AURALIS STUDIO

DATA INTEGRITY & PRIVACY PROTOCOL

Privacy & Data Protection

Effective Date: September 2026 • Policy Version: CSP-PRIV-1.0

Core Privacy Doctrine
AURALIS STUDIO operates on strict data minimization principles. We do not monetize personal data, deploy behavioral tracking beacons, or harvest visitor profiles. Your digital autonomy is respected by structural design.

01. Information We Collect

We deliberately minimize data collection to the absolute technical baseline required to operate and secure our digital synthesis systems:

  • Server Infrastructure Logs: When accessing our servers, ephemeral network logs are recorded by our edge proxy (IP address, browser user-agent, requested URI, referer, and response status code). These logs are processed solely to defend against cyber threats, mitigate DDoS attempts, and preserve server stability.
  • Direct Inquiries: If you voluntarily contact the studio via email ([email protected]), we retain your message and email address strictly to reply to your inquiry.

02. Cookies & Local Storage Policy

AURALIS STUDIO is committed to a cookie-free experience:

  • We do not use third-party advertising cookies or cross-site tracking trackers.
  • We do not employ Google Analytics, Meta Pixel, or behavioral profiling tools.
  • Transient browser storage may only be used for client-side state (such as UI interaction preferences), stored exclusively on your local machine.

03. Legal Basis for Processing (GDPR)

Under the European General Data Protection Regulation (GDPR), our processing of server metadata is governed by Article 6(1)(f) GDPR (Legitimate Interest) — specifically, ensuring network security, prevention of malicious requests, and uninterrupted system availability.

04. Infrastructure & Data Location

Our web services and containerized nodes are hosted on Hetzner Cloud infrastructure located within data centers in the European Union (Helsinki, Finland), conforming to stringent European data security protocols. Encrypted transit is enforced across all connections via modern TLS v1.3 encryption.

05. Data Retention

Automated server security logs are routinely purged on an automated cycle. Email correspondences are retained only as long as necessary to address your communication or comply with statutory archival duties.

06. Your Data Protection Rights

Under applicable data protection laws (including the GDPR), you possess enforceable rights regarding your personal data:

  • Right of Access: Request verification of whether personal data concerning you is processed.
  • Right to Rectification: Request correction of inaccurate information.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data.
  • Right to Restriction & Objection: Object to processing carried out under legitimate interest.

07. Contact for Data Privacy Inquiries

For any questions concerning this Privacy Policy, your data rights, or to submit a privacy inquiry, please reach our designated data point:

PRIVACY & COMPLIANCE: [email protected]