Privacy Policy

Last updated: 10 September 2026

At AURE, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.

Information We Collect

We collect information you provide directly to us, including: name, email address, company name, job title, and procurement-related data you enter into the platform. We also automatically collect technical data such as IP address, browser type, device information, and usage patterns through cookies and similar technologies.

How We Use Your Information

We use the information we collect to: provide, maintain, and improve our platform; process transactions and send related information; match buyers with relevant suppliers using our AI algorithms; send you technical notices, updates, and support messages; respond to your comments and questions; and comply with legal obligations.

Data Sharing and Disclosure

We do not sell your personal data. We may share your information with: other platform users as necessary for procurement transactions (e.g., your company name and RFP details with matched suppliers); service providers who assist us in operating the platform; and law enforcement or government agencies when required by applicable law.

Data Security

We implement industry-standard security measures including encryption in transit (TLS 1.3), encryption at rest (AES-256), role-based access controls, regular security audits, and SOC 2 Type II compliance. While we strive to protect your data, no method of transmission over the Internet is 100% secure.

Your Rights (GDPR)

If you are located in the European Economic Area, you have the right to: access, correct, or delete your personal data; restrict or object to processing; data portability; and withdraw consent at any time. To exercise these rights, contact us at altin@aure-network.com.

Cookies

We use essential cookies to operate the platform, analytics cookies to understand usage patterns, and preference cookies to remember your settings. You can manage cookie preferences through your browser settings or our cookie management tool.

Contact Us

For privacy-related inquiries, contact us at altin@aure-network.com.

Contacting Business Partners Who Are Not Members

When a member sends a collaboration request through AURE, we process the recipient's business contact details: their name and business email address, together with the message the member writes, which is stored with the request. Where our contact discovery suggested a job title and the member kept that suggestion, the title is stored with the name. We do this on the basis of our legitimate interest in business to business communication. These are details that reach a person in their working role.

A request that is never answered is deleted automatically once it reaches 24 months at the latest. A request the recipient answered or accepted is kept as a record of that business contact and is not deleted on that schedule. Opting out stops further requests; it does not erase a request you already answered, and we keep the record of the opt-out itself precisely so that we can go on honouring it. You can still ask us to delete what we hold, and we will unless we are required to keep it.

Every message we send on a member's behalf carries an opt-out link. One click stops all further collaboration requests to that address, from any member, and we record the opt-out so the address is not contacted again. A message that was already on its way may still arrive.

Company Data from Public Registers

The company records in our directory come from official public business registers: the Finnish Patent and Registration Office (PRH), the Norwegian Register of Business Enterprises (Brønnøysund), the Danish Central Business Register (CVR), the Swedish Companies Registration Office (Bolagsverket), the Estonian Business Register (ariregister), the Belgian Crossroads Bank for Enterprises (KBO/BCE), the Romanian Trade Register (ONRC), the French business register (INSEE), the Czech business register (ARES), the Slovak business register (RPO) and the Global LEI Foundation (GLEIF).

We also query OpenCorporates. It is a commercial aggregator of company data rather than an official register, and the collaboration request we send names the source a record came from. Where an official register holds the same company, we keep whichever record is more complete and prefer the official one when they are equally complete.

These records are about companies, but some of them contain personal data all the same: a confirmed contact address at the company, and, for a sole trader, a business name that is also a person's name. We treat them accordingly. A record nobody has looked at for 90 days is deleted. Two kinds of record are kept longer: one linked to an AURE member's own company, and one a collaboration request refers to. Those are kept for as long as that relationship lasts.

AI-Assisted Contact Discovery

To help a member reach the right person, our AI assistant reads the company's own public website and suggests who the likely decision maker is. Where we have enabled it, it also runs one public web search for the company's current decision makers and, when the company has no website on record, one further public web search to find the company's own website, which is then read in the same way. Any name found through a web search is shown with a link to the page it came from. It never fabricates an email address. An address is marked as verified only when it appears on the company's own pages and belongs to the company's own domain, and a personal address is suggested only when the company itself publishes that address, publishes the format its addresses follow, or publishes two or more addresses that plainly follow one format. An address derived from such published evidence is always marked as derived and is never presented as confirmed. The member always decides whether anything is sent.

Separately from that, when we hold no confirmed address for a company, the directory suggests a generic company address built from the company's own registered website, in the form info@ and the company's domain. That is a suggestion for the member to check before sending. It is not an address we found, and we do not store it.

Suggestions from the AI step are cached for 30 days so the same website is not fetched again and again, and are deleted within 90 days at the latest. In Germany, Austria, Italy and Poland the request is addressed by default to the company's general address rather than to a named person; a member who enters a personal address there is warned that the person's prior consent is required.

How to Object

If you received a collaboration request and do not want to hear from us again, use the opt-out link in the message or email altin@aure-network.com. We will stop all further requests to your address and, on request, tell you what we hold and delete it unless we are required to keep it.