Privacy Policy
Last updated: June 2026
Introduction and Scope
This Privacy Policy describes how AURALOGICAL LTD ("we", "us", or "our"), a company registered in England and Wales and operating from LYTCHETT HOUSE Unit 13 Freeland Park, Wareham Road, Lytchett Matravers, POOLE, BH16 6FA United Kingdom, collects, uses, stores, shares, and protects personal data when you visit our website at https://auralogical.guru, use our software products, engage our professional services, or otherwise interact with us.
As a software publisher providing SaaS solutions, enterprise software, custom computer programming services, systems integration, and related information technology services, we process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) as incorporated into UK law by the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), and all applicable supplementary guidance issued by the Information Commissioner's Office (ICO).
This policy applies to all individuals whose personal data we process, including website visitors, prospective clients, current clients, software end users, business contacts, suppliers, contractors, and any other individuals who interact with our organisation through digital or physical channels.
We are committed to ensuring that your privacy is protected and that all personal data processing activities are conducted lawfully, fairly, and transparently. This document provides comprehensive information about our data processing practices so that you can make informed decisions about sharing your personal data with us.
Data Controller Information
AURALOGICAL LTD is the data controller responsible for your personal data. Our registered office is located at LYTCHETT HOUSE Unit 13 Freeland Park, Wareham Road, Lytchett Matravers, POOLE, BH16 6FA United Kingdom.
For all data protection enquiries, requests to exercise your rights, or concerns about how we handle your personal data, please contact us at it@auralogical.guru or by telephone at +44 7378 336699. We aim to respond to all data protection enquiries within one calendar month, in accordance with statutory requirements.
Where we process personal data on behalf of our clients in connection with software products or services we develop, host, or manage, we may act as a data processor. In such cases, the relevant client remains the data controller, and processing is governed by a separate Data Processing Agreement that defines the scope, purpose, and security obligations of our processing activities.
Categories of Personal Data We Collect
We collect and process various categories of personal data depending on the nature of your relationship with us and the services you use. The categories of personal data we may collect include:
Identity Data
This includes your full name, job title, company name, username, and similar identifiers that allow us to recognise you in the context of our business relationship.
Contact Data
This includes your email address, telephone number, postal address, and any other contact details you provide when submitting enquiries, registering for services, or communicating with our team.
Technical Data
This includes your Internet Protocol (IP) address, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform, device identifiers, and other technology on the devices you use to access our website or software products.
Usage Data
This includes information about how you use our website, software applications, and services, including pages visited, features accessed, session duration, click patterns, navigation paths, and interaction with content.
Communication Data
This includes records of correspondence when you contact us, including emails, telephone call notes, meeting records, support tickets, and production request submissions.
Transaction Data
This includes details about payments to and from you, billing addresses, invoice records, purchase history, and other financial information related to services you have purchased from us.
Professional Data
This includes information about your business requirements, project specifications, technical infrastructure, and other professional details shared during alignment consultations, proofing engagements, and ongoing service delivery.
Marketing Data
This includes your preferences in receiving marketing communications from us and your communication preferences across different channels.
How We Collect Personal Data
We collect personal data through various methods, both directly and indirectly. Direct collection occurs when you provide data to us voluntarily, such as when you complete our contact form, submit a production request, register for a software product, sign a service agreement, communicate with us by email or telephone, or visit our offices.
We also collect data automatically when you interact with our website or software products. This includes technical and usage data collected through cookies, server logs, analytics tools, and similar technologies. For detailed information about our use of cookies, please refer to our Cookie Policy.
We may receive personal data about you from third parties, including publicly available sources such as Companies House records and professional networking platforms, our business partners and referral sources, credit reference agencies where applicable for commercial transactions, and publicly accessible directories and databases relevant to our business development activities.
When we receive personal data from third parties, we ensure that the data has been collected lawfully and that appropriate notices have been provided to the data subjects concerned. We apply the same data protection standards to third-party sourced data as we do to data collected directly from you.
Purposes and Legal Bases for Processing
We process your personal data only where we have a valid legal basis under the UK GDPR. The purposes for which we process personal data and the corresponding legal bases are set out below.
Service Delivery and Contract Performance
We process identity, contact, professional, and communication data to perform our contract with you, deliver software products and services, manage production engagements, provide technical support, and fulfil our obligations under service agreements. The legal basis for this processing is Article 6(1)(b) UK GDPR — processing necessary for the performance of a contract.
Legitimate Business Interests
We process technical, usage, and communication data to improve our website and software products, develop new features, conduct internal analytics, maintain network security, prevent fraud, and pursue our legitimate business interests in operating and growing our software publishing business. The legal basis is Article 6(1)(f) UK GDPR, balanced against your rights and freedoms.
Legal and Regulatory Compliance
We process personal data where necessary to comply with legal obligations, including tax reporting, financial record keeping, responding to lawful requests from public authorities, and meeting industry-specific regulatory requirements applicable to software publishers and information service providers. The legal basis is Article 6(1)(c) UK GDPR.
Consent-Based Processing
Where we send direct marketing communications or use non-essential cookies, we rely on your consent as the legal basis for processing. You may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. The legal basis is Article 6(1)(a) UK GDPR.
Data Sharing and Disclosure
We do not sell your personal data to third parties. We may share your personal data with trusted third parties in the following circumstances, always ensuring appropriate safeguards are in place.
Service providers and subprocessors who assist us in delivering our services, including cloud hosting providers, payment processors, email service providers, analytics platforms, customer relationship management systems, and IT infrastructure providers. All such parties are bound by contractual obligations to process data only on our instructions and maintain appropriate security measures.
Professional advisers including solicitors, accountants, auditors, and insurers who require access to personal data in the course of providing their services to us. These parties are bound by professional obligations of confidentiality.
Regulatory bodies, law enforcement agencies, courts, and other public authorities when required by law, court order, or regulatory obligation, or when disclosure is necessary to protect our legal rights, your safety, or the safety of others.
In connection with any merger, acquisition, reorganisation, or sale of assets, personal data may be transferred to the acquiring entity, subject to the same privacy protections described in this policy. We will notify affected individuals of any such change in ownership or control of their personal data.
Where we transfer personal data outside the United Kingdom, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the UK Information Commissioner, adequacy decisions, or binding corporate rules, as applicable under UK data protection law.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, accounting, and reporting requirements. Retention periods vary depending on the category of data and the purpose of processing.
Contact and enquiry data submitted through our website is retained for three years from the date of last interaction, unless a business relationship is established, in which case data is retained for the duration of the relationship plus seven years for legal and accounting purposes.
Client and contract data, including project specifications, correspondence, and deliverable records, is retained for the duration of the service agreement plus seven years following termination, in accordance with UK limitation periods for contractual claims and HMRC record-keeping requirements.
Technical and usage data collected through cookies and analytics tools is retained in accordance with the periods specified in our Cookie Policy, typically between thirteen and twenty-six months depending on the specific technology.
Marketing consent records are retained for as long as consent remains active, plus three years following withdrawal, to demonstrate compliance with consent requirements.
When personal data is no longer required, we securely delete or anonymise it using industry-standard methods. Anonymised data that cannot be linked back to an individual may be retained indefinitely for statistical and analytical purposes.
Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, destruction, and accidental loss. Our security framework is designed to meet the standards expected of a software publisher handling client data and proprietary business information.
Technical measures include encryption of data in transit using TLS 1.2 or higher, encryption of sensitive data at rest, multi-factor authentication for systems accessing personal data, regular security patching and vulnerability management, network segmentation and firewall protection, intrusion detection and monitoring systems, and regular automated and manual security testing of our applications and infrastructure.
Organisational measures include role-based access controls limiting data access to authorised personnel, mandatory data protection training for all staff, documented information security policies and procedures, incident response plans with defined escalation procedures, regular security risk assessments and audits, and contractual security requirements imposed on all third-party processors.
Despite our comprehensive security measures, no method of electronic transmission or storage is completely secure. While we strive to protect your personal data using commercially acceptable means, we cannot guarantee absolute security. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office within seventy-two hours and affected individuals without undue delay, as required by UK GDPR.
Your Rights Under UK GDPR
Under the UK General Data Protection Regulation, you have several rights regarding your personal data. We respect and facilitate the exercise of these rights without undue delay and within one month of receiving your request.
Right of Access
You have the right to request a copy of the personal data we hold about you, together with information about how we process it. This is commonly known as a Subject Access Request.
Right to Rectification
You have the right to request correction of inaccurate personal data and to have incomplete data completed.
Right to Erasure
You have the right to request deletion of your personal data where there is no compelling reason for its continued processing, subject to certain exceptions such as legal obligations requiring retention.
Right to Restrict Processing
You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of data or object to processing based on legitimate interests.
Right to Data Portability
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
Right to Object
You have the right to object to processing based on legitimate interests, including profiling, and to object to direct marketing at any time.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal or similarly significant effects, except where necessary for contract performance, authorised by law, or based on your explicit consent.
Children's Privacy
Our website and services are not directed at individuals under the age of eighteen. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate parental consent, we will take steps to delete that information promptly. If you believe we have collected data from a child, please contact us at the address provided in this policy.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. The updated policy will be posted on this page with a revised effective date. We encourage you to review this policy periodically. For material changes that significantly affect how we process your personal data, we will provide additional notice through email or a prominent notice on our website.
This Privacy Policy was last updated in June 2026. Previous versions are available upon request by contacting it@auralogical.guru.
Complaints and Supervisory Authority
If you have concerns about how we handle your personal data, we encourage you to contact us first at it@auralogical.guru so that we can address your concerns directly. We take all complaints seriously and will investigate and respond within the statutory timeframe.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection. The ICO can be contacted at Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, telephone 0303 123 1113, or via the website at ico.org.uk.
We regularly review our data processing activities to ensure ongoing compliance with UK data protection legislation. Our Data Protection Impact Assessment procedures require evaluation of any new processing activity that may result in high risk to individuals. Internal audits of data handling practices are conducted annually, with findings documented and remedial actions tracked to completion. Staff members with access to personal data receive mandatory data protection training upon commencement of employment and annual refresher training thereafter. Our information asset register documents all systems processing personal data, including the categories of data processed, legal bases, retention periods, and security controls applied to each system.
We regularly review our data processing activities to ensure ongoing compliance with UK data protection legislation. Our Data Protection Impact Assessment procedures require evaluation of any new processing activity that may result in high risk to individuals. Internal audits of data handling practices are conducted annually, with findings documented and remedial actions tracked to completion. Staff members with access to personal data receive mandatory data protection training upon commencement of employment and annual refresher training thereafter. Our information asset register documents all systems processing personal data, including the categories of data processed, legal bases, retention periods, and security controls applied to each system.
We regularly review our data processing activities to ensure ongoing compliance with UK data protection legislation. Our Data Protection Impact Assessment procedures require evaluation of any new processing activity that may result in high risk to individuals. Internal audits of data handling practices are conducted annually, with findings documented and remedial actions tracked to completion. Staff members with access to personal data receive mandatory data protection training upon commencement of employment and annual refresher training thereafter. Our information asset register documents all systems processing personal data, including the categories of data processed, legal bases, retention periods, and security controls applied to each system.
We regularly review our data processing activities to ensure ongoing compliance with UK data protection legislation. Our Data Protection Impact Assessment procedures require evaluation of any new processing activity that may result in high risk to individuals. Internal audits of data handling practices are conducted annually, with findings documented and remedial actions tracked to completion. Staff members with access to personal data receive mandatory data protection training upon commencement of employment and annual refresher training thereafter. Our information asset register documents all systems processing personal data, including the categories of data processed, legal bases, retention periods, and security controls applied to each system.
We regularly review our data processing activities to ensure ongoing compliance with UK data protection legislation. Our Data Protection Impact Assessment procedures require evaluation of any new processing activity that may result in high risk to individuals. Internal audits of data handling practices are conducted annually, with findings documented and remedial actions tracked to completion. Staff members with access to personal data receive mandatory data protection training upon commencement of employment and annual refresher training thereafter. Our information asset register documents all systems processing personal data, including the categories of data processed, legal bases, retention periods, and security controls applied to each system.
We regularly review our data processing activities to ensure ongoing compliance with UK data protection legislation. Our Data Protection Impact Assessment procedures require evaluation of any new processing activity that may result in high risk to individuals. Internal audits of data handling practices are conducted annually, with findings documented and remedial actions tracked to completion. Staff members with access to personal data receive mandatory data protection training upon commencement of employment and annual refresher training thereafter. Our information asset register documents all systems processing personal data, including the categories of data processed, legal bases, retention periods, and security controls applied to each system.
We regularly review our data processing activities to ensure ongoing compliance with UK data protection legislation. Our Data Protection Impact Assessment procedures require evaluation of any new processing activity that may result in high risk to individuals. Internal audits of data handling practices are conducted annually, with findings documented and remedial actions tracked to completion. Staff members with access to personal data receive mandatory data protection training upon commencement of employment and annual refresher training thereafter. Our information asset register documents all systems processing personal data, including the categories of data processed, legal bases, retention periods, and security controls applied to each system.
We regularly review our data processing activities to ensure ongoing compliance with UK data protection legislation. Our Data Protection Impact Assessment procedures require evaluation of any new processing activity that may result in high risk to individuals. Internal audits of data handling practices are conducted annually, with findings documented and remedial actions tracked to completion. Staff members with access to personal data receive mandatory data protection training upon commencement of employment and annual refresher training thereafter. Our information asset register documents all systems processing personal data, including the categories of data processed, legal bases, retention periods, and security controls applied to each system.
We regularly review our data processing activities to ensure ongoing compliance with UK data protection legislation. Our Data Protection Impact Assessment procedures require evaluation of any new processing activity that may result in high risk to individuals. Internal audits of data handling practices are conducted annually, with findings documented and remedial actions tracked to completion. Staff members with access to personal data receive mandatory data protection training upon commencement of employment and annual refresher training thereafter. Our information asset register documents all systems processing personal data, including the categories of data processed, legal bases, retention periods, and security controls applied to each system.
We regularly review our data processing activities to ensure ongoing compliance with UK data protection legislation. Our Data Protection Impact Assessment procedures require evaluation of any new processing activity that may result in high risk to individuals. Internal audits of data handling practices are conducted annually, with findings documented and remedial actions tracked to completion. Staff members with access to personal data receive mandatory data protection training upon commencement of employment and annual refresher training thereafter. Our information asset register documents all systems processing personal data, including the categories of data processed, legal bases, retention periods, and security controls applied to each system.
We regularly review our data processing activities to ensure ongoing compliance with UK data protection legislation. Our Data Protection Impact Assessment procedures require evaluation of any new processing activity that may result in high risk to individuals. Internal audits of data handling practices are conducted annually, with findings documented and remedial actions tracked to completion. Staff members with access to personal data receive mandatory data protection training upon commencement of employment and annual refresher training thereafter. Our information asset register documents all systems processing personal data, including the categories of data processed, legal bases, retention periods, and security controls applied to each system.
We regularly review our data processing activities to ensure ongoing compliance with UK data protection legislation. Our Data Protection Impact Assessment procedures require evaluation of any new processing activity that may result in high risk to individuals. Internal audits of data handling practices are conducted annually, with findings documented and remedial actions tracked to completion. Staff members with access to personal data receive mandatory data protection training upon commencement of employment and annual refresher training thereafter. Our information asset register documents all systems processing personal data, including the categories of data processed, legal bases, retention periods, and security controls applied to each system.
We regularly review our data processing activities to ensure ongoing compliance with UK data protection legislation. Our Data Protection Impact Assessment procedures require evaluation of any new processing activity that may result in high risk to individuals. Internal audits of data handling practices are conducted annually, with findings documented and remedial actions tracked to completion. Staff members with access to personal data receive mandatory data protection training upon commencement of employment and annual refresher training thereafter. Our information asset register documents all systems processing personal data, including the categories of data processed, legal bases, retention periods, and security controls applied to each system.
We regularly review our data processing activities to ensure ongoing compliance with UK data protection legislation. Our Data Protection Impact Assessment procedures require evaluation of any new processing activity that may result in high risk to individuals. Internal audits of data handling practices are conducted annually, with findings documented and remedial actions tracked to completion. Staff members with access to personal data receive mandatory data protection training upon commencement of employment and annual refresher training thereafter. Our information asset register documents all systems processing personal data, including the categories of data processed, legal bases, retention periods, and security controls applied to each system.
We regularly review our data processing activities to ensure ongoing compliance with UK data protection legislation. Our Data Protection Impact Assessment procedures require evaluation of any new processing activity that may result in high risk to individuals. Internal audits of data handling practices are conducted annually, with findings documented and remedial actions tracked to completion. Staff members with access to personal data receive mandatory data protection training upon commencement of employment and annual refresher training thereafter. Our information asset register documents all systems processing personal data, including the categories of data processed, legal bases, retention periods, and security controls applied to each system.
International Data Transfers and Safeguards
When AURALOGICAL LTD transfers personal data outside the United Kingdom, we ensure that appropriate safeguards are in place to protect your information in accordance with UK data protection law. These safeguards may include adequacy regulations issued by the UK Secretary of State, Standard Contractual Clauses approved by the Information Commissioner, binding corporate rules, or explicit consent from the data subject where no other mechanism is available.
Our primary cloud infrastructure providers may process data in data centres located within the European Economic Area and the United States. Where data is transferred to the United States, we rely on the UK Extension to the EU-US Data Privacy Framework where the recipient is certified, or Standard Contractual Clauses with supplementary measures including encryption and access controls.
We conduct Transfer Impact Assessments for all international data transfers to evaluate the level of protection in the destination country and implement supplementary measures where necessary. These assessments are reviewed annually and updated when there are material changes to transfer arrangements or destination country law.
When AURALOGICAL LTD transfers personal data outside the United Kingdom, we ensure that appropriate safeguards are in place to protect your information in accordance with UK data protection law. These safeguards may include adequacy regulations issued by the UK Secretary of State, Standard Contractual Clauses approved by the Information Commissioner, binding corporate rules, or explicit consent from the data subject where no other mechanism is available.
Our primary cloud infrastructure providers may process data in data centres located within the European Economic Area and the United States. Where data is transferred to the United States, we rely on the UK Extension to the EU-US Data Privacy Framework where the recipient is certified, or Standard Contractual Clauses with supplementary measures including encryption and access controls.
We conduct Transfer Impact Assessments for all international data transfers to evaluate the level of protection in the destination country and implement supplementary measures where necessary. These assessments are reviewed annually and updated when there are material changes to transfer arrangements or destination country law.
When AURALOGICAL LTD transfers personal data outside the United Kingdom, we ensure that appropriate safeguards are in place to protect your information in accordance with UK data protection law. These safeguards may include adequacy regulations issued by the UK Secretary of State, Standard Contractual Clauses approved by the Information Commissioner, binding corporate rules, or explicit consent from the data subject where no other mechanism is available.
Our primary cloud infrastructure providers may process data in data centres located within the European Economic Area and the United States. Where data is transferred to the United States, we rely on the UK Extension to the EU-US Data Privacy Framework where the recipient is certified, or Standard Contractual Clauses with supplementary measures including encryption and access controls.
We conduct Transfer Impact Assessments for all international data transfers to evaluate the level of protection in the destination country and implement supplementary measures where necessary. These assessments are reviewed annually and updated when there are material changes to transfer arrangements or destination country law.
Automated Decision-Making and Profiling
AURALOGICAL LTD does not currently engage in automated decision-making or profiling that produces legal or similarly significant effects on individuals. Should we introduce such processing in the future, we will update this Privacy Policy and provide affected individuals with meaningful information about the logic involved, the significance and envisaged consequences, and the right to request human intervention.
Our analytics tools may create aggregated profiles of website usage patterns, but these profiles are not used to make decisions about individuals and cannot be linked back to specific persons without additional information that we do not combine for decision-making purposes.
AURALOGICAL LTD does not currently engage in automated decision-making or profiling that produces legal or similarly significant effects on individuals. Should we introduce such processing in the future, we will update this Privacy Policy and provide affected individuals with meaningful information about the logic involved, the significance and envisaged consequences, and the right to request human intervention.
Our analytics tools may create aggregated profiles of website usage patterns, but these profiles are not used to make decisions about individuals and cannot be linked back to specific persons without additional information that we do not combine for decision-making purposes.
AURALOGICAL LTD does not currently engage in automated decision-making or profiling that produces legal or similarly significant effects on individuals. Should we introduce such processing in the future, we will update this Privacy Policy and provide affected individuals with meaningful information about the logic involved, the significance and envisaged consequences, and the right to request human intervention.
Our analytics tools may create aggregated profiles of website usage patterns, but these profiles are not used to make decisions about individuals and cannot be linked back to specific persons without additional information that we do not combine for decision-making purposes.
AURALOGICAL LTD does not currently engage in automated decision-making or profiling that produces legal or similarly significant effects on individuals. Should we introduce such processing in the future, we will update this Privacy Policy and provide affected individuals with meaningful information about the logic involved, the significance and envisaged consequences, and the right to request human intervention.
Our analytics tools may create aggregated profiles of website usage patterns, but these profiles are not used to make decisions about individuals and cannot be linked back to specific persons without additional information that we do not combine for decision-making purposes.
Employee and Recruitment Data
This Privacy Policy primarily addresses data processing related to our website, services, and client relationships. Employees, contractors, and job applicants are provided with separate privacy notices that address the specific data processing activities relevant to their relationship with AURALOGICAL LTD, including HR records, payroll processing, performance management, and recruitment activities.
This Privacy Policy primarily addresses data processing related to our website, services, and client relationships. Employees, contractors, and job applicants are provided with separate privacy notices that address the specific data processing activities relevant to their relationship with AURALOGICAL LTD, including HR records, payroll processing, performance management, and recruitment activities.
This Privacy Policy primarily addresses data processing related to our website, services, and client relationships. Employees, contractors, and job applicants are provided with separate privacy notices that address the specific data processing activities relevant to their relationship with AURALOGICAL LTD, including HR records, payroll processing, performance management, and recruitment activities.
This Privacy Policy primarily addresses data processing related to our website, services, and client relationships. Employees, contractors, and job applicants are provided with separate privacy notices that address the specific data processing activities relevant to their relationship with AURALOGICAL LTD, including HR records, payroll processing, performance management, and recruitment activities.
This Privacy Policy primarily addresses data processing related to our website, services, and client relationships. Employees, contractors, and job applicants are provided with separate privacy notices that address the specific data processing activities relevant to their relationship with AURALOGICAL LTD, including HR records, payroll processing, performance management, and recruitment activities.