Privacy notice

Last updated: 5 October 2026

This notice explains what personal data we collect when you visit this website, ask us for a cash report or contact us, and how we handle data in the Auromis app. Auromis is for businesses only.

On this page24
  1. Who we are
  2. The short version
  3. Visiting this website
  4. Cookies
  5. Fonts and third-party content
  6. Cash-report requests
  7. Contacting us
  8. Your account
  9. Documents you upload
  10. AI extraction and improving the service
  11. Support chat
  12. App usage logs
  13. Payments
  14. If we contacted you first
  15. Who we share data with
  16. International transfers
  17. How long we keep data
  18. Your rights
  19. Your right to object
  20. Complaints
  21. Do you have to give us your data?
  22. Automated decisions
  23. Keeping your data secure
  24. Changes to this notice

Note:

This notice covers two things. This website creates standard server logs when you open a page, and collects what you type into the cash-report or contact form — nothing else. The Auromis app is where accounts, uploaded documents, support chats and billing come in.

Who we are

The controller responsible for your personal data is:
Auromis
Email: support@auromis.com
Email is the fastest way to reach us about anything in this notice, including a request about your data or a complaint.

The short version

  • This website stores nothing on your device and makes no request to any other company’s server: no analytics, no advertising, no tracking cookies, no third-party embeds, and fonts served from our own server.
  • We don’t sell personal data.
  • We process the documents you upload on your behalf, under a data processing agreement.
  • We never send anything in your name. Letters are drafts that you check and send yourself.
  • Corrections you make may help us improve how Auromis reads documents of that kind.
  • Statistics combined across many customers are only produced with your consent.
  • You can ask to see, correct or delete your data, and object to how we use it.

Visiting this website

When you open a page, your browser automatically sends some data to our server. It is kept for a short time in server logs:

  • IP address,
  • date and time of the request,
  • the page or file requested and the amount of data sent,
  • status code (for example, whether the page was found),
  • browser and operating system (user agent),
  • the page you came from (referrer), if your browser sends it.

We need this data to deliver the website, keep it secure (for example, to detect and block attacks) and fix errors. Our lawful basis is our legitimate interest in running a secure, reliable website (Article 6(1)(f) UK GDPR). We don’t use the logs to identify you or build profiles.

The website is hosted and delivered by Cloudflare, Inc., which processes this data on our behalf. Cloudflare serves our pages from its global network, so a request may be answered, and logged, outside the UK — see “International transfers”. Logs are deleted after 30 days, unless we need them longer to investigate a security incident.

Cookies

We don’t use analytics, advertising or tracking cookies. In fact this website stores nothing at all on your device, which is why you see no cookie banner. Our cookie notice explains that in full.

Fonts and third-party content

Our fonts are stored on our own server, so opening a page doesn’t connect your browser to a third-party font service such as Google Fonts. We don’t embed third-party videos, maps or social media buttons. Loading a page of this website makes no request to any other company’s server.

Cash-report requests

When you ask us for a cash report, we collect:

  • your name and work email address,
  • your company, role and trade, where you mainly work and how many active contracts you have, if the form asks for them,
  • how you heard about us, if you choose to tell us,
  • which version of the website you used (US, UK or Germany) and the page you signed up on.

We use these details to put your cash report together and send it to you, decide who we set up first, keep you updated about Auromis and prepare your account, for example whether you’ll use Auromis for your own firm or as an accountant. Our lawful basis is taking steps at your request before entering into a contract (Article 6(1)(b) UK GDPR). If you tell us how you heard about us, we use that answer to see which channels work, based on our legitimate interests (Article 6(1)(f)). We’ll only send you a newsletter or other marketing emails if you’ve agreed to them separately.

We delete your details when you unsubscribe, or at most 24 months after we last heard from you if you haven’t opened an account.

Note:

What you type into a form reaches us only when you press send. Submissions go to our own server, run for us by Cloudflare, Inc. (see “Who we share data with”); they are not passed to any other company, and we use them only for the purpose the form is for.

Contacting us

When you use the contact form or email us, we use what you send, such as your name, email address, company, topic and message, to reply. Our lawful basis is taking steps at your request before a contract (Article 6(1)(b) UK GDPR) where your enquiry is about using Auromis, and otherwise our legitimate interest in answering enquiries (Article 6(1)(f)).

We delete enquiries 24 months after they’re closed, unless we must keep them for longer by law or need them to deal with a legal claim.

Your account

To run your account, we use your name, work email address, company, role, login details and settings, as well as the details of other users you add, such as your accounts team or your accountant. We also use your email address to send deadline reminders. Our lawful basis is performing our contract with you (Article 6(1)(b) UK GDPR).

Documents you upload

In Auromis you upload documents such as applications for payment, payment notices and pay less notices, contract and variation details, remittances, CIS deduction statements, bank statements and accounting exports. From them, we extract amounts, dates, main contractors, projects and contact names.

As our customer, you’re the controller of this data. We only process it on your behalf and on your instructions, under a data processing agreement (Article 28 UK GDPR). We’ll provide that agreement before your first upload — email support@auromis.com to ask for a copy.

If you’re named in a document that one of our customers uploaded, for example as a contact at a main contractor, please contact that customer first. We’ll help them respond.

We never send letters or notices in your name, and we never log in to your contractors’ portals. Letters are drafts that you check, edit and send yourself.

AI extraction and improving the service

Auromis uses artificial intelligence (AI) to read your documents. To do that, we send document content to an AI provider, which processes it on our behalf and returns what it has read. Every extracted figure links back to where it was found in the document, so you can check it. Totals and dates are calculated by fixed program code, not by the AI.

What we do, and don’t do, with what you upload:

  • We use it to run Auromis for you. That’s what you give it to us for, and we don’t use it for our own marketing.
  • We never sell it, and we never hand it to your main contractors, your competitors or data brokers.
  • Corrections may improve how documents are read. When an extracted value is corrected, by you or by our team, we may keep that example — the relevant extract of the document and the correct value — and use it to check and improve how Auromis reads documents of that kind.
  • Document layouts. We learn the layout of recurring documents, such as a particular main contractor’s payment notice, so Auromis reads that format faster for every customer. Other customers never see your figures or your content.
  • Statistics only with your consent. Combined figures across many customers, such as how quickly a main contractor pays on average, are produced only if you agree to it. The data is anonymised and grouped first, so no individual customer can be identified.
  • You can delete it. Deleting a document in Auromis deletes the data extracted from it too, on the schedule in “How long we keep data”.

Where we use data from your documents for these purposes of our own, we’re the controller for that use. Our lawful basis is our legitimate interest in accurate, reliable extraction (Article 6(1)(f) UK GDPR). You can object to it at any time (see “Your right to object”), and we’ll stop unless we have compelling grounds not to.

We choose AI providers on the basis of what their contracts allow them to do with the content we send. Before any provider handles a document you upload, we name it in the table under “Who we share data with”, say where it processes data and set out what we agreed.

Support chat

You’ll be able to ask questions in a chat. The first answers come from an AI assistant, and the chat will say so clearly. If you’d like a person to answer, we’ll reply by email. We keep chat transcripts for 24 months to help you and to improve our help content. Our lawful basis is performing our contract (Article 6(1)(b) UK GDPR) and, for improving help content, our legitimate interests (Article 6(1)(f)).

There is no chat on this website: the chat is part of the app. We name its provider, and where it processes data, under “Who we share data with” before it handles anything.

App usage logs

When you use Auromis, we log technical events such as sign-ins, uploads, errors and which features are used, each with a time and user account. We do this to keep the service secure, fix problems and improve it (Article 6(1)(f) UK GDPR). We keep these logs for 12 months. If we ever use an outside service for this, we’ll name it here before we start.

Payments

Paid plans are billed through a payment provider. You enter your card or bank details directly with that provider, not with us. We name it under “Who we share data with”, and show it at checkout, before you can buy anything. If the provider acts as a reseller (merchant of record), you buy from it, and it handles your payment data as an independent controller under its own privacy notice.

We use billing details, such as company name, address, VAT number and plan, to perform our contract (Article 6(1)(b) UK GDPR), and we keep invoices and accounting records for as long as tax and company law requires us to (Article 6(1)(c)).

If we contacted you first

We may email people at limited companies and other corporate bodies to tell them about Auromis. For that we use company details and the names and work email addresses of directors or relevant staff, taken from public sources such as Companies House, company websites and trade directories. If we ever buy business contact data from a provider, we’ll name the provider here before we use it. Our lawful basis is our legitimate interest in telling businesses about a relevant service (Article 6(1)(f) UK GDPR).

We don’t send unsolicited marketing emails to sole traders or partnerships. Every email we send says who we are and includes a simple way to opt out. If you opt out, we add you to a suppression list so we don’t contact you again. Other outreach data is deleted 12 months after our last email if you don’t reply.

Who we share data with

We only share data where the purposes above need it, and only with providers that process it on our behalf and on our instructions. Today there is exactly one:

ProviderWhat they doDataWhere
Cloudflare, Inc.Hosts this website, delivers it to your browser and runs the server that receives our formsServer logs: IP address and request details. What you send us through the cash-report or contact formCloudflare’s global network. Form submissions are stored in its Western Europe region. The company is based in the United States

Nothing else about this website reaches a third party: there is no analytics provider, no advertising network, no font, map or video service and no chat widget.

We will also need providers for our mailbox, for AI document reading, for support chat and for payments. Each one goes into the table above, with what it does and where it processes data, before it starts handling anything — and each is bound by a written processing agreement first.

Otherwise, we only share data when the law requires it (for example, with authorities), when it’s needed to establish or defend legal claims (for example, with lawyers or courts), with our professional advisers, or as part of a sale or restructuring of our business, in which case we’ll tell you first. We don’t sell personal data.

International transfers

Cloudflare, Inc. is based in the United States and runs a global network, so the server logs created when you visit this website may be processed outside the UK.

We only use providers that offer the transfer protections UK law recognises: UK adequacy regulations covering the destination (these cover the European Economic Area, and the United States for organisations certified under the UK Extension to the EU–U.S. Data Privacy Framework), or the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses in the contract with the provider. Email support@auromis.com to ask which protection applies to a particular provider, and we’ll tell you and send you a copy.

Each provider we add is listed above with where it processes data, and we name the protection that applies to its transfer here.

How long we keep data

DataHow long
Server logs30 days, unless we need them longer to investigate a security incident
Cash-report requestsUntil you unsubscribe, or at most 24 months after we last heard from you
Enquiries24 months after the enquiry is closed
Account and contract dataWhile you’re a customer, then deleted within 90 days of your account closing
Uploaded documents and extracted dataUntil you delete them or your contract ends. You can then export your data for 30 days, after which we delete it from our active systems. Backups are overwritten within a further 35 days
Correction examples (see “AI extraction and improving the service”)24 months
Support chats24 months
App usage logs12 months
Invoices and accounting recordsAs long as tax and company law requires us to keep them
Suppression list after you opt outFor as long as you shouldn’t be contacted

Where we have to keep something longer because the law requires it, or because we need it to establish or defend a legal claim, we keep only that and nothing more.

Your rights

You have the right to:

  • get a copy of the personal data we hold about you,
  • have inaccurate data corrected,
  • have your data deleted,
  • restrict how we use it,
  • receive your data in a common, machine-readable format, or have it sent to another organisation,
  • withdraw consent at any time, where we rely on consent,
  • object to how we use your data (see below).

Email support@auromis.com to use any of these rights. We’ll respond within one month. If a request is complex, we may need up to two more months, and we’ll tell you if so. If your request concerns documents a customer uploaded, we’ll pass it to that customer, because they’re responsible for that data.

Your right to object

Note:

You can object at any time
Where we rely on legitimate interests (Article 6(1)(f) UK GDPR), you can object on grounds relating to your particular situation. We’ll then stop, unless we have compelling legitimate grounds that override your interests, rights and freedoms, or we need the data to establish, exercise or defend legal claims.
You can object to direct marketing at any time, without giving a reason, and we’ll stop.
Just email support@auromis.com.

Complaints

If you’re unhappy with how we’ve handled your personal data, please tell us at support@auromis.com. We’ll acknowledge your complaint within 30 days, look into it without undue delay, keep you updated and tell you the outcome.

You also have the right to complain to the UK regulator, the Information Commission, which continues to be known as the ICO: ico.org.uk.

Do you have to give us your data?

No law or contract requires you to give us personal data. But without the fields marked as required, we can’t send your cash report, answer your enquiry or set up your account. Server logs are created automatically when you visit the website.

Automated decisions

We don’t make decisions about you based solely on automated processing that have legal or similarly significant effects on you. Auromis creates deadline reminders and draft letters automatically, but you decide what to do with them.

Keeping your data secure

This website is served only over an encrypted connection (HTTPS/TLS). It sends strict security headers, including a content security policy that blocks third-party code, it loads nothing from any other company’s server, and it stores nothing on your device — so there is very little about a visit to attack.

In the app we encrypt stored data, give access only to the people who need it and log that access; our Security page describes how. If you find a security problem, please email support@auromis.com and we’ll look into it.

Changes to this notice

We’ll update this notice when our service or the law changes. The version published here always applies. We’ll also email customers about significant changes.