Privacy Policy

Last updated August 31, 2026

AurexSystems Inc. ("AurexSystems," "we," "us," or "our") provides this Privacy Policy to explain how we collect, use, disclose, and safeguard information when you use our website and the AurexSystems WhatsApp campaign automation service (collectively, the "Service"). This policy is written to address the requirements of the EU/UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and comparable data protection laws in other jurisdictions. If a specific law grants you rights beyond what is described here, that law controls.

1. Who we are and how to reach us

AurexSystems Inc. is the data controller (or "business," under the CCPA) for the personal data described in this policy. For any privacy question, data subject request, or complaint, contact us at privacy@aurexsystems.to. If you are in the EU/UK and believe we have not resolved your concern, you also have the right to lodge a complaint with your local data protection supervisory authority.

2. Personal data we collect

  • Account data: name, email address, hashed password, and account preferences.
  • Billing data: processed by our payment processor, Stripe. We store your Stripe customer and subscription identifiers, plan tier, and billing status — we do not store full card numbers.
  • WhatsApp connection data: your WhatsApp connection status and the phone number associated with the WhatsApp account you connect.
  • Campaign and contact data: contact lists and phone numbers you upload or enter, message templates, and per-recipient delivery status (sent, failed, pending) used to generate campaign reports.
  • Message content: the text and media of messages you send are transmitted through your connected WhatsApp session to deliver your campaigns, and retained only as needed to display campaign history and reports to you.
  • Usage and device data: IP address, browser type, device identifiers, log data, and analytics collected automatically when you use the Service.
  • Communications: records of support requests and correspondence with us.

We do not knowingly collect special category data (e.g., health, religious belief, biometric data) about you, and ask that you do not include such data in message content sent through the Service unless you have an independent legal basis and appropriate safeguards for doing so.

3. How and why we use personal data (GDPR legal bases)

  • To provide the Service (contract performance) — authenticating you, operating your WhatsApp connection, running campaigns, generating reports, and providing customer support.
  • To bill your subscription (contract performance / legal obligation) — processing payments and maintaining financial records.
  • To maintain security and prevent abuse (legitimate interests) — detecting fraud, enforcing our Terms of Service, and protecting the Service and its users.
  • To communicate with you (legitimate interests / consent where required) — service notices, security alerts, and, where you have opted in, product updates.
  • To comply with legal obligations — responding to lawful requests from public authorities and meeting tax, accounting, and regulatory requirements.

Where we rely on your consent (for example, optional marketing communications), you may withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.

4. Cookies and similar technologies

We use the following categories of cookies and similar technologies:

  • Strictly necessary: session and authentication cookies required for login and core functionality. These cannot be disabled without breaking the Service.
  • Functional: cookies that remember your preferences (e.g., dashboard settings).
  • Analytics: aggregated usage data to help us understand and improve the Service.

Where required by law, we will request your consent before setting non-essential cookies and provide a mechanism to withdraw that consent. You can also control cookies through your browser settings.

5. How we share personal data

We do not sell your personal data. We share it only with:

  • Service providers (processors): Stripe (payments), our cloud hosting and database providers, and email delivery providers — each bound by contract to process data only on our instructions and to appropriate security standards.
  • WhatsApp / Meta Platforms, Inc.: message delivery occurs through your own connected WhatsApp account; Meta's own privacy policy governs its handling of data on its platform.
  • Legal and safety: where required to comply with law, enforce our Terms, or protect the rights, property, or safety of AurexSystems, our users, or others.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this policy or a materially equivalent one.

6. International data transfers

We may process and store personal data in countries other than your own, including the United States. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on recognized transfer mechanisms such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), or transfers to recipients in jurisdictions covered by an applicable adequacy decision.

7. Data retention

We retain personal data for as long as your account is active and as needed to provide the Service. After account closure, we retain data only as necessary to comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements, after which it is deleted or anonymized.

8. Your privacy rights

If you are in the EEA, UK, or another jurisdiction with similar law (GDPR-equivalent rights), you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten"), subject to legal exceptions.
  • Restrict or object to certain processing, including processing based on legitimate interests.
  • Data portability — receive your data in a structured, commonly used format.
  • Withdraw consent at any time, where processing is based on consent.
  • Lodge a complaint with your supervisory authority.

If you are a California resident (CCPA/CPRA), you have the right to:

  • Know what personal information we collect, use, disclose, and (if applicable) sell or share.
  • Delete personal information we hold about you, subject to exceptions.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of personal information — AurexSystems does not sell or share personal information as those terms are defined by the CPRA.
  • Limit the use of sensitive personal information — AurexSystems does not use sensitive personal information beyond what is necessary to provide the Service.
  • Non-discrimination for exercising any of these rights.

To exercise any of these rights, email privacy@aurexsystems.to. We will verify your request using your account email and respond within the timeframe required by applicable law (generally 30 days under GDPR, 45 days under CCPA/CPRA, extendable as permitted by law). You may designate an authorized agent to submit a request on your behalf.

9. Children's privacy

The Service is not directed to, and we do not knowingly collect personal data from, individuals under 16 years of age. If we learn we have collected personal data from a child under 16 without appropriate consent, we will delete it.

10. Security

We use administrative, technical, and physical safeguards designed to protect personal data, including password hashing, encrypted connections (TLS), and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Changes to this policy

We may update this policy from time to time. Material changes will be notified via the Service or by email, with the "Last updated" date revised above.

12. Contact us

Privacy inquiries and data subject requests: privacy@aurexsystems.to
General support: support@aurexsystems.to