- You are the controller; Aurora processes visitor data only on your instructions.
- Current subprocessors are listed below, with 30 days' notice before any new one.
- Personal data breaches are reported to you within 72 hours.
- Standard Contractual Clauses cover transfers outside the EEA, UK and Switzerland.
Contents
Scope and roles#
This Data Processing Agreement (“DPA”) forms part of the Terms of Service or other agreement between you (“Customer”) and Aurora Labs (“Aurora”). It applies whenever Aurora processes personal data on Customer's behalf in providing the service. Customer is the controller and Aurora is the processor. Where Customer is itself a processor, Aurora acts as its subprocessor.
No signature is required: this DPA is incorporated by reference. Customers who need a countersigned copy can request one from privacy@aurora.io.
Definitions#
“Personal data”, “processing”, “controller”, “processor”, “data subject” and “supervisory authority” have the meanings given in the GDPR. “Data Protection Laws” means the GDPR, the UK GDPR, the Swiss FADP, the CCPA/CPRA and other laws that apply to the processing. For the CCPA, Aurora is a “service provider”.
Details of processing#
| Subject matter | Provision of behavioral lead scoring, routing and related services |
| Duration | The term of the agreement, plus the deletion period described below |
| Data subjects | Visitors to Customer's websites; Customer's users; contacts synced from Customer's CRM |
| Categories of data | Online identifiers (visitor ID, truncated IP), page views and events, device information, company information, and names, emails and traits Customer chooses to send |
| Special categories | None. Customer agrees not to send special-category data. |
| Processing operations | Collection, storage, scoring, routing, synchronization with Customer's integrations, and deletion |
Aurora's obligations#
- Process personal data only on Customer's documented instructions, including those given through the service's settings, unless law requires otherwise — in which case Aurora will inform Customer first where legally permitted.
- Ensure staff with access are bound by confidentiality and trained in data protection.
- Assist Customer with data protection impact assessments and prior consultations where reasonably required.
- Not sell, share or use personal data for any purpose other than providing the service, and not combine it with data from other customers.
Security measures#
Aurora maintains the technical and organizational measures described in Annex II below and on the Security page, including encryption in transit (TLS 1.2+) and at rest (AES-256), SSO and hardware-key authentication for staff, least-privilege access with quarterly reviews, logging and monitoring, and an annual SOC 2 Type II audit. Aurora may update these measures provided the overall level of protection isn't reduced.
Subprocessors#
Customer authorizes Aurora to engage the subprocessors below. Aurora imposes data protection terms on each at least as protective as this DPA and remains responsible for their performance.
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Hosting, storage and infrastructure | Frankfurt (EU) or Oregon (US), per workspace |
| Cloudflare, Inc. | Content delivery and DDoS protection for the tracker | Global edge network |
| Postmark (ActiveCampaign, LLC) | Transactional email delivery | United States |
| Sentry (Functional Software, Inc.) | Error monitoring (scrubbed of visitor data) | EU or US, per workspace region |
| Stripe, Inc. | Payment processing (account data only) | United States |
| Intercom R&D Unlimited Company | Customer support conversations (account data only) | EU |
Aurora will give at least 30 days' notice of a new subprocessor by email to workspace owners and on this page. Customer may object on reasonable data protection grounds within that period; if the parties can't resolve the objection, Customer may terminate the affected service and receive a refund of prepaid fees for it.
Data subject requests#
Aurora provides tools to find, export and delete a visitor's data through the dashboard and the API. If Aurora receives a request directly, it will refer the data subject to Customer. Aurora will provide reasonable additional assistance at no cost for standard requests.
Personal data breaches#
Aurora will notify Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer's data. The notice will describe the nature of the breach, likely consequences, measures taken and a contact point, and Aurora will provide updates as more information becomes available.
International transfers#
Customer chooses EU or US data residency. Where personal data is transferred from the EEA, UK or Switzerland to a country without an adequacy decision, the parties agree to the Standard Contractual Clauses (Module 2, controller to processor, or Module 3, processor to processor), the UK International Data Transfer Addendum and the Swiss amendments, which are incorporated by reference. Aurora Labs, Inc. also participates in the EU–US Data Privacy Framework.
Audits#
Aurora will make its current SOC 2 Type II report and completed security questionnaires available on request under confidentiality. If these are insufficient to demonstrate compliance, or where a supervisory authority requires it, Customer may conduct an audit once per year with 30 days' notice, during business hours and at its own cost.
Return and deletion#
Customer can export its data at any time. After termination, Customer data remains available for export for 30 days and is then deleted from production systems; backups roll off within a further 35 days. Aurora will confirm deletion in writing on request.
Liability and precedence#
Each party's liability under this DPA is subject to the limitations in the agreement. If this DPA conflicts with the agreement, this DPA prevails for matters of data protection; the Standard Contractual Clauses prevail over both.
Annex II — technical and organizational measures#
- Access control: SSO with hardware keys, role-based access, just-in-time production access with approval and logging.
- Encryption: TLS 1.2+ in transit; AES-256 at rest with keys managed in AWS KMS and rotated annually.
- Availability: multi-zone deployment, a failover region per residency area, daily encrypted backups tested quarterly.
- Development: peer review of all changes, automated dependency and static analysis, annual third-party penetration test.
- Organization: background checks where lawful, annual security and privacy training, documented incident response plan.