Privacy Policy

Privacy Policy

Effective Date: 28th October 2025

Effective Date: 28th October 2025

This Privacy Policy explains how Aura 300 Inc. ("Aura", "we", "us") collects, uses, and protects personal data when providing AI-powered communication and automation services to salons and beauty businesses ("Client").

This Privacy Policy explains how Aura 300 Inc. ("Aura", "we", "us") collects, uses, and protects personal data when providing AI-powered communication and automation services to salons and beauty businesses ("Client").

  1. Who We Are

Aura 300 Inc. is a Delaware C-Corp providing AI assistants (e.g., Emma, Yuki, Nami) that automate salon communication, scheduling, marketing, and analytics.

  1. Who This Applies To

  • Salon owners and their authorized staff using Aura 300 Services.

  • End customers of salons who interact with AI agents by phone, SMS, WhatsApp, or other channels.

  1. What Personal Data We Process

  • From Salon Clients: Name, business contact info, CRM login or API credentials, subscription and usage data.

  • From Salon Customers (on behalf of salon): Name, contact info (email, phone), booking history, preferences, and responses to AI agents.

  • Meta/WhatsApp Data: Message content, delivery status, opt-in/out preferences (as applicable).

  1. Legal Basis for Processing

Aura processes personal data:

  • As a data processor on behalf of salons (the data controller), per GDPR Art. 28.

  • As a data controller for limited administrative data (e.g., salon accounts, support logs) under legitimate interests or contractual necessity.

  1. Data Use

We use data to:

  • Deliver our AI reception, booking, marketing, and analytics services.

  • Authenticate and sync with CRM systems.

  • Improve our AI performance and customer experience.

  • Comply with legal obligations and enforce our terms.

  1. Sharing and Sub-Processors

We use third-party sub-processors to deliver services, including:

  • Twilio (telephony and SMS)

  • Meta (WhatsApp Business)

  • OpenAI/Anthropic/Retell.ai (language models)

  • AWS (infrastructure hosting)

  • All sub-processors are under contract with equivalent data protection obligations. A current list is available upon request.

  1. International Transfers

We use Standard Contractual Clauses and UK Addendum where required for transfers outside the EU/UK.

  1. Data Retention

  • Salon account data is retained while the subscription is active.

  • Customer data processed on behalf of salons is deleted within 30 days of termination unless otherwise instructed by the salon.

  1. Your Rights (if applicable)

Depending on your jurisdiction, you may have the right to:

  • Access personal data held about you

  • Request correction or deletion

  • Object to certain types of processing

  • Withdraw consent where processing is based on consent

  1. Security

We implement encryption, access controls, audit logs, and regular testing to protect data.

  1. Children

Aura services are not directed at individuals under the age of 16. Salons are responsible for ensuring lawful data collection from minors where applicable.

  1. Marketing Communications

All marketing communications sent via Aura AI are governed by the salon’s lawful basis and consent mechanisms. We honor opt-out preferences at all times.

  1. Changes to this Policy

We may update this policy periodically. Significant changes will be notified via email or platform dashboard.

  1. Mergers and Acquisitions

In the event of a merger, acquisition, or sale of Aura 300 Inc., personal data may be transferred to the acquiring party, provided they commit to data protection standards no less protective than those in this Policy.

15. Contact

Email: privacy@aura300.ai