Aurix
Aurix Governance Risk Compliance
← Back to Aurix Log in

Privacy Policy

Effective date: September 5, 2026 · Last reviewed: September 5, 2026

Aurix GRC is a product of Xaephyr Reliance Group KK ("XRG," "we," "us," "our"), a Japan-based managed IT and technology services company. This policy applies to the Aurix GRC website and platform, and is maintained consistently with XRG's group-wide legal and privacy practices.

This Privacy Policy explains how Aurix collects, uses, and protects information when you visit this website or use the platform.

1. Information We Collect

  • Information you provide directly — account and workspace details when your organization signs up or a teammate is invited (name, work email, role), along with the risk, control, and evidence records your team creates or uploads while running your compliance program in Aurix.
  • Information from connected systems — where you link a production system (such as a cloud provider, identity provider, or ticketing tool) for automated evidence collection, Aurix reads the specific signal needed to verify a control — for example, whether MFA is enforced — rather than pulling a general copy of that system's data.
  • Automatically collected information — standard technical data generated by your browser and our hosting provider, such as IP address, browser type, device type, and timestamps, used for security, performance, and abuse prevention.
  • Cookies and similar technologies — see our Cookie Policy for full detail on what we use and why.

2. How We Use Information

  • To provide, operate, and secure the Aurix platform and the workspace your organization runs on it.
  • To map the controls and evidence you enter to the frameworks you're pursuing, and show you what's already covered and what's still open.
  • To respond to inquiries submitted through this site or the app.
  • To meet legal, contractual, and regulatory obligations relevant to our services.
  • To communicate with existing or prospective customers about the service, where you have not opted out.

We do not sell personal information, and we do not use advertising trackers on this site.

3. Legal Basis for Processing

Where applicable data protection law requires a stated legal basis, we rely on: performance of a contract or steps taken at your request prior to entering one (such as provisioning your workspace after an invite), our legitimate interests in operating and securing this platform, and compliance with legal obligations, including Japan's Act on the Protection of Personal Information (APPI) and, where applicable, the EU General Data Protection Regulation (GDPR).

4. Sharing of Information

We do not sell or rent personal information. We may share limited information with:

  • Service providers who support our platform and operations — currently a hosting and database infrastructure provider, an AI model provider used to power evidence analysis and drafting features within the platform, a transactional email provider for invites and notifications, and a web font provider.
  • Customer engagements — where your organization has a signed agreement with XRG, information relevant to that agreement is handled under its terms, which take precedence over this website-level policy for engagement-specific data.
  • Legal and regulatory bodies, where required by applicable law or a valid legal process.

5. International Data Transfers

Some service providers we rely on operate global infrastructure, which may involve processing data outside Japan. Where this occurs, we expect our providers to maintain appropriate safeguards consistent with their own published data protection commitments.

6. Data Retention

We retain information only for as long as reasonably necessary for the purposes described in this policy, to comply with legal or contractual obligations, or to resolve disputes.

7. Your Rights

Depending on where you are located, you may have rights to access, correct, delete, or restrict the use of your personal information, and to object to certain processing. To exercise any of these rights, contact us using the details in Section 10.

8. Security of Your Information

As a platform built by a managed IT and security services provider, we take the protection of information seriously and apply reasonable administrative, technical, and organizational safeguards, including role-based access control and mandatory two-factor authentication on every account. No method of transmission or storage is completely secure — see our Security Policy for how to report a concern.

9. Children's Privacy

This website and platform are intended for a business audience and are not directed at children. We do not knowingly collect personal information from children.

10. Contact Us

Questions about this Privacy Policy, or requests relating to your personal information, can be directed to [email protected].

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last reviewed" date above.

Aurix Aurix
Privacy Policy Cookie Policy Security Contact
© 2026 Aurix, a product of Xaephyr Reliance Group. Not a substitute for a certified security or legal audit.