Skip to content
A Auraflow Digital
Process Services About FAQ
Book a growth audit

Legal

Privacy Policy

Last updated: 25 May 2026 · Effective: 25 May 2026

1. Who we are

This privacy notice applies to Auraflow Digital LLP (referred to as "Auraflow Digital", "we", "us" or "our"), a limited liability partnership registered in England and Wales with company number OC460656, whose registered office is at 27 Old Gloucester Street, London WC1N 3AX, United Kingdom.

Auraflow Digital LLP is the data controller for personal data collected through our website at auraflowdigital.ai and in the ordinary course of our business with prospects, clients and partners.

2. The data we collect

We collect and process the following categories of personal data:

  • Identification and contact data — name, business email address, company name, job title, country, telephone number where you provide it.
  • Enquiry data — the content of any enquiry, message or communication you send us through our contact form, by email or by other channels.
  • Technical data — IP address, browser type and version, time zone, operating system, device type, referring website and the pages you visit on our website.
  • Engagement data — if we work together, information necessary to deliver our services, including contractual, financial, accounting and operational records.
  • Cookies and similar technologies — see our separate Cookie Policy.

3. How we collect your data

We collect personal data:

  • directly from you, when you contact us, complete a form, send us an email, sign a contract or interact with us;
  • automatically through our website, via cookies, analytics tools and server logs (see our Cookie Policy);
  • from third parties, where you have authorised them to share data with us (for example, scheduling tools, your CRM, or referrals), and only to the extent necessary to provide our services.

4. Why we use your data and the legal basis

We process personal data only where we have a lawful basis to do so under the UK GDPR. The table below sets out our principal processing activities, their purpose and the legal basis we rely on:

PurposeLegal basis
Responding to your enquiry and providing information about our servicesLegitimate interests (responding to a request you initiated) and/or steps preparatory to entering into a contract
Providing our services to clients under an agreed engagementPerformance of a contract
Sending you occasional updates about our services (only if you have opted in)Consent (which you may withdraw at any time)
Maintaining our business records, accounting and tax recordsLegal obligation; legitimate interests
Operating, maintaining and improving our websiteLegitimate interests in running a functional, secure website
Detecting and preventing fraud, misuse or security incidentsLegitimate interests; legal obligation
Complying with our legal, regulatory and compliance obligations (including anti-money-laundering and sanctions screening where applicable)Legal obligation

5. Who we share your data with

We do not sell personal data to third parties. We share personal data only with:

  • Service providers and processors who help us operate our business, including: our website hosting provider, email service providers, customer relationship management tools, scheduling tools, accounting and tax software, and document-storage providers. These providers act only on our instructions and are subject to confidentiality and data-protection obligations.
  • Professional advisers such as our accountants, bankers, lawyers and auditors, where reasonably necessary.
  • Government authorities, regulators, courts, Companies House or HMRC where we are required by law to do so.
  • A buyer or successor in the event of a merger, acquisition or business transfer, subject to confidentiality.

6. International transfers

Because our team operates remotely and serves clients internationally, some personal data may be transferred outside the United Kingdom and the European Economic Area, including to the United Arab Emirates, the United States, and other jurisdictions where our service providers or team members are located. Where we make such transfers, we ensure an appropriate level of protection by relying on lawful transfer mechanisms, including UK adequacy decisions, the UK International Data Transfer Agreement, or the UK addendum to the EU Standard Contractual Clauses, as applicable.

7. How long we keep your data

We retain personal data only for as long as necessary for the purpose for which it was collected:

  • Enquiry data — up to twelve (12) months from your last interaction, unless we are in active discussions with you.
  • Client and contractual data — for the duration of the engagement and for at least six (6) years after the end of the engagement, in line with our legal and tax record-keeping obligations.
  • Accounting records — six (6) years from the end of the financial year to which they relate.
  • Website analytics — typically up to twenty-six (26) months.

We may retain anonymised or aggregated data indefinitely for analytical purposes.

8. Your rights

Under UK and EU data-protection law, you have the following rights in respect of your personal data:

  • Right of access — to ask us for a copy of the personal data we hold about you.
  • Right to rectification — to ask us to correct inaccurate or incomplete data.
  • Right to erasure — to ask us to delete your data in certain circumstances.
  • Right to restrict processing — to ask us to limit how we use your data.
  • Right to data portability — to receive your data in a structured, machine-readable format.
  • Right to object — to object to processing based on legitimate interests, or to direct marketing.
  • Right to withdraw consent — where we rely on consent, you can withdraw it at any time.
  • Right to lodge a complaint — with a supervisory authority (see section 11).

To exercise any of these rights, contact us at admin@auraflowdigital.ai. We will respond within one month of receiving your request.

9. Security

We take appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, alteration or disclosure. These include access controls, encrypted communications, secure storage, and limiting access to personal data to those who need it to perform their role. No transmission over the internet, however, can be guaranteed completely secure.

10. Children

Our website and services are not directed at children under the age of 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.

11. Complaints

If you have a concern about how we are handling your personal data, we would like the opportunity to address it directly. Please email us at admin@auraflowdigital.ai.

You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO), the UK supervisory authority for data protection:

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom
Telephone: 0303 123 1113
Website: ico.org.uk

12. Changes to this policy

We may update this privacy notice from time to time. When we do, we will update the "Last updated" date at the top of this page. Material changes will be brought to your attention through a prominent notice on our website or, where appropriate, by email.

13. Contact us

For any question about this privacy notice or your personal data:

Auraflow Digital LLP
27 Old Gloucester Street, London WC1N 3AX, United Kingdom
Email: admin@auraflowdigital.ai

← Back to home

Auraflow Digital LLP — a limited liability partnership registered in England and Wales. LLP number OC460656. Registered office: 27 Old Gloucester Street, London WC1N 3AX, United Kingdom.

© 2026 Auraflow Digital LLP. All rights reserved.