Privacy Policy
This notice explains how AUREON is designed to handle personal data. The final controller identity, processors, lawful bases and market-specific retention obligations must be completed before commercial launch.
1. Data AUREON may process
Account identity and age-confirmation data; login and security metadata; consent timestamps and legal-document versions; generated analyses, favorites and history; guest and account order records; payment-provider identifiers and transaction status; credit events; support messages; account-deletion/export requests; technical logs needed for security and reliability. AUREON is designed not to store raw payment-card PAN or CVC data.
2. Purposes
Data is used to create and secure accounts, provide requested analyses, preserve user history and favorites, process or reconcile purchases, deliver credits or subscriptions, respond to support requests, prevent abuse and fraud, maintain service reliability, meet accounting/legal obligations and document user choices.
3. Legal bases
Before launch, the operator must map each processing activity to the applicable legal basis. Depending on the activity, this may include performance of a contract, compliance with legal obligations, legitimate interests such as service security and fraud prevention, and consent where required for optional technologies or marketing.
4. Payments and processors
When payments are enabled, payment data will be handled primarily by the approved payment provider. AUREON should store only the metadata needed to reconcile the transaction, such as provider transaction ID, amount, currency, status and timestamps. The provider list and privacy links must be published before live payments are enabled.
5. Cookies and local storage
AUREON uses strictly necessary session/security technologies to keep users signed in and protect requests. Optional analytics or marketing technologies are disabled unless separately enabled and, where required, consented to. Current preferences can be reviewed through Cookie Preferences.
6. Retention
Account and activity data should be retained only as long as needed for the service, security and user-requested history. Transaction and accounting records may need to be retained for longer under applicable law. Support and technical records should follow documented retention schedules. The final schedule must be approved for each launch market.
7. International transfers
If a processor stores or accesses personal data outside the user's jurisdiction, AUREON must document the transfer mechanism and safeguards required by applicable data-protection law before using that processor.
8. Your rights and controls
Depending on applicable law, users may have rights to access, correct, delete, restrict or object to processing, obtain portable data, withdraw consent and lodge a complaint with a supervisory authority. AUREON includes account export and deletion-request flows; some records may be retained where law requires it.
9. Security
AUREON uses server-side authorization, CSRF protection, secure session configuration in production, rate limiting, restricted owner/admin areas, security headers and secret configuration outside the source code. No system can guarantee absolute security.
10. Children
AUREON is intended for adults aged 18 or over and is not designed for children.
11. Contact
Privacy requests: TO BE CONFIGURED BEFORE COMMERCIAL LAUNCH