Privacy Policy
1.
Introduction
a.
Purpose of the Privacy Policy
This Privacy Policy aims to inform users about how AuroraWise Limited ("AuroraWise," "AW," "we," "us," or "our"), a financial technology company registered under company number 15186955 in the United Kingdom, collects, uses, discloses, and protects the personal information of its users ("you" or "your"). This policy applies to all users of the AuroraWise platform, website, mobile application, and related services (collectively, the "Services"), including but not limited to retail investors in the United Kingdom.
We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy outlines our practices regarding the collection, use, storage, sharing, and protection of your personal information in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
By using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with any part of this Privacy Policy, please refrain from using our Services.
b.
Scope of the Privacy Policy
This Privacy Policy applies to all personal information collected, used, or disclosed by AuroraWise in connection with the Services. It covers information collected through our website, mobile application, platform, and any other channels where we interact with users.
This Privacy Policy also applies to personal information collected by AuroraWise from third-party sources, such as credit reference agencies, retail banks, HMRC tax records, social media platforms, and messaging platforms, to the extent permitted by applicable laws.
The Privacy Policy does not apply to any third-party websites, applications, or services that may be linked to or accessible through our Services. We encourage you to review the privacy policies of those third parties to understand their data practices.
c.
Definition of key terms
For the purposes of this Privacy Policy, the following key terms are defined as:
- "Personal information" refers to any information that directly or indirectly relates to an identified or identifiable natural person. This may include but is not limited to, name, address, email address, phone number, financial information, and online identifiers.
- "Processing" means any operation or set of operations performed on personal information, whether by automated means or otherwise, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- "Data controller" refers to the entity that determines the purposes and means of processing personal information. In this case, AuroraWise Limited is the data controller for the personal information collected in connection with the Services.
- "Data processor" refers to the entity that processes personal information on behalf of the data controller. AuroraWise may engage third-party data processors to assist in providing the Services.
- "Consent" means any freely given, specific, informed, and unambiguous indication of the user's wishes by which they, through a statement or clear affirmative action, signify agreement to the processing of their personal information.
By providing clear definitions and explanations in the introduction, AuroraWise aims to ensure that users have a comprehensive understanding of the purpose, scope, and key terms used throughout the Privacy Policy.
2.
Information We Collect
AuroraWise collects various types of personal information from users in order to provide, maintain, and improve our Services. We collect this information directly from users, through automated means, and from third-party sources. The types of information we collect may include:
a.
Personal Information
- Identity Information
- Full name, including middle name
- Date of birth
- Gender
- Father's name
- Mother's name
- Guardian's name
- Contact Information
- Residential address, including postcode
- Billing address, including postcode
- Gender
- Email address
- Phone number
- Employment Information
- Occupation
- Employer name and address
- Employment status
- Employment history
- Education Information
- Highest level of education
- Educational institutions attended
- Qualifications obtained
b.
Financial Information
- Income Information
- Gross income
- Net income
- Sources of income (e.g., employment, investments, rental properties)
- Frequency of income (e.g., monthly, annually)
- Dates of income receipt
- Tax Information
- Tax identification number (e.g., National Insurance Number)
- Tax code
- Tax allowances and deductions
- Tax payment history
- Expense Information
- Types of expenses (e.g., housing, transportation, utilities, groceries)
- Amounts of expenses
- Frequency of expenses
- Liability Information
- Mortgages (e.g., lender, outstanding balance, monthly payments, interest rate)
- Loans (e.g., personal loans, student loans, car loans)
- Credit card balances and limits
- Other debts and financial obligations
- Asset Information
- Bank account details (e.g., account numbers, balances, transaction history)
- Investment accounts (e.g., brokerage accounts, ISAs, pensions)
- Property ownership and value
- Vehicle ownership and value
- Credit Information
- Credit scores and reports
- Credit history, including past credit applications and decisions
c.
Transactional Information
- Records of purchases, sales, and other transactions made through the Services
- Payment information, such as bank account details or payment card information
- Transaction amounts, dates, and counterparties
d.
User-Generated Content
- Profile information, such as biography, profile picture, and interests
- User preferences and settings
- Uploaded documents, images, or videos
- Comments, feedback, and reviews provided through the Services
- Messages and communications sent through the Services
e.
Usage Information
- IP address
- Device type, operating system, and browser type
- Referring and exit pages, and clickstream data
- Dates and times of access
- Pages viewed and features used within the Services
- Search queries made through the Services
f.
Location Information
- Approximate geographic location based on IP address
- Precise location (if permitted by the user's device settings)
g.
Cookies and Similar Technologies
- Information collected through cookies, web beacons, and other tracking technologies
- Unique device identifiers
- Advertising IDs
- Information about user preferences, interests, and online behaviour
h.
Information from Third-Party Sources
- Credit reference agencies
- Retail Banks
- HMRC tax records
- Electoral register
- Social media platforms
- Messaging platforms
- Publicly available sources
Please note that the specific types of information collected may vary depending on the nature of the Services used and the user's interactions with AuroraWise. We will only collect personal information that is necessary for the purposes outlined in this Privacy Policy and in accordance with applicable data protection laws.
If you choose not to provide certain personal information when requested, we may not be able to provide you with the full range of Services or features available through the AuroraWise platform.
3.
How We Use Your Information
AuroraWise uses the personal information collected from users for various purposes, including providing and improving our Services, personalizing user experiences, communicating with users, and complying with legal obligations. We may use your information for the following specific purposes:
a.
Providing and Improving Our Services
- To create and maintain user accounts
- To process transactions and deliver the Services requested by users
- To provide customer support and respond to user inquiries
- To assess user eligibility for specific products or services
- To develop, test, and improve new features and functionality
- To conduct research and analysis to understand user needs and preferences
- To monitor and analyse usage trends and patterns
- To troubleshoot and resolve technical issues
- To maintain the security and integrity of our Services
b.
Personalization and Profiling
- To tailor the content, features, and advertisements displayed to users
- To recommend products, services, or information that may be of interest to users
- To create user profiles based on information such as:
- Initial knowledge assessment, financial literacy, end-of-module tests, simulation outcomes, and performance in the sandbox environment
- Past and current trade performance
- Information about who the user follows and copies their strategy for trade
- Information on what stories users liked, bookmarked for follow-up and shared
- Various third-party integrations that the user follows or uses and for what purpose
- Information about the genre and literacy level of users
- Cookies and other tracking methods to assess user interests, preferences, and buying behaviour
- To use artificial intelligence (AI) and machine learning to:
- Determine user affordability and product eligibility
- Recommend products and services
- Provide investment and financial well-being advisory
- Curate personalized financial intelligence
c.
Marketing and Advertising
- To send promotional emails, newsletters, and other marketing communications
- To display targeted advertisements on our Services or third-party platforms
- To measure the effectiveness of our marketing and advertising efforts
- To organize events, promotions, surveys, and other marketing activities
d.
Communication and Customer Support
- To send administrative notices, updates, and alerts related to the Services
- To respond to user comments, questions, and requests for assistance
- To provide information about changes to our Services, policies, or terms
- To request user feedback and ratings
- To communicate with users for other purposes related to the Services
e.
Legal Obligations and Protection of Rights
- To comply with applicable laws, regulations, and legal processes
- To enforce our Terms of Service, Privacy Policy, and other policies
- To investigate and prevent fraudulent, unauthorized, or illegal activities
- To protect the rights, property, and safety of AuroraWise, our users, and the public
- To establish, exercise, or defend legal claims
f.
Aggregated and Anonymized Data
- To create aggregated or anonymized data that does not identify individual users
- To use aggregated or anonymized data for statistical analysis, research, and business purposes
- To share aggregated or anonymized data with third parties, such as advertisers, partners, or the public
We will only use your personal information for the purposes described in this Privacy Policy or as otherwise disclosed to you at the time of collection. If we intend to use your personal information for a new or different purpose, we will obtain your consent or provide you with an opportunity to opt out, as required by applicable law.
We will retain your personal information for as long as necessary to fulfil the purposes outlined in this Privacy Policy, comply with our legal obligations, resolve disputes, and enforce our agreements. The specific retention periods may vary depending on the type of information and the applicable legal requirements.
4.
Information Sharing and Disclosure
AuroraWise may share or disclose your personal information in certain circumstances, as described below. We will only share your information with third parties when necessary for the purposes outlined in this Privacy Policy or as required by law.
a.
Service Providers and Business Partners
- We may share your personal information with third-party service providers and business partners who assist us in providing, maintaining, and improving our Services. These may include:
- Payment processors and financial institutions
- Cloud storage and hosting providers
- Analytics and advertising platforms
- Customer support and communication services
- Fraud detection and prevention services
- Identity verification and background check providers
- We require these third parties to maintain the confidentiality and security of your personal information and to use it only for the purposes specified in our agreements with them.
b.
Structured Product Providers
- When executing structured product agreements between users and third-party providers, such as investment banks, wealth management entities, brokers, and agents, we may share necessary personal information to facilitate the transaction.
- The information shared may include identity, contact, and financial information required to complete the agreement and comply with applicable laws and regulations.
c.
Credit Reference Agencies and Compliance Vendors
- We may share your personal information with credit reference agencies for the purpose of assessing your eligibility for instalment-based products or services.
- We may also share your information with vendors performing Know Your Customer (KYC) or other compliance checks, as required by law or to prevent fraudulent activities.
d.
Legal Requirements and Protection of Rights
- We may disclose your personal information if required to do so by law, regulation, or legal process, such as a court order or subpoena.
- We may also disclose your information if we believe, in good faith, that such disclosure is necessary to:
- Comply with a legal obligation.
- Protect and defend the rights, property, or safety of AuroraWise, our users, or the public.
- Prevent or investigate possible wrongdoing in connection with the Services.
- Enforce our Terms of Service, Privacy Policy, or other agreements.
e.
Business Transfers and Corporate Restructuring
- In the event of a merger, acquisition, bankruptcy, or other sale of all or a portion of our assets, your personal information may be among the assets transferred to the acquiring entity.
- We will notify you via email and/or a prominent notice on our website of any change in ownership or uses of your personal information, as well as any choices you may have regarding your personal information.
f.
Aggregated and Anonymized Data
- We may share aggregated or anonymized data that does not identify individual users with third parties, such as advertisers, partners, or the public.
- This data may be used for statistical analysis, research, or business purposes, and may be shared in the form of reports or insights.
g.
Affiliates and Subsidiaries
- We may share your personal information with our affiliates and subsidiaries, who may use it for the purposes described in this Privacy Policy.
- Our affiliates and subsidiaries are bound by the same privacy and security obligations as AuroraWise.
h.
Consent and User Requests
- We may share your personal information with third parties if you have given us your consent to do so, or if you have requested that we share your information with a specific third party.
- You may revoke your consent or request at any time, subject to legal or contractual restrictions and reasonable notice.
We will not sell, rent, or lease your personal information to third parties for their marketing purposes without your explicit consent.
If we share your personal information with third parties, we will use reasonable efforts to ensure that they maintain appropriate safeguards to protect your information and use it only for the purposes specified in our agreements with them.
We may also disclose your personal information in other ways, with your prior consent or as otherwise permitted or required by law.
5.
Your Choices and Rights
At AuroraWise, we respect your privacy rights and strive to provide you with meaningful choices regarding the collection, use, and sharing of your personal information. This section outlines the choices and rights you have in relation to your personal information.
a.
Accessing and Updating Your Information
- You have the right to access, correct, and update the personal information we hold about you.
- You can review and update certain account information by logging into your AuroraWise account and visiting the account settings page.
- If you need assistance accessing or updating your information, or if you wish to request a copy of the personal information we have about you, please contact us using the information provided in the "Contact Us" section of this Privacy Policy.
b.
Deleting Your Account
- You have the right to request the deletion of your AuroraWise account and the personal information associated with it.
- To delete your account, please log into your account, navigate to the account settings page, and follow the instructions for account deletion. Alternatively, you can contact us directly with your deletion request.
- Please note that certain information may be retained for legal, regulatory, or business purposes, as permitted by applicable law.
c.
Opting Out of Marketing Communications
- You have the right to opt-out of receiving marketing communications from AuroraWise.
- You can unsubscribe from our marketing emails by clicking the "Unsubscribe" link at the bottom of the email or by contacting us directly.
- Please note that even if you opt-out of receiving marketing communications, we may still send you important transactional or administrative messages related to your account and the Services.
d.
Cookies and Tracking Technologies
- You have the right to control the use of cookies and similar tracking technologies on your device.
- Most web browsers are set to accept cookies by default. You can usually change your browser settings to remove or reject browser cookies. Please note that removing or rejecting cookies may affect the availability and functionality of our Services.
- For more information on how we use cookies and similar technologies, please refer to our Cookie Policy.
e.
Data Portability
- You have the right to receive a copy of your personal information in a structured, commonly used, and machine-readable format.
- You also have the right to request that we transfer your personal information to another data controller, where technically feasible.
- To exercise your data portability rights, please contact us using the information provided in the "Contact Us" section of this Privacy Policy.
f.
Right to Object and Restrict Processing
- You have the right to object to the processing of your personal information, including for direct marketing purposes.
- You also have the right to request that we restrict the processing of your personal information in certain circumstances, such as when you contest the accuracy of the information or when the processing is unlawful.
- To exercise these rights, please contact us using the information provided in the "Contact Us" section of this Privacy Policy.
g.
Right to Withdraw Consent
- Where we rely on your consent as the legal basis for processing your personal information, you have the right to withdraw your consent at any time.
- Withdrawing your consent will not affect the lawfulness of any processing carried out before you withdrew your consent.
- To withdraw your consent, please contact us using the information provided in the "Contact Us" section of this Privacy Policy.
h.
Lodging a Complaint
- If you have any concerns or complaints about how we handle your personal information, you have the right to lodge a complaint with the relevant supervisory authority.
- In the United Kingdom, the supervisory authority is the Information Commissioner's Office (ICO). You can find more information about lodging a complaint on the ICO's website: https://ico.org.uk/make-a-complaint/.
We will respond to your requests to exercise your rights within the timeframes required by applicable law. Please note that in some cases, we may need to verify your identity before processing your request or may have valid legal reasons to deny your request.
If you have any questions or need assistance exercising your rights, please contact us using the information provided in the "Contact Us" section of this Privacy Policy.
6.
Data Security
At AuroraWise, we take the security of your personal information seriously and have implemented appropriate technical and organizational measures to protect your data from unauthorized access, use, disclosure, alteration, or destruction.
a.
Secure Data Storage and Transmission
- We store your personal information on secure servers and systems that are protected by firewalls, encryption, and other industry-standard security measures.
- When transmitting sensitive information, such as financial data or payment details, we use secure encryption protocols, such as Transport Layer Security (TLS) or Secure Socket Layer (SSL), to ensure the confidentiality and integrity of the data.
b.
Access Controls and Authentication
- We employ strict access controls to ensure that only authorized personnel can access your personal information on a need-to-know basis.
- Our employees and contractors are required to sign confidentiality agreements and undergo training on data protection and security best practices.
- We use multi-factor authentication, strong passwords, and regular access reviews to prevent unauthorized access to our systems and data.
c.
Third-Party Security Measures
- When sharing your personal information with third-party service providers or business partners, we require them to maintain appropriate security measures to protect your data.
- We conduct regular security assessments and audits of our third-party providers to ensure they meet our security standards and comply with applicable data protection laws.
d.
Data Breach Response Plan
- We have implemented a comprehensive data breach response plan to detect, investigate, and respond to any suspected or confirmed security incidents promptly.
- In the event of a data breach that may affect your personal information, we will notify you and the relevant authorities as required by applicable law and take appropriate measures to mitigate any potential risks or damages.
e.
Regular Security Monitoring and Updates
- We continuously monitor our systems and networks for potential vulnerabilities and threats, and regularly update our security measures to address new risks and maintain a high level of protection.
- We keep abreast of the latest security best practices and industry standards to ensure that our security measures remain effective and up-to-date.
f.
Employee Training and Awareness
- We provide regular training and awareness programs to our employees and contractors on data protection, security best practices, and the importance of maintaining the confidentiality and integrity of personal information.
- Our employees are required to comply with our internal security policies and procedures, which are designed to safeguard your personal information and prevent unauthorized access or disclosure.
g.
Physical Security Measures
- We have implemented physical security measures at our offices and data centers to prevent unauthorized access to our systems and data.
- These measures include access controls, surveillance systems, and secured storage for physical records containing personal information.
Despite our best efforts, no security measures are perfect or impenetrable. Therefore, while we strive to protect your personal information, we cannot guarantee the absolute security of your data. In the event of a data breach, we will take prompt action to investigate the incident, notify affected individuals, and take appropriate measures to prevent future occurrences.
It is also important for you to take steps to protect your personal information, such as keeping your account credentials secure, using strong passwords, and being cautious when sharing personal information online.
If you have any concerns about the security of your personal information or suspect any unauthorized access to your account, please contact us immediately using the information provided in the "Contact Us" section of this Privacy Policy.
7.
Data Retention
AuroraWise retains your personal information for as long as necessary to fulfil the purposes outlined in this Privacy Policy, comply with our legal obligations, resolve disputes, and enforce our agreements.
a.
Retention Period
- We will retain your personal information for the duration of your relationship with AuroraWise, and for a reasonable period thereafter, as required or permitted by applicable law.
- The specific retention period may vary depending on the type of personal information, the purpose for which it was collected, and the applicable legal or regulatory requirements.
- For example, we may retain your account information for a longer period to comply with tax, accounting, or anti-money laundering laws, or to prevent fraud and abuse.
b.
Criteria for Determining Retention Periods
- When determining the appropriate retention period for your personal information, we consider various factors, including:
- The purpose(s) for which we collected the information
- The sensitivity and volume of the information
- The potential risk of harm from unauthorized use or disclosure of the information
- The applicable legal, regulatory, tax, accounting, or other requirements
- The need to defend against potential legal claims or disputes
- The feasibility of anonymizing or pseudonymizing the information while still retaining its utility
c.
Anonymization and Pseudonymization
- In some cases, we may choose to anonymize or pseudonymize your personal information instead of deleting it entirely.
- Anonymization involves irreversibly altering the personal information so that it can no longer be used to identify an individual, even when combined with other data.
- Pseudonymization involves replacing personally identifiable information with a pseudonym or alias, which can only be re-identified with additional information that is kept separately and securely.
- Anonymized or pseudonymized data may be retained for longer periods, as it no longer constitutes personal information and is not subject to the same retention limitations.
d.
Data Deletion and Destruction
- When your personal information is no longer needed for the purposes for which it was collected, or when required by applicable law, we will securely delete or destroy the information.
- We follow industry-standard practices for data deletion and destruction, such as secure wiping, physical destruction of storage media, or other methods that ensure the data is permanently and irreversibly erased.
- In some cases, we may be required to retain certain information for legal or regulatory purposes, even after a deletion request has been made. In such instances, we will limit the use of the retained information to the specific purpose for which it is being retained.
e.
Your Rights Regarding Data Retention
- You have the right to request the deletion of your personal information, subject to certain exceptions and limitations, as outlined in the "Your Choices and Rights" section of this Privacy Policy.
- If you request the deletion of your personal information, we will promptly review your request and take appropriate action in accordance with applicable law.
- Please note that deleting your personal information may affect your ability to use certain features or services provided by AuroraWise, and we may need to retain certain information to comply with our legal obligations or enforce our agreements.
f.
Third-Party Data Retention
- When we share your personal information with third-party service providers or business partners, we require them to adhere to appropriate data retention policies and securely delete or destroy your information when it is no longer needed for the purposes for which it was shared.
- However, we are not responsible for the data retention practices of third parties with whom you choose to share your personal information directly. We encourage you to review the privacy policies and data retention practices of any third parties with whom you share your information.
We periodically review our data retention policies and practices to ensure that we are only retaining your personal information for as long as necessary and in compliance with applicable laws and regulations. If you have any questions or concerns about our data retention practices, please contact us using the information provided in the "Contact Us" section of this Privacy Policy.
8.
International Data Transfers
AuroraWise is based in the United Kingdom, but we may transfer your personal information to other countries for processing and storage in accordance with this Privacy Policy and applicable laws.
a.
Legal Basis for Transfers
- When transferring your personal information outside of the United Kingdom or the European Economic Area (EEA), we will ensure that appropriate safeguards are in place to protect your data and comply with applicable data protection laws.
- We may rely on various legal bases for international data transfers, including:
- Adequacy decisions: We may transfer your personal information to countries that have been deemed to provide an adequate level of data protection by the European Commission or the UK government.
- Standard Contractual Clauses: We may use Standard Contractual Clauses approved by the European Commission or the UK Information Commissioner's Office (ICO) when transferring your personal information to countries that do not provide an adequate level of data protection.
- Binding Corporate Rules: We may transfer your personal information within our group of companies under Binding Corporate Rules approved by the relevant data protection authorities.
- Your consent: In some cases, we may seek your explicit consent to transfer your personal information to a country that does not provide an adequate level of data protection.
b.
Transfers to the United States
- If we transfer your personal information to the United States, we will ensure that the recipient is certified under the EU-US Privacy Shield Framework or the Swiss-US Privacy Shield Framework, or that other appropriate safeguards are in place, such as Standard Contractual Clauses.
- However, please note that the Privacy Shield Frameworks were invalidated by the Court of Justice of the European Union in July 2020, and we may need to rely on alternative transfer mechanisms or seek your explicit consent for such transfers.
c.
Transfers to Other Countries
- If we transfer your personal information to countries other than the United States, we will ensure that appropriate safeguards are in place, such as Standard Contractual Clauses, Binding Corporate Rules, or your explicit consent.
- We will carefully assess the data protection laws and practices of the recipient country to ensure that your personal information will be adequately protected in accordance with applicable data protection laws.
d.
Safeguards for Transfers
- Regardless of the country to which your personal information is transferred, we will implement appropriate technical, organizational, and contractual safeguards to protect your data and ensure that it is processed in accordance with this Privacy Policy and applicable data protection laws.
- These safeguards may include:
- Encryption and pseudonymization of personal information
- Confidentiality and security obligations imposed on the recipient of the information
- Restrictions on the use and disclosure of the information by the recipient
- Your rights to access, correct, delete, or object to the processing of your information
- The right to seek legal remedies in case of a data breach or violation of your rights
e.
Your Rights Regarding International Transfers
- You have the right to receive information about the safeguards we have put in place for international data transfers and to obtain a copy of any Standard Contractual Clauses or other relevant transfer agreements.
- If you have concerns about the transfer of your personal information to a specific country, you may object to the transfer or withdraw your consent, where applicable. However, please note that objecting to or withdrawing consent for international transfers may affect our ability to provide certain services to you.
If you have any questions or concerns about our international data transfer practices, please contact us using the information provided in the "Contact Us" section of this Privacy Policy.
We will regularly review and update our international data transfer practices to ensure compliance with applicable data protection laws and to protect your personal information when it is transferred outside of the United Kingdom or the EEA.
9.
Children's Privacy
AuroraWise is committed to protecting the privacy of children and complying with applicable laws and regulations, such as the United Kingdom's Age Appropriate Design Code (AADC) and the United States' Children's Online Privacy Protection Act (COPPA).
a.
Age Restrictions
- Our Services are not intended for use by children under the age of 18 or the age of majority in their jurisdiction, whichever is higher.
- We do not knowingly collect personal information from children under the age specified above without obtaining verifiable parental consent, except as permitted by applicable law.
- If we learn that we have inadvertently collected personal information from a child under the specified age without parental consent, we will take prompt steps to delete the information from our records.
b.
Parental Consent and Control
- If we offer Services that are specifically designed for children or where we have actual knowledge that a user is under the age specified above, we will obtain verifiable parental consent before collecting, using, or disclosing the child's personal information, except as permitted by applicable law.
- We will provide parents or legal guardians with the ability to review, update, or delete their child's personal information, and to withdraw their consent for the collection, use, or disclosure of their child's personal information at any time.
- We will also provide parents or legal guardians with information about our practices regarding the collection, use, and disclosure of children's personal information, and the specific controls available to them.
c.
Information Collected from Children
- We will limit the collection of personal information from children to only what is reasonably necessary for their participation in the Services and as permitted by applicable law.
- We will not condition a child's participation in an activity or Service on the disclosure of more personal information than is reasonably necessary for that activity or Service.
- We will not use children's personal information for marketing or advertising purposes, except as permitted by applicable law and with verifiable parental consent.
d.
Disclosure of Children's Information
- We will not disclose children's personal information to third parties, except as necessary to provide the Services, comply with applicable law, or protect the safety of the child or others.
- If we disclose children's personal information to third-party service providers, we will ensure that they are contractually obligated to protect the information and use it only for the specific purposes for which it was disclosed.
e.
Age Verification and Parental Notification
- Where required by applicable law, we will use reasonable efforts to verify the age of our users and obtain verifiable parental consent for the collection, use, or disclosure of children's personal information.
- We may use various methods for age verification and obtaining parental consent, such as requiring a credit card or other online payment system, providing a consent form to be signed and returned, or verifying a parent's identity through a third-party verification service.
- If we learn that we have collected personal information from a child under the specified age without parental consent, we will promptly notify the parent or legal guardian and seek to obtain their consent or delete the information from our records.
f.
Educational and Child-Directed Services
- If we offer Services that are specifically designed for schools, educational institutions, or other child-directed purposes, we will comply with any additional legal requirements applicable to such Services, such as the Family Educational Rights and Privacy Act (FERPA) in the United States.
- We will clearly disclose our practices regarding the collection, use, and disclosure of children's personal information in connection with these Services and obtain any necessary consents from parents, legal guardians, or educational institutions.
If you have any questions or concerns about our practices regarding children's privacy or if you believe that we have collected personal information from a child under the specified age without parental consent, please contact us immediately using the information provided in the "Contact Us" section of this Privacy Policy.
We will regularly review and update our children's privacy practices to ensure compliance with applicable laws and regulations and to protect the privacy and safety of children who use our Services.
10.
Third-Party Links and Services
AuroraWise's Services may contain links to third-party websites, applications, or services that are not owned, controlled, or operated by us. This Privacy Policy does not apply to those third-party services, and we encourage you to review the privacy policies of any third parties before providing them with your personal information.
a.
Links to Other Websites
- Our Services may include links to other websites or online services for your convenience and information. These websites may operate independently from AuroraWise and may have their own privacy policies or notices.
- We do not endorse, screen, or approve, and are not responsible for the privacy practices or content of such other websites or online services.
- Clicking on links to third-party websites or online services may allow those third parties to collect or share information about you. We do not control these third-party websites and are not responsible for their privacy statements or practices.
- We strongly advise you to review the privacy policy of every website you visit, especially before providing any personal information to those websites.
b.
Third-Party Services and Integrations
- Our Services may allow you to connect or interact with third-party services, such as financial institutions, payment processors, or social media platforms, through APIs, SDKs, or other integrations.
- When you choose to connect or interact with a third-party service through our Services, you are authorizing AuroraWise to share your personal information with that third party, and the collection, use, and disclosure of your information will be subject to the third party's privacy policy and practices.
- We do not control the privacy practices of these third-party services and are not responsible for how they collect, use, or share your personal information. We encourage you to carefully review the privacy policies of any third-party services you connect to or interact with through our Services.
c.
Third-Party Advertisements and Analytics
- We may allow third-party advertising companies to serve advertisements on our Services or use web beacons, cookies, or other tracking technologies to collect information about your use of our Services and other websites over time.
- These third parties may use this information to display advertisements that are more relevant to you, to measure the effectiveness of their advertising campaigns, or for other purposes.
- We may also use third-party analytics services, such as Google Analytics, to collect information about your use of our Services and other websites over time. These analytics providers may use cookies, web beacons, or other tracking technologies to collect this information and may combine it with information collected from other sources.
- We do not have control over these third-party advertising companies or analytics providers, and their use of tracking technologies and the information they collect are subject to their own privacy policies.
- If you wish to opt-out of interest-based advertising or analytics, you may be able to do so by adjusting your browser settings, using ad-blocking tools, or following the instructions provided by the relevant third-party service.
d.
Social Media Features and Widgets
- Our Services may include social media features and widgets, such as the Facebook "Like" button, the Twitter "Tweet" button, or other interactive mini-programs that run on our Services.
- These features may collect your IP address and information about which pages you visit on our Services and may set a cookie to enable the feature to function properly.
- Your interactions with these features are governed by the privacy policy of the third party providing them, not by this Privacy Policy.
- We are not responsible for the privacy practices or content of the social media platforms providing these features, and we encourage you to review their privacy policies before using these features on our Services.
If you have any questions or concerns about the privacy practices of any third parties linked to or from our Services, please contact those third parties directly.
While we strive to work with trusted and reputable third-party partners, we cannot be held responsible for the privacy practices or content of external websites, services, or platforms. We encourage you to be aware of when you leave our Services and to carefully review the privacy policies of any third-party websites or services you visit or use.
11.
Changes to the Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, the Services we offer, or applicable laws and regulations. We will notify you of any material changes to this Privacy Policy and obtain your consent, where required by law, before making any significant changes to how we collect, use, or share your personal information.
a.
Notification of Changes
- When we make material changes to this Privacy Policy, we will update the "Last Updated" date at the top of the policy and provide a prominent notice on our website or Services, or by sending you an email notification.
- We may also provide additional notice or obtain your explicit consent for certain changes, as required by applicable law.
- It is your responsibility to review this Privacy Policy periodically to stay informed about our data practices and your rights.
b.
Effective Date of Changes
- Any changes to this Privacy Policy will become effective on the date specified in the notice or, if no date is specified, on the date the revised Privacy Policy is posted on our website or Services.
- Your continued use of our Services after the effective date of the changes constitutes your acceptance of the revised Privacy Policy.
- If you do not agree with the changes to the Privacy Policy, you should stop using our Services and contact us to request the deletion of your personal information.
c.
Archived Versions
- We will archive previous versions of this Privacy Policy and make them available on our website or upon request, so that you can review the changes and understand how our data practices have evolved over time.
- However, please note that the archived versions of the Privacy Policy are provided for informational purposes only and are not legally binding. The current version of the Privacy Policy, as posted on our website or Services, will always govern our data practices and your use of the Services.
d.
Significant Changes
- If we make significant changes to this Privacy Policy that materially affect your rights or the way we collect, use, or share your personal information, we will take additional steps to bring these changes to your attention and obtain your consent, where required by law.
- Significant changes may include, but are not limited to:
- New purposes for collecting, using, or sharing your personal information that are incompatible with the purposes disclosed in the previous version of the Privacy Policy
- Changes to the categories of personal information we collect or the sources from which we collect that information
- Expansion of the categories of third parties with whom we share your personal information or the purposes for which we share that information
- Changes to your rights or choices regarding your personal information, such as limiting your ability to access, correct, or delete your information
- In such cases, we may provide additional notice, such as prominent banners or pop-up notifications on our website or Services, or send you a separate email notification, to ensure that you are aware of the changes and have the opportunity to exercise your rights.
e.
Contact Us
- If you have any questions or concerns about the changes to this Privacy Policy or our data practices, please contact us using the information provided in the "Contact Us" section of this Privacy Policy.
- We will make every effort to address your inquiries and resolve any issues you may have regarding the changes to the Privacy Policy or the way we collect, use, or share your personal information.
We encourage you to regularly review this Privacy Policy to stay informed about how we protect your privacy and handle your personal information. By continuing to use our Services after any changes to this Privacy Policy become effective, you acknowledge that you have read, understood, and agree to be bound by the revised Privacy Policy.
12.
Contact Us
If you have any questions, concerns, or feedback regarding this Privacy Policy, our data practices, or your personal information, please do not hesitate to contact us. We are committed to addressing your inquiries and resolving any issues you may have in a timely and transparent manner.
a.
Data Protection Officer
- We have appointed a Data Protection Officer (DPO) who is responsible for overseeing our compliance with applicable data protection laws and handling any privacy-related inquiries or complaints.
- You can contact our DPO using the following information:
- Name: [DPO Name]
- Email: dpo@aurorawise.com
- Postal Address:
- Data Protection Officer
- AuroraWise Limited
- 71-75 Shelton Street, Covent Garden
- London, WC2H 9JQ
- United Kingdom
b.
General Contact Information
- For general privacy inquiries or concerns, you can contact us using the following methods:
- Email: privacy@aurorawise.com
- Contact Form: [Link to contact form on the website]
- Postal Address:
- Privacy Team
- AuroraWise Limited
- 71-75 Shelton Street, Covent Garden
- London, WC2H 9JQ
- United Kingdom
- Phone: [Phone number]
c.
Response Time
- We will make every effort to respond to your inquiry or complaint within a reasonable period, typically within 30 days of receipt.
- If we require additional time to investigate your inquiry or resolve your complaint, we will notify you of the delay and provide an estimated timeline for our response.
d.
Dispute Resolution
- If you are not satisfied with our response to your privacy-related inquiry or complaint, you may have the right to lodge a complaint with the relevant supervisory authority, such as the Information Commissioner's Office (ICO) in the United Kingdom.
- Before lodging a complaint with a supervisory authority, we encourage you to contact us directly and give us the opportunity to address your concerns.
- If we are unable to resolve your complaint to your satisfaction, we will provide you with the contact information for the relevant supervisory authority and assist you in the complaint process, as required by applicable law.
e.
Feedback and Suggestions
- We welcome your feedback and suggestions on how we can improve our privacy practices or the clarity and usability of this Privacy Policy.
- If you have any ideas or recommendations, please contact us using the information provided above or through any feedback channels we may provide on our website or Services.
f.
Accessibility
- We strive to make this Privacy Policy and our communications about privacy accessible to individuals with disabilities.
- If you need this Privacy Policy or any related information in an alternative format, such as large print, Braille, or audio, please contact us using the information provided above, and we will make reasonable efforts to accommodate your request.
g.
Language
- This Privacy Policy is written in English. If there are any discrepancies or conflicts between the English version and any translated versions of the Privacy Policy, the English version shall prevail.
- If you have any questions or concerns about the interpretation of the Privacy Policy in your language, please contact us for clarification.
We are committed to building and maintaining a trusted relationship with our users, and we believe that open, honest, and transparent communication is essential to that goal. If you have any questions, concerns, or feedback about our privacy practices or this Privacy Policy, please do not hesitate to reach out to us. We are here to listen, learn, and work with you to ensure that your privacy is protected, and your personal information is handled with the utmost care and respect.
13.
Specific Provisions for UK Users
As AuroraWise is based in the United Kingdom and subject to UK data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we have included this section to address specific provisions and rights that apply to users located in the UK.
a.
Legal Basis for Processing
- Under the UK GDPR, we are required to have a valid legal basis for processing your personal information. The legal bases we rely on include:
- Consent: Where you have provided your explicit, informed, and freely given consent for us to process your personal information for a specific purpose.
- Contract: Where processing your personal information is necessary for the performance of a contract with you or to take steps at your request before entering into a contract.
- Legal Obligation: Where processing your personal information is necessary for us to comply with a legal obligation under UK law.
- Legitimate Interests: Where processing your personal information is necessary for our legitimate interests or the legitimate interests of a third party, except where such interests are overridden by your fundamental rights and freedoms.
- If you have any questions about the legal basis we rely on for a specific processing activity, please contact us using the information provided in the "Contact Us" section of this Privacy Policy.
b.
Your Rights Under UK Data Protection Law
- Under the UK GDPR and the Data Protection Act 2018, you have the following rights regarding your personal information:
- Right to be Informed: You have the right to be informed about how we collect, use, and share your personal information, as set out in this Privacy Policy.
- Right of Access: You have the right to request access to the personal information we hold about you and to receive a copy of that information in a structured, commonly used, and machine-readable format.
- Right to Rectification: You have the right to request that we correct any inaccurate or incomplete personal information we hold about you.
- Right to Erasure (Right to be Forgotten): You have the right to request that we erase your personal information in certain circumstances, such as when the information is no longer necessary for the purposes for which it was collected or when you withdraw your consent (where applicable).
- Right to Restrict Processing: You have the right to request that we restrict the processing of your personal information in certain circumstances, such as when you contest the accuracy of the information or when you object to the processing.
- Right to Data Portability: You have the right to receive a copy of your personal information in a structured, commonly used, and machine-readable format and to transmit that information to another controller, where technically feasible.
- Right to Object: You have the right to object to the processing of your personal information, including for direct marketing purposes and where we are relying on legitimate interests as the legal basis for processing.
- Rights Related to Automated Decision-Making and Profiling: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless certain exceptions apply.
- To exercise any of these rights, please contact us using the information provided in the "Contact Us" section of this Privacy Policy. We will respond to your request within the timeframes required by the UK GDPR and will provide you with any additional information required by law.
c.
Data Protection Authority
- If you are located in the UK and have any concerns about our data practices or believe that we have violated your data protection rights, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues.
- You can find more information about lodging a complaint with the ICO on their website: https://ico.org.uk/make-a-complaint/.
- Before lodging a complaint with the ICO, we encourage you to contact us directly and give us the opportunity to address your concerns.
d.
International Data Transfers
- Following the UK's withdrawal from the European Union (Brexit), the UK is considered a third country under the EU GDPR. As a result, transfers of personal information from the European Economic Area (EEA) to the UK must comply with the EU GDPR's requirements for international data transfers.
- AuroraWise has implemented appropriate safeguards, such as Standard Contractual Clauses approved by the European Commission, to ensure that personal information transferred from the EEA to the UK is adequately protected in accordance with the EU GDPR.
- If you have any questions or concerns about the transfer of your personal information from the EEA to the UK, please contact us using the information provided in the "Contact Us" section of this Privacy Policy.
e.
Retention of Personal Information
- We will retain your personal information for as long as necessary to fulfill the purposes for which it was collected, as outlined in this Privacy Policy, and to comply with our legal obligations under UK law.
- When determining the appropriate retention period for your personal information, we will consider factors such as the amount, nature, and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure of the information, the purposes for which we process the information, and whether we can achieve those purposes through other means.
- If you have any questions or concerns about our retention of your personal information, please contact us using the information provided in the "Contact Us" section of this Privacy Policy.
f.
Children's Personal Information
- If you are a child under the age of 13 and located in the UK, we will not knowingly collect or process your personal information without obtaining verifiable parental consent, except as permitted by the UK GDPR and the Data Protection Act 2018.
- If we become aware that we have inadvertently collected personal information from a child under 13 without verifiable parental consent, we will take prompt steps to delete the information from our records.
- If you are a parent or legal guardian and believe that your child under 13 has provided us with personal information without your consent, please contact us using the information provided in the "Contact Us" section of this Privacy Policy, and we will take steps to delete the information.
g.
Cookies and Similar Technologies
- We use cookies and similar technologies on our website and Services to collect information about your use of our Services and to provide certain features and functionality.
- Under the UK GDPR and the Privacy and Electronic Communications Regulations (PECR), we are required to obtain your consent before placing certain types of cookies on your device, unless the cookies are strictly necessary for the operation of our website or Services.
- When you first visit our website or use our Services, we will provide you with information about the types of cookies we use and the purposes for which we use them, and we will ask for your consent to place non-essential cookies on your device.
- You can manage your cookie preferences at any time by adjusting your browser settings or using the cookie consent tools we provide on our website.
- For more information about the cookies and similar technologies we use and how to manage your preferences, please refer to our Cookie Policy.
We are committed to ensuring that our data practices comply with UK data protection laws and that we protect the rights and freedoms of our UK users. If you have any questions or concerns about how we collect, use, or share your personal information, or if you would like to exercise any of your rights under UK data protection law, please do not hesitate to contact us using the information provided in the "Contact Us" section of this Privacy Policy.