top of page
#aura
#aura_policy

DATA POLICY

PROTECTING INFORMATION PRESERVING TRUST.       

At Aura Solution Company Limited (“Aura”, “we”, “us” or “our”), privacy is an essential part of the confidence placed in us by our clients, partners, colleagues and visitors to our digital platforms.

We recognise that personal information can be highly private and, in many circumstances, commercially sensitive. We therefore approach the handling of information with discretion, discipline and care.

This Data Privacy & Protection Policy explains how Aura collects, uses, stores, protects and, where appropriate, discloses personal information through our websites, digital platforms, communications, professional relationships and other legitimate interactions.

 

Our objective is straightforward: to collect information responsibly, use it for legitimate purposes, protect it appropriately and retain it only for as long as necessary.

 

Last updated: August 2026

AURA DATA PRIVACY & PROTECTION

1. PURPOSE & SCOPE

Aura Solution Company Limited (“Aura”, “we”, “us” or “our”) recognises that personal information entrusted to the Company must be handled with a high degree of care, discretion and responsibility. This Privacy & Data Protection Policy describes the principles and practices that govern the collection, use, processing, storage, protection and disclosure of personal information obtained by Aura through its websites, digital platforms, services, communications, contractual relationships, business activities and other legitimate interactions. The Policy applies to information relating to clients, prospective clients, business partners, counterparties, professional advisers, service providers, website users, applicants and other individuals who communicate or interact with Aura. Aura seeks to ensure that personal information is processed fairly, appropriately and only to the extent reasonably necessary for legitimate and identifiable purposes. The Company recognises that privacy and data protection requirements may differ between jurisdictions and therefore seeks to apply the legal and regulatory requirements relevant to the particular circumstances. This Policy should be read together with any specific privacy notices, contractual provisions or other terms that may apply to a particular service or relationship. Nothing in this Policy is intended to restrict or remove any rights or protections that individuals may have under applicable data-protection or privacy legislation.

2. INFORMATION WE COLLECT

The nature and extent of personal information collected by Aura will depend upon the relationship with the relevant individual and the purpose for which the information is required. In the ordinary course of its activities, Aura may collect contact details, identification information, professional and corporate information, contractual records, correspondence and information relating to business relationships. Where necessary and appropriate, information may also include financial, transactional, payment, account and other information required to establish, administer or maintain a legitimate business relationship. Aura may receive information directly from an individual, from an authorised representative or adviser, from an organisation with which the individual is associated, or from other legitimate sources. When individuals use Aura’s websites or digital platforms, certain technical information may also be generated automatically, including information relating to devices, browsers, operating systems, access activity and security events. Aura seeks to ensure that information collected is relevant and proportionate to the purpose for which it is required. The Company does not seek to collect personal information indiscriminately and will generally avoid requesting information that is not reasonably connected with a legitimate business, operational, contractual, legal or regulatory purpose.

 

3. HOW WE USE INFORMATION

Aura may use personal information for purposes connected with the provision and administration of its services, the management of client and business relationships and the proper operation of the Company. This may include responding to enquiries, communicating with clients and counterparties, administering agreements, maintaining corporate and operational records and managing relevant business processes. Information may also be used to operate, maintain and secure Aura’s technological infrastructure and digital platforms and to identify, assess and manage operational, financial, security and other risks. Where appropriate, Aura may process personal information for the prevention and detection of fraud, misuse, unauthorised activity or other conduct that may adversely affect the Company, its clients or its systems. Personal information may also be processed where necessary to comply with applicable laws, regulations, court orders, governmental requirements or other legitimate obligations. Aura may use information for internal administration, service development, quality control, operational planning and other legitimate corporate purposes. Such use is intended to remain connected to the purpose for which the information was obtained or to another purpose permitted by applicable law. Aura does not intend to use personal information indiscriminately or in a manner inconsistent with the legitimate expectations associated with the relevant relationship.

4. LAWFUL PROCESSING

Aura processes personal information on a lawful basis appropriate to the nature and circumstances of the processing activity. Depending on the circumstances and the applicable jurisdiction, the legal basis for processing may include the performance of a contract, the taking of steps at the request of an individual prior to entering into a contractual relationship, compliance with a legal or regulatory obligation, the legitimate interests of Aura or another party, consent or another lawful basis recognised by applicable legislation. The appropriate legal basis may differ depending upon the purpose of the processing, the type of information involved, the nature of the relationship and the jurisdiction concerned. Where consent is required, Aura will seek to obtain it in an appropriate manner and, where required, provide individuals with relevant information concerning the processing. In circumstances where processing is necessary to perform contractual obligations or comply with applicable legal requirements, Aura may process information without relying upon consent where permitted by law. Similarly, Aura may process information on the basis of legitimate interests where such processing is lawful and appropriate, taking into account the relevant circumstances and applicable individual rights. Aura seeks to ensure that personal information is not processed without an appropriate legal basis. The Company may maintain appropriate records and internal controls to support its approach to lawful and accountable processing.

 

5. CONFIDENTIALITY & ACCESS

Aura regards personal information as confidential and seeks to maintain appropriate organisational and operational controls governing access to such information. Access is generally limited to employees, officers, advisers, service providers or other authorised persons who have a legitimate need to know the information in connection with their responsibilities or the provision of relevant services. Aura seeks to avoid unnecessary access, duplication or circulation of personal information within its organisation. Access rights may be determined according to the responsibilities, authority and operational requirements of the relevant individual. Employees and authorised personnel may be required to comply with confidentiality obligations, internal policies and information-security requirements. Professional advisers and approved service providers may also be subject to contractual, professional and confidentiality obligations where they handle information on behalf of Aura. Where appropriate, technical systems may record or monitor access to information in order to support security and accountability. Aura seeks to ensure that confidential information is handled responsibly throughout its lifecycle and that access is granted only where there is a legitimate reason for doing so. The protection of confidential information forms an important part of Aura’s broader approach to institutional governance, information security and responsible client relationships.

 

6. DISCLOSURE & INTERNATIONAL TRANSFERS

Aura may disclose or share personal information where there is a legitimate reason for doing so and where such disclosure is permitted or required under applicable law. Depending upon the circumstances, information may be provided to relevant Aura group entities, professional advisers, consultants, technology providers, administrative service providers, financial institutions, counterparties or other parties involved in the provision or administration of legitimate services and business activities. Aura may also disclose information to governmental, regulatory, judicial or law-enforcement authorities where required or permitted by law. Information may be shared where necessary to perform contractual obligations, establish or protect legal rights, manage transactions, address operational requirements or protect the legitimate interests of Aura or other relevant parties. Where third-party service providers process information on behalf of Aura, the Company seeks to apply appropriate contractual and operational controls. Certain activities may require personal information to be transferred to, stored in or accessed from jurisdictions outside the country in which the information was originally collected. Where international transfers are subject to specific legal requirements, Aura seeks to implement the safeguards required by the applicable legal framework. The protection of personal information remains relevant regardless of where information is processed, stored or accessed.

 

7. INFORMATION SECURITY

Aura considers information security to be an essential component of responsible privacy and data governance. The Company maintains organisational, technical and administrative measures designed to protect personal information against unauthorised access, inappropriate use, alteration, disclosure, loss or destruction. Depending upon the nature of the information and the relevant systems, such measures may include access controls, authentication mechanisms, encryption, system monitoring, security testing, network protections and other information-security procedures. Access to systems and information may be restricted according to individual responsibilities and levels of authority, with additional controls applied to information requiring heightened protection. Aura seeks to maintain appropriate internal procedures governing the handling, storage and transmission of confidential information. The Company also seeks to consider the security practices of relevant service providers and other third parties that process information on its behalf. Aura recognises that no information system or method of electronic transmission can be guaranteed to be completely secure. Accordingly, the Company maintains processes intended to identify, investigate, contain and address potential information-security incidents. Where an incident is determined to require notification under applicable law, Aura will take the appropriate steps within the applicable legal and regulatory framework.

 

8. RETENTION, COOKIES & THIRD-PARTY SERVICES

Aura retains personal information for a period appropriate to the purpose for which it was collected and, where applicable, for the period required or permitted by law. Retention periods may depend upon the nature of the information, the continuing business relationship, contractual obligations, legal and regulatory requirements, dispute-resolution requirements and legitimate operational considerations. When information is no longer reasonably required, Aura may securely delete, anonymise or otherwise dispose of it in accordance with applicable requirements and internal procedures. Aura may also use cookies and similar technologies on its websites and digital platforms to support essential functionality, security, user preferences, analytics and general website performance. The use of such technologies may vary depending upon the particular website or service and the requirements applicable to the relevant jurisdiction. Aura’s websites may contain links to websites or services operated by third parties. Those third-party websites and services are generally governed by their own privacy policies and information-handling practices. Aura does not control and is not responsible for the privacy or security practices of third-party websites or services that it does not operate.

 

9. YOUR PRIVACY RIGHTS

Subject to applicable law, individuals may have certain rights in relation to their personal information held or processed by Aura. Depending upon the jurisdiction and circumstances, these rights may include the right to request access to personal information, seek correction of inaccurate or incomplete information, request deletion or restriction of processing, object to certain processing activities, request data portability or withdraw consent where processing is based on consent. The availability and scope of these rights may vary according to the applicable legal framework and the circumstances in which the information is processed. The exercise of a privacy right does not necessarily require Aura to delete information or cease processing where the Company has a continuing legal, contractual or legitimate basis for retaining or processing it. Aura may request reasonable information to verify the identity and authority of an individual submitting a privacy request, particularly where disclosure of information could otherwise create a risk of unauthorised access. Requests will be assessed and handled in accordance with the requirements applicable to the relevant jurisdiction. Aura seeks to respond to legitimate privacy requests in a timely and appropriate manner. Individuals wishing to exercise applicable privacy rights or obtain further information concerning the processing of their personal information may contact Aura through its recognised official communication channels.

 

10. GOVERNANCE, SECURITY INCIDENTS & CONTACT

Aura considers privacy, data protection and information governance to be matters of institutional responsibility. The Company seeks to maintain appropriate policies, procedures, controls and responsibilities governing the collection, use, storage, disclosure and protection of personal information throughout its operations. Privacy and information security may form part of Aura’s broader governance, risk-management, compliance and operational-control framework. Where a potential privacy or security incident is identified, Aura may assess its nature, scope, impact and potential consequences and take measures appropriate to the circumstances. Such measures may include investigation, containment, remediation, internal escalation, documentation and the implementation of measures intended to prevent recurrence. Where applicable law requires notification to regulators, authorities or affected individuals, Aura will seek to make such notifications in accordance with the relevant legal requirements. Aura may periodically review this Policy and its associated privacy and information-security practices to reflect changes in its activities, technology, legal obligations and institutional requirements. Questions, concerns or formal privacy requests may be directed to info@aura.co.th through Aura’s recognised official communication channels. Aura may update this Policy from time to time, and the most recent version published on the official Aura Website will represent the current version of the Policy.

 

OUR PRINCIPLE

 

INFORMATION ENTRUSTED TO AURA IS A RESPONSIBILITY.

Aura approaches privacy not simply as a technical or administrative requirement, but as an important part of the trust placed in the Company by its clients, counterparties, employees and other stakeholders. Personal information is therefore handled with discretion and only for legitimate and appropriate purposes. Aura seeks to maintain proportionate collection practices, controlled access, responsible use, appropriate retention and robust information-security measures throughout the information lifecycle. Where information must be shared, Aura seeks to ensure that the disclosure is justified by a legitimate purpose and conducted in accordance with applicable requirements. The Company’s approach is designed to preserve confidentiality while enabling Aura to conduct its activities effectively and responsibly.

 

AURA SOLUTION COMPANY LIMITED

PRIVATE BY PRINCIPLE. RESPONSIBLE BY DESIGN.

Last Updated: August 2026

 

DOWNLOAD IN PDF 

#aurapedia

THE ARCHITECT OF THE WORLD ECONOMY

We welcome your enquiries by email. Every correspondence is handled with discretion, professionalism, and the highest standards of confidentiality.

HEAD OFFICE

74, 75 หมู่ที่ 5 Vichitsongkram Rd, Wichit, Mueang Phuket District, Mueang, Mueang, Phuket, 83000 Kingdom of Thailand 

EMAIL  –  info@aura.co.th

​ 

CALL   –  +66 8241 88 111 ( VERIFIED  WHATSAPP )

 

AURA    |    AURAPEDIA   |   PODCAST  |   NEWS  |  CONTACT

​​​

We look forward to connecting with you.

AURA SOLUTION COMPANY LIMITED

INFO@AURA.CO.TH

AURA.CO.TH

+66 8241 88 111  ( VERIFIED WHATSAPP )

+66 8042 12345   ( VERIFIED WHATSAPP )

1890–2026 | AURA SOLUTION COMPANY LIMITED™
bottom of page