Privacy Policy

Last updated: May 20, 2026

1. Information We Collect

We collect information you provide when creating an account (name, email address), CRM data you enter into the platform (leads, contacts, deals, notes), technical data (IP address, browser type, device identifiers), and usage data (features used, action timestamps). This information is necessary to provide and operate the service.

2. How We Use Your Data

We use your data to provide and continuously improve the AUBDATA platform, authenticate users via magic links, send transactional emails (magic links, task reminders, notifications), generate reports and analytics scoped to your tenant, and comply with applicable legal obligations. We do not use your data for advertising.

3. Data Storage and Security

Your data is hosted on Supabase infrastructure and encrypted in transit using TLS and encrypted at rest. Row-level security enforces strict tenant isolation so no workspace can access another's data. We conduct regular security audits and maintain automated backups to protect against data loss.

4. Data Sharing

We never sell your personal data. Data is shared only with the following subprocessors: Supabase (database hosting and authentication), Resend (transactional email delivery), and Vercel (application hosting). Each subprocessor is bound by data processing agreements. Data is disclosed to authorities only when required by applicable law.

5. Your Rights

You have the right to access your personal data, correct inaccuracies, request deletion of your data, export your data in a portable format (GDPR Articles 15–20), restrict processing, and withdraw consent at any time. To exercise these rights, contact your workspace administrator or reach us at aubdata.services@gmail.com.

6. Cookies and Tracking

We use session cookies solely for authentication purposes and a locale preference cookie to remember your language choice. We do not use third-party advertising cookies or tracking pixels. You can manage cookie settings in your browser, though disabling authentication cookies will prevent you from signing in.

7. Data Retention

Your data is retained for as long as your account is active. Upon account termination, your data remains available for export for 30 days, after which it is permanently and irreversibly deleted from our systems. Audit logs are retained for a period of 12 months to support compliance and security review obligations.

8. Platform Admin Access

AUBDATA platform administrators cannot access your tenant data by default. Access can only be granted explicitly by your workspace owner from the Settings panel (Phase 24.9 access toggle). All admin access events are recorded in the audit log. You may revoke platform admin access at any time from your Settings.

9. CNDP Compliance

AUBDATA complies with Morocco's Law 09-08 on the protection of individuals with regard to the processing of personal data, enforced by the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP). Users located in Morocco have the right to access, rectify, and oppose the processing of their personal data by submitting a request to aubdata.services@gmail.com.

10. GDPR Compliance

For users in the European Economic Area (EEA), AUBDATA processes personal data in accordance with the General Data Protection Regulation (EU 2016/679). Our legal basis for processing is contract performance and legitimate interest. Any transfer of personal data outside the EEA is covered by standard contractual clauses (SCCs) as approved by the European Commission.

11. Children's Privacy

AUBDATA is a professional business tool intended exclusively for use by individuals aged 18 and over. We do not knowingly collect, process, or store personal data from minors. If we become aware that a minor has provided us with personal data, we will promptly delete it.

12. Contact Us

For privacy inquiries, data access or deletion requests, or complaints regarding our data practices, please contact us at: aubdata.services@gmail.com. We aim to respond to all legitimate privacy requests within 30 days, as required by the CNDP and GDPR frameworks.

We use essential cookies for authentication and language preferences. No tracking or advertising cookies are used. Learn more