00

Privacy Policy

Privacy Policy

Effective Date: September 7, 2026Website: www.aurahealth.ch

01. Introduction

Aura Health ApS, referred to below as “Aura Health”, “we”, “our” or “us”.

Aura Health is the controller for the personal data described in this policy, unless stated otherwise.

This Privacy Policy explains how and why we collect, store, use and otherwise process the personal data of people who visit www.aurahealth.ch, contact us through the website, or interact with us in the course of our business.

We review this policy regularly to keep it accurate. The current version is always published on this page and the effective date of the current version appears above. This policy should be read together with our Cookie Policy.

02. Contact details

For any question about this policy or about how your personal data is handled, contact us at ivano@aurahealth.ch, by phone on +385995588800, or by mail at our office at Savska cesta 32, 10000 Zagreb, Croatia.

We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. Data protection matters are handled internally at the address above.

You have the right to lodge a complaint with a supervisory authority. You may lodge that complaint with the supervisory authority in the country where you live, where you work, or where you believe the issue occurred.

03. Definitions

Personal data is any information that can identify you directly or indirectly, whether on its own or combined with other information.

Processing is any operation performed on personal data, including collecting, storing, using, sharing, erasing and destroying it.

Controller is the person or organisation that decides why and how personal data is processed.

Processor is the person or organisation that processes personal data on behalf of a controller.

Data subject is the individual the personal data relates to, in most cases you.

Consent is a freely given, specific, informed and unambiguous indication of your wishes, given by a statement or a clear affirmative action.

Cookies are small files stored on your device by a website. Our Cookie Policy explains which ones we use.

04. Personal data we collect

We collect only data that is necessary, relevant and adequate for the purpose it is provided for.

a. When you visit our website

Some data is collected automatically. Our hosting provider records standard server log data, including your IP address, the date and time of your request, the pages requested, and your browser and operating system.

We also use cookies and comparable technologies. Necessary cookies are set automatically. Preferences, statistics and marketing cookies are set only if you consent through our cookie banner. This includes technology from Apollo that identifies the organisation a visitor is associated with. Full details are in our Cookie Policy.

b. When you contact us

If you use the form on our contact page, we ask for your first name, last name, job title, work email address, phone number, company name, the type of collaboration you are interested in, and your preferred time to be contacted. If you write to us by email or call us, we process whatever information you choose to share.

Our contact form is protected by Cloudflare Turnstile, which processes technical data such as your IP address and browser characteristics to distinguish human visitors from automated abuse.

Please do not include health information or other special categories of personal data in your enquiry. We do not seek to collect such data through this website.

c. When you are a client, supplier or business contact

In the course of an engagement we may process your name, job title, contact details, and where relevant billing information such as address, company registration and VAT number, and bank account details.

d. Publicly available sources

For business development we may also use information that is publicly available, for example professional profiles and company websites.

05. Why we process it and on what legal basis

Consent, Article 6(1)(a) GDPR

Storing and reading preferences, statistics and marketing cookies on your device. You can withdraw consent at any time by opening your cookie settings, without affecting the lawfulness of processing carried out beforehand.

Contract and steps taken before a contract, Article 6(1)(b) GDPR

Responding to enquiries about a possible engagement, delivering our services, and administering the contractual relationship.

Legal obligation, Article 6(1)(c) GDPR

Keeping accounting and tax records and responding to lawful requests from authorities.

Legitimate interests, Article 6(1)(f) GDPR

Responding to general enquiries, keeping our website and forms secure, and developing business to business relationships, including following up on information obtained through visitor identification once you have consented to the underlying cookies. You have the right to object to this processing at any time.

We do not send newsletters or mass marketing emails, and we do not sell personal data.

06. How long we keep it

  • Enquiries that do not lead to an engagement: two years after our last contact with you
  • Enquiries that lead to an engagement: for the duration of the engagement, and afterwards for as long as required by applicable accounting and limitation rules
  • Accounting and billing records: for the period prescribed by applicable law
  • Cookies and similar technologies: for the period stated for each item in our Cookie Policy
  • Records of cookie consent: for as long as needed to demonstrate that consent was given
  • Server logs: deleted within 30 days

When a retention period ends, the data is deleted or anonymised.

07. Who we share it with

We do not sell personal data. The following providers process personal data on our behalf or in connection with our website, each under a written data processing agreement:

  • Namecheap, website hosting, with our website data held in its data centre in Amsterdam, the Netherlands
  • Google, analytics, tag management, advertising measurement and business email
  • Cloudflare, form protection and abuse prevention
  • Apollo.io, website visitor identification and business development
  • HubSpot, managing enquiries and contact records
  • Usercentrics, managing and recording cookie consent

We may also disclose personal data to professional advisers or to public authorities where we are legally required to do so.

Our website may contain links to other websites. We do not control how those sites process personal data and we encourage you to read their privacy notices.

08. Transfers outside the European Economic Area

Our website and the data submitted through it are hosted within the European Union. Some of the other providers listed above are established in the United States. Where personal data is transferred outside the EEA, we rely on the European Commission adequacy decision for the EU-U.S. Data Privacy Framework where the recipient is certified under it, and on the European Commission Standard Contractual Clauses together with supplementary measures where it is not.

You can request further information about the safeguards applied to a specific transfer by writing to ivano@aurahealth.ch.

09. Automated decision making

We do not carry out automated decision making, including profiling, that produces legal effects concerning you or similarly significantly affects you.

10. Security

We use encryption in transit for our website and email, restrict access to personal data to people who need it for their work, review those permissions periodically, and keep the software behind the website up to date.

11. Your rights

Subject to the conditions set out in the GDPR, you have the right to:

  • Access the personal data we hold about you and receive information about how we process it (Article 15)

  • Have inaccurate or incomplete data corrected or completed (Article 16)

  • Have your data erased (Article 17)

  • Have processing restricted (Article 18)

  • Receive the data you provided in a structured, commonly used and machine readable format and have it transmitted to another controller (Article 20)

  • Object to processing based on our legitimate interests, and to object at any time to processing for direct marketing (Article 21)

  • Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (Article 7(3))

  • Lodge a complaint with a supervisory authority (Article 77)

To exercise any of these rights, write to ivano@aurahealth.ch. We will respond within one month. For complex requests we may extend that period by two further months and will tell you within the first month if we do. We may need to verify your identity before acting on a request.

12. Personal data breaches

If a personal data breach occurs, we assess the risk without undue delay. Where the breach is likely to result in a risk to the rights and freedoms of individuals, we notify the competent supervisory authority within 72 hours of becoming aware of it, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to you, we inform you without undue delay, in accordance with Article 34 GDPR.

13. Visitors in Switzerland

If you are in Switzerland, the Swiss Federal Act on Data Protection applies to the processing described here in addition to, or instead of, the GDPR. References to the GDPR should be read as including the equivalent provisions of Swiss law, and you may lodge a complaint with the Federal Data Protection and Information Commissioner.

14. Residents of California

If you are a California resident, the California Consumer Privacy Act gives you the right to know what personal information we have collected and why, to request its deletion, to request correction of inaccurate information, to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights.

To submit a request, email hello@aurahealth.ch or call +385995588800. We will verify your request against our records before responding. If you disagree with our decision, you may appeal within 60 days of receiving our response by writing to the same address, quoting your original request, the date of our response, and why you believe the decision was incorrect.

15. Changes to this policy

We may update this policy to reflect changes in our processing or in legal requirements. The effective date at the top of the page shows when the current version was published. Where a change materially affects processing that relies on your consent, we will ask for your consent again before it takes effect.