CRM Access Authorization Statement

CRM Access Authorization Statement

Effective Date: 28th October 2025

Effective Date: 28th October 2025

This document authorizes Aura 300 Inc. (“Aura”), a Delaware corporation, to access the Client’s salon Customer Relationship Management (CRM) system strictly for the purposes of delivering its AI-powered services, including voice and messaging automation, appointment scheduling, follow-ups, and analytics.

This document authorizes Aura 300 Inc. (“Aura”), a Delaware corporation, to access the Client’s salon Customer Relationship Management (CRM) system strictly for the purposes of delivering its AI-powered services, including voice and messaging automation, appointment scheduling, follow-ups, and analytics.

  1. Parties

  • Controller (Client): The salon or business entity that subscribes to and activates the Aura 300 Services

  • Processor: Aura 300 Inc., 8 The Green, STE R, Dover, DE 19901, USA

  1. Purpose of Access

Aura requires CRM access to:

  • Retrieve and update appointment availability

  • Sync booking confirmations, cancellations, and changes

  • Personalize outbound communications

  • Enrich AI conversations with service/stylist data

  • Update customer records following calls or WhatsApp interactions

  1. Nature of Access

  • CRM login credentials will be provided by the Client or created for Aura as a unique service user (recommended)

  • Where possible, multi-factor authentication (MFA) or one-time passcodes (OTP) should be disabled for this service user to enable continuous automation

  • Aura will access the system through encrypted connections and perform role-based access control

  1. Data Scope

Data accessed may include:

  • Customer name, contact information, and notes

  • Appointment history and preferences

  • Service menus and staff assignments

  1. Limitations & Security

Aura will:

  • Only access data required for contracted services

  • Not store or export CRM data outside of permitted systems

  • Log all API or manual access events for auditability

  1. Sub-Processors

Aura may use sub-processors (e.g., AWS, OpenAI, Retell AI) under written agreements mirroring data protection obligations.

  1. Revocation of Access

Client may revoke access at any time by disabling credentials and notifying privacy@aura300.ai. Upon revocation, Aura will cease processing within 24 hours.

  1. Consent and Authorization

By ticking the checkbox during signup, Client confirms authorization of access and processing for the above purposes, and agrees to Aura’s Terms, Privacy Policy, and DPA.