Skip to content
AURI
IntegrationsPricing
enpldear
Get my demo

Modules

Product overview SPA Operation Aggregator Integrations

Modules built around hotel SPA operations.

Product overview

By segment

Hotel chains Luxury hotels Day SPA

Built for hotel chains, luxury hotels, and day spa operators.

Get my demo

Insights

Blog Research Field notes

Conversion research, field notes, and the blog.

Research

About AURI

About AURI Founder ExploreTech

Talk to us

Contact Demo

Founder-led, ExploreTech UAE onboarded, talk to us anytime.

Founder

Modules

Product overview SPA Operation Aggregator Integrations

By segment

Hotel chains Luxury hotels Day SPA
Integrations

Insights

Blog Research Field notes
Pricing

About AURI

About AURI Founder ExploreTech

Talk to us

Contact Demo
Get my demo
enpldear
LEGAL Last updated · 1 May 2026

Privacy Policy

What personal data Auri collects, why we collect it, and the rights you have over it.

Maciej Adamski Sp. z o.o. ("Auri", "we", "us"), registered in Poland, operates the Auri hotel SPA management system. This policy explains what personal data we collect, why we collect it, how long we keep it, and how to exercise your rights under GDPR, UAE PDPL, and Saudi Arabia PDPL.

On this page

  • Data we collect
  • How we use personal data
  • Cookies and tracking
  • How long we keep data
  • Your rights as a data subject
  • Where data lives and how it moves
  • Privacy contact

Data we collect

Auri collects personal data in three contexts.

Marketing website (auri-system.com): demo and contact form submissions (name, work email, property name, country, source attribution). Anonymised analytics via Google Analytics 4 with Consent Mode v2 — no tracking fires until you accept, and IPs are anonymised.

Hotel SPA management system (one isolated deployment per client): each client tenant collects guest personal data — names, contact details, treatment histories, payment tokens, reservation records — under the client's own privacy policy. Auri is the processor; the hotel is the controller.

Customer admin accounts: admin names, work emails, and credentials (passwords stored as bcrypt hashes — never plain text). Audit logs of administrative actions are retained for traceability.

How we use personal data

Demo and contact submissions are used to reply to your inquiry. We do not sell, rent, or share marketing data with third parties. Records live in a private markdown CRM, not third-party SaaS.

Analytics improves the marketing site only. Aggregated, never per-user. No remarketing, no advertising pixels, no AI-training extraction.

Admin account data authenticates access, writes an audit trail, and lets us send service notices (planned maintenance, security advisories).

Cookies and tracking

Strictly-necessary cookies (session, CSRF) are set without consent — the site cannot function without them.

Analytics cookies fire only after the consent banner is accepted. Consent Mode v2 means GA4 receives no identifiers until you allow it. You can change your choice anytime via the footer link.

We do not set advertising, marketing, or remarketing cookies. If that ever changes the banner and this policy will be updated 30 days in advance.

Cookie behaviour inside the hotel SPA management system is configured per client and disclosed in each hotel's own privacy notice.

How long we keep data

Marketing inquiries: 24 months from last contact, then deleted unless you opt into longer retention.

Analytics: 14 months (GA4 default). Aggregated counts retained for trend analysis.

Admin accounts: duration of the customer contract + 12 months (legal hold / audit window), then anonymised.

Tenant data inside the system: configured per client. Each hotel's own privacy notice sets the actual retention windows for guest records.

Your rights as a data subject

Under GDPR, UAE PDPL, and Saudi Arabia PDPL you have the right to:

Access — request a copy of the personal data we hold about you.
Rectification — request correction of inaccurate data.
Erasure — request deletion ("right to be forgotten"), subject to legal retention obligations.
Restrict processing — limit how we use your data.
Data portability — receive your data in machine-readable JSON.
Object — object to processing based on legitimate interest.
Withdraw consent — for anything we process based on consent.

To exercise any right, email privacy@auri-system.com. We respond within 30 days. If we refuse a request we explain why and you may complain to your national supervisory authority (in Poland, UODO).

Where data lives and how it moves

Auri runs on Google Cloud Platform. Default regions: Frankfurt (europe-west3) for European clients, Bahrain (me-central1) for GCC clients. Other regions are configurable per deployment.

For EU/EEA data transferred outside the EU/EEA we use Standard Contractual Clauses (SCCs). For UAE data we honour PDPL data-localisation requirements where they apply.

Sub-processors (Stripe, Tap Payments, Twilio, Resend, SMSAPI.pl) operate under their own data-transfer mechanisms — documented in the Data Processing Agreement.

Privacy contact

Email: privacy@auri-system.com
Postal: Maciej Adamski Sp. z o.o., Poland (registered address provided on request).
Data Protection Officer: Maciej Adamski (founder, acting DPO).

For supervisory authority complaints, contact your national data protection authority — UODO (Poland), the relevant EU DPA, or the UAE Data Office.

Privacy or data-subject request

Email privacy@auri-system.com. We acknowledge within 2 business days and respond in full within 30 days, per GDPR Art. 12(3).

AURI

Booking software for prestigious hotel SPAs. Your brand, your data, zero booking commissions.

Made in Poland · ExploreTech UAE onboarded vendor

Product

Product overviewSPA OperationAggregatorIntegrations

For

Hotel chainsLuxury hotelsDay SPA

Resources

BlogPricingIntegrations

Company

AboutFounderExploreTechDemoContact

© 2026 AURI · Privacy · Terms · Data Processing · Security