This policy explains how Aucip ("we", "us"), [company address], processes personal data when you visit aucip.com, buy products or use our license and update APIs. Contact: noreply@aucip.com.
1. Data we collect
| Category | Examples | Why |
|---|---|---|
| Account | name, email, password hash, language, currency | To provide your account (contract) |
| Orders & billing | items, amounts, currency, billing address, company, IP at checkout | To sell and invoice (contract, legal obligation) |
| Payments | gateway reference, UTR/transfer details, proof uploads | To confirm payment and prevent fraud (contract, legitimate interest) |
| Licenses | license key, activated domains, server IP, product version, last check-in | To enforce licenses and deliver updates (contract) |
| Support | tickets, replies, attachments | To help you (contract) |
| Security | login history, IP, device, 2FA status | To protect accounts (legitimate interest) |
| Marketing | newsletter subscription (double opt-in), referral code | Only with consent / for the affiliate program |
| Cookies | see Cookie policy | Essential operation; optional analytics only with consent |
We do not sell personal data.
2. Processors we share data with
Payment gateways you choose (e.g. Stripe, Razorpay, PayPal, Cashfree, PayU, Easebuzz, Instamojo, crypto processors), our hosting provider, email delivery provider, and — if enabled — Cloudflare (CDN/security) and Telegram (internal staff alerts without card data). Each acts under its own terms and our instructions.
3. International transfers
Some processors are outside your country. Where required we rely on adequacy decisions or standard contractual clauses.
4. Retention
- Account data: while your account is active.
- Orders and invoices: 8 years (accounting law), anonymised if you delete your account.
- License activation logs: life of the license + 1 year.
- Support tickets: 3 years after closure.
- Login history: 12 months. Backups: rolling 30 days.
5. Your rights
You can access, correct, export and delete your data. Export and delete are self-service under Dashboard → Privacy. Deletion happens after a 14-day grace period; invoices are kept in anonymised form as required by law. You may also object to processing, withdraw consent and lodge a complaint with your data-protection authority (e.g. under GDPR or India's DPDP Act).
6. Security
Passwords are hashed, staff accounts use two-factor authentication, license responses are signed, and payment card data never touches our servers.
7. Children
Our services are not directed at children under 16.
8. Changes
We'll post changes here and, if material, email you. Last updated: October 11, 2026.
Last updated: October 11, 2026