Legal and Compliance

Privacy Policy.

How Aurakore collects, uses, stores, and protects personal data. Your data never trains anyone else's model, in any region, and section 5 sets out exactly what that means.

Effective date28 July 2026
Version1.0
JurisdictionGlobal
EntityAurakore IT Solutions LLC

Aurakore IT Solutions LLC and its affiliates ("Aurakore," "we," "us," or "our") provide an AI-native enterprise resource planning (ERP) platform and related professional services (the "Services"). This Privacy Policy describes how we collect, process, store, transfer, and protect personal data in connection with the Services and our websites, including aurakore.com.

This Policy applies globally. Where local law imposes stricter obligations, those obligations govern. Aurakore is committed to compliance with the following frameworks:

CCPA / CPRA Texas TDPSA PIPEDA GDPR UK GDPR LGPD LFPDPPP UAE PDPL Qatar PDPPL
Section 01

Who This Policy Applies To

  • Customers
    Businesses and individuals who subscribe to Aurakore Services
  • End Users
    Individuals who access Aurakore on behalf of a Customer
  • Visitors
    Individuals who access our websites without subscribing
  • Contacts
    Prospects, partners, and other individuals whose information Aurakore receives in a business context

Where Aurakore processes personal data on behalf of a Customer (as a data processor or service provider), the Customer's privacy policy and data processing agreement govern that processing. This Policy governs Aurakore's own data controller activities.

Section 02

Data We Collect

2.1 Data You Provide

  • Account & Identity
    Name, business email, job title, company name, billing information, and authentication credentials
  • Transaction Data
    Subscription details, payment method, and purchase history
  • Communications
    Support tickets, email correspondence, and feedback submitted to Aurakore
  • ERP Business Data
    Data uploaded or generated through the platform — financial records, HR data, inventory, legal documents, compliance filings, and similar business records

2.2 Data We Collect Automatically

  • Usage Data
    Features accessed, session duration, and actions performed within the platform
  • Device & Technical
    IP address, browser type, operating system, and device identifiers
  • Log Data
    Server logs, API call records, error logs, and security event logs
  • Cookies
    Session cookies, authentication tokens, and analytics identifiers — see Section 10

2.3 Data We Receive from Third Parties

  • Authentication
    Data from OAuth providers (Google, Microsoft) when you use single sign-on
  • Payment Processors
    Tokenized payment confirmation and billing address from Stripe and other processors
  • Partner Referrals
    Contact information from resellers, cloud marketplaces, and integration partners
  • Public Sources
    Business registry data and professional directories, used solely for account verification and sales outreach
Section 03

Legal Bases for Processing

  • Contract Performance
    To deliver the Services you have subscribed to and fulfill our contractual obligations
  • Legitimate Interests
    Security monitoring, fraud prevention, product improvement, and business communications, where not overridden by your rights
  • Legal Obligation
    To comply with applicable laws, regulations, court orders, and government authority requests
  • Consent
    Where required by law, we obtain explicit consent prior to processing — including for certain marketing communications and cookies
  • Vital Interests
    In limited circumstances, to protect the vital interests of individuals

Where Aurakore acts as a processor on behalf of a Customer, the Customer's lawful basis for processing governs.

Section 04

How We Use Personal Data

  • Service delivery — provisioning accounts, processing transactions, and providing platform functionality
  • Security and compliance — detecting and preventing fraud, unauthorized access, and abuse; complying with legal obligations; conducting SOC 2 and other compliance audits
  • AI and platform operations — powering AI features and operating RAG pipelines and agent workflows. See Section 5 for complete AI data use prohibitions.
  • Support — responding to inquiries, resolving technical issues, and providing customer success services
  • Communications — sending service notifications, product updates, and (where consented) marketing communications
  • Analytics and product development — understanding usage patterns using aggregated and de-identified data only
  • Legal and regulatory — enforcing our terms, protecting our rights, and responding to lawful government requests

Aurakore does not sell personal data.

Section 05

AI Data Use and Training

No shared model training, all regions

Aurakore does not use Customer Data to train, fine-tune, or improve any model that serves another Customer. This applies in every jurisdiction, including the United States, to every Customer. There is no configuration required for it to apply and no setting that changes it. It replaces the jurisdiction-dependent defaults set out in earlier versions of this Policy.

5.1 Absolute Prohibitions, All Jurisdictions

  • Customer Data is never used to train, fine-tune, or improve Aurakore's shared models, foundation models, or any model made available to another Customer
  • End User prompts, outputs, and AI-generated responses are never used for model training
  • Raw ERP data (financial records, HR data, legal documents) is never used as training data
  • Customer Data is never pooled or combined across tenants for any modelling purpose

5.2 Models Trained Inside a Customer's Own Workspace

Some Aurakore features compute a statistical model from a Customer's own records in order to serve that same Customer. The predictive lead-scoring model in the Marketing module is one example: it derives feature weights from that Customer's own contact engagement history, such as open, click, conversion, and bounce rates.

These models are created and stored inside the Customer's own tenant, are applied only to that Customer, and neither their inputs nor their outputs leave it. They are not language models and they are not shared. Contacts that have been suppressed, and contacts whose erasure requests have completed, are excluded from the computation.

5.3 Downstream Model Providers

Downstream AI providers, including the Google Gemini Enterprise Agent Platform (formerly Vertex AI) and Anthropic Claude models accessed via Google Model Garden, are contractually prohibited from using Customer Data for their own model training under Aurakore's enterprise agreements.

5.4 Anonymized Platform Telemetry

Aurakore may use fully anonymized, aggregated, and irreversibly de-identified data, from which no individual or Customer can be identified, to improve platform performance and monitor system health in all jurisdictions. This does not constitute personal data processing under applicable law and it is not model training.

5.5 Legal Basis

Because Customer Data is not used to train shared or foundation models, Aurakore does not rely on consent or on legitimate interests for that purpose in any jurisdiction. Processing that supports a model trained inside a Customer's own workspace is carried out on the Customer's instructions, under the Customer's agreement with Aurakore.

5.6 No Training Has Taken Place

Earlier versions of this Policy permitted AI training by default for Customers billed in the United States, Latin America, the Middle East and Africa. That permission was never exercised. No Customer Data has ever been used to train, fine-tune, or improve a model that serves another Customer, under this or any prior version of this Policy. There is no historical training set to withdraw from and nothing to delete.

Section 06

Data Sharing and Disclosure

6.1 Service Providers

All processors are bound by data processing agreements requiring appropriate technical and organizational safeguards.

  • Cloud Infrastructure
    Enterprise cloud infrastructure providers under contract, with a primary and a secondary provider. The current list is available on request.
  • AI & ML
    Google Gemini Enterprise Agent Platform (formerly Vertex AI), including Anthropic Claude models accessed via Google Model Garden
  • Payments
    Stripe
  • Financial Connections
    Plaid (where a Customer connects a financial account)
  • Billing & Metering
    Lago
  • Productivity
    Google Workspace

6.2 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, personal data may be transferred to the successor entity subject to equivalent privacy protections. Affected individuals will be notified as required by law.

6.3 Legal Disclosure

Aurakore may disclose personal data where required by law, regulation, court order, or lawful governmental authority. Where permitted, Aurakore will notify the affected Customer prior to disclosure.

6.4 Aggregated or De-identified Data

Aurakore may share aggregated or de-identified data that does not identify any individual for research, benchmarking, or product improvement purposes.

Section 07

International Data Transfers

Aurakore is headquartered in Austin, Texas, USA. Personal data is processed in the following regions, selected based on Customer location, regulatory requirements, and data residency commitments.

🇺🇸
Iowa, USA
Live · Primary
🇨🇦
Montréal, Canada
Live · PIPEDA
🇨🇦
Toronto, Canada
Live · PIPEDA
🇩🇪
Frankfurt, Germany
Live · GDPR
🇫🇷
Paris, France
Live · GDPR
🇪🇸
Madrid, Spain
Live · GDPR
🇬🇧
London, UK
Live · UK GDPR
🇧🇷
São Paulo, Brazil
Activating · LGPD
🇦🇪
Dubai, UAE
Activating · UAE PDPL
🇶🇦
Doha, Qatar
Activating · Qatar PDPPL

When transferring personal data from the EEA, UK, or other jurisdictions with data transfer restrictions, Aurakore relies on Standard Contractual Clauses (SCCs), UK International Data Transfer Agreements (IDTAs), adequacy decisions, or other lawful mechanisms as required by applicable law.

Canadian data is processed and stored in Canada (Montréal and/or Toronto) unless the Customer elects otherwise in writing. EU data is processed and stored within the EEA. UK data is processed and stored in the United Kingdom.

Section 08

Data Retention

  • Active Accounts
    Data retained for the duration of the Customer relationship
  • Post-Termination
    Account data retained for a minimum of 90 days and a maximum of 7 years, as required by applicable law or data processing agreement
  • Security & Audit Logs
    Retained for a minimum of 12 months and up to 7 years for compliance purposes
  • Marketing Data
    Retained until you withdraw consent or opt out

Upon expiration of the applicable retention period, Aurakore will securely delete or anonymize personal data.

Section 09

Your Privacy Rights

  • Access
    Request confirmation of whether we process your data and obtain a copy
  • Correction
    Request correction of inaccurate or incomplete data
  • Deletion
    Request erasure of your data, subject to legal retention obligations
  • Restriction
    Request that we limit processing in certain circumstances
  • Portability
    Receive your data in a structured, machine-readable format where technically feasible
  • Objection
    Object to processing based on legitimate interests or for direct marketing
  • Withdraw Consent
    Where processing is based on consent, withdraw at any time without affecting prior processing
  • Non-Discrimination
    Exercise your rights without receiving discriminatory treatment — applicable under CCPA/CPRA and TDPSA

To submit a request, contact privacy@aurakore.com. We will respond within the timeframe required by applicable law (generally 30 days, with extensions where permitted). Identity verification may be required before processing requests.

End Users whose data is processed on behalf of a Customer should direct requests to the relevant Customer, who is the data controller for that processing.

Section 10

Cookies and Tracking Technologies

  • Strictly Necessary
    Session management, authentication, and platform security. These cannot be disabled.
  • Functional
    User preferences and settings that improve your experience
  • Analytics
    Aggregated usage statistics used to improve the platform
  • Marketing
    Used only where you have provided explicit consent

You may control non-essential cookies through our consent management interface or your browser settings. Disabling cookies may affect platform functionality.

Section 11

Security

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access controls and least-privilege principles
  • Multi-layer AI security architecture with autonomous threat detection agents
  • Human-in-the-loop (HITL) gates on all consequential AI-driven actions — no automated action completes without explicit human approval
  • Continuous security monitoring and automated incident response
  • SOC 2 Type II audit in progress; certification targeted for Q1 2027
  • Independent penetration testing planned as part of our security program ahead of and following general availability

No security measure is guaranteed to be impenetrable. In the event of a personal data breach, Aurakore will notify affected parties and regulators as required by applicable law.

Section 12

Children's Privacy

The Services are not directed to individuals under the age of 18. Aurakore does not knowingly collect personal data from minors. If we become aware that we have inadvertently collected data from a minor, we will take prompt steps to delete it.

Section 13

Third-Party Services and Integrations

The Services may integrate with or link to third-party services including cloud marketplaces and Customer-selected integrations. This Policy does not govern the privacy practices of third parties. We encourage you to review the privacy policies of any third-party services you connect to Aurakore.

13.1 Financial Account Connections (Plaid)

Where a Customer chooses to connect a financial account to Aurakore — for example, to enable transaction reconciliation or expense posting within the platform — Aurakore uses Plaid Inc. ("Plaid") to facilitate that connection. When you connect an account, you authorize Plaid to access information from your financial institution on your behalf. Plaid accesses and processes that information in accordance with the Plaid End User Privacy Policy, and your use of Plaid is subject to Plaid's terms.

Financial account data obtained through this connection (such as account and transaction details) is used by Aurakore solely to provide the functionality the Customer initiates — for example, posting reconciled transactions to the Finance/Accounting module or expenses to the Expense module. This data is encrypted in transit (TLS 1.2+) and at rest (AES-256), is subject to the access controls and retention terms described in this Policy, and is not used for AI model training. Aurakore does not sell financial account data. The Customer acts as the controller of their End Users' financial data; Aurakore processes it on the Customer's behalf.

Section 14

Changes to This Policy

Aurakore reserves the right to update this Policy at any time. We will notify Customers of material changes via email or in-platform notification at least 30 days prior to the effective date of the change. Continued use of the Services after the effective date constitutes acceptance of the updated Policy.

The version history of this Policy is maintained and available upon request.

Section 15

Contact and Data Protection

Aurakore IT Solutions LLC

Address5900 Balcones Dr, Suite 23709
Austin, TX 78731, USA

If you are located in the EEA or UK and believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local supervisory authority.

If you are located in Canada and your complaint is unresolved, you may contact the Office of the Privacy Commissioner of Canada.