Privacy Policy
Auronys.com --- Privacy Policy
Effective: 21 August 2026 • Slovak law / EU requirements
1. Controller and contact
Auronys processes personal data as a controller for account administration, contracting, billing, support, security, abuse prevention and legal compliance.
Controller: Ján Danko - BitsLab.io, trading under the brand Auronys.com; Pri kríži 1176/18, 841 02 Bratislava-Dúbravka, Slovak Republic; IČO 56018991.
Privacy contact: legal@auronys.com. No Data Protection Officer is designated in this Policy unless Auronys separately communicates such appointment.
2. Personal data we may process
Account and identity data: name, email address, contact details and account identifiers.
Contract and billing data: ordered Services, invoices, payment status, transaction identifiers and information needed to administer the contractual relationship. Auronys does not require an unmasked card security code such as a CVV.
Technical and security data: IP addresses, service identifiers, connection metadata, authentication events, system and network logs, security telemetry and information about incidents or abuse.
Support data: support tickets, messages, attachments and information supplied to diagnose or resolve a problem.
Hosting content: data stored or transmitted through a Service. Where such content contains personal data controlled by the Client, the Client may be the controller and Auronys may act as processor; see the Data Processing Agreement.
3. Purposes and legal bases
Contract performance: account creation, provisioning, support, billing and delivery of Services (GDPR Article 6(1)(b)).
Legal obligations: accounting, tax, lawful requests and other statutory duties (Article 6(1)(c)).
Legitimate interests: security, fraud prevention, abuse detection, service reliability, incident response, protection of customers and infrastructure, and establishment or defence of legal claims (Article 6(1)(f)).
Consent: optional processing where consent is legally required, such as optional marketing communications (Article 6(1)(a)). Consent may be withdrawn at any time without affecting processing already carried out lawfully.
4. Monitoring and automated security
Auronys may process network metadata, logs and security telemetry where reasonably necessary to provide Services, detect abuse, troubleshoot incidents, protect infrastructure or comply with law.
Automated systems may be used for fraud detection, abuse detection, capacity management and security. Protective measures may include additional verification, rate limiting or temporary restriction. Where required by law, a data subject may request human review of a solely automated decision.
5. Recipients and service providers
Personal data may be disclosed to payment providers, infrastructure providers, security or DDoS-mitigation providers, professional advisers and competent authorities where necessary for the stated purpose and permitted or required by law.
The current list of recipients and subprocessors, including processing locations and transfer mechanisms, is published at auronys.com/legal/subprocessors.
Auronys uses processors only subject to appropriate data-protection requirements. Where a third-party provider processes personal data on Auronys's behalf, appropriate contractual and organisational safeguards are used.
6. International transfers
Services or supporting providers may process data in the European Economic Area or elsewhere where legally permissible. Where personal data is transferred to a third country, Auronys will use an applicable GDPR transfer mechanism and appropriate safeguards (such as an adequacy decision or Standard Contractual Clauses); per-recipient details are stated in the list at auronys.com/legal/subprocessors.
7. Retention
Personal data is retained only for as long as necessary for the purpose for which it was collected, and thereafter where required or permitted by law. In particular, the following periods apply:
Accounting and invoicing records: 10 years (Slovak Accounting Act).
Account and contract data: for the duration of the contractual relationship and for 4 years after its termination, to satisfy legal obligations and to establish or defend claims.
Security and technical logs: 6 months; during an ongoing security incident or abuse case, up to 12 months or until the matter is closed.
Support records: 2 years from closure of the request.
Hosting content: 30 days after termination of the Service (see Terms, sec. 4), followed by permanent deletion; backup copies expire within the normal backup rotation cycle no later than a further 30 days. The Client is responsible for exporting data before the deadline.
8. Your rights
Subject to the conditions in the GDPR, you may request access, rectification, erasure, restriction of processing, data portability and may object to processing based on legitimate interests. You may also withdraw consent where processing is based on consent.
You may lodge a complaint with the supervisory authority. In Slovakia, this is the Office for Personal Data Protection of the Slovak Republic.
9. Security and confidentiality
Auronys applies technical and organisational measures appropriate to the risks of processing. Access to Client Content is limited to what is reasonably necessary for an operational, security or legal purpose and is subject to confidentiality obligations.
Where Auronys becomes aware of a personal-data breach for which it is responsible as controller, it will act in accordance with applicable GDPR notification requirements.
10. Cookies and similar technologies
The website and client portal use only technically essential cookies (session, login, CSRF protection) and Stripe payment-gateway cookies set during checkout for payment processing and fraud prevention.
Auronys does not use third-party analytics or marketing cookies; consent is therefore not required for the essential technologies listed above. Should this change in the future, legally required consent will be obtained before such technologies are deployed.
11. Updates
This Privacy Policy may be updated where necessary to reflect changes in law, Services, processing activities or security practices. Material changes will be communicated where required by law.
Effective date: 21 August 2026