Legal

Terms & Privacy

Version 2.0Last updated 23 September 2026Governing law: Estonia, EU
Fokus Labs OÜSepapaja 6, Tallinn 15551, EstoniaVAT EE102560833Registry code 16378504info@auralata.com
Draft for review. Written to match what the product actually does today, but it has not yet been through a lawyer. Do not rely on it as final legal advice before launch.

One document in three parts: the terms of service you agree to by using Auralata, the privacy policy covering your own account data, and the data processing agreement that governs your customers' data under Article 28 GDPR. They used to be three separate pages; they say the same thing they always did, just in one place instead of three.

Part 1 — Terms of service

1. What Auralata is

Auralata is a marketing tool for WooCommerce shops. It generates content, builds campaigns for email, SMS, WhatsApp, Viber, social and Meta ads, runs automated flows, and reports on what they earned. It connects to your shop through a connector plugin that you install.

Auralata does not send anything on its own. Every campaign, flow message and ad waits for a person with the right role to approve it.

2. Your account

You need a real company and a valid VAT number where one applies. You are responsible for everyone you invite and for what they do; roles decide who can create, who can approve and who can see billing. Keep credentials to yourself — two-factor authentication is available and recommended.

3. Plans, price and payment

  • Plans are priced per connected store, per month, and all prices include VAT where VAT applies. Businesses with a valid VAT number in another EU country are invoiced under the reverse charge.
  • There is no free trial. The first month is charged when you connect the store, and every following month on the same date.
  • Each plan includes an allowance of emails and AI credits. Nothing rolls over — unused allowance ends with the billing period.
  • Usage above the allowance is billed at the rates shown on the pricing page and inside the product, on the next invoice.
  • Sending credits for SMS, WhatsApp and Viber and any advertising budget are paid to your own provider at their price. We add a handling fee that is shown before every send.
  • You can set a monthly ceiling for AI spending. When it is reached, generation stops and asks; it does not keep spending.

4. Cancelling and refunds

Cancel at any time from Billing. The subscription runs to the end of the paid month and is not renewed; we do not refund a month already started, because the capacity for it is already bought. Sending stops, nothing is deleted immediately, and you can export profiles, campaigns and the brand kit for twelve months.

5. What you may not do with it

  • Send to people who did not consent on that channel. The product enforces this; working around it is a breach of these terms.
  • Buy, rent or scrape lists, or import a list you cannot prove consent for.
  • Send content that is illegal, misleading about who you are, or in breach of the rules of the channel — Meta's WhatsApp policy, for example.
  • Use the AI to imitate another brand, forge endorsements, or produce content that infringes someone else's rights.
  • Resell access to the product as your own, or run automated load against it beyond normal use.

If any of this happens we may suspend sending first and talk afterwards, because the alternative is your domain and our platform being blocked together.

6. Who owns what

Your shop data, your lists, your brand kit and everything generated for you remain yours. We claim no licence to your content beyond what is needed to run the service — storing it, rendering it, and sending it where you tell us.

The product itself, its design system, its templates and its documentation remain ours. The format library and the starting templates may be used inside your campaigns without restriction; they may not be repackaged and sold on.

AI output is not automatically protected by copyright everywhere. You are responsible for checking that what you publish does not infringe a third party's rights, which is why every generated item is labelled and editable before it goes out.

7. Availability and support

We aim for 99.5 % monthly availability of the product, excluding planned maintenance announced at least 48 hours ahead — see the status page for what that looks like right now. Sending depends on the providers you connect, and their outages are not ours to fix, though we will tell you what we see. Support is by email, Monday to Friday, with a first reply within one working day.

8. Liability

Nothing here limits liability for intent, gross negligence, personal injury, or anything else the law does not allow to be limited. Beyond that, our total liability in any twelve-month period is capped at the fees you paid in that period, and we are not liable for lost profit, lost revenue or lost goodwill.

Specifically: we are not liable for a campaign you approved, for content the AI produced and you published, or for charges from your own sending provider.

9. Changes

We can change these terms and the prices. Material changes are announced at least 30 days ahead, in the product and by email, and take effect on your next billing period. If you do not accept them, cancel before that date and nothing is charged.

10. Law and disputes

Estonian law applies and Harju County Court in Tallinn has jurisdiction. If you are a consumer rather than a business, the mandatory protections of your own country still apply. Before going to court, write to info@auralata.com — most of this is solvable by a person reading the message.

Part 2 — Privacy policy

1. Two very different roles

Auralata handles two kinds of personal data, and the law treats them differently.

  • Your account data — your name, work email, phone, company, VAT number, billing details, the people you invite and what they do in the product. For this we are the controller.
  • Your customers' data — the profiles, orders, carts, consent records and message history that come from your WooCommerce shop. For this you are the controller and we are your processor. What we may do with it is set by the data processing agreement, not by this policy.

2. What we collect, and why

Account and billing

Name, email, phone, company, address, VAT number, plan, and the invoices we issue. Legal basis: performance of the contract, and our legal obligation to keep accounting records. We never see your full card number — payments run through our payment providers.

Product usage

Which screens are opened, which actions are taken, error traces, and the volume of emails, messages and AI credits used. Legal basis: legitimate interest in running and improving a product you pay for, and in billing correctly.

Shop data

Products, prices, stock, orders, customers, carts and consent, read from your WooCommerce through the connector. We write back only coupons you approve. Legal basis: your instruction, as processor.

Content you create

Briefs, generated images and copy, campaigns and flows. Legal basis: performance of the contract. Generated assets belong to you, as set out in Part 1.

3. AI generation

When you generate an image, a clip or a line of copy, the brief you write and the relevant brand kit and product details are sent to the model provider that produces it. We do not send your customer lists to model providers, and we do not use your content to train models. Every generated item is labelled as AI inside the product and in the campaign log.

The help chat. The assistant in the app bar sends what you type, the recent messages of that conversation and a short briefing about the store on screen — its name, domain, currency and connector state — to the model provider that answers. It does not send your customer list. The conversations are kept against your account and our staff can read them: it is how we find out where the product confuses people, where the assistant answers badly and what it is being asked to do, so that we can fix it and make it work as intended. We do not use them to train models, and we do not sell or share them. Please do not type anything into the chat that you would not want us to read — a password, a card number, or a customer's personal details. Legal basis: legitimate interest in running and improving a product you pay for.

4. Who else touches the data

We use a small number of sub-processors, each for one job:

PurposeWhere
Hosting, database and backupsEU
Email deliveryEU region of the sending provider you connect
SMS, WhatsApp and Viber deliveryYour own messaging provider
AI image, video and text generationEU or US, depending on the model
Payments — Stripe and PayPalEU and US
Advertising — Meta, when you connect an ad accountEU and US
Error monitoring and product analyticsEU

The current list with company names and locations is published with the data processing agreement and updated at least thirty days before a new sub-processor starts, so you have time to object.

5. Transfers outside the EU

Where a provider processes data outside the EEA — today that is some AI models, payment providers and Meta — the transfer is covered by the European Commission's standard contractual clauses and, where applicable, by the EU–US Data Privacy Framework. You can ask us for a copy of the clauses.

6. How long we keep things

  • Account data: while the account exists, then 30 days, then deleted.
  • Invoices and accounting records: seven years, which is what the Estonian Accounting Act requires.
  • Shop and customer data: deleted or returned within 30 days of the account closing, unless you ask for it sooner.
  • Generated assets: kept for 12 months after creation so you can reuse them, then removed from active storage.
  • Assistant conversations: 12 months after the last message, then deleted.
  • Logs: 90 days for technical logs, 24 months for the campaign and approval log, because it is what proves who approved what.

7. Your rights

You can ask for access, correction, deletion, restriction, a copy of your data in a portable format, and you can object to processing based on legitimate interest. Write to info@auralata.com and we answer within 30 days. If you are unhappy with the answer you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or to the supervisory authority in your own country.

If you are a customer of a shop that uses Auralata, we are only the processor — ask the shop. If you write to us anyway, we will pass the request on and tell you we did.

8. Cookies

The marketing site uses no tracking cookies and no advertising pixels. The product uses one cookie to keep you signed in and one local setting for your theme and language. No consent banner is shown because there is nothing to consent to; see cookie settings for the full list, and if that ever changes the banner will come with the change.

9. Security

Encryption in transit and at rest, access on a need-to-know basis with two-factor authentication for our own team, separate environments for development and production, backups with tested restores, and an audit log inside the product that you can read yourself. The full list of technical and organisational measures is an annex to the data processing agreement.

10. Contact

Fokus Labs OÜ, Estonia · info@auralata.com. We have not appointed a formal data protection officer because we are below the threshold that requires one; the address above reaches the person responsible.

Part 3 — Data processing agreement

This agreement is part of the terms above. It applies whenever Auralata processes personal data on your behalf, under Article 28 GDPR, and it takes precedence over Part 1 where the two disagree about data protection.

1. Parties and roles

You, the shop that connects a WooCommerce store, are the controller. Fokus Labs OÜ, registered in Estonia, is the processor. We process personal data only on your documented instructions, which are given through the product itself and through this agreement.

2. Subject, duration, nature and purpose

  • Subject: running marketing for your shop — generating content, building and sending campaigns, running flows, and reporting on them.
  • Duration: for as long as your account exists, plus the deletion period in section 8.
  • Nature: collection from your shop, storage, organisation, enrichment with engagement data, transmission to the channels you connect, and deletion.
  • Purpose: only what you instruct. We do not use your customers' data for our own purposes, and we never sell it.

3. Categories of data and data subjects

Data subjects: your customers and subscribers, and the people in your team who use the product.

CategoryExamples
Identity and contactEmail, name, phone, city, country, language
CommercialOrders, order value, products bought, carts, lifetime value
ConsentPer channel — email, SMS, WhatsApp, Viber — with source and timestamp
EngagementOpens, clicks, deliveries, failures, flow membership, unsubscribes
TeamName, email, role, actions in the approval and audit log

We do not need, and ask you not to send, special categories of data under Article 9 — health, beliefs, biometrics and the rest.

4. Sub-processors

You give general authorisation for the sub-processors listed above in Part 2. We inform you at least 30 days before adding or replacing one, in the product and by email. If you object on reasonable data-protection grounds within that period and we cannot offer an alternative, you may terminate the affected part of the service without penalty. Each sub-processor is bound by written terms no less protective than this agreement.

5. Security measures

  • TLS 1.2 or better in transit; encryption at rest for databases, backups and stored media.
  • Role-based access inside the product, and least-privilege access for our own team with mandatory two-factor authentication.
  • Separate development, staging and production environments; production data is never copied into development.
  • Daily backups with restores tested quarterly, and a documented recovery objective of 24 hours.
  • An audit log in the product recording who created, approved, changed or deleted what, retained for 24 months.
  • Dependency and vulnerability scanning, with a disclosure address at security@auralata.com acknowledged within 72 hours.

6. Helping you meet your obligations

We help with data-subject requests: profiles can be exported, corrected, anonymised or deleted from the product itself, and we answer any request we cannot solve that way within ten working days. We also assist with impact assessments and with prior consultation, to the extent the information is ours to give.

7. Personal data breach

If a breach affects your data we notify you without undue delay and within 72 hours of becoming aware, with what happened, which categories and roughly how many people are affected, the likely consequences, and what we are doing. We do not notify your customers on your behalf — that decision is yours as controller.

8. Deletion and return

On termination you can export everything from the product. Thirty days after the account closes we delete your customer data from active systems, and backups age out within a further 90 days. Anything we must keep by law — invoices, for example — is kept only for that purpose and is not otherwise processed.

9. Audits

You may audit our compliance once per year, or after a breach, with 30 days' notice. In the first instance we answer a written questionnaire and share our current documentation; an on-site audit is possible where that is genuinely insufficient, at your cost and under confidentiality.

10. International transfers

Where a sub-processor is outside the EEA, transfers rely on the European Commission's standard contractual clauses, on an adequacy decision, or on the EU–US Data Privacy Framework where the provider is certified. A copy of the clauses is available on request.

11. Signing this

Accepting the terms of service accepts this agreement. If your own compliance process needs a signed copy on paper or a countersigned version of your own template, write to info@auralata.com and we will do it.