Effective 15 August 2026
Privacy notice
1. Controller
Jakob Al Ssawaf, trading as Aurevia Market, Senftenberger Ring 32, 13435 Berlin, Germany. Email: support@aureviaaccess.com. Telephone: +49 176 45615857.
2. Local browser processing
Transaction files, imported rows, calculations, payment-behavior analysis, recurring-commitment checks, and generated reports are processed in the user's browser by default. They are not automatically uploaded to Aurevia. The latest workspace is automatically retained in browser storage on that device so it can be restored after a reload. Clearing the workspace removes this local copy. Cross-device recovery remains available only when the user deliberately saves an encrypted project to Cloud Vault.
When a visitor selects a non-English interface language, Aurevia may use the browser's built-in Translator API to translate visible interface text locally. Availability and language-pack downloads are controlled by the browser. Values entered into form controls are not replaced, and Revia conversations use Revia's separate language handling. The selected language and a local phrase cache may be stored on the device.
3. License and order data
Digistore24 supplies the order and product identifiers, buyer email address, license or payment status, API mode, and event timestamps required to create and administer access. Aurevia stores the order identifier, product identifier, buyer email, license status, encrypted license material, and creation, update, and last-use timestamps. Address and payment-card information are not collected or persistently stored by this application.
This processing is necessary to perform the contract, prevent unauthorized access, and respond to payment, refund, and chargeback events (Article 6(1)(b) GDPR) and to comply with applicable legal obligations where relevant (Article 6(1)(c) GDPR).
4. Optional encrypted Cloud Vault
If Cloud Vault is selected, project content is encrypted in the browser with AES-256-GCM before transmission. Aurevia stores the ciphertext, integrity fingerprint, project name, version, and timestamps. The private passphrase is never transmitted and cannot be recovered by Aurevia. Project names, approval roles, signer names, decisions, comments, evidence fingerprints, and timestamps are workflow metadata and are not protected by the vault passphrase; confidential financial details must not be entered in those fields.
Vault and collaboration data are processed to provide the requested service (Article 6(1)(b) GDPR). Server-side access control and limited audit evidence are also processed for security and the establishment, exercise, or defence of legal claims (Article 6(1)(f) GDPR).
5. Team access and security records
When team access is used, Aurevia stores invited email addresses, display names, assigned roles, invitation and activity timestamps, account status, and an access audit trail. Invitation tokens and license keys are stored as one-way lookup hashes; license delivery material is encrypted. Security cookies are HTTP-only and same-site where applicable.
6. Affiliate attribution and consent choice
The sales page does not load the Digistore24 affiliate script until the visitor chooses “Allow”. If consent is given, Digistore24 may read referral or campaign parameters and store attribution information in browser storage or cookies so a later checkout can be credited to a partner. The legal basis for access to the device and related processing is consent (section 25(1) TDDDG and Article 6(1)(a) GDPR).
The selection itself is kept in local browser storage on the device. It can be changed at any time through “Privacy choices” on the sales page. Rejecting or withdrawing consent does not prevent access to the product page, preview, or checkout; it only disables affiliate attribution. Withdrawal does not affect processing lawfully carried out before withdrawal.
7. Hosting, recipients, and international transfers
Cloudflare provides hosting, content delivery, security, and database infrastructure as a processor. It may receive IP addresses, request metadata, device/browser information, and security events needed to deliver and protect the service. Cloudflare may set strictly necessary security cookies such as __cf_bm, typically with a short duration, to distinguish legitimate traffic from automated abuse.
Digistore24 processes purchase, payment, invoice, refund, affiliate, and checkout data under its own privacy information as reseller/payment provider. Cloudflare routes messages sent to the listed support address, and Google may process email content and contact data in the destination mailbox when support is requested. No payment-card information is collected by Aurevia.
Where a recipient processes data outside the European Economic Area, appropriate safeguards such as an adequacy decision, the EU-US Data Privacy Framework where applicable, or EU Standard Contractual Clauses are used as required.
8. Affiliate applications
Prospective affiliates may submit their Digistore24 affiliate ID, name, business email, country, public channel links, audience information, promotion plan, traffic methods, compliance confirmations, and content examples. Aurevia uses these details to assess audience relevance, brand safety, fraud and spam risk, and whether to enter an affiliate partnership. The legal basis is taking steps at the applicant's request before a potential partnership and Aurevia's legitimate interest in selecting suitable partners and protecting customers and the brand (Article 6(1)(b) and (f) GDPR).
Automated risk signals may highlight missing evidence or risky wording for human review. They do not approve or reject an applicant. Digistore24 partnership decisions are always made separately. Applicants should provide only public professional links and must not submit buyer lists, passwords, private analytics exports, financial files, or other third-party personal data.
9. Customer feedback
Customers with an active license may submit a rating, category, message, optional page reference, contact email, and optional permission to be contacted. The submission is linked to the active license and product identifiers to verify customer status, prevent abuse, and understand which product the feedback concerns. Customers must not include transaction files, passwords, license keys, confidential financial figures, or unnecessary third-party personal data.
Feedback is processed to improve and secure the contracted product and to respond when requested (Article 6(1)(b) and (f) GDPR). Contact permission applies only to the submitted feedback and does not subscribe the customer to marketing.
10. Retention
- Browser-only transaction and forecast data: retained on the user's device until the workspace is cleared or browser data is removed; not retained by Aurevia unless Cloud Vault is deliberately used.
- Failed activation security records containing pseudonymous IP hashes: automatically limited to a rolling 24-hour period.
- License-session cookie: up to 7 days; team-session cookie: up to 30 days.
- License and order-access records: for the access period and then generally up to 3 years to resolve contractual claims, unless a longer statutory duty applies.
- Cloud Vault projects: until an authorized user deletes them. Following a valid account-deletion request or final termination, active data is scheduled for deletion within 30 days unless retention is legally required.
- Team and audit records: while collaboration is active and then generally up to 3 years where required to document access, security, or legal claims.
- Support correspondence: generally up to 3 years after the request is closed, unless a longer duty or unresolved claim requires retention.
- Affiliate applications: generally up to 180 days after a declined or inactive application; approved-partner records may be retained for the partnership and applicable contractual or legal limitation periods.
- Customer feedback: up to 24 months from submission, unless it remains necessary to resolve an open support, security, contractual, or legal matter.
11. Required data and automated decisions
Order and license data are required to grant paid access; without them the service cannot authenticate the purchase. Optional Cloud Vault, team, and affiliate-attribution data are not required for the local forecasting functions. Aurevia does not make decisions producing legal or similarly significant effects solely by automated processing.
12. Rights
Where the GDPR applies, data subjects may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Consent may be withdrawn at any time. A request can be sent to the controller using the contact details above. Identity may need to be verified before a request is completed.
A complaint may be lodged with a supervisory authority, including the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59-61, 10555 Berlin, Germany.
13. Security and updates
Aurevia uses access controls, encrypted transport, one-way key lookup hashes, encrypted license material, browser-side vault encryption, rate limiting, and audit records appropriate to the service. No internet system can be guaranteed completely secure. This notice will be updated when the product, providers, or legal requirements materially change.
