
PRIVACY
YOUR TRUST IS OUR MOST VALUABLE ASSETS.
At Aura Solution Company Limited, data security is a fiduciary obligation. Trust exists only where protection is absolute, and every system, process, and decision reflects this principle.
Our framework combines institutional governance, layered defenses, continuous monitoring, and strict access control—designed to anticipate risk, not react to it.Security is also cultural.
Our professionals operate with accountability, discretion, and ethical discipline beyond compliance.We treat data as an extension of trust. Our commitment is simple: to protect every piece of information with resilience, consistency, and respect.Trust through protection. Protection through discipline. Discipline defines Aura.
1. INTRODUCTION
Aura Solution Company Limited ("Aura", "we", "us", or "our") is committed to protecting the privacy, confidentiality, and security of the personal information entrusted to us. As a global financial institution, we recognise that safeguarding personal data is fundamental to maintaining the trust of our clients, business partners, employees, and all individuals with whom we engage.This Privacy Policy explains how Aura collects, uses, stores, shares, and otherwise processes Personal Data when you visit or interact with our websites, communicate with us, or use our products and services. It should be read together with our Website Terms of Use, Cookie Policy, and any other privacy notices that may apply to a particular relationship or service.
Aura is committed to processing Personal Data responsibly, transparently, and in accordance with applicable data protection, privacy, and cybersecurity laws and regulations in the jurisdictions in which we operate, together with the principles set out in our Code of Business Conduct and Ethics.Where required by applicable law, supplementary privacy notices may apply to individuals residing in specific jurisdictions. For example, Annex A provides additional information and statutory privacy rights available to residents of certain U.S. states.
Unless otherwise stated, this Privacy Policy applies to all visitors and users of Aura's websites and digital services.
For the purposes of applicable data protection legislation, Aura Solution Company Limited acts as the Data Controller in relation to the Personal Data described in this Privacy Policy.As our business, technologies, regulatory obligations, and legal requirements continue to evolve, this Privacy Policy may be updated from time to time. We encourage you to review this page periodically to remain informed of any changes.
Last Updated: 29 June 2026
2. DEFINITIONS
For the purposes of this Privacy Policy, the following terms shall have the meanings set out below.
Aura
"Aura", "we", "us", or "our" means Aura Solution Company Limited and any of its subsidiaries, affiliated companies, representative offices, or group entities that operate a website or service governed by this Privacy Policy.
Personal Data
"Personal Data" means any information relating to an identified or identifiable natural person, whether directly or indirectly, as defined under applicable data protection legislation. Depending upon the jurisdiction, equivalent terms may include personal information, personally identifiable information (PII), or non-public personal information.
Personal Data may include, without limitation:
-
Name and contact details
-
Date of birth
-
Government-issued identification numbers
-
Nationality and citizenship
-
Residential or business address
-
Telephone number and email address
-
Financial and transactional information
-
Online identifiers and IP addresses
-
Location data
-
Professional information
-
Any opinions, assessments, correspondence, or records relating to an identifiable individual.
Processing
"Processing" means any operation performed on Personal Data, whether by automated or manual means, including its collection, recording, organisation, storage, consultation, use, analysis, disclosure, transmission, transfer, retention, restriction, deletion, or destruction.
Sensitive Personal Data
"Sensitive Personal Data" means Personal Data that receives enhanced protection under applicable law, including where relevant information relating to racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health information, sexual orientation, criminal convictions, or any other category designated by applicable data protection legislation.
Websites
"Websites" means any website, online platform, portal, or digital service operated by Aura Solution Company Limited that references or links to this Privacy Policy, including, without limitation, www.aura.co.th, unless such website is governed by a separate privacy notice.
3. PERSONAL DATA WE COLLECT
The categories of Personal Data collected by Aura depend upon the nature of your relationship with us and the manner in which you interact with our business, websites, products, or services.Where you are an employee, applicant, investor, or another individual whose relationship with Aura is governed by a separate privacy notice, the processing of your Personal Data will be subject to the relevant policy applicable to that relationship.
For all other individuals, Aura may collect and process the following categories of Personal Data.
Website Information
When you access or browse our websites, we may collect information you voluntarily provide through online forms together with technical information generated through your interaction with our digital platforms.This may include your name, contact details, date of birth, location, nationality, IP address, browser characteristics, device information, cookies, usage statistics, navigation history, and other technical identifiers necessary to operate, maintain, improve, and secure our websites.Where certain information is required to provide a requested service, failure to provide such information may limit your ability to access particular features or services.
Identity Verification Information
Where necessary for regulatory, legal, security, or client onboarding purposes, Aura may collect information used to verify your identity, including copies of passports, national identity cards, driving licences, or other government-issued identification documents, together with supporting authentication information where permitted by applicable law.
Communications Information
When you contact Aura, submit an enquiry, register for an event, subscribe to publications, request information, or otherwise communicate with us, we may collect information including your name, organisation, professional title, telephone number, email address, country of residence, and the contents of your correspondence.
Business Relationship Information
Where you represent a client, supplier, service provider, regulator, adviser, or other business partner, Aura may collect information relating to your professional role, business affiliations, contact details, due diligence records, reputation assessments, regulatory status, business history, and other information necessary to establish, manage, or maintain our professional relationship.
Information Generated Through Our Relationship
During the course of our relationship, Aura may create or maintain records relating to your interactions with us, including correspondence, service history, transaction records, relationship management information, preferences, compliance records, and other information generated in connection with the services we provide.
Cookies and Similar Technologies
Aura uses cookies and similar technologies to enhance website functionality, improve user experience, analyse website performance, maintain security, and better understand how visitors interact with our digital services. Further information is available in our Cookie Policy, which forms part of this Privacy Policy.
Do Not Track
Some internet browsers offer a "Do Not Track" feature that communicates a preference regarding online tracking. As there is currently no universally accepted industry standard governing such signals, Aura's websites do not presently respond to Do Not Track requests. Third-party providers, including analytics and technology partners, may process information in accordance with their own privacy policies.
4. HOW WE COLLECT YOUR PERSONAL DATA
Aura may collect Personal Data:
a) directly from you (e.g., via the Websites, email, visits to our premises or other communications);
b) through automated technologies (e.g., cookies and similar tools);
c) from within Aura and our affiliates;
d) from third parties acting on your behalf (e.g., intermediaries, legal counsel or service providers);
e) from publicly available sources; and
f) from other organizations (e.g., fund administrators and service providers).
5. HOW WE USE YOUR PERSONAL DATA
Aura collects and processes Personal Data for the purposes and on the legal bases described below, including to:
a) provide marketing communications and business updates;
b) understand your needs and respond to enquiries;
c) analyze and improve services;
d) manage and administer our business;
e) provide subscribed products and services;
f) comply with applicable laws, regulations, codes and internal policies;
g) verify identity and conduct due diligence and sanctions screening;
h) detect, investigate and prevent fraud or malpractice;
i) conduct or defend legal proceedings and obtain legal advice;
j) administer databases and IT systems;
k) meet contractual obligations;
l) maintain Website security, functionality and resilience;
m) analyze Website traffic and usage trends;
n) enable Website features and access;
o) conduct cybersecurity threat detection and analysis; and
p) other purposes set out in this Policy.
Aura relies on one or more of the following legal bases: performance of a contract; consent (where required); compliance with legal obligations; establishment, exercise or defense of legal rights; and legitimate business interests that do not override your rights.Where required by law, by accepting this Policy you consent to the collection, use, processing and disclosure of your Personal Data as described.
6. Disclosure of Your Personal Data to Third Parties
Aura Solution Company Limited may disclose Personal Data to affiliates and carefully selected third parties strictly for legitimate business, operational, and legal purposes. Such disclosures are limited to what is necessary and proportionate to fulfill defined institutional objectives.
Third-party recipients may include, but are not limited to:
-
Group affiliates and controlled entities
-
Professional advisors, including legal, regulatory, audit, and compliance service providers
-
Technology and infrastructure providers supporting system administration, data hosting, cybersecurity, and operational resilience
-
Payment, settlement, escrow, and transaction support providers
-
Regulatory authorities, law enforcement bodies, courts, or governmental agencies where disclosure is required by law
-
Counterparties involved in corporate transactions, restructurings, or change-of-control events, subject to applicable legal safeguards
All third parties receiving Personal Data are required to adhere to appropriate confidentiality, data protection, and information security obligations consistent with applicable law and Aura’s governance standards. Where required, contractual safeguards or other legally recognized protections are implemented to ensure lawful processing and continued protection of Personal Data.Aura may also disclose Personal Data where necessary to establish, exercise, or defend legal rights, to protect institutional interests, or to comply with legal or regulatory obligations.Where data is anonymized or aggregated such that individuals can no longer be identified, Aura may use or share such data for lawful analytical, operational, or institutional purposes.Aura does not engage in automated decision-making, including profiling, that produces legal or similarly significant effects based solely on Personal Data, except where expressly permitted by applicable law and subject to appropriate safeguards.
7. Links to Other Websites
Aura’s websites may contain links to third-party websites or external resources that are not owned, operated, or controlled by Aura Solution Company Limited.This Privacy Policy applies solely to Aura’s websites and services. Aura is not responsible for the privacy practices, content, security, or data handling policies of third-party websites. Accessing linked third-party sites is done at the user’s own discretion and risk.Aura encourages individuals to review the privacy policies and terms of use of any external websites before providing Personal Data or engaging with their services.
8. Transfers of Personal Data
Aura Solution Company Limited operates on a global basis and, in the course of its operations, may transfer Personal Data to jurisdictions outside the country in which the data subject resides. Such transfers occur only where necessary to support lawful business operations, regulatory obligations, or client mandates.Where cross-border transfers are subject to legal restrictions, Aura implements appropriate safeguards in accordance with applicable law. These safeguards may include approved contractual protections, legally recognized transfer mechanisms, or other measures required by data protection authorities. Where mandated, Aura will obtain explicit consent prior to transferring Personal Data internationally. All transfers are governed by Aura’s internal data governance standards to ensure continued confidentiality, integrity, and lawful processing.
9. How We Safeguard Your Personal Data
Aura maintains robust technical, organizational, and administrative safeguards designed to protect Personal Data against unauthorized access, loss, misuse, alteration, or disclosure.
These measures include, but are not limited to, controlled access systems, physical security protections, information security protocols, and mandatory confidentiality obligations for employees and authorized service providers. Access to Personal Data is restricted strictly to individuals with a legitimate business or legal need. Aura regularly reviews its safeguards to ensure they remain effective, proportionate, and aligned with evolving legal and security requirements.
10. Retention and Destruction of Personal Data
Aura retains Personal Data only for as long as necessary to fulfill the purposes for which it was collected, to meet contractual commitments, and to comply with applicable legal, regulatory, or reporting obligations.Once Personal Data is no longer required, Aura ensures that it is securely deleted, destroyed, or irreversibly anonymized in accordance with applicable law and internal retention schedules. Retention practices are periodically reviewed to ensure compliance with regulatory expectations and data minimization principles.
5. HOW WE USE YOUR PERSONAL DATA
Aura processes Personal Data only where there is a legitimate and lawful purpose for doing so. Depending on the nature of your relationship with us, we may use Personal Data to:
-
provide our products and services and administer client relationships;
-
respond to enquiries, requests, and communications;
-
deliver publications, market insights, event invitations, and other communications you have requested or are otherwise permitted to receive;
-
understand client needs and enhance the quality of our services;
-
operate, manage, and develop our business and internal operations;
-
comply with applicable legal, regulatory, tax, risk management, and compliance obligations;
-
verify identity and undertake know-your-client (KYC), anti-money laundering (AML), sanctions screening, fraud prevention, and other due diligence activities;
-
detect, investigate, and prevent fraud, financial crime, cyber threats, or other unlawful activities;
-
establish, exercise, or defend legal rights and obtain professional legal advice;
-
administer and secure our information technology infrastructure, databases, and business systems;
-
monitor, maintain, and improve the security, performance, and functionality of our websites and digital services;
-
analyse website usage, visitor behaviour, and operational performance to improve user experience; and
-
fulfil any other purpose described in this Privacy Policy or otherwise permitted or required by applicable law.
Aura will process Personal Data only to the extent necessary and proportionate for these purposes and in accordance with applicable data protection legislation.
6. LEGAL BASIS FOR PROCESSING
Where required by applicable law, Aura processes Personal Data on one or more of the following lawful grounds:
-
the performance of a contract or the taking of steps prior to entering into a contract;
-
compliance with legal or regulatory obligations;
-
the protection or establishment of legal rights;
-
Aura's legitimate business interests, provided such interests do not override the rights and freedoms of the individual; or
-
the individual's consent, where consent is required by law.
Where processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of processing carried out before such withdrawal.
7. DISCLOSURE OF PERSONAL DATA
Aura may disclose Personal Data to affiliated entities and carefully selected third parties where necessary to support our business activities, comply with legal or regulatory obligations, or protect legitimate institutional interests.
Recipients may include:
-
Aura group companies and affiliated entities;
-
professional advisers, including legal counsel, auditors, tax advisers, and compliance consultants;
-
technology, cybersecurity, cloud hosting, and infrastructure service providers;
-
payment, settlement, custody, escrow, and transaction support providers;
-
regulators, supervisory authorities, courts, governmental agencies, and law enforcement bodies;
-
counterparties involved in mergers, acquisitions, reorganisations, financing transactions, or other corporate events.
All third parties processing Personal Data on Aura's behalf are required to maintain appropriate confidentiality, information security, and data protection standards consistent with applicable law and Aura's internal governance framework.Aura may also disclose Personal Data where necessary to protect its legal rights, safeguard its business, prevent fraud or financial crime, or comply with applicable legal or regulatory requirements.Where information has been anonymised or aggregated so that individuals can no longer be identified, Aura may use or disclose such information for lawful business, analytical, statistical, or research purposes.Aura does not make decisions based solely on automated processing, including profiling, where such decisions produce legal or similarly significant effects on individuals, except where expressly authorised by applicable law.
8. LINKS TO THIRD-PARTY WEBSITES
Aura's websites may contain links to third-party websites or digital services that are not owned, operated, or controlled by Aura.This Privacy Policy applies solely to Aura's websites and services. Aura is not responsible for the privacy practices, security measures, or content of third-party websites. Users should review the privacy policies applicable to those websites before providing Personal Data.
9. INTERNATIONAL TRANSFERS OF PERSONAL DATA
Aura operates internationally and may transfer Personal Data across jurisdictions where necessary to support its global operations, provide services, or comply with applicable legal or regulatory requirements.Where Personal Data is transferred internationally, Aura implements appropriate safeguards in accordance with applicable data protection legislation. Such safeguards may include approved contractual clauses, recognised transfer mechanisms, or other legally acceptable measures designed to ensure an appropriate level of protection.
10. INFORMATION SECURITY
Protecting confidential information is fundamental to Aura's business.Aura maintains appropriate technical, organisational, and administrative safeguards designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or unauthorised access.These measures include access controls, encryption where appropriate, network security, physical security, continuous monitoring, employee confidentiality obligations, and periodic reviews of our information security framework.Access to Personal Data is restricted to individuals who require such access for legitimate business purposes.
11. DATA RETENTION
Aura retains Personal Data only for as long as necessary to fulfil the purposes for which it was collected, satisfy contractual obligations, comply with applicable legal or regulatory requirements, resolve disputes, or protect Aura's legal interests.Once Personal Data is no longer required, it is securely deleted, anonymised, or destroyed in accordance with Aura's records management and data retention policies.
12. YOUR PRIVACY RIGHTS
Subject to applicable law, individuals may have rights in relation to their Personal Data, including the right to:
-
request access to Personal Data;
-
request correction or updating of inaccurate information;
-
request deletion of Personal Data where appropriate;
-
restrict or object to certain processing activities;
-
withdraw consent where processing is based on consent;
-
request data portability where applicable; and
-
lodge a complaint with the relevant supervisory authority.
Aura may request proof of identity before responding to any request to protect the security and confidentiality of Personal Data.
13. CHILDREN
Aura's websites and services are intended exclusively for individuals aged eighteen (18) years or older.Aura does not knowingly collect Personal Data from children. If Aura becomes aware that Personal Data relating to a child has been collected inadvertently, such information will be deleted as soon as reasonably practicable.
14. MARKETING COMMUNICATIONS
Where permitted by applicable law, Aura may send information relating to its products, services, market insights, publications, or events.Individuals may withdraw from receiving marketing communications at any time by following the unsubscribe instructions contained within the communication or by contacting Aura directly.Operational, contractual, legal, regulatory, or security-related communications will continue where necessary.
15. ADDITIONAL INFORMATION FOR U.S. RESIDENTS
Residents of certain U.S. states may benefit from additional privacy rights under applicable state legislation.Aura does not sell Personal Data and does not process Sensitive Personal Data in a manner requiring opt-in consent unless required by law. Where anonymised or de-identified information is used, Aura maintains appropriate safeguards to prevent re-identification except where permitted by law.
16. CALIFORNIA PRIVACY NOTICE
For California residents, Aura complies with the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and other applicable legislation.
Aura does not sell Personal Information or share Personal Information for cross-context behavioural advertising. California residents may exercise their statutory rights by submitting a verified request to Aura.
17. CONTACT US
Questions regarding this Privacy Policy or the processing of Personal Data may be directed to:
Privacy Officer
Aura Solution Company Limited
PrivacyOfficer@aura.co.th
Aura will respond to requests in accordance with applicable law and its internal governance procedures.
18. CHANGES TO THIS PRIVACY POLICY
Aura may amend this Privacy Policy periodically to reflect changes in legal requirements, regulatory guidance, technology, or business operations.Any revised version will become effective upon publication on Aura's official website unless otherwise required by applicable law.We encourage visitors to review this Privacy Policy regularly to remain informed of how Personal Data is collected, used, and protected.
19. LIMITATION OF LIABILITY
While Aura maintains comprehensive administrative, technical, and organisational safeguards, no method of transmitting or storing information can be guaranteed to be completely secure.To the fullest extent permitted by applicable law, Aura shall not be liable for any unauthorised access, disclosure, alteration, or loss of Personal Data arising from events beyond its reasonable control, including cyberattacks, force majeure events, or unlawful acts committed by third parties.Nothing in this Privacy Policy limits any liability that cannot lawfully be excluded.
20. GOVERNING LAW
This Privacy Policy shall be governed by and interpreted in accordance with the laws applicable to Aura Solution Company Limited, unless mandatory data protection legislation provides otherwise.Any dispute arising from or relating to this Privacy Policy shall be subject to the jurisdiction of the competent courts or regulatory authorities having jurisdiction over the relevant matter.