Privacy Policy
How Aurora collects, uses, and protects your data
Last updated: 1 October 2026
Legal Basis for Processing
Aurora processes personal data when you visit this website or otherwise interact with us. As the data controller, we protect your personal data under applicable law, including the EU General Data Protection Regulation 2016/679 (GDPR) and the Swiss Federal Act on Data Protection (nDSG). Our legal bases are:
Consent: analytics cookies and product-update emails you opt into (GDPR Article 6(1)(a)).
Contract performance: processing your image submissions (Article 6(1)(b)).
Legitimate interests: essential security measures, including CSRF protection and session management, and understanding and improving our communications (Article 6(1)(f)).
Data We Collect
Account data: your email address, first and last name, and a hashed password when you create an account.
Submission data: uploaded H&E images, any paired spatial and molecular data (such as training pairs or data for model adaptation), and generated results, associated with your email. When you submit images, we record the version of the Terms you accepted and when.
Website analytics: Google Analytics page views, session duration and approximate geographic region, collected only after consent. Our own page counts and result usage logging are described below.
Demo enquiries: your email address and any optional institution, company or industry details you provide when downloading a demo dataset or report. We use these to deliver the file. Product updates require a separate opt-in confirmed by email (double opt-in).
We do not ask for patient identifiers or clinical records. You must fully anonymise uploaded data before submission.
Use of Uploaded Data for Model Development
Under the academic terms, Aurora uses uploaded data and generated results to develop, train, validate, and improve its models and services, including those it offers commercially. These uses and your permission for them are described in our Terms under Use of Data for Model Development. Commercial access is governed by a separate written agreement, under which a customer's data is not used for model development without the customer's written permission.
When You View or Download Results
When someone opens a result link, Aurora records events such as opening the spatial map, loading a slide image, viewing a gene symbol or downloading a result. Events are linked to the submission and, where relevant, its image. Downloads record an artefact category rather than a filename. We use these events to understand result usage and improve the service.
To identify repeat requests from the same network, the server derives a daily, submission-specific hash from the request IP address. Event records do not store the raw IP address, browser user agent or referrer. This first-party logging uses no analytics cookies or third-party analytics service.
Links in our emails
We may record interactions with links in our emails, including information relating to the relevant communication or submission and the time of the interaction. We use this information to understand and improve our communications.
Cookies & Tracking
Cookies are small text files placed on your device to operate the website. Aurora does not use targeting, advertising or profiling cookies. Analytics cookies are set only after you accept them in the cookie banner.
Rejecting or withdrawing consent stops analytics collection and deletes existing analytics cookies. You can change your choice through "Cookie Settings" in the footer at any time.
Essential Cookies (no consent required)
| Cookie | Purpose | Lifetime |
|---|---|---|
| __Secure-next-auth.session-token | Authenticated session (JWT) | Session / 30 days |
| __Host-next-auth.csrf-token | NextAuth CSRF protection | Session |
| __Secure-next-auth.callback-url | Redirect after login | Session |
| XSRF-TOKEN | Application-level CSRF protection | 1 hour |
Non-essential Cookies (consent required)
| Cookie | Purpose | Lifetime |
|---|---|---|
| _ga | Google Analytics: distinguishes unique visitors | 2 years |
| _ga_G-6CJGEC0G6H | Google Analytics: maintains session state | 2 years |
Page View Counts
Aurora counts how many times each public page of this website is viewed. Your browser sends the page address without any query string, and we add one to its daily count. The counter sets no cookie, uses no browser storage and stores no IP address, browser details or other identifier: only the page, the date and the number of views. To prevent duplicate counts and flooding, the server keeps hashes of your IP address, browser user agent and page for about 30 minutes, in memory only, using a random key that is replaced every day and never stored. Nothing is counted on admin or sign-in pages, or when your browser sends Global Privacy Control or Do Not Track. Counts stay with Aurora and are shared with no one.
Newsletter and Updates
If you subscribe to updates, we send occasional emails about Aurora's models and features. You can subscribe on this website, where we ask you to confirm by email first, or by opting in to news when you request access to one of our repositories.
We record your email address, where you subscribed, the wording you agreed to and when. We send these emails on the basis of your consent (GDPR Article 6(1)(a)).
Every update includes an unsubscribe link, and you can unsubscribe at any time. Unsubscribing also stops our reminder emails. Emails about your submissions and your account are not affected.
We keep your subscription record until you unsubscribe or ask us to delete it. After you unsubscribe, we keep your email address only to make sure we do not email you again.
Data Storage & Security
Uploaded images, generated results and account information are stored on infrastructure in Switzerland, where analyses also run. Aurora's administrators may access these data when needed to operate the service, provide support or investigate a problem. Cloudflare may process website traffic outside Switzerland, including decrypting and inspecting requests for security; see International Data Transfers below.
Aurora applies technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction, including encryption in transit, access controls and security monitoring. No electronic storage or transmission method is fully secure; we cannot guarantee absolute security.
Data Retention
We retain personal data for as long as needed to provide the service and meet legal obligations. Uploaded data, generated results and account data remain accessible while your account is active.
Result usage events have no separate time limit. They remain linked to their submission and are deleted with it. Records of interactions with links in our emails have no separate time limit and are deleted when you request deletion of your data. Demo enquiry details, including your email and any institution, company or industry information, are kept until you request deletion or withdraw consent.
You can request deletion of your account and associated data through the contact form. Deleting uploaded data does not withdraw models already developed with it. Deletion does not remove copies already held in backups.
Your Statutory Rights
Under the GDPR and Swiss nDSG, you may request access to and a copy of your personal data, or ask us to correct inaccurate or incomplete data. Depending on the circumstances, you may also object to processing, request restrictions, erasure or data portability.
You can withdraw consent at any time without affecting processing carried out before withdrawal. Use "Cookie Settings" in the footer to change analytics consent. To exercise other rights, use the contact form. You may also complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC).
Third-Party Services
Google Analytics measures website usage after explicit consent. Cloudflare provides TLS termination, web application firewalling and Zero Trust access controls for the admin panel.
Aurora does not sell personal data. We share it with these providers as needed to deliver their services and otherwise only where required by law.
International Data Transfers
Google Analytics data may be processed by Google LLC in the United States. Google states that it has certified its adherence to the EU-U.S. Data Privacy Framework (DPF). The European Commission's adequacy decision covers transfers to participating organisations.
Cloudflare may process requests outside Switzerland through its global edge network, including decrypting and inspecting traffic for security. Its Data Processing Addendum describes the applicable transfer safeguards, including DPF certifications and standard contractual clauses where relevant.
Contact
For privacy questions or to exercise your rights, use the contact form. We respond to requests under GDPR Articles 15–22 within one month of receipt. Where necessary, Article 12(3) allows up to two further months; we will notify you of an extension within the first month.