Skip to content
Aurexus

Legal

GDPR Information

GDPR Information

Effective 30 July 2026 · Last updated 30 July 2026

Introduction

This page provides supplementary information about how Aurexus Group Ltd ("Aurexus", "we", "us" or "our") complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

It supplements our Privacy Policy, which contains detailed information about data collection, use and rights. Together, these documents explain our data protection framework.

Data Controller

Legal name: Aurexus Group Ltd
Company number: 17152745
Registered office: Unit A, 82 James Carter Road, Mildenhall, Bury St. Edmunds, Suffolk, England, IP28 7DE
Website: https://www.aurexus-group.com
Contact: admin@aurexus-group.com

Aurexus is generally the data controller for personal data processed through our corporate website, enquiries, partnerships and direct client relationships.

Where we process personal data on behalf of clients within deployed platforms (such as BioAegix in healthcare settings), the client organisation is typically the data controller and Aurexus acts as a data processor. This relationship is governed by a data processing agreement.

Legal Framework

We comply with:

  • UK GDPR — retained EU GDPR as incorporated into UK law
  • Data Protection Act 2018 — UK legislation supplementing UK GDPR
  • Privacy and Electronic Communications Regulations (PECR) — for cookies and electronic marketing
  • Sector-specific requirements — where applicable to healthcare, pharmaceutical and public sector deployments

We monitor guidance from the Information Commissioner's Office (ICO) and adapt our practices accordingly.

Lawful Bases for Processing

Under UK GDPR Article 6, we rely on the following lawful bases:

Lawful basis Typical application
Consent Marketing communications, non-essential cookies, optional surveys
Contract Delivering services, managing client relationships, fulfilling orders
Legal obligation Tax records, regulatory compliance, responding to lawful requests
Legitimate interests Website security, enquiry management, business development, service improvement (balanced against individual rights)
Vital interests Rare emergency situations affecting life or safety
Public task Not typically applicable to Aurexus corporate processing

Special category data (Article 9) is processed only where a valid condition applies — typically explicit consent, substantial public interest with appropriate safeguards, or processing necessary for healthcare provision under the responsibility of a health professional, as defined in client platform deployments.

Data Protection Principles

We adhere to the seven UK GDPR principles:

  1. Lawfulness, fairness and transparency — we process data lawfully with clear notices
  2. Purpose limitation — data is collected for specified purposes and not misused
  3. Data minimisation — we collect only what is necessary
  4. Accuracy — we take reasonable steps to keep data accurate and current
  5. Storage limitation — data is retained only as long as necessary
  6. Integrity and confidentiality — appropriate security measures are in place
  7. Accountability — we document compliance and can demonstrate it

Data Subject Rights

Individuals whose personal data we process have the following rights:

Right Description
Access Obtain confirmation of processing and a copy of personal data
Rectification Correct inaccurate or incomplete data
Erasure Request deletion ("right to be forgotten") in applicable circumstances
Restriction Limit processing in certain situations
Portability Receive data in a structured, machine-readable format
Objection Object to processing based on legitimate interests or direct marketing
Automated decision-making Not be subject to solely automated decisions with significant effects, except where permitted with safeguards

To exercise rights, email admin@aurexus-group.com. We respond within one month, extendable by two months for complex requests with notification.

We may request identity verification. We do not charge fees except for manifestly unfounded or excessive requests.

Data Protection Impact Assessments

We conduct Data Protection Impact Assessments (DPIAs) where processing is likely to result in high risk to individuals — for example, systematic monitoring, large-scale special category data processing, or new AI capabilities in sensitive environments.

DPIA outcomes inform mitigation measures, governance controls and documentation.

Processors and Subprocessors

We use carefully selected processors for hosting, email delivery and infrastructure security where required. We do not currently use third-party website analytics or marketing trackers on www.aurexus-group.com. Processors are bound by written contracts requiring UK GDPR-compliant data protection terms (Article 28).

A list of key subprocessors is available on request. We notify clients of material subprocessor changes where required by contract.

International Transfers

Transfers outside the UK are protected by:

  • UK adequacy regulations
  • UK International Data Transfer Agreement (IDTA)
  • Binding Corporate Rules (where applicable)
  • Other mechanisms recognised under UK GDPR

We assess transfer risks and implement supplementary measures where necessary.

Data Breach Notification

We maintain procedures to detect, investigate and respond to personal data breaches. Where a breach is likely to result in a risk to individuals' rights and freedoms:

  • We notify the ICO within 72 hours where required
  • We notify affected individuals without undue delay where required
  • We document all breaches, including those not requiring notification

Clients are notified of processor breaches affecting their data in accordance with contractual terms.

Records of Processing

We maintain records of processing activities as required by UK GDPR Article 30, documenting purposes, categories of data, recipients, retention and security measures.

Data Protection by Design and Default

Privacy considerations are integrated into system architecture, product development and operational processes from the outset — including data minimisation, pseudonymisation, access controls and retention defaults.

This aligns with our engineering principle that trust is designed in, not added later.

Marketing and PECR

We send marketing communications only where permitted — typically with consent or under the soft opt-in for existing clients where applicable. Every marketing message includes an unsubscribe mechanism. We honour opt-out requests promptly.

Children's Data

Our corporate services are not directed at children under 16. We do not knowingly process children's data through corporate channels.

Supervisory Authority

You have the right to lodge a complaint with the ICO:

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: https://ico.org.uk/make-a-complaint

We encourage you to contact us first so we can address concerns directly.

Governance

As a growing company, our data protection governance is proportionate to our current scale and expanding in line with our product deployments. We review policies annually and following significant changes to processing activities.

We will appoint a Data Protection Officer if required by UK GDPR criteria as we scale.

Related Documents

Contact

Data protection enquiries: admin@aurexus-group.com
Post: Data Protection, Aurexus Group Ltd, Unit A, 82 James Carter Road, Mildenhall, Bury St. Edmunds, Suffolk, England, IP28 7DE

Governing law: England and Wales