Data privacy notice

This explains what business contact data we hold, where it came from, what we do with it, and how to have it removed. If you want to be taken off our records, one email does it and we do not ask why.

Just want to be removed?

Email info@aureonglobal.de and say so. We delete your record and add you to a permanent suppression list, so you are not collected again from a public source later. No reason needed, no charge, no forms.

In the United States the same email is your Do Not Sell or Share My Personal Information request.

Who we are

Aureon Global L.L.C., Dushkaja 20, 71000 Kaçanik, Republic of Kosovo. Business registration number 812368240. Contact: info@aureonglobal.de

We act as a data controller for the business contact information described below. We have not appointed a data protection officer, and are not required to: we carry out no large scale monitoring, hold no special category data, and are not a public authority.

Why you are reading this

We hold business contact information about people who did not give it to us directly. Where that happens, data protection law (Article 14 of the UK and EU GDPR) requires us to tell those people what we hold, why, where it came from and what rights they have. This page is how we do that.

What we process

FieldNote
Full nameOnly where the employer has published it. We never guess a name.
Job title and employerProfessional capacity only.
Business telephone numberPlus a label for what the line reaches, switchboard or direct.
Business email addressOnly where published. We never construct one from a name pattern.
The employer's public hiring activityThe advertisement that identified the business as a prospect.

We do not process personal mobile numbers, home addresses, personal email addresses, dates of birth, financial data, government identifiers, or any special category data as defined in Article 9.

Where we get it

Public sources only, and each record notes which one:

We do not buy consumer data, we do not scrape private profiles, and we do not take data from social networks behind a login.

Why we process it, and on what basis

Purpose: to compile business to business prospect lists that our clients use to make business development contact.

Lawful basis: legitimate interests, Article 6(1)(f). The interest is identifying relevant business contacts for B2B communication. We have assessed that interest against the rights of the people concerned and recorded the assessment. The data is limited to a professional capacity, is already published by the employer, and involves no special category data.

You have the right to object to this processing. See Your rights.

Who we share it with

Business clients who purchase a prospect list. They are bound by terms that require them to use the data for their own B2B contact only, not to resell it, and to honour any objection or erasure request they receive directly, including telling us so we can suppress you at source.

We do not disclose personal data to consumer marketers, advertising networks or list resellers.

These are the only service providers that touch the data. Each processes it on our instructions under a data processing agreement:

ProviderWhat it doesWhere
Resend (Plus Five Five, Inc.)Email deliveryUnited States. EU Standard Contractual Clauses, and certified under the EU–US Data Privacy Framework.
Hostinger International LtdMailbox and website hostingLuxembourg company. EU Standard Contractual Clauses and the UK Addendum apply.
Calendly LLCMeeting schedulingUnited States. EU Standard Contractual Clauses and the UK Addendum apply.
Hyonix (Krixe Pte. Ltd.)Server hosting for the production databaseUnited States, New Jersey. Standard Contractual Clauses apply.

How long we keep it

Prospect records are kept for a maximum of 12 months from collection, after which they are deleted or re-verified.

One deliberate exception. If you object or ask to be removed, we keep the minimum needed to identify you on a suppression list indefinitely. That is the only way to guarantee we do not collect you again from a public source you do not control. Deleting the record on its own would simply mean you reappear on the next sweep, which is not what you asked for.

Your rights

If you are in the UK, the EU, or a jurisdiction with equivalent law, you may:

Email info@aureonglobal.de. We respond within 30 days and there is no charge. An objection or erasure request is honoured without question and we do not ask for a reason.

Automated decisions

None. We do not profile individuals and we make no automated decision that produces a legal or similarly significant effect. Selection is by business attribute, not by any assessment of a person.

International transfers

We are based in Kosovo and our production database is hosted in the United States. Both are outside the EEA and neither is covered by a European Commission adequacy decision, so every transfer out of the EEA or the UK is made under the European Commission's Standard Contractual Clauses (Decision 2021/914), with the UK International Data Transfer Addendum where UK data is involved. Our email delivery provider is additionally certified under the EU–US Data Privacy Framework.

As a controller established in Kosovo we are also subject to the Kosovo Law on Protection of Personal Data (Law No. 06/L-082), which follows the GDPR. The supervisory authority there is the Information and Privacy Agency.

If you are in the United States

This section is our notice at collection under the California Consumer Privacy Act as amended by the CPRA. We apply it to residents of every US state, not only California.

Category collectedExamples we actually hold
IdentifiersName, employer, business telephone number, business email address
Professional or employment-related informationJob title, and the employer's own published hiring or trading activity
Internet activity, in a narrow senseThe public web page the information was published on, kept so you can check the record against its source

We collect no sensitive personal information as the CCPA defines it: no government identifiers, no financial account data, no precise geolocation, no biometrics, no racial, health, religious, union, sexual orientation or private communications data. There is therefore nothing to limit under the right to limit the use of sensitive personal information.

Purpose. To compile business to business prospect lists that our clients use for their own business development contact. Retention: 12 months from collection, then deleted or re-verified, with the single suppression-list exception described above.

We do sell personal information, in the sense the CCPA means. We disclose business contact information to business clients in exchange for money. We say so plainly rather than hide behind the word. What we do not do is "share" it for cross-context behavioural advertising, and we do not disclose it to advertising networks or to consumer marketers. We do not knowingly collect or sell the personal information of anyone under 16.

Do Not Sell or Share My Personal Information

Email info@aureonglobal.de with that subject line, or use the contact form. Either one works and you do not need an account.

We treat an opt-out the same way we treat an objection under European law: we delete the record and add you to a permanent suppression list, so you are not collected again from a public source later. We will never charge you a different price or refuse you service for exercising a privacy right.

You may also ask us to tell you what we have collected about you, where we got it, who we disclosed it to and why; to give you a copy; to correct it; or to delete it. We answer within 45 days, and if we genuinely need longer we will tell you inside those 45 days and take at most 45 more. An authorised agent may act for you if you give them written permission and we can verify it.

Global Privacy Control. This website sets no advertising or analytics cookies and we do not disclose visitors' browsing data to anyone, so there is nothing on the site itself to opt out of. We still read the Global Privacy Control signal, and where your browser sends one we treat it as a valid opt-out request without asking you to do anything else.

Where we stand on the CCPA thresholds, stated openly. The CCPA applies to a business that has more than $25 million in annual revenue, or buys, sells or shares the personal information of 100,000 or more California consumers or households in a year, or derives 50 per cent or more of its annual revenue from selling or sharing California residents' personal information. We are under all three. We apply the rights on this page anyway, because a person asking to be left alone should not have to work out whether a threshold was crossed. If we do cross one, we will register as a data broker with the California Privacy Protection Agency and say so here.

Changes to this notice

If we change how we process data we update this page and change the date below. Material changes are described here rather than made quietly.

Last updated: 17 August 2026. Previous version: 15 August 2026, which did not carry the United States section or name our service providers.