Privacy Policy
Aura Link FZ-LLC engineers infrastructure that carries other organisations' data, so we hold ourselves to the same standard we are audited against. This policy explains what we collect through this website, why we collect it, how long we keep it and how you exercise your rights under the EU GDPR and the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021).
Last updated
Who is the controller
Aura Link FZ-LLC, registered at Dubai Internet City, Building 17, Dubai, United Arab Emirates, is the data controller for personal data collected through auralink.ae.
Our Data Protection Officer can be reached directly at dpo@auralink.ae. You do not need to go through a sales contact to raise a privacy matter.
What we collect
We deliberately collect as little as possible. There is no advertising pixel, no cross-site tracker and no third-party session recorder on this site.
- Enquiry data you submit yourself: your name, role, company, corporate email address, phone number, the service area you selected and your project brief.
- Technical data our servers necessarily observe to serve a page and defend against abuse: IP address, user-agent string, timestamp and the requested URL.
- Non-essential analytics: only after you opt in through Cookie Preferences. Off by default.
We do not ask for, and ask that you do not send us, special-category data or the personal data of third parties inside a project brief.
Why we process it, and on what lawful basis
- To respond to a commercial enquiry you initiated — performance of a contract, or steps taken at your request prior to entering one.
- To qualify and route your enquiry to the right engineering division — legitimate interests in operating a B2B sales function, balanced against the limited, business-context nature of the data.
- To rate-limit submissions and block automated abuse — legitimate interests in the security and availability of the service.
- To send marketing communications — your consent, which you may withdraw at any time.
- To meet accounting, tax and regulatory obligations — compliance with a legal obligation.
Fonts, CDNs and third-party requests
This site self-hosts its typefaces. Loading a page does not send your IP address to Google Fonts or any other third-party font service. We consider that a baseline requirement rather than a feature.
Where a third party does process data on our behalf — hosting, email delivery, CRM — they act as a processor under a written agreement and are listed on our Sub-processors page.
How long we keep it
- Enquiries that do not become an engagement: retained for 24 months from last contact, then deleted.
- Enquiries that become an engagement: retained for the life of the contract plus the statutory retention period applicable to the contracting entity.
- Server and security logs: 90 days, then rotated out.
- Marketing consent records: retained for as long as needed to evidence the consent, then deleted.
These periods are reviewed annually. «TBC — confirm against the backend retention job before launch.»
International transfers
We are headquartered in the UAE and operate across EMEA. Where personal data moves between jurisdictions we rely on an adequacy decision where one exists, and otherwise on the European Commission's Standard Contractual Clauses together with a transfer impact assessment.
Enterprise and sovereign clients with a data-residency requirement should raise it during scoping: our deployment model supports in-country hosting, and we would rather design for it than retrofit it.
Your rights
Subject to the conditions in the applicable law, you may ask us to:
- confirm whether we process data about you, and give you a copy;
- correct data that is inaccurate or incomplete;
- erase data we no longer have a lawful basis to keep;
- restrict or object to a particular processing activity;
- port your data to another controller in a machine-readable form;
- withdraw a consent you previously gave, without affecting processing already carried out.
Write to dpo@auralink.ae or use the Subject Access Request page. We respond within one month and will tell you if we need to extend that, and why. You may also complain to your local supervisory authority.
Security
Access to enquiry data is restricted to the personnel who need it, over authenticated channels, with transport encryption enforced end to end. Our security posture is aligned to ISO/IEC 27001 controls and is the subject of periodic internal and third-party testing.
If you believe you have found a vulnerability in this site or in anything we operate, please report it to dpo@auralink.ae before disclosing it publicly. We will acknowledge you and keep you updated.
Changes to this policy
When we change this policy we update the effective date at the top of this page. Material changes that affect how we process data you have already given us will be notified to you directly rather than left to a silent edit.
Questions about this page?
Our team can clarify anything here — including data-protection requests.