PRIVACY @ AURORA INFRA
Privacy Policy
Last updated: 24 September 2026 | Version: 1.1
This Privacy Policy explains how Aurora Infrastructure EU sp. z o.o. handles personal data when you visit our websites, create an account on or use the Aurora cloud platform (object storage, compute, and AI inference), contact us, or interact with our sales team. It also explains your rights under the EU General Data Protection Regulation ("GDPR").
1. Who we are; contact
The controller of your personal data is:
Aurora Infrastructure EU sp. z o.o.
ul. Wadowicka 6/88, 30-415 Kraków, Poland
Registered in the National Court Register (KRS) under no. 0001166368
Privacy contact: legal@aurorainfra.ai
General support: support@aurorainfra.ai
This policy covers our websites (including www.aurorainfra.ai and docs.aur.lu), the Aurora Portal (portal.aur.lu) and APIs, our billing and support processes, and our sales and marketing activities.
2. Two roles: when this policy applies — and when it doesn't
- We act as controller — and this policy applies — for personal data about you: website visitors, account holders and their team members, billing contacts, sales prospects and business contacts, and people who communicate with us.
- We act as processor — and this policy does not govern — personal data contained in Customer Content: the files, objects, virtual machines, and AI prompts that our customers store or process on the platform. For that data, the customer is the controller, we process it only on the customer's instructions, and the Data Processing Addendum in our Terms of Service applies. If your data has been stored on Aurora by one of our customers, please direct requests to that customer; we will assist them as required by law.
3. What personal data we collect
| Category | Examples | Source |
|---|---|---|
| Account and identity data | First and last name, email address, organization name, password (held by our identity provider in hashed form), roles and team memberships, email-verification status, login history (including login IP addresses and timestamps, held by our identity provider) | You; a colleague who invites you to a team |
| Billing data | Company name, billing address, VAT/tax identification number, payment method details (held by our payment processor — we never receive full card numbers), invoices, transactions, prepaid balance | You; our payment processor; the European Commission's VIES service (which returns the company name and address registered for a VAT number) |
| Usage and technical data | API and Portal activity metadata: operation types and counts, buckets and resources touched, bytes transferred, inference token counts per model, request timestamps and statuses, error events; user-agent information in diagnostic traces; security and audit logs of storage API operations; client IP addresses and similar identifiers in operational and security logs (abuse prevention and security only) | Generated when you use the services |
| Support and communications data | Emails you send us, complaint contents, notices submitted to our abuse mailbox | You |
| Sales and marketing data (business contacts) | Name, business email and phone, employer, job title, meeting and correspondence notes, event attendance, product interests | You (e.g., a demo request or contact form); your organization; event organizers and business partners; publicly available professional sources |
| Website data | Server logs of website visits (IP address, requested pages, browser type, timestamps); information you submit through website forms; and, where you consent, analytics data about pages viewed, referral source, and interactions, which may be linked to your business-contact record if you submit a form (see Section 10) | Generated when you browse; you |
Things we deliberately do not do, as of the date of this policy:
- We do not store the content of AI inference prompts or outputs — our inference gateway records token counts and technical metadata only, and we do not use your prompts or outputs to train models.
- We do not persist client IP addresses in our usage analytics — request IPs are not stored in our analytics database. We may collect IP addresses and similar identifiers for abuse prevention and security purposes (for example, in operational and security logs), used solely for those purposes and retained for a limited period — as a rule, no longer than a few months — unless needed longer for a specific investigation (Section 7).
- We do not run third-party advertising, tracking, or behavioral-analytics tools on the Portal, and we do not sell personal data.
4. Why we process personal data, and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and managing your account, authenticating you, providing the services, support, and complaint handling | Art. 6(1)(b) — performance of a contract |
| Billing, invoicing, VAT validation, payment collection, refunds | Art. 6(1)(b); Art. 6(1)(c) — legal obligations (tax and accounting law) |
| Verifying VAT numbers via VIES and applying correct tax treatment | Art. 6(1)(c) |
| Securing the services: abuse and fraud prevention (including CAPTCHA at signup and rejection of disposable email domains), access logging, incident detection and response, enforcement of our Terms | Art. 6(1)(f) — legitimate interest in the security and integrity of our platform and in protecting our customers and third parties |
| Service analytics and capacity planning using aggregated, non-content usage metrics | Art. 6(1)(f) — legitimate interest in operating and improving the services |
| Processing illegal-content notices and cooperating with authorities | Art. 6(1)(c) (including Regulation (EU) 2022/2065); Art. 6(1)(f) |
| Sales outreach and relationship management with business contacts; responding to demo and contact requests | Art. 6(1)(f) — legitimate interest in marketing our services to businesses; Art. 6(1)(b) where you request something from us |
| Sending marketing communications (e.g., newsletters or product updates), where we do so | Consent (Art. 6(1)(a)) and/or Art. 6(1)(f) for similar-services messages to existing customers, always with an opt-out; also subject to Polish electronic-communications law |
| Website analytics and measuring the effectiveness of our marketing | Consent (Art. 6(1)(a)), given via our cookie banner and withdrawable at any time |
| Establishing, exercising, or defending legal claims; corporate transactions | Art. 6(1)(f) |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights, taking into account the business context and the limited, non-intrusive nature of the data involved. You may request a summary of our balancing assessments via legal@aurorainfra.ai, and you can object at any time (Section 9). Providing account and billing data is required to contract with us; without it we cannot provide the services.
5. Who receives personal data
We share personal data with a small set of service providers ("processors") and other recipients, only to the extent needed:
| Recipient | What for | Location / transfer safeguard |
|---|---|---|
| Okta (Auth0) — identity platform | Account registration, login, password storage, email verification, password reset and invitation emails, login history | EU-hosted tenant; Okta group companies may access support data from outside the EEA under the EU–US Data Privacy Framework (DPF) and/or Standard Contractual Clauses (SCCs) |
| Stripe (Stripe Payments Europe Ltd. and affiliates) — payment processor | Payments, prepaid balance, invoicing, billing address and VAT ID storage, payment-method handling; Stripe also acts as an independent controller for its own regulatory obligations (e.g., fraud prevention, KYC) | EU entity; transfers to Stripe, Inc. (US) under DPF/SCCs |
| HubSpot (HubSpot, Inc. and affiliates) — CRM and website platform | Website hosting, website forms, website analytics (with your consent), CRM records for business contacts, sales and marketing email | Our HubSpot account is hosted in the United States; transfers under DPF/SCCs |
| Google (Google Ireland Ltd. / Google LLC) — reCAPTCHA; Google Analytics and Google Tag Manager on our websites | Bot and abuse prevention on account registration; website usage analytics, only with your consent | Transfers to the US under DPF/SCCs |
| European Commission — VIES | Validation of EU VAT numbers you provide | EU public service |
| Data-centre providers: CELESTE (Albi and Champs-sur-Marne, France) and S-NET (Kraków, Poland) | Physical hosting / colocation of our servers; our own databases, logging, and monitoring run on this infrastructure under our control | EU |
| Professional advisers, auditors, insurers | Where necessary for legal, accounting, or insurance purposes | Case-by-case, with safeguards where outside the EEA |
| Authorities, courts, and regulators | Where required by law or a valid order; to report CSAM or other illegal content where legally required | Per applicable law |
| A buyer or successor | In connection with a merger, acquisition, financing, or sale of assets, under confidentiality obligations | Case-by-case, with safeguards |
We may also share data within our corporate group (if affiliates exist from time to time) for the purposes above. Our authorized resale partners see the account data of the tenants they manage.
A note on Filecoin (Customer Content, not account data): object data stored on our object-storage service is tiered to the public Filecoin network — in the current region, exclusively to Aurora-operated storage providers located in the European Union (France). Data in unencrypted buckets is nonetheless publicly retrievable from the network by content identifier, because that is how the public network's protocol works, regardless of where the data physically sits. This concerns Customer Content (Section 2), the storing customer controls it via their encryption choices, and our Terms of Service require encryption for any personal data. We cannot retract copies that third parties have already obtained from the public network.
6. International transfers
We are an EU company; our servers are in the European Union (primary region: France; corporate seat: Poland), and we prefer EU processing. Some providers listed in Section 5 are part of US groups or process limited data in the United States. Our public website and our CRM for business contacts are operated on HubSpot's infrastructure in the United States. Where personal data is transferred outside the EEA, we rely on European Commission adequacy decisions (including the EU–US Data Privacy Framework for certified recipients) and/or Standard Contractual Clauses with supplementary measures where needed. You can request a copy of the relevant safeguards via legal@aurorainfra.ai.
7. How long we keep personal data
| Data | Retention |
|---|---|
| Account and identity data | For the life of the account. After account closure or the end of a trial, account data is kept no longer than necessary to complete deletion, settle balances, and defend claims — as a rule up to 3 years after closure (the Polish limitation period for business-related claims), after which it is deleted or anonymized |
| Customer Content after account closure | Retrieval window of at least 30 days, then deletion (see Terms of Service Sections 9.3, 11.4, and 12; public Filecoin copies of unencrypted data cannot be recalled — Section 5 note) |
| Billing records, invoices, tax data | 5 years from the end of the tax year concerned (Polish tax and accounting law) |
| Usage metering records used for billing | Kept as billing records (above); raw event streams in our messaging pipeline are retained for approximately 24 hours before aggregation |
| Aggregated usage analytics (per-tenant operation counts, byte counts, token counts — no content, no IPs) | Kept while the account exists; after account deletion (once the account-data retention above ends), tenant identifiers in the aggregates are deleted or irreversibly re-keyed, after which the aggregates are anonymous service statistics |
| Website analytics | Google Analytics data is retained for up to 14 months; analytics linked to a business-contact record follows the Sales/CRM retention below |
| Security, audit, and diagnostic logs | Up to 12 months, unless needed longer for a specific investigation or legal claim; operational and security logs containing client IP addresses are kept for a shorter period — as a rule, no longer than a few months |
| Support correspondence and complaints | Up to 3 years after the matter is closed |
| Sales/CRM data for business contacts | Up to 24 months after our last meaningful interaction, unless you object earlier or a contract results |
| Marketing consents and opt-outs | For as long as the consent is relied on; opt-out records are kept to honor the opt-out |
8. How we protect personal data
We apply technical and organizational measures appropriate to the risk, including: TLS 1.2+ encryption in transit; optional encryption at rest for stored objects with managed keys; network and tenant isolation; role-based access control and least-privilege access for staff; storage of API-token secrets only in hashed form; centralized secrets management; audit logging of storage API operations; and vendor due diligence. No system is perfectly secure; we will notify you and the competent supervisory authority of personal-data breaches where the GDPR requires it.
9. Your rights
Under the GDPR you may, subject to its conditions and exemptions:
- access your personal data and receive a copy;
- rectify inaccurate or incomplete data;
- erase data (right to be forgotten);
- restrict processing;
- receive data you provided in a portable format (data portability);
- object to processing based on legitimate interests — and to direct marketing at any time, without justification;
- withdraw consent at any time, without affecting prior processing.
To exercise your rights, email legal@aurorainfra.ai. We may need to verify your identity, and we respond within one month (extendable by two months for complex requests, with notice). Exercising these rights is free of charge, except for manifestly unfounded or excessive requests.
You also have the right to lodge a complaint with a supervisory authority — in Poland, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl) — or with the authority of your habitual residence or place of work.
Automated decision-making: we do not make decisions based solely on automated processing that produce legal or similarly significant effects for you. Automated anti-abuse checks (such as CAPTCHA scoring at signup) are security measures with human review available — if a signup is blocked, you can contact support.
10. Cookies and similar technologies
Aurora Portal: we keep the Portal deliberately light on cookies. We currently use:
| Name / type | Purpose | Duration | Category |
|---|---|---|---|
| sidebar_state (first-party cookie) | Remembers your dashboard sidebar preference | 7 days | Functional |
| Authentication tokens (browser local storage) and identity-provider session cookies (set on our Auth0 login domain) | Keeping you signed in securely | Session / until logout or expiry | Strictly necessary |
| Google reCAPTCHA (script and associated cookies, loaded on the registration page) | Distinguishing humans from bots at signup; Google processes device and interaction signals, including IP address | Per Google's policy | Security / anti-abuse |
Our websites (aurorainfra.ai):
| Name / type | Purpose | Duration | Category |
|---|---|---|---|
| __hs_cookie_cat_pref (HubSpot) | Stores your cookie choices | 6 months | Strictly necessary |
| __hstc, hubspotutk (HubSpot) | Website visitor analytics; links your visits to a form you submit | 6 months | Analytics |
| __hssc, __hssrc (HubSpot) | Session tracking for website analytics | 30 minutes / session | Analytics |
| _ga, _ga_YDWDL9Q64N (Google Analytics) | Website usage analytics | Up to 2 years | Analytics |
Analytics cookies on our websites are set only after you accept them in our cookie banner. You can change your choice at any time: Cookie settings.
We do not use advertising or cross-site tracking cookies, and we do not currently run third-party analytics on the Portal. If this changes, we will update this policy and, where required, ask for your consent first. Browser settings can block cookies, but strictly necessary items are required for login to work.
11. Marketing communications
We send transactional emails (verification, invitations, password resets, billing and service notices). We also send business outreach and product-news emails to business contacts, based on legitimate interest or your consent, in accordance with Polish and EU electronic-communications rules, and every such message will include a working unsubscribe option. Opting out of marketing never affects transactional messages needed to run your account.
12. Children
Our websites and services are directed to businesses and professionals, not to children. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us personal data, contact legal@aurorainfra.ai and we will delete it.
13. Changes to this policy
We may update this policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes affecting account holders, notify you by email or via the Portal before the changes take effect. Earlier versions are available on request.