Data Processing Addendum
Where Aura Link processes personal data on a client's behalf, we do so as a processor under a Data Processing Addendum that forms part of the master services agreement. This page summarises the standing terms of that addendum so procurement and privacy teams can review them before contracting. The executed addendum, not this summary, is the operative document.
Last updated
Roles
For data processed in the delivery of our services, the client is the controller and determines the purposes and means of processing. Aura Link is the processor and acts only on the client's documented instructions.
For our own commercial and employment data — including enquiries submitted through this website — Aura Link is the controller, and our Privacy Policy applies instead.
Scope and instructions
Processing is limited to what is necessary to deliver the services described in the applicable statement of work. We do not process client personal data for our own purposes, we do not sell it, and we do not use it to train models.
If an instruction appears to breach applicable data-protection law, we will say so and pause rather than proceed quietly.
Security measures
- Encryption in transit for all client data, and at rest where the platform supports it.
- Role-based access on the principle of least privilege, with named accounts and no shared credentials.
- Segregation between client environments; no shared production tenancy unless expressly agreed.
- Change control, logging and audit trails over administrative actions.
- Personnel bound by confidentiality obligations that survive the engagement, with security training on onboarding and annually.
The controls schedule attached to the executed addendum is the authoritative list. «TBC — align this summary with the current Annex II before publishing.»
Sub-processors
We engage sub-processors only where necessary, under written terms no less protective than our own obligations. Our current list is published on the Sub-processors page. Clients may subscribe to change notifications and may object to a new sub-processor on reasonable data-protection grounds.
Personal data breach
We notify the controller without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting their data. Notification includes what we know, what we do not yet know, the measures taken and our point of contact. We do not wait for a complete picture before telling you something has happened.
Assistance, audit and deletion
- We assist the controller with data subject requests, impact assessments and regulator engagement.
- We make available the information needed to demonstrate compliance and accommodate audits, on reasonable notice and subject to confidentiality.
- On termination we return or delete client personal data at the controller's election, except where law requires retention, in which case we tell you what is retained and why.
Requesting the addendum
Procurement and privacy teams can request the current executable addendum, our security controls schedule and our transfer impact assessment template from dpo@auralink.ae.
Questions about this page?
Our team can clarify anything here — including data-protection requests.