Skip to content
Back to home

Privacy policy

Last updated: [PENDIENTE: publication date of the legal texts]

This policy explains how Aurantis Consulting, S.L. processes the personal data of those who visit the site and of the users of its services, and how it processes the data that its clients entrust to it when using the platform.

1. Data controller

Controller: Aurantis Consulting, S.L. Tax identification number: [PENDIENTE]. Address: Calle Carranza 25, 5th floor office 4, 28004 Madrid, Spain. Email: hello@aurantis.io. Data protection officer: [PENDIENTE: name and contact email of the DPO, where appointment is required].

2. Two distinct roles

Aurantis acts as controller in respect of commercial contact data, of the users it administers directly and of browsing on the site. Aurantis acts as processor when it handles personal data contained in the information that the client enters into or connects to the platform, for example files on end customers, counterparties or wallet holders. In that case the controller is the client entity and Aurantis acts only on its documented instructions.

3. Data we process as controller

Identification and professional contact data (name, job title, entity, email and telephone) provided in forms, demo requests or sandbox access requests. Account and platform usage data for the client's users (identifier, role, access and activity logs). Technical browsing data (IP address, device, browser and pages visited), in accordance with the Cookie policy.

4. Purposes and legal bases

Handling requests for information, demos and sandbox access: legitimate interest in responding to the request and, where applicable, pre-contractual measures. Providing and administering the contracted service: performance of the contract. Ensuring the security, traceability and auditability of access: legitimate interest and legal obligation. Sending commercial communications about similar services to clients or to those who consent: legitimate interest or consent, with the right to object at any time. Complying with accounting, tax and regulatory obligations: legal obligation.

5. Processing on behalf of the client and DPA

When Aurantis acts as processor, it handles the data solely to provide the contracted services and following the client's instructions. The conditions (subject matter, duration, nature, types of data, categories of data subjects, security measures, assistance to the controller and return or deletion at the end of the service) are set out in a data processing agreement (DPA) that forms part of the contract. You can request the current template at hello@aurantis.io.

6. Sub-processors

Aurantis uses providers acting as sub-processors, mainly for cloud infrastructure, communications and support. All of them are subject to contractual obligations equivalent to those of this policy and of the DPA. The current list of sub-processors, with their purpose and location, is made available to clients and is updated with prior notice so that reasoned objections can be raised. Current list: [PENDIENTE: list of sub-processors and processing locations].

7. Data location and international transfers

The default infrastructure is located in the European Union (Frankfurt and Madrid regions). Clients that require it may opt for infrastructure in the United States (US East). Where an international transfer takes place, it relies on an adequacy decision or on the European Commission's standard contractual clauses, with any supplementary measures that may be required.

8. Retention

Commercial contact data is kept for as long as there is an interest in the relationship and until its deletion is requested. Contractual relationship data is kept for the duration of the contract and thereafter, blocked, for the applicable limitation periods. Data processed on behalf of the client is kept as agreed in the DPA and is returned or deleted at the end of the service, unless there is a legal retention obligation. Specific periods by category: [PENDIENTE: detailed retention policy].

9. Security measures

AES-256 encryption at rest and TLS 1.3 in transit, with managed key rotation. Role based access control, mandatory two factor authentication and federated authentication via SAML or OIDC. Dual validation on critical operations, audit logging with timestamp and hash, and periodic security reviews.

10. Recipients

We do not sell personal data. It may be accessed by the providers that render services to Aurantis under a processing agreement, as well as by authorities, courts and supervisory bodies where there is a legal obligation to disclose it.

11. Data subject rights

You can exercise the rights of access, rectification, erasure, restriction, objection and portability, and withdraw any consent given, by writing to hello@aurantis.io with suitable identification. If your data is processed by Aurantis as processor on behalf of a client entity, address your request to that entity: Aurantis will give it the necessary assistance and will forward any requests it receives.

12. Complaints

If you believe we have not properly handled your rights, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).

13. Changes to this policy

This policy may be updated to reflect legal, technical or organisational changes. We will publish the version in force on this page and state the date it was last updated.

14. Contact

For any privacy query or to request the DPA, write to hello@aurantis.io.

Aurantis Consulting, S.L. · hello@aurantis.io