GDPR Compliance
Effective August 1, 2026
For customers and users in the European Economic Area and UK, this page summarizes how Aurora processes personal data in line with the GDPR/UK GDPR, in addition to our general Privacy Policy.
Roles
For Customer Data you input into Aurora (your contacts, tickets, campaign recipients), your organization is the data controller and Aurora acts as data processor, processing that data only on your documented instructions via the Service.
For account and billing data collected directly from you as our customer, Aurora acts as data controller.
Legal basis for processing
We process account data to perform our contract with you (providing the Service), and limited additional data based on legitimate interest (security, fraud prevention) or consent (marketing communications you’ve opted into).
Data Processing Agreement
Organizations subject to GDPR can request a Data Processing Agreement (DPA) covering Aurora’s processing of Customer Data, including our Standard Contractual Clauses for any international transfers, by emailing privacy@aurora.com.
Data subject rights
Individuals have the right to access, rectify, erase, restrict, or port their personal data, and to object to certain processing. Where Aurora is the processor, we support your organization in fulfilling these requests through in-app export/delete tools and, where needed, direct assistance from our team.
International transfers & breach notification
Where personal data is transferred outside the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses. In the event of a personal data breach affecting Customer Data, we will notify affected organizations without undue delay so they can meet their own regulatory notification obligations.
Questions about this policy? Contact us.