

At Aura Solution Company Limited, data security is not an operational task—it is a fiduciary obligation.In a world where information moves instantly and risks evolve constantly, Aura was built with a clear conviction: trust can only exist where protection is absolute. Every system we design, every process we approve, and every decision we make reflects this responsibility.
We protect data with the same discipline and foresight that define our approach to capital stewardship. Our security framework is anchored in institutional-grade governance, layered technological defenses, continuous monitoring, and strict access controls. These measures are not reactive—they are proactive, designed to anticipate threats rather than merely respond to them.
Equally important is our human discipline. At Aura, security is a culture. Our professionals are trained, accountable, and bound by ethical standards that go beyond compliance. Confidentiality, integrity, and discretion are not policies—they are expectations.
We do not view data as a byproduct of business.
We recognize it as an extension of trust placed in us.
As digital ecosystems grow more complex, Aura remains steadfast in its commitment to safeguarding information across borders, platforms, and generations. Our objective is simple and uncompromising: to ensure that every piece of data entrusted to Aura is protected with resilience, consistency, and respect.
Trust is earned through protection.
Protection is sustained through discipline.
Discipline defines Aura.
Hany Saad
President of the Aura Solution Company Limited
Website Data Protection Policy and Privacy Notice
1. INTRODUCTION
Aura Solution Company Limited (“Aura”, “we”, “us”, “our”) is committed to compliance with applicable legal and regulatory requirements relating to data protection, privacy and cybersecurity, as further set out in our Code of Business Conduct and Ethics. At Aura, we respect your privacy and this Policy, together with our Website Terms of Use and our Cookie Policy, governs how Aura collects, processes (as defined below) and uses your Personal Data (as defined below) when you use our websites (as defined below).
Annex A provides additional information for residents of certain U.S. states that supplements the information provided throughout this Policy and sets out privacy rights relevant to residents of such states.
This Policy applies to users of the Websites (as defined below).
For the purposes of applicable laws and regulations relating to data protection and privacy (“Data Protection Legislation”), Aura acts as a controller in respect of your Personal Data.
This Policy may change from time to time and you should review it periodically.
This Policy was last updated on August 29, 2025.
2. DEFINITIONS
The following definitions shall apply to this Policy:
“Aura”, “we”, “us”, “our” means Aura Solution Company Limited and any of its affiliated entities to which a Website relates.“Personal Data” has the meaning given to it or any similar term (e.g., “personal information”, “non‑public personal information”, “PII”, “personally identifiable information”) in applicable Data Protection Legislation and, for the avoidance of doubt, means any information which directly or indirectly identifies or otherwise relates to an individual, which is in the possession or under the control of Aura (or its representatives or service providers). Such Personal Data may include, without limitation, name, age, identification number, email address, address, telephone number, location data, financial data, or an online identifier. In addition to factual information, such Personal Data includes any expression of opinion about an individual and any indication of the intentions of Aura or any other person in respect of an individual.
“Process” or “Processing” means any operation that is carried out in respect of Personal Data, including but not limited to collecting, storing, using, disclosing, transferring or deleting Personal Data.
“Sensitive Personal Data” has the meaning ascribed to this or any similar term provided by applicable Data Protection Legislation (e.g., “sensitive personal information”, “sensitive data”, or “special categories of personal data”).
“Websites” means Aura websites that link to this Policy unless such websites have their own data protection policy and privacy notice, including without limitation https://www.aura.co.th.
3. THE TYPES OF PERSONAL DATA WE COLLECT
If you are an Aura employee or an Aura investor, Aura’s policies and practices regarding the collection and processing of your Personal Data are detailed in Aura’s Employee and Personnel Data Protection Policy and Privacy Notice and Investor Data Protection Policy and Privacy Notice, respectively. If you make an application for employment with Aura, the collection and processing of your Personal Data is detailed in Aura’s Applicant Data Protection Policy and Privacy Notice, which will be provided to you via our applications partner website before you submit your application.
For all other individuals, Aura may collect and process the following categories of Personal Data about you from the sources identified below:
a) Website Data. When you browse the Websites, depending on how you interact with them, we may collect (i) information submitted through online forms (including name, age, date of birth, email address, address, telephone number, identification number, online identifier, location, gender, nationality, citizenship and contact information); and (ii) technical information collected by cookies and similar technologies regarding your use of the Websites, which may include device‑specific information, navigation data, technical and browsing preferences, location and entry point to the Websites. If you do not provide certain Personal Data when requested (and where relevant, provide consent), we may be unable to provide access to all areas of the Websites or related services.
b) Identity Verification Data. Identity verification information such as images of government‑issued identification (passport, national ID card, or driving license), as permitted by applicable law, or other authentication information.
c) Communications Data. Personal Data you provide when you contact Aura for any reason, including to request information, submit enquiries, use “Contact Us” features, subscribe to communications, attend events or download content. This may include name, job title, company name, phone number, location and email address.
d) Reputation & Background Check Data. If you are a service provider, business partner, or a representative thereof, Personal Data obtained from you and third parties concerning contact details, business practices, creditworthiness, reputation, business history, and roles or job titles.
e) Data Generated by Aura. Personal Data generated through our interactions with you or in the course of providing services, including information about your relationship with Aura or the services provided.
Cookies. Please refer to our Cookie Policy, which forms part of this Policy.
Do Not Track. Browsers may permit “do not track” signals. Due to the absence of an industry standard, Aura does not currently respond to such signals. Third parties (e.g., analytics providers) may collect Personal Data across websites; their practices are governed by their own privacy policies.
4. HOW WE COLLECT YOUR PERSONAL DATA
Aura may collect Personal Data:
a) directly from you (e.g., via the Websites, email, visits to our premises or other communications);
b) through automated technologies (e.g., cookies and similar tools);
c) from within Aura and our affiliates;
d) from third parties acting on your behalf (e.g., intermediaries, legal counsel or service providers);
e) from publicly available sources; and
f) from other organizations (e.g., fund administrators and service providers).
5. HOW WE USE YOUR PERSONAL DATA
Aura collects and processes Personal Data for the purposes and on the legal bases described below, including to:
a) provide marketing communications and business updates;
b) understand your needs and respond to enquiries;
c) analyze and improve services;
d) manage and administer our business;
e) provide subscribed products and services;
f) comply with applicable laws, regulations, codes and internal policies;
g) verify identity and conduct due diligence and sanctions screening;
h) detect, investigate and prevent fraud or malpractice;
i) conduct or defend legal proceedings and obtain legal advice;
j) administer databases and IT systems;
k) meet contractual obligations;
l) maintain Website security, functionality and resilience;
m) analyze Website traffic and usage trends;
n) enable Website features and access;
o) conduct cybersecurity threat detection and analysis; and
p) other purposes set out in this Policy.
Aura relies on one or more of the following legal bases: performance of a contract; consent (where required); compliance with legal obligations; establishment, exercise or defense of legal rights; and legitimate business interests that do not override your rights.
Where required by law, by accepting this Policy you consent to the collection, use, processing and disclosure of your Personal Data as described.
6. Disclosure of Your Personal Data to Third Parties
Aura Solution Company Limited may disclose Personal Data to affiliates and carefully selected third parties strictly for legitimate business, operational, and legal purposes. Such disclosures are limited to what is necessary and proportionate to fulfill defined institutional objectives.
Third-party recipients may include, but are not limited to:
-
Group affiliates and controlled entities
-
Professional advisors, including legal, regulatory, audit, and compliance service providers
-
Technology and infrastructure providers supporting system administration, data hosting, cybersecurity, and operational resilience
-
Payment, settlement, escrow, and transaction support providers
-
Regulatory authorities, law enforcement bodies, courts, or governmental agencies where disclosure is required by law
-
Counterparties involved in corporate transactions, restructurings, or change-of-control events, subject to applicable legal safeguards
All third parties receiving Personal Data are required to adhere to appropriate confidentiality, data protection, and information security obligations consistent with applicable law and Aura’s governance standards. Where required, contractual safeguards or other legally recognized protections are implemented to ensure lawful processing and continued protection of Personal Data.
Aura may also disclose Personal Data where necessary to establish, exercise, or defend legal rights, to protect institutional interests, or to comply with legal or regulatory obligations.
Where data is anonymized or aggregated such that individuals can no longer be identified, Aura may use or share such data for lawful analytical, operational, or institutional purposes.
Aura does not engage in automated decision-making, including profiling, that produces legal or similarly significant effects based solely on Personal Data, except where expressly permitted by applicable law and subject to appropriate safeguards.
7. Links to Other Websites
Aura’s websites may contain links to third-party websites or external resources that are not owned, operated, or controlled by Aura Solution Company Limited.
This Privacy Policy applies solely to Aura’s websites and services. Aura is not responsible for the privacy practices, content, security, or data handling policies of third-party websites. Accessing linked third-party sites is done at the user’s own discretion and risk.
Aura encourages individuals to review the privacy policies and terms of use of any external websites before providing Personal Data or engaging with their services.
8. Transfers of Personal Data
Aura Solution Company Limited operates on a global basis and, in the course of its operations, may transfer Personal Data to jurisdictions outside the country in which the data subject resides. Such transfers occur only where necessary to support lawful business operations, regulatory obligations, or client mandates.Where cross-border transfers are subject to legal restrictions, Aura implements appropriate safeguards in accordance with applicable law. These safeguards may include approved contractual protections, legally recognized transfer mechanisms, or other measures required by data protection authorities. Where mandated, Aura will obtain explicit consent prior to transferring Personal Data internationally. All transfers are governed by Aura’s internal data governance standards to ensure continued confidentiality, integrity, and lawful processing.
9. How We Safeguard Your Personal Data
Aura maintains robust technical, organizational, and administrative safeguards designed to protect Personal Data against unauthorized access, loss, misuse, alteration, or disclosure.
These measures include, but are not limited to, controlled access systems, physical security protections, information security protocols, and mandatory confidentiality obligations for employees and authorized service providers. Access to Personal Data is restricted strictly to individuals with a legitimate business or legal need. Aura regularly reviews its safeguards to ensure they remain effective, proportionate, and aligned with evolving legal and security requirements.
10. Retention and Destruction of Personal Data
Aura retains Personal Data only for as long as necessary to fulfill the purposes for which it was collected, to meet contractual commitments, and to comply with applicable legal, regulatory, or reporting obligations.Once Personal Data is no longer required, Aura ensures that it is securely deleted, destroyed, or irreversibly anonymized in accordance with applicable law and internal retention schedules. Retention practices are periodically reviewed to ensure compliance with regulatory expectations and data minimization principles.
11. Your Rights
Subject to applicable law, individuals may have certain rights in relation to their Personal Data. These rights may include the right to access, correct, update, delete, restrict, or object to the processing of Personal Data; the right to withdraw consent where processing is consent-based; the right to request data portability; and the right to receive information regarding disclosures of Personal Data.
Individuals may also have the right to lodge a complaint with a competent data protection authority. To exercise these rights, Aura may require submission of a formal Subject Access Request or verification of identity to ensure data security and lawful handling.
12. Children
Aura’s websites, services, and communications are intended solely for individuals aged eighteen (18) years and over. Aura does not knowingly collect, process, or retain Personal Data relating to children under the age of eighteen.If Aura becomes aware that Personal Data relating to a minor has been collected inadvertently, appropriate steps will be taken to delete such information promptly in accordance with applicable law.
13. Marketing Communications
Where permitted by applicable law, Aura may send marketing or informational communications related to its services. Individuals may opt out of marketing communications at any time using the methods provided in the communication or by contacting Aura directly.
Opting out of marketing communications does not affect the receipt of non-marketing communications, including legal notices, regulatory disclosures, service-related communications, or other messages required for lawful business operations.
14. Additional Information for Certain U.S. State Residents
For residents of certain U.S. states, Aura confirms that it does not sell Personal Data and does not engage in processing activities that require opt-in consent for sensitive Personal Data under applicable state privacy laws.Where de-identified or aggregated data is used, Aura maintains safeguards to ensure such data is not re-identified, except where permitted or required by law. Aura processes Personal Data in a manner consistent with applicable U.S. state privacy requirements.
15. California Privacy Notice
For residents of California, Aura complies with the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), as applicable.
Aura does not sell Personal Information and does not share Personal Information for cross-context behavioral advertising. California residents may exercise their statutory rights in accordance with applicable law by submitting a verified request to Aura.
16. Contact
For questions regarding this Privacy and Data Protection framework, or to exercise applicable data protection rights, individuals may contact Aura’s designated Privacy Officer:
Privacy Officer
Aura Solution Company Limited
📧 PrivacyOfficer@aura.co.th
All requests will be handled in accordance with applicable legal requirements and Aura’s internal governance procedures.
17. Changes to This Privacy Policy
Aura Solution Company Limited reserves the right to amend, update, or modify this Privacy Policy at any time to reflect changes in legal requirements, regulatory guidance, operational practices, or institutional governance standards.Any material changes will become effective upon publication on Aura’s official platforms or through other lawful means of notification where required. Continued interaction with Aura’s services following such updates constitutes acknowledgment of the revised policy, subject to applicable law.
Aura encourages periodic review of this Privacy Policy to remain informed of how Personal Data is governed and protected.
18. Legal Basis for Processing
Aura processes Personal Data only where a lawful basis exists under applicable data protection laws. Such legal bases may include the performance of contractual obligations, compliance with legal or regulatory requirements, protection of legitimate institutional interests, or consent where required by law.Where consent is relied upon, it is obtained in a clear and lawful manner and may be withdrawn at any time, subject to legal and regulatory constraints. Aura ensures that all processing activities are proportionate, justified, and documented in accordance with its governance framework.
19. Limitation of Liability
While Aura implements rigorous legal, technical, and organizational safeguards to protect Personal Data, no system can guarantee absolute security. To the extent permitted by applicable law, Aura shall not be held liable for unauthorized access, loss, or disclosure of Personal Data arising from events beyond its reasonable control, including force majeure events or unlawful acts of third parties.
Nothing in this Privacy Policy limits or excludes liability where such limitation is prohibited by law.
20. Governing Law and Jurisdiction
This Privacy Policy, and any disputes arising from or related to it, shall be governed by and construed in accordance with the laws applicable to Aura Solution Company Limited, without regard to conflict of law principles.Any legal proceedings relating to this Privacy Policy shall be subject to the exclusive jurisdiction of the competent courts or authorities, unless otherwise required by mandatory applicable law.

WEB FRAUD
Aura Solution Company Limited (“Aura”) is a global investment and financial services institution. Cybercriminals may attempt to misuse Aura’s name, brand, logos, websites, or the identities of our executives and employees to conduct fraudulent schemes.
These schemes may occur through fake websites, emails, text messages, phone calls, social media platforms, messaging applications, job postings, or other communication channels. Such activities are designed to deceive individuals and unlawfully obtain personal, financial, or confidential information. Many of these attempts constitute phishing, vishing, or impersonation fraud.
Fraud tactics continuously evolve. We encourage all stakeholders to remain vigilant and informed.
Common Fraud Schemes
Be alert to the following common types of scams falsely associated with Aura:
-
Investment Scams
Unsolicited offers promising “high-yield,” “guaranteed,” or “exclusive” investments using Aura’s name or reputation are almost always fraudulent. -
Email or Text Phishing
Messages containing suspicious links, attachments, or requests for personal, login, or banking details. -
Phone Fraud (Vishing)
Urgent or threatening phone calls impersonating Aura representatives, regulators, or law enforcement agencies. -
Payment or Wire Instruction Changes
Sudden requests to redirect funds, change bank account details, or expedite transfers under pressure. -
Employment and Social Media Scams
Fake job offers, paid “interviews,” or recruitment messages sent via chat apps or social media platforms. -
Fake Websites or Applications
Look-alike domains or mobile applications imitating Aura branding or online presence.
Best Practices to Protect Yourself
To help safeguard yourself and your organization:
-
Verify the Source
Aura’s official website is https://www.aura.co.th. Official communications originate from verified Aura email domains. If in doubt, contact us directly through our website. -
Read Communications Carefully
Watch for spelling errors, unusual formatting, unfamiliar links, unexpected attachments, or overly urgent language. -
Never Share Credentials
Aura will never request passwords, verification codes, or multi-factor authentication details. -
Avoid Suspicious Downloads
Only download applications or files from trusted, official sources. -
Be Cautious with Unsolicited Contact
Do not provide personal, financial, or identification information to unknown callers or messages. -
Independently Confirm Payment Instructions
Always verify any change to payment or wiring details using previously established and trusted contact information. -
Exercise Caution with Job Offers
Aura does not charge candidates at any stage of recruitment. All legitimate opportunities are communicated through official Aura channels.
How to Report Suspected Fraud
If you believe you have been targeted by, or have identified, a suspicious activity involving Aura:
-
Stop engaging immediately. Do not click links, download files, or transfer funds.
-
Verify directly using trusted Aura contact channels or by visiting https://www.aura.co.th.
-
Report the incident to your local law enforcement authorities and relevant cybercrime agencies in your jurisdiction.
Aura reserves all rights to protect its name, brand, systems, and stakeholders. We are not responsible for third-party content and provide external references for informational purposes only.
Contact Us
If you have any questions regarding the authenticity or security of a communication purported to be from Aura, or if you wish to report a suspicious website or message, please contact us through our official website:
Aura Solution Company Limited
🌐 https://www.aura.co.th
CONDE OF CONDUCT
Global Governance & Code of Conduct Charter – 2026 (Condensed Board Edition)
1. Purpose
This Charter establishes the governance, ethical and professional standards guiding Aura Solution Company Limited (“Aura”), its directors, officers, employees and affiliates.It reflects Aura’s commitment to integrity, transparency, sustainability and responsible global business conduct, and is approved by the Board of Directors.
2. Scope
This Charter applies globally to:
-
All employees and leadership
-
Subsidiaries and controlled affiliates
-
Client engagements and investment activities
-
Communications, disclosures and operations
Where local law conflicts with this Charter, the highest ethical and legal standard shall apply.
3. Governance Oversight
-
The Board of Directors holds ultimate oversight.
-
Senior leadership ensures implementation.
-
Legal & Regulatory, Compliance and Internal Audit monitor adherence and risks.
-
The Charter is reviewed annually.
4. Ethical Conduct
All personnel must:
-
Act honestly and professionally
-
Protect Aura’s reputation
-
Avoid illegal or unethical conduct
-
Place client and company interests ahead of personal gain
5. Financial Integrity & Disclosure
Aura commits to:
-
Accurate books and records
-
Authorized business transactions
-
Honest and transparent public disclosures
-
Full cooperation with auditors and regulators
6. Stakeholder Responsibilities
Personnel must:
-
Deal fairly with clients, investors and partners
-
Manage client capital responsibly
-
Avoid conflicts of interest or perceived misconduct
7. Communications & Data Protection
Employees must:
-
Use only approved business communication systems
-
Protect confidential information
-
Follow cybersecurity and enterprise information security policies
-
Avoid unauthorized public statements
Only authorized spokespersons may speak on behalf of Aura.
8. Conflicts of Interest & Outside Activities
Personnel must:
-
Disclose conflicts and close personal relationships
-
Obtain approval for outside business activities
-
Avoid personal use of corporate opportunities
9. Workplace Culture & Safety
Aura maintains a workplace that is:
-
Inclusive and respectful
-
Free from discrimination, harassment and violence
-
Safe and compliant with health and safety laws
Illegal drugs, weapons and dangerous conduct are prohibited.
10. Sustainability & Human Rights
Aura integrates sustainability and human rights into its operations by:
-
Supporting net-zero environmental goals
-
Upholding labor rights and anti-modern slavery standards
-
Promoting diversity, inclusion and employee wellbeing
-
Supporting responsible corporate citizenship
© 2026 Aura Solution Company Limited
Aura refers to Aura Solution Company Limited and/or its member firms, each a separate legal entity.


HUMAN RIGHTS
Aura Solution Company Limited is committed to conducting business with integrity, responsibility, and respect for the dignity and rights of all individuals. As a global organisation serving clients and communities across diverse regions, Aura recognises that respect for human rights is fundamental to sustainable growth, ethical leadership, and the trust placed in us by society.
Guided by our purpose — to build trust in society and solve important problems — we embed human rights principles into our culture, decision-making processes, and daily operations. Our people work collaboratively with a shared commitment to fairness, inclusion, and accountability, ensuring that every interaction reflects our core values and ethical responsibilities.
Aura is a purpose-led and values-driven organisation. We strive to uphold the highest standards of professional conduct by acting honestly, taking responsibility for our actions, and promoting an environment where individuals are treated with respect and dignity. Our approach to human rights goes beyond compliance; we aim to make these principles understandable, accessible, and practical in real-world business decisions.
Through transparency, ethical leadership, and a strong governance framework, Aura seeks to foster workplaces and partnerships that respect fundamental freedoms, encourage diversity and equal opportunity, and contribute positively to communities. By integrating human rights considerations into our business strategy and stakeholder engagement, we reinforce our role as a responsible corporate citizen and a force for sustainable, positive change.
Human Rights & Sustainability Commitment
At Aura, our Human Rights Policy is shaped by a careful assessment of the issues most relevant to our global business and the communities we serve. It reflects our strong commitment to the United Nations Guiding Principles on Business and Human Rights, alongside related international treaties, declarations, and the ethical foundations that guide responsible leadership. The Universal Declaration of Human Rights (1948) stands as a cornerstone of this commitment, affirming the fundamental rights and freedoms that must be respected and protected for every individual. Additional international standards and frameworks that inform this policy are outlined in the International Frameworks section.
The expectations set out in this policy guide how we act every day — in our business conduct, our relationships with one another, our engagement with communities, and our stewardship of information. When we refer to “Aura,” “we,” “our,” or “us,” we mean every part of the Aura network: our partners, employees, contractors, subcontractors, and all affiliated Aura firms working together globally. We also encourage our suppliers, collaborators, and community stakeholders to uphold these same principles wherever possible, ensuring that trust and responsibility extend across our entire ecosystem.
Aura also recognises the deep connection between human rights and global environmental challenges, including climate change, pollution, and sustainable resource management. We understand that environmental responsibility is inseparable from the dignity, health, and well-being of individuals and communities worldwide. As we work to minimise our environmental footprint and advance sustainable business growth, we remain unwavering in our commitment to human rights as a non-negotiable foundation. By aligning our sustainability efforts with global human rights principles, Aura strives to help build a world where every person’s rights are respected, their well-being is protected, and ethical, responsible business becomes a force for lasting positive change.
