Privacy Policy
Last updated 9 July 2026
This Privacy Policy explains how Aura collects, uses and protects personal information when you use our platform and services (the "Service"). We process personal information in line with the Protection of Personal Information Act, 2013 (POPIA) and other applicable data-protection laws.
1. Information we collect
- Account information — your name, email address, and the organisation and role associated with your account.
- Usage information — how you interact with the Service, including pages viewed, actions taken, device and browser details, and approximate location derived from your IP address.
- Content and campaign data — the content, creatives, settings and data you upload or configure in the Service.
- Communications — messages you send us, such as support requests.
2. How we use your information
We use personal information to provide and secure the Service, authenticate you, operate advertising and content features, measure performance, provide support, comply with legal obligations, and improve our products. We process information on the lawful bases of performing our contract with you, our legitimate interests in operating the Service, your consent where required, and compliance with the law.
3. Cookies and similar technologies
We use cookies and similar technologies to keep you signed in, remember your preferences (such as your theme), keep the Service secure, and understand how it is used. You can control cookies through your browser settings; disabling some cookies may affect how the Service works.
4. Advertising and measurement
The Service includes advertising features. We and publishers may record events such as ad impressions, views and clicks to deliver, cap the frequency of, and measure advertising. Aggregate and de-identified metrics — such as reach and click-through rate — are used for reporting and optimisation. We do not sell your personal information.
5. How we share information
We share personal information only as needed to run the Service:
- with other members of your organisation, according to roles and permissions;
- with service providers who process data on our behalf under appropriate safeguards;
- where required by law, regulation or valid legal process; and
- in connection with a business transfer, subject to this Policy.
6. Data retention
We keep personal information for as long as your account is active and as needed to provide the Service, then for a reasonable period to meet legal, accounting or reporting requirements, after which it is deleted or de-identified.
7. Security
We use technical and organisational measures — including encryption in transit, access controls and least-privilege roles — to protect personal information. No system is completely secure, so we cannot guarantee absolute security, but we work to protect your data and to notify you of significant incidents where required.
8. Your rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal information, object to certain processing, and lodge a complaint with the Information Regulator. To exercise these rights, contact us using the details below. We may need to verify your identity before acting on a request.
9. International transfers
Where personal information is processed outside South Africa, we take steps to ensure it receives a comparable level of protection, consistent with POPIA.
10. Children's privacy
The Service is intended for use by organisations and adults. We do not knowingly collect personal information from children without appropriate consent.
11. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will take reasonable steps to notify you, and the "last updated" date above will reflect the latest version.
To contact our Information Officer or ask about this Policy, email support@nandie.com. See also our Terms of Service.