AureonLead Privacy Policy
Last updated: January 31, 2026
Version: 1.0
Important: This document describes how we handle data in connection with the AureonLead dashboard and lead intelligence platform. It does not constitute legal advice and should be reviewed by a professional.
1. Who we are
This policy describes how Aureoncorp (hereinafter "Aureoncorp", "we", "our") processes personal data of users who:
- access and use the AureonLead dashboard (the "Service")
- create an account, log in, or manage settings
- request support or contact us regarding AureonLead
- purchase or access lead packages, exports, or related features
Data Controller
- Legal name: Mihai-Rafael Iosef
- Address: Bucharest, Romania
- Privacy contact email: rafael@aureoncorp.com
2. Types of data processed
2.1 Data provided voluntarily (accounts, support, billing)
AureonLead account
When you create and use an AureonLead account we may process:
- Name and surname (if provided)
- Email address
- Password (stored only in encrypted/hash form)
- Language / communication preferences
- Company name, website, niche, country/city (if provided)
- Account configuration and preferences
Support & contact
When you contact us we may process:
- Name, email, company name / website
- Message content
- Any additional information you provide voluntarily
Payments (if applicable)
If you purchase services, payments are handled by third-party payment providers. We may receive limited metadata such as:
- Plan name / purchase type
- Billing status (active, canceled, failed)
- Invoice identifiers (where applicable)
We do not store full card details.
2.2 Automatically collected data (logs and security)
When you use AureonLead, the following technical data may be collected:
- IP address (possibly anonymized)
- User agent (browser, operating system)
- Login events and timestamps
- Pages visited within the dashboard
- Technical events (errors, HTTP responses)
- Security logs related to abuse prevention and access control
2.3 B2B lead data (AureonLead)
AureonLead provides B2B lead intelligence generated from publicly accessible sources, such as:
- public business listings (e.g., Google Maps)
- business websites and public directories
Lead data may include:
- Business / company name
- Address, city, country
- Category / niche
- Phone number (public)
- Professional email address (public)
- Website URL
- Any contact names/roles only if publicly displayed on the business website
This data is provided to AureonLead customers as "lead lists" and may be accompanied by technical/audit indicators derived from website analysis.
Important: AureonLead customers determine how they use leads for outreach. In most cases, the AureonLead customer is the data controller for any outreach activity. Aureoncorp typically acts as a service provider / data processor with respect to lead list generation and delivery.
3. Processing purposes and legal bases
3.1 Account creation and service delivery
- Purpose: create and manage accounts; provide access to the dashboard; deliver lead packages; enable exports; provide support.
- Data: account data, service usage data, limited billing metadata.
- Legal basis:
- Art. 6(1)(b) GDPR – contract performance / pre-contractual measures
- Art. 6(1)(f) GDPR – legitimate interest (service maintenance, fraud prevention)
3.2 Customer support and communication
- Purpose: respond to requests, fix issues, provide technical support, and communicate about service operations.
- Data: contact details, message content, technical metadata.
- Legal basis:
- Art. 6(1)(b) GDPR – contract / pre-contractual measures
- Art. 6(1)(f) GDPR – legitimate interest (efficient support and abuse prevention)
3.3 Platform security and abuse prevention
- Purpose: protect accounts and infrastructure; prevent fraud, unauthorized access, and misuse.
- Data: IP address, access logs, user agent, security events.
- Legal basis: Art. 6(1)(f) GDPR – legitimate interest (security of the Service)
3.4 Service analytics and improvement (if enabled)
- Purpose: understand usage patterns to improve performance and reliability.
- Data: pseudonymized usage events and technical metrics.
- Legal basis:
- Art. 6(1)(f) GDPR – legitimate interest (service improvement)
- and/or Art. 6(1)(a) GDPR – consent (if cookie-based analytics is used)
Aureoncorp does not use automated decision-making or profiling producing legal effects under Art. 22 GDPR.
4. Processing methods
Data is processed primarily with electronic tools, adopting reasonable technical and organizational measures to:
- limit access to authorized personnel only
- protect data from loss, misuse, unauthorized access
- minimize data processed relative to the purpose
5. Data recipients and third-party providers
To operate AureonLead we use third-party providers ("data processors"), which may include:
- Hosting and infrastructure providers
- Database and backend providers (e.g., Supabase)
- Email delivery providers (transactional communications)
- Security/CDN providers
- Monitoring/logging providers
- Email verification providers for lead enrichment
We use Data Processing Agreements (DPAs) and/or Standard Contractual Clauses (SCC) where required.
6. Data transfers to non-EU countries
Some providers may be located outside the EEA. Where required, transfers are based on:
- Standard Contractual Clauses (SCC)
- additional security measures where technically and contractually possible
Residual risks related to third-country legislation cannot be fully excluded.
7. Data retention periods
We retain data only for as long as necessary:
- Account data: for the duration of the customer relationship and up to 5 years afterwards where required for legal/tax protection
- Support requests: up to 24 months from last interaction (unless longer retention is legally required)
- Technical/security logs: generally up to 12 months
- Lead data in the dashboard: retention depends on plan configuration and operational needs
8. Data subject rights
You have the right to:
- access (Art. 15)
- rectification (Art. 16)
- erasure (Art. 17)
- restriction (Art. 18)
- portability (Art. 20)
- object to processing based on legitimate interest (Art. 21)
- withdraw consent (where consent applies)
To exercise your rights contact: rafael@aureoncorp.com
You may also lodge a complaint with a competent supervisory authority.
9. Minors
AureonLead is designed for professionals and businesses (B2B). We do not knowingly process personal data of individuals under 18 years of age. If you believe that a person under 18 has provided us with personal data, please contact us so we can take appropriate steps to remove it.
10. Changes to this policy
We may periodically update this Privacy Policy. The always updated version is published on this page, with indication of the last update date.
11. Contact
For any questions regarding this Privacy Policy you can contact us at: