1. Distinction of Roles (Data Controller vs Data Processor)
In accordance with Articles 4(7) and 4(8) of the General Data Protection Regulation (GDPR), two distinct legal frameworks apply depending on the type of data processed:
For data relating to the creation and administration of your developer account, subscription billing, technical support correspondence, and console system telemetry.
For the application data of your end-users that you store in your databases, storage buckets, or serverless functions. This processing is governed by our Data Processing Agreement (DPA).
2. Data Controller & Data Protection Officer (DPO)
The data controller is the operating entity of Aurabase (Art. 13.1.a of the GDPR):
Registered office: Paris, France · General contact: contact@aurabase.cloud
Security, privacy & DPO contact (Art. 37 of the GDPR): privacy@aurabase.cloud (response within 48 business hours).
3. Personal Data Collected & Contractual Requirement (Art. 13.2.e)
We only collect information strictly necessary for the provision and security of our services:
- Account data (mandatory for service performance): Email address, username, organization name, and cryptographic password hash (salted individually).
- Billing data (contractual and statutory requirement): Billing contact information, VAT ID number, and Mollie Customer IDs. Banking details and payment card numbers are processed directly by Mollie and never transit through our servers.
- Technical data & access logs (legitimate security interest): Connecting IP address, browser type (User-Agent), session tokens, and API Gateway request timestamps.
- Telemetry data: Aggregated resource usage metrics (RAM, CPU, storage volume, concurrent connections) required for capacity management.
4. Purposes and Legal Bases of Processing
5. Data Residency & European Sovereignty
When creating your project, you select your primary hosting region. Primary databases, read replicas, backups, and storage buckets physically reside in the selected region (for example, France (Paris fr-par) on Scaleway managed infrastructure or Germany on Hetzner).
- Free / Pro Plans: Sovereign hosting in the European Union (France fr-par-1/2/3, Germany).
- Enterprise Plan: Dedicated geographic pinning per country and fully isolated private VPC.
6. List of Subprocessors
In accordance with Article 28 of the GDPR, here is the exhaustive list of our technical subprocessors involved in providing our services:
7. Data Transfers Outside the European Union (Art. 44 to 49)
Aurabase prioritizes hosting and storage infrastructure 100% located within the European Union (France and Germany), shielded from extraterritorial legislation such as the US CLOUD Act.
In the event that secondary technical transfers to service providers located outside the European Economic Area (EEA) become necessary (particularly for global SMS dispatch via Twilio or mobile push notifications via Apple and Google), Aurabase ensures that these transfers are strictly governed by:
- Adherence to the EU-U.S. Data Privacy Framework (DPF) where the recipient entity is certified.
- Execution of Standard Contractual Clauses (SCCs) adopted by the European Commission (Implementing Decision 2021/914).
- Enforcement of Binding Corporate Rules (BCR) duly approved by European supervisory authorities.
8. Data Retention Periods (Art. 13.2.a)
- Active account data: Retained throughout the duration of account activation and until effective termination.
- Account / project deletion: Complete and irreversible purge of databases and storage volumes within a maximum of 72 hours.
- Audit and security logs: Retained for 365 rolling days for security forensics, fraud prevention, and statutory audit obligations.
- Billing records and accounting documents: Statutory archiving for 10 years pursuant to applicable commercial and tax regulations.
9. Your GDPR Rights & Statutory Response Timelines (Art. 12 & 15 to 22)
In accordance with Articles 12 to 22 of the General Data Protection Regulation (GDPR) and applicable data protection legislation, you hold the following rights over your personal data:
- Right of access (Art. 15): You can obtain confirmation as to whether your personal data is being processed, along with a comprehensive copy in an intelligible format.
- Right to rectification (Art. 16): You may request the immediate correction or completion of inaccurate or incomplete information.
- Right to erasure / Right to be forgotten (Art. 17): You may request the permanent deletion of your personal data (excluding statutory tax and accounting retention obligations).
- Right to restriction of processing (Art. 18): You can request the temporary freezing of processing in case of dispute or verification.
- Right to data portability (Art. 20): You can receive your data in a structured, commonly used, and machine-readable format (JSON, CSV, SQL dump) to transmit to another controller.
- Right to object (Art. 21): You may object at any time, on legitimate grounds, to the processing of your personal data.
- Post-mortem directives: You have the right to define general or specific guidelines regarding the retention, erasure, and disclosure of your personal data after your death.
Exercising your rights is strictly free of charge (Art. 12.5 GDPR).
Aurabase commits to processing your request and responding as promptly as possible, and at the latest within a statutory timeline of one (1) month from receipt of your request.
This deadline may be extended by two (2) additional months where necessary, taking into account the complexity and number of requests; in such cases, Aurabase will notify you of the extension and reasons for delay within the initial one-month period.
How to exercise your rights?
• Directly from the Studio: Settings → Compliance → Export / Erasure.
• By emailing the DPO: privacy@aurabase.cloud.
10. Absence of Automated Decision-Making & Profiling (Art. 13.2.f & 22)
In accordance with Articles 13(2)(f) and 22 of the GDPR, Aurabase informs you that it does not engage in fully automated decision-making nor in any profiling of users or their behavior.
No decision-making algorithm, automated evaluation system, or artificial intelligence model produces legal effects concerning you or similarly significantly affects you without effective human intervention and review.
11. Technical and Organizational Security Measures (TOMs - Art. 32)
- Encryption: Data encrypted at rest using AES-256 and in transit via TLS 1.3 with Perfect Forward Secrecy.
- Multitenant isolation: Logical project separation with native PostgreSQL Row-Level Security (RLS) enforcement.
- Access controls: Multi-factor authentication (MFA TOTP), time-limited access tokens, and automated API key rotation.
13. Security Incident & Breach Notification (Art. 33 & 34)
In the event of a confirmed personal data breach presenting a risk to your rights and freedoms, Aurabase commits to notifying the competent supervisory authority (CNIL) within a maximum of 72 hours after becoming aware of it, and informing affected customers without undue delay along with remediation measures taken.
14. Complaints to the Supervisory Authority (CNIL - Art. 77)
If you believe, after contacting us at privacy@aurabase.cloud, that the processing of your personal data does not comply with applicable data protection regulations, you have the right to lodge a complaint with the competent supervisory authority:
3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
Phone: +33 (0)1 53 73 22 22
Online complaint submission: www.cnil.fr/en/plaintes