Privacy Policy
Effective date: 19 May 2026
This Privacy Policy explains how AIORAS TECHNOLOGY LTD ("we", "us", "our") collects and uses personal data when you use our website and the aiora platform (the "Service"). We are the data controller for the personal data described below.
Our details
- AIORAS TECHNOLOGY LTD
- Company number: 16037096
- Registered office: 4th Floor Office, 205 Regent Street, London, England, W1B 4HB
- Contact for privacy enquiries: contact@aioras.ai
- Data Protection Officer (if appointed): privacy@aioras.ai
- ICO registration: pending registration
1. The personal data we collect
Information you give us
- Account details: name, email address, password (hashed), billing details where applicable.
- Configurator information: the role you hold (self, parent, adult-child-for-elder, employer, clinician) and any verification information required for that role.
- User profile: name or chosen name for your aiora, preferences, and personalisation settings.
- Configuration data: the guardrails, presets, and capability settings a Configurator chooses.
- Content of interactions: messages, prompts, voice input where applicable, and other content you submit when using the Service.
- Support communications.
Information we collect automatically
- Technical data: IP address, device identifiers, browser type, operating system.
- Usage data: pages viewed, features used, timestamps, error logs.
- Cookies and similar technologies (see our Cookie Policy).
Information from third parties
- Authentication providers if you sign in via a third party.
- Payment processors (we do not store full card details ourselves).
- Third-party AI providers where you use BYOK arrangements.
- Google Ads, Google Analytics, and Google Merchant Center, where you connect an account (see section 12).
- Amazon Selling Partner API, where a seller authorises access (see section 13).
2. Special-category and sensitive data
Conversations with an aiora may include sensitive information (about health, beliefs, relationships, or similar). We do not actively solicit this data, but we recognise it may be shared. We process such data only where we have an appropriate lawful basis and condition under UK GDPR, and we apply additional safeguards including access controls and minimisation.
3. Data about minors
Where a Configurator establishes an aiora for a User who is a minor, we process the minor's data in reliance on the Configurator's authority (typically parental responsibility) and apply age-appropriate safeguards consistent with the ICO's Age-Appropriate Design Code. Configurators are responsible for ensuring they have the authority to set up accounts on a minor's behalf.
4. Why we use your data and our lawful bases
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Providing and operating the Service | Contract (Art. 6(1)(b)) |
| Account management, billing, and customer support | Contract or Legal obligation |
| Improving the Service, debugging, and security | Legitimate interests (Art. 6(1)(f)): running and protecting our business |
| Detecting and responding to safety risks (including self-harm and abuse signals) | Legitimate interests or Vital interests where applicable |
| Marketing communications (where opted in) | Consent (Art. 6(1)(a)) |
| Complying with legal and regulatory obligations | Legal obligation (Art. 6(1)(c)) |
| Processing special-category data | An Article 9 condition will be identified for each case (e.g. explicit consent, vital interests, substantial public interest) |
You can withdraw consent at any time where consent is the lawful basis, without affecting prior processing.
5. AI processing and model training
We use your prompts and content to generate responses through AI systems operated by us or by third-party AI providers. We do not use your conversation content to train foundation models unless you have given separate, explicit consent. Where third-party providers process content on our behalf, we put data-processing agreements in place that prohibit them from using your content to train their models, to the extent the provider supports this.
6. Automated decision-making and data processing
The Service uses AI to generate responses and recommendations. These are not decisions that produce legal or similarly significant effects on you within the meaning of Article 22 UK GDPR. Where we do introduce any such decisions, we will tell you in advance and apply the additional safeguards required by law.
7. Sharing your data
We share personal data with:
- Service providers acting as data processors (hosting, infrastructure, AI providers, analytics, payment processors, customer-support tools), bound by data-processing agreements;
- Configurators, to the extent of their configured access to a User's account, as established at setup and consistent with applicable law;
- Authorities or third parties where required by law or to protect rights, property, or safety;
- A successor entity in the event of a merger, acquisition, or asset sale, subject to equivalent protections;
- With your consent, in any other case.
We do not sell personal data.
Sub-processors
We use the following categories of sub-processor to deliver the Service. Each sub-processor is bound by a data-processing agreement that limits processing to the purposes described in this Policy.
| Category | Purpose | Location |
|---|---|---|
| Cloud infrastructure | Hosting, compute, edge delivery | Global (edge infrastructure provider) |
| AI model providers | Generating AI responses on our behalf | US, EU |
| Payment processor | Subscription billing | US, EU |
| Analytics | Anonymised usage analytics | EU |
| Email delivery | Transactional and support email | EU |
| Amazon data connector | Retrieves a connected seller's Amazon order, fee and inventory data, on that seller's own authorisation | US |
A current list of named sub-processors is available on request by emailing privacy@aioras.ai. We will notify you of material changes to this list.
8. International transfers
Some of our providers are located outside the UK. Where personal data is transferred outside the UK, we rely on appropriate safeguards under UK GDPR, such as the International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or adequacy regulations. You can request details of the safeguards in place.
9. How long we keep your data
We keep personal data for as long as needed for the purposes set out above:
- Account data: while your account is active and for a reasonable period afterwards.
- Conversation content: per your retention settings; defaulted to a limited period and deletable on request.
- Billing records: as required by tax and accounting law (typically six years).
- Logs and security data: for a limited operational period.
After these periods we delete, anonymise, or securely archive the data.
10. Security
We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, audit logging, and developer policies. We are hardening our handling of credentials and API keys as a priority. No system is perfectly secure, and you share information at your own risk.
11. Your rights
Under UK GDPR you have the right to:
- access your personal data;
- have inaccurate data corrected;
- have data erased ("right to be forgotten") in certain circumstances;
- restrict or object to processing in certain circumstances;
- data portability;
- withdraw consent, where consent is the lawful basis;
- not be subject to solely automated decisions with legal or similarly significant effects (see section 6).
To exercise your rights, email contact@aioras.ai. We respond within one month.
If you are not satisfied, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk or by phoning 0303 123 1113. We would appreciate the chance to address concerns first.
12. Google API Services user data
Where a Configurator connects a Google Ads, Google Analytics, or Google Merchant Center account to the Service (for advertising performance reporting, analytics reporting, or product-feed reconciliation), we access the Google user data covered by the scopes you authorise through Google's OAuth consent screen.
Aioras's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We use Google user data only to provide the reporting, campaign, and reconciliation features you have requested within the Service for the account that authorised access.
- We do not use Google user data to serve advertisements, to train or improve AI or machine-learning models, or for any purpose other than operating the feature you authorised.
- We do not sell Google user data, and we do not transfer it to third parties except: (a) with your explicit consent; (b) as necessary to provide the Service through a sub-processor bound by a data-processing agreement; (c) to comply with applicable law, regulation, or a valid legal process; or (d) as part of a merger, acquisition, or asset sale, subject to equivalent protections.
- Human access to Google user data is limited to what is necessary for security, debugging at your request, or legal compliance, and is logged.
- You can revoke Aioras's access to your Google account at any time from your Google Account permissions page or from within the Service. On revocation, we stop syncing new data and delete stored Google user data within 30 days, except where retention is required by law.
13. Amazon Services API data
Where a seller connects an Amazon Seller Central account to the e-commerce audit product, we access Amazon order, financial-event, and FBA inventory data in one of two ways: today, via DataDoe, a third-party service the seller separately authorises against their own Amazon account, using a DataDoe access key the seller provides to us; or, once Aioras operates as a registered Amazon Solution Provider, directly through the seller's own Login with Amazon (LWA) authorisation. Whichever path applies to a given seller, the same commitments apply:
- Access is read-only. It covers order, financial-event (fee), and FBA inventory data, and (as those features are completed) read-only catalogue and pricing data. We do not request or receive any write access: no order fulfilment, price changes, or listing management. See our Data Handling and Security page for the full detail.
- We use Amazon-sourced data solely to reconcile the seller's own bookkeeping against their Amazon sales, fees, and inventory, for that seller's own audit reports.
- We handle Amazon Information in accordance with Amazon's Data Protection Policy and Acceptable Use Policy: it is not used for advertising, is not sold, and is not shared with any party other than the connecting seller, DataDoe (where used), and the sub-processors necessary to run the audit (bound by data-processing agreements).
- The DataDoe access key or Amazon LWA tokens are encrypted at rest and scoped per seller; no seller's Amazon data is accessible to another seller.
- A seller can disconnect at any time, by revoking their DataDoe key with us or their Amazon authorisation with DataDoe or Seller Central directly. On disconnection, we stop syncing new data and delete stored Amazon Information within 30 days, except where retention is required by law.
14. Changes
We will update this Policy from time to time. The "Effective date" at the top will reflect the latest version. Material changes will be notified to you where required.
15. Contact
contact@aioras.ai. AIORAS TECHNOLOGY LTD, 4th Floor Office, 205 Regent Street, London, England, W1B 4HB.