any time. Disconnect inside your Auro AI dashboard, or go directly to your Google account at myaccount.google.com/permissions.

Auro AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

9. Sub-Processors

Auro AI uses the following sub-processors to deliver the service. We have a Data Processing Agreement (DPA) with each. Transfers to US-based providers rely on the EU-US Data Privacy Framework (DPF) where the provider is certified, and on Standard Contractual Clauses (SCCs) otherwise; the specific mechanism in force for each provider is available on request.

Provider Purpose Location Transfer basis
Anthropic (Claude) AI conversation + content generation USA SCCs
Google Cloud (Gemini, Imagen, Places, Calendar, Drive) AI embeddings + image generation + maps + calendar + file sync EU (Gemini) / USA (Imagen, Places) EU-US DPF and/or SCCs
Microsoft (Graph, Azure AD) Outlook / Teams / M365 integration EU (tenant-bound) EU-US DPF and/or SCCs
Meta (WhatsApp, FB, IG) Messaging + social publishing USA / Ireland EU-US DPF and/or SCCs
LinkedIn Social publishing Ireland / USA EU-US DPF and/or SCCs
Zoom Video meeting creation EU (Frankfurt) EU
Revolut AI meeting notetaker bot EU (Frankfurt) EU
Hetzner Online Payment processing Lithuania / Ireland EU
Slack, Notion, HubSpot, Jira, Stripe, Shopify, Zapier Server hosting + DB + email delivery infrastructure Germany / Finland EU-US DPF and/or SCCs

We update this list when we add or remove sub-processors. We notify active clients of material changes by email, with at least 30 days notice. If you have specific residency requirements (for example healthcare or legal), contact [email protected]. We can discuss an EU-only deployment.

10. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email to active clients. The "Last updated" date at the top of this page always reflects the latest revision.

Questions about how we handle your data? Email [email protected]. See also our Data Processing Agreement, Data deletion request page, and Terms of Service.
AuroAI

Auro brings finance, sales and operations into one workspace. Use AI assistance for routine work, with human review and approval.

Product

  • Pricing
  • Founding program
  • Help & docs

Company

  • Get started
  • Log in
  • Contact

Legal

  • Privacy Policy
  • Data Processing (DPA)
  • Data deletion
  • Terms of Service
© 2026 Auro AI — a brand of Evosolve KFT, Szeged, Hungary.
EU-hosted GDPR EU AI Act
We use only essential cookies to keep you signed in and secure. No tracking, no advertising, no third-party analytics — ever. Read our Privacy Policy.