Terms & Privacy
One document in three parts: the terms of service you agree to by using Auralata, the privacy policy covering your own account data, and the data processing agreement that governs your customers' data under Article 28 GDPR. They used to be three separate pages; they say the same thing they always did, just in one place instead of three.
Part 1 — Terms of service
1. What Auralata is
Auralata is a marketing tool for WooCommerce shops. It generates content, builds campaigns for email, SMS, WhatsApp, Viber, social and Meta ads, runs automated flows, and reports on what they earned. It connects to your shop through a connector plugin that you install.
Auralata does not send anything on its own. Every campaign, flow message and ad waits for a person with the right role to approve it.
2. Your account
You need a real company and a valid VAT number where one applies. You are responsible for everyone you invite and for what they do; roles decide who can create, who can approve and who can see billing. Keep credentials to yourself — two-factor authentication is available and recommended.
3. Plans, price and payment
- Plans are priced per connected store, per month, and all prices include VAT where VAT applies. Businesses with a valid VAT number in another EU country are invoiced under the reverse charge.
- There is no free trial. The first month is charged when you connect the store, and every following month on the same date.
- Each plan includes an allowance of emails and AI credits. Nothing rolls over — unused allowance ends with the billing period.
- Usage above the allowance is billed at the rates shown on the pricing page and inside the product, on the next invoice.
- Sending credits for SMS, WhatsApp and Viber and any advertising budget are paid to your own provider at their price. We add a handling fee that is shown before every send.
- You can set a monthly ceiling for AI spending. When it is reached, generation stops and asks; it does not keep spending.
4. Cancelling and refunds
Cancel at any time from Billing. The subscription runs to the end of the paid month and is not renewed; we do not refund a month already started, because the capacity for it is already bought. Sending stops, nothing is deleted immediately, and you can export profiles, campaigns and the brand kit for twelve months.
5. What you may not do with it
- Send to people who did not consent on that channel. The product enforces this; working around it is a breach of these terms.
- Buy, rent or scrape lists, or import a list you cannot prove consent for.
- Send content that is illegal, misleading about who you are, or in breach of the rules of the channel — Meta's WhatsApp policy, for example.
- Use the AI to imitate another brand, forge endorsements, or produce content that infringes someone else's rights.
- Resell access to the product as your own, or run automated load against it beyond normal use.
If any of this happens we may suspend sending first and talk afterwards, because the alternative is your domain and our platform being blocked together.
6. Who owns what
Your shop data, your lists, your brand kit and everything generated for you remain yours. We claim no licence to your content beyond what is needed to run the service — storing it, rendering it, and sending it where you tell us.
The product itself, its design system, its templates and its documentation remain ours. The format library and the starting templates may be used inside your campaigns without restriction; they may not be repackaged and sold on.
AI output is not automatically protected by copyright everywhere. You are responsible for checking that what you publish does not infringe a third party's rights, which is why every generated item is labelled and editable before it goes out.
7. Availability and support
We aim for 99.5 % monthly availability of the product, excluding planned maintenance announced at least 48 hours ahead — see the status page for what that looks like right now. Sending depends on the providers you connect, and their outages are not ours to fix, though we will tell you what we see. Support is by email, Monday to Friday, with a first reply within one working day.
8. Liability
Nothing here limits liability for intent, gross negligence, personal injury, or anything else the law does not allow to be limited. Beyond that, our total liability in any twelve-month period is capped at the fees you paid in that period, and we are not liable for lost profit, lost revenue or lost goodwill.
Specifically: we are not liable for a campaign you approved, for content the AI produced and you published, or for charges from your own sending provider.
9. Changes
We can change these terms and the prices. Material changes are announced at least 30 days ahead, in the product and by email, and take effect on your next billing period. If you do not accept them, cancel before that date and nothing is charged.
10. Law and disputes
Estonian law applies and Harju County Court in Tallinn has jurisdiction. If you are a consumer rather than a business, the mandatory protections of your own country still apply. Before going to court, write to info@auralata.com — most of this is solvable by a person reading the message.
Part 2 — Privacy policy
1. Two very different roles
Auralata handles two kinds of personal data, and the law treats them differently.
- Your account data — your name, work email, phone, company, VAT number, billing details, the people you invite and what they do in the product. For this we are the controller.
- Your customers' data — the profiles, orders, carts, consent records and message history that come from your WooCommerce shop. For this you are the controller and we are your processor. What we may do with it is set by the data processing agreement, not by this policy.
2. What we collect, and why
Account and billing
Name, email, phone, company, address, VAT number, plan, and the invoices we issue. Legal basis: performance of the contract, and our legal obligation to keep accounting records. We never see your full card number — payments run through our payment providers.
Product usage
Which screens are opened, which actions are taken, error traces, and the volume of emails, messages and AI credits used. Legal basis: legitimate interest in running and improving a product you pay for, and in billing correctly.
Shop data
Products, prices, stock, orders, customers, carts and consent, read from your WooCommerce through the connector. We write back only coupons you approve. Legal basis: your instruction, as processor.
Content you create
Briefs, generated images and copy, campaigns and flows. Legal basis: performance of the contract. Generated assets belong to you, as set out in Part 1.
3. AI generation
When you generate an image, a clip or a line of copy, the brief you write and the relevant brand kit and product details are sent to the model provider that produces it. We do not send your customer lists to model providers, and we do not use your content to train models. Every generated item is labelled as AI inside the product and in the campaign log.
The help chat. The assistant in the app bar sends what you type, the recent messages of that conversation and a short briefing about the store on screen — its name, domain, currency and connector state — to the model provider that answers. It does not send your customer list. The conversations are kept against your account and our staff can read them: it is how we find out where the product confuses people, where the assistant answers badly and what it is being asked to do, so that we can fix it and make it work as intended. We do not use them to train models, and we do not sell or share them. Please do not type anything into the chat that you would not want us to read — a password, a card number, or a customer's personal details. Legal basis: legitimate interest in running and improving a product you pay for.
4. Who else touches the data
We use a small number of sub-processors, each for one job:
| Purpose | Where |
|---|---|
| Hosting, database and backups | EU |
| Email delivery | EU region of the sending provider you connect |
| SMS, WhatsApp and Viber delivery | Your own messaging provider |
| AI image, video and text generation | EU or US, depending on the model |
| Payments — Stripe and PayPal | EU and US |
| Advertising — Meta, when you connect an ad account | EU and US |
| Error monitoring and product analytics | EU |
The current list with company names and locations is published with the data processing agreement and updated at least thirty days before a new sub-processor starts, so you have time to object.
5. Transfers outside the EU
Where a provider processes data outside the EEA — today that is some AI models, payment providers and Meta — the transfer is covered by the European Commission's standard contractual clauses and, where applicable, by the EU–US Data Privacy Framework. You can ask us for a copy of the clauses.
6. How long we keep things
- Account data: while the account exists, then 30 days, then deleted.
- Invoices and accounting records: seven years, which is what the Estonian Accounting Act requires.
- Shop and customer data: deleted or returned within 30 days of the account closing, unless you ask for it sooner.
- Generated assets: kept for 12 months after creation so you can reuse them, then removed from active storage.
- Assistant conversations: 12 months after the last message, then deleted.
- Logs: 90 days for technical logs, 24 months for the campaign and approval log, because it is what proves who approved what.
7. Your rights
You can ask for access, correction, deletion, restriction, a copy of your data in a portable format, and you can object to processing based on legitimate interest. Write to info@auralata.com and we answer within 30 days. If you are unhappy with the answer you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or to the supervisory authority in your own country.
If you are a customer of a shop that uses Auralata, we are only the processor — ask the shop. If you write to us anyway, we will pass the request on and tell you we did.
8. Cookies
The marketing site uses no tracking cookies and no advertising pixels. The product uses one cookie to keep you signed in and one local setting for your theme and language. No consent banner is shown because there is nothing to consent to; see cookie settings for the full list, and if that ever changes the banner will come with the change.
9. Security
Encryption in transit and at rest, access on a need-to-know basis with two-factor authentication for our own team, separate environments for development and production, backups with tested restores, and an audit log inside the product that you can read yourself. The full list of technical and organisational measures is an annex to the data processing agreement.
10. Contact
Fokus Labs OÜ, Estonia · info@auralata.com. We have not appointed a formal data protection officer because we are below the threshold that requires one; the address above reaches the person responsible.
Part 3 — Data processing agreement
This agreement is part of the terms above. It applies whenever Auralata processes personal data on your behalf, under Article 28 GDPR, and it takes precedence over Part 1 where the two disagree about data protection.
1. Parties and roles
You, the shop that connects a WooCommerce store, are the controller. Fokus Labs OÜ, registered in Estonia, is the processor. We process personal data only on your documented instructions, which are given through the product itself and through this agreement.
2. Subject, duration, nature and purpose
- Subject: running marketing for your shop — generating content, building and sending campaigns, running flows, and reporting on them.
- Duration: for as long as your account exists, plus the deletion period in section 8.
- Nature: collection from your shop, storage, organisation, enrichment with engagement data, transmission to the channels you connect, and deletion.
- Purpose: only what you instruct. We do not use your customers' data for our own purposes, and we never sell it.
3. Categories of data and data subjects
Data subjects: your customers and subscribers, and the people in your team who use the product.
| Category | Examples |
|---|---|
| Identity and contact | Email, name, phone, city, country, language |
| Commercial | Orders, order value, products bought, carts, lifetime value |
| Consent | Per channel — email, SMS, WhatsApp, Viber — with source and timestamp |
| Engagement | Opens, clicks, deliveries, failures, flow membership, unsubscribes |
| Team | Name, email, role, actions in the approval and audit log |
We do not need, and ask you not to send, special categories of data under Article 9 — health, beliefs, biometrics and the rest.
4. Sub-processors
You give general authorisation for the sub-processors listed above in Part 2. We inform you at least 30 days before adding or replacing one, in the product and by email. If you object on reasonable data-protection grounds within that period and we cannot offer an alternative, you may terminate the affected part of the service without penalty. Each sub-processor is bound by written terms no less protective than this agreement.
5. Security measures
- TLS 1.2 or better in transit; encryption at rest for databases, backups and stored media.
- Role-based access inside the product, and least-privilege access for our own team with mandatory two-factor authentication.
- Separate development, staging and production environments; production data is never copied into development.
- Daily backups with restores tested quarterly, and a documented recovery objective of 24 hours.
- An audit log in the product recording who created, approved, changed or deleted what, retained for 24 months.
- Dependency and vulnerability scanning, with a disclosure address at security@auralata.com acknowledged within 72 hours.
6. Helping you meet your obligations
We help with data-subject requests: profiles can be exported, corrected, anonymised or deleted from the product itself, and we answer any request we cannot solve that way within ten working days. We also assist with impact assessments and with prior consultation, to the extent the information is ours to give.
7. Personal data breach
If a breach affects your data we notify you without undue delay and within 72 hours of becoming aware, with what happened, which categories and roughly how many people are affected, the likely consequences, and what we are doing. We do not notify your customers on your behalf — that decision is yours as controller.
8. Deletion and return
On termination you can export everything from the product. Thirty days after the account closes we delete your customer data from active systems, and backups age out within a further 90 days. Anything we must keep by law — invoices, for example — is kept only for that purpose and is not otherwise processed.
9. Audits
You may audit our compliance once per year, or after a breach, with 30 days' notice. In the first instance we answer a written questionnaire and share our current documentation; an on-site audit is possible where that is genuinely insufficient, at your cost and under confidentiality.
10. International transfers
Where a sub-processor is outside the EEA, transfers rely on the European Commission's standard contractual clauses, on an adequacy decision, or on the EU–US Data Privacy Framework where the provider is certified. A copy of the clauses is available on request.
11. Signing this
Accepting the terms of service accepts this agreement. If your own compliance process needs a signed copy on paper or a countersigned version of your own template, write to info@auralata.com and we will do it.