Legal
GDPR Information
GDPR Information
Effective 30 July 2026 · Last updated 30 July 2026
Introduction
This page provides supplementary information about how Aurexus Group Ltd ("Aurexus", "we", "us" or "our") complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
It supplements our Privacy Policy, which contains detailed information about data collection, use and rights. Together, these documents explain our data protection framework.
Data Controller
Legal name: Aurexus Group Ltd
Company number: 17152745
Registered office: Unit A, 82 James Carter Road, Mildenhall, Bury St. Edmunds, Suffolk, England, IP28 7DE
Website: https://www.aurexus-group.com
Contact: admin@aurexus-group.com
Aurexus is generally the data controller for personal data processed through our corporate website, enquiries, partnerships and direct client relationships.
Where we process personal data on behalf of clients within deployed platforms (such as BioAegix in healthcare settings), the client organisation is typically the data controller and Aurexus acts as a data processor. This relationship is governed by a data processing agreement.
Legal Framework
We comply with:
- UK GDPR — retained EU GDPR as incorporated into UK law
- Data Protection Act 2018 — UK legislation supplementing UK GDPR
- Privacy and Electronic Communications Regulations (PECR) — for cookies and electronic marketing
- Sector-specific requirements — where applicable to healthcare, pharmaceutical and public sector deployments
We monitor guidance from the Information Commissioner's Office (ICO) and adapt our practices accordingly.
Lawful Bases for Processing
Under UK GDPR Article 6, we rely on the following lawful bases:
| Lawful basis | Typical application |
|---|---|
| Consent | Marketing communications, non-essential cookies, optional surveys |
| Contract | Delivering services, managing client relationships, fulfilling orders |
| Legal obligation | Tax records, regulatory compliance, responding to lawful requests |
| Legitimate interests | Website security, enquiry management, business development, service improvement (balanced against individual rights) |
| Vital interests | Rare emergency situations affecting life or safety |
| Public task | Not typically applicable to Aurexus corporate processing |
Special category data (Article 9) is processed only where a valid condition applies — typically explicit consent, substantial public interest with appropriate safeguards, or processing necessary for healthcare provision under the responsibility of a health professional, as defined in client platform deployments.
Data Protection Principles
We adhere to the seven UK GDPR principles:
- Lawfulness, fairness and transparency — we process data lawfully with clear notices
- Purpose limitation — data is collected for specified purposes and not misused
- Data minimisation — we collect only what is necessary
- Accuracy — we take reasonable steps to keep data accurate and current
- Storage limitation — data is retained only as long as necessary
- Integrity and confidentiality — appropriate security measures are in place
- Accountability — we document compliance and can demonstrate it
Data Subject Rights
Individuals whose personal data we process have the following rights:
| Right | Description |
|---|---|
| Access | Obtain confirmation of processing and a copy of personal data |
| Rectification | Correct inaccurate or incomplete data |
| Erasure | Request deletion ("right to be forgotten") in applicable circumstances |
| Restriction | Limit processing in certain situations |
| Portability | Receive data in a structured, machine-readable format |
| Objection | Object to processing based on legitimate interests or direct marketing |
| Automated decision-making | Not be subject to solely automated decisions with significant effects, except where permitted with safeguards |
To exercise rights, email admin@aurexus-group.com. We respond within one month, extendable by two months for complex requests with notification.
We may request identity verification. We do not charge fees except for manifestly unfounded or excessive requests.
Data Protection Impact Assessments
We conduct Data Protection Impact Assessments (DPIAs) where processing is likely to result in high risk to individuals — for example, systematic monitoring, large-scale special category data processing, or new AI capabilities in sensitive environments.
DPIA outcomes inform mitigation measures, governance controls and documentation.
Processors and Subprocessors
We use carefully selected processors for hosting, email delivery and infrastructure security where required. We do not currently use third-party website analytics or marketing trackers on www.aurexus-group.com. Processors are bound by written contracts requiring UK GDPR-compliant data protection terms (Article 28).
A list of key subprocessors is available on request. We notify clients of material subprocessor changes where required by contract.
International Transfers
Transfers outside the UK are protected by:
- UK adequacy regulations
- UK International Data Transfer Agreement (IDTA)
- Binding Corporate Rules (where applicable)
- Other mechanisms recognised under UK GDPR
We assess transfer risks and implement supplementary measures where necessary.
Data Breach Notification
We maintain procedures to detect, investigate and respond to personal data breaches. Where a breach is likely to result in a risk to individuals' rights and freedoms:
- We notify the ICO within 72 hours where required
- We notify affected individuals without undue delay where required
- We document all breaches, including those not requiring notification
Clients are notified of processor breaches affecting their data in accordance with contractual terms.
Records of Processing
We maintain records of processing activities as required by UK GDPR Article 30, documenting purposes, categories of data, recipients, retention and security measures.
Data Protection by Design and Default
Privacy considerations are integrated into system architecture, product development and operational processes from the outset — including data minimisation, pseudonymisation, access controls and retention defaults.
This aligns with our engineering principle that trust is designed in, not added later.
Marketing and PECR
We send marketing communications only where permitted — typically with consent or under the soft opt-in for existing clients where applicable. Every marketing message includes an unsubscribe mechanism. We honour opt-out requests promptly.
Children's Data
Our corporate services are not directed at children under 16. We do not knowingly process children's data through corporate channels.
Supervisory Authority
You have the right to lodge a complaint with the ICO:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: https://ico.org.uk/make-a-complaint
We encourage you to contact us first so we can address concerns directly.
Governance
As a growing company, our data protection governance is proportionate to our current scale and expanding in line with our product deployments. We review policies annually and following significant changes to processing activities.
We will appoint a Data Protection Officer if required by UK GDPR criteria as we scale.
Related Documents
Contact
Data protection enquiries: admin@aurexus-group.com
Post: Data Protection, Aurexus Group Ltd, Unit A, 82 James Carter Road, Mildenhall, Bury St. Edmunds, Suffolk, England, IP28 7DE
Governing law: England and Wales