Legal
Privacy policy
What data the service actually handles, why it is needed and the choices you have.
Last updated 17 August 2026
Who controls your data
Auxo, trading as Auxo, operates tryauxo.net and is the controller for account, billing, website and support data.
The operator’s full legal identity is stated in the order form and invoice supplied before or at purchase.
For personal data in leads, messages, files and records that a business customer submits or connects, the customer is the controller and Auxo acts as processor under the Data Processing Addendum.
Data we collect
- Account and billing: name, work email, company, plan, subscription state, invoice data, and payment method brand and last four digits. Full card data is entered with the payment provider and does not reach our servers.
- Authentication and preferences: one-time sign-in codes in hashed form, signed session cookies, language, theme, accessibility choices and demo state.
- Product content: instructions, AI outputs, workflows, lead details and messages, follow-up history, approvals and activity records.
- Connected services: OAuth tokens, permissions and records or messages needed for an action you request. Tokens are encrypted before storage.
- Optional banking: after explicit consent at the bank, Open Finance supplies bank-account details, balances and movements, including amount, currency, date, description, category and reference when the bank provides them. Bank login credentials do not reach Auxo.
- Support and security: support messages and contact details; IP address and request metadata may be processed for rate limiting, fraud prevention, troubleshooting and infrastructure logs.
Why we use it
We use data to provide and secure the service, authenticate users, execute requested automations, deliver support, process subscriptions, keep legally required financial records and communicate material changes.
Where the GDPR applies, the bases are performance of our contract, compliance with law, our legitimate interests in securing and operating the service, and consent where specifically requested.
We do not sell personal data, share it for cross-context behavioural advertising, or run advertising cookies.
AI and connected tools
Content needed for an AI task may be sent to the configured model provider. Submit only material needed for the request. AI output can be inaccurate; approval controls are available and customers remain responsible for consequential uses.
A connected tool is accessed only after its owner completes OAuth and only within enabled permissions. Disconnecting it removes the stored grant. The provider’s own terms and privacy policy also apply.
The Banking category is optional and read-only. Connection uses the Open Finance and bank consent journey. Removing it revokes access through Open Finance; “money received” describes an incoming movement, not a tax receipt or invoice.
Service providers and transfers
Data is disclosed only as needed to infrastructure and database hosts, the configured AI provider, Resend for transactional email, Paddle or Grow for payments, Open Finance for optional consent-based banking, professional advisers when necessary, and tools the customer chooses to connect. We may also disclose data when law requires it.
Providers may process data outside your country. Where transfer law requires a safeguard, we use an applicable adequacy mechanism or contractual safeguard. Contact us for the current provider list.
Retention, deletion and your rights
Account and product content is kept while the account is active and until deleted or no longer reasonably needed to provide the service, resolve disputes or comply with law. Expired login codes cannot be used. Payment and tax records are kept as applicable law requires.
Disconnecting an integration removes its stored credentials. Customers can delete leads and workflows in the product and request account deletion or an export through the contact page. Deletion from resilient backups may complete on their ordinary rotation cycle.
Depending on where you live, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent. You may also complain to your local data-protection authority. We may verify identity before acting.
Send requests to [email protected].
Security, children and changes
We use TLS, signed secure sessions, encrypted integration tokens, scoped permissions, hosted payment pages and activity records. No system is risk-free; see the security page.
The service is for businesses and is not directed to children. Do not submit a child’s data without authority and a lawful business need.
We update the date above when this policy changes and provide reasonable notice of material changes. Privacy questions and complaints go to [email protected].