Privacy & Data Protection

How Aurora MSP handles personal data and service information.

This Privacy & Data Protection Notice explains how Aurora MSP handles personal data across our website, client service delivery, documentation portals, support systems, and third-party service platforms.

Overview

Aurora MSP (Cayman) Limited, trading as Aurora MSP, respects privacy and is committed to handling personal data and client service information responsibly, securely, and transparently.

This notice is intended to give website visitors, clients, authorised users, suppliers, partners, and other relevant individuals a clear explanation of the personal data Aurora MSP may process, why it is processed, how it is protected, and how privacy-related enquiries can be raised.

This notice should be read alongside any applicable client agreement, service schedule, order form, data processing terms, support policy, acceptable use terms, or other written agreement between Aurora MSP and the relevant client.

Privacy Notice

Privacy information for website visitors, clients, and authorised users.

The sections below are designed so they can be linked directly from IT Glue, client portal notes, service desk tickets, onboarding materials, proposals, and other client-facing documentation.

General Privacy Notice

Who this notice applies to

This notice applies to visitors to the Aurora MSP website, prospective clients, client contacts, authorised users, suppliers, partners, and individuals whose information may be processed while Aurora MSP delivers IT support, consultancy, documentation, project, procurement, or managed service activities.

Where Aurora MSP provides services to an organisation, information relating to that organisation’s users, contacts, systems, devices, service records, tickets, documentation, and authorised representatives may be processed as part of delivering, securing, documenting, supporting, or improving those services.

Who we are

Aurora MSP (Cayman) Limited, trading as Aurora MSP, provides IT managed services, support services, consultancy, technical delivery, technology solutions, documentation services, and hardware and software sourcing services.

In this notice, “Aurora MSP”, “we”, “us”, and “our” refer to Aurora MSP (Cayman) Limited.

Our role when handling personal data

For client service delivery, Aurora MSP will usually process personal data as a service provider or data processor acting on behalf of the client. In that context, the client is normally responsible for determining why personal data is processed, what personal data is made available to Aurora MSP, who is authorised to access it, and the lawful basis for that processing.

Aurora MSP processes client personal data only to the extent reasonably necessary to deliver, administer, support, secure, document, improve, monitor, troubleshoot, transition, or offboard the agreed services, or where otherwise required by applicable law or written client instructions.

For Aurora MSP’s own website, administration, marketing, finance, security, supplier management, and general business operations, Aurora MSP may act as a controller of the relevant personal data.

Client responsibility for data

The client remains responsible for the personal data, business data, user information, system information, and service information it provides to Aurora MSP or makes accessible through client systems, third-party platforms, integrations, documentation portals, support channels, or administrative access.

This includes responsibility for ensuring that personal data is lawful, accurate, appropriate for the services, subject to any required internal notices or consents, and shared only by authorised users or representatives. Aurora MSP may rely on the client’s instructions, approvals, access permissions, user lists, system records, and authorised contacts when delivering services.

Aurora MSP supports clients by applying reasonable security controls, maintaining service records, documenting relevant information, and providing visibility where appropriate; however, the client remains responsible for its own internal data governance, user lifecycle processes, access approvals, and decisions about how its systems and data are used.

Personal data we handle

Depending on the relationship and service scope, Aurora MSP processes personal data and technical information that may include names, business contact details, job titles, organisation names, email addresses, phone numbers, user account information, device and asset records, service ticket information, access records, approval records, configuration information, billing and procurement details, website enquiry information, and technical data required to support, secure, document, monitor, or administer client systems.

Aurora MSP may also process technical or operational information such as IP addresses, device names, usernames, email addresses, system logs, alert data, asset identifiers, network information, configuration records, support notes, diagrams, service history, and related information where this is required for service delivery, security, documentation, monitoring, troubleshooting, or reporting.

How we use personal data

Aurora MSP uses personal data to provide, administer, support, secure, improve, monitor, document, troubleshoot, onboard, transition, and offboard services. We also use personal data for service management, client communication, vendor coordination, billing, procurement, legal compliance, security, audit, reporting, insurance, dispute management, and operational recordkeeping.

We do not sell personal data. We use personal data only where there is a lawful and legitimate reason to do so, including where processing is necessary to respond to enquiries, take steps before entering into a contract, perform a contract, comply with legal obligations, protect our rights and systems, administer services, or where consent has been provided.

Client Services & Documentation

Client documentation portals

As part of Aurora MSP’s transparency, clarity, and service documentation approach, authorised client users may be given access to selected documentation and service information relating to their organisation’s IT environment.

This may include approved documentation, configuration records, knowledge articles, passwords or credential records, diagrams, network information, asset records, service records, ticket references, vendor information, and other client-facing documentation maintained by Aurora MSP.

Access is role-based and permission-controlled. The information available to each user may vary depending on their role, organisation, approved access level, business need, and applicable security controls. Access may be increased, reduced, suspended, or removed where appropriate, including where a user changes role, leaves the organisation, no longer requires access, or where Aurora MSP or the client identifies a security or confidentiality concern.

The client is responsible for confirming which users are authorised to access client documentation and for notifying Aurora MSP when access should be changed or removed. Aurora MSP will use reasonable efforts to apply role-based access, multi-factor authentication where supported, and secure access controls within the relevant documentation or portal platform.

Client visibility and transparency

Aurora MSP’s documentation approach is designed to give clients clearer visibility of the information used to support their environment. Where appropriate and approved, clients may be able to review selected documentation, service records, assets, configurations, diagrams, credentials, vendor details, and support information through client-facing portals or documentation platforms.

This visibility supports Aurora MSP’s values of clarity, accountability, and practical service delivery. It also helps clients understand what is documented, identify missing or outdated information, and request corrections where records no longer reflect their environment.

Some information will remain restricted where access could expose privileged credentials, security controls, internal operational procedures, third-party confidential information, information relating to other users, or information that is not appropriate for a user’s role.

Support tickets and service records

Aurora MSP records service requests, incidents, alerts, changes, approvals, notes, actions, outcomes, evidence, and related communications in our service management systems. These records form part of the service history and help us provide support, maintain accountability, track activity, identify trends, support reporting, and improve service quality over time.

Service records may include information provided by the client, authorised users, client systems, monitoring tools, vendors, suppliers, or Aurora MSP personnel. These records may also include technical notes, troubleshooting steps, business impact information, user contact information, device information, screenshots, logs, timestamps, approvals, and closure notes.

Administrative access and credentials

Where required to deliver services, Aurora MSP may hold, use, or access administrative credentials, delegated access, privileged access records, recovery information, tokens, configuration records, service accounts, vendor portal access, or other sensitive operational information.

Aurora MSP applies reasonable access controls for administrative and sensitive information, including role-based access, least-privilege principles, multi-factor authentication where supported, secure credential handling, logging, approval workflows for significant changes, and time-bound or elevated access controls where feasible.

Access to client systems is used for service delivery purposes only, including support, administration, monitoring, documentation, troubleshooting, project work, vendor coordination, security review, backup administration, and approved changes. The client remains responsible for maintaining accurate authorised contacts, internal approvers, user lifecycle information, and any client-side access governance requirements.

Monitoring, telemetry, and service tools

Aurora MSP may use internal systems and third-party tools to collect telemetry, inventory, configuration records, documentation outputs, alerts, health information, backup status, endpoint information, network information, change-awareness data, and service visibility information.

These tools support visibility, documentation, monitoring, troubleshooting, security review, reporting, and service improvement. They do not guarantee detection of every event, vulnerability, misconfiguration, outage, unauthorised change, or security issue.

Accuracy of documentation and access requests

Aurora MSP aims to maintain clear, useful, and accurate service documentation. However, documentation may change over time as systems, users, devices, suppliers, vendors, and business requirements change.

If an authorised client user believes documentation is missing, inaccurate, outdated, or no longer appropriate for their role, they should contact the Aurora MSP Service Desk so the relevant access or records can be reviewed.

Third-Party Platforms

Third-party systems and service providers

Aurora MSP uses third-party platforms and service providers to operate our business, deliver managed services, provide support, maintain documentation, manage security, process billing, communicate with clients, host website services, coordinate vendors, and support service improvement.

These platforms may include systems for documentation, ticketing, remote support, monitoring, endpoint management, identity administration, cloud administration, backup and disaster recovery, email, collaboration, billing, accounting, scheduling, analytics, website hosting, content delivery, secure credential management, procurement, and vendor support.

Subprocessors and vendor controls

Aurora MSP may use third-party service providers, software vendors, hosting providers, distributors, subcontractors, and other platforms as subprocessors where reasonably necessary to deliver services, operate our business, support clients, maintain documentation, manage security, process billing, or coordinate service delivery.

Aurora MSP remains responsible for subprocessors as required by applicable law and the relevant client agreement, and uses reasonable care when selecting third-party providers that process personal data on Aurora MSP’s behalf.

Some third-party products, cloud services, SaaS platforms, hardware vendors, and distributors operate under their own terms, privacy notices, security practices, support processes, retention rules, and data locations. Where a client directly selects, owns, or contracts with a third-party platform, that platform may also process personal data under its own terms and the client’s own relationship with that provider.

SMS and messaging providers

Where Aurora MSP sends a requested text message, the recipient’s mobile number is processed through a third-party messaging provider (for example, Twilio) acting as a service provider to Aurora MSP. The number is used solely to deliver the message the recipient requested on the call. Mobile numbers and SMS consent are not sold or shared with third parties for their own marketing.

Vendor trust and assurance resources

For transparency, Aurora MSP may link to official vendor trust, privacy, security, or compliance resources for key platforms used in our website, service delivery, documentation, support, analytics, or client service workflows. These links are provided for reference only and may not represent every vendor, service, subprocessor, or tool used for every client.

Vendor trust portals and privacy resources are maintained by the relevant third parties and may change over time. Clients should review the applicable vendor terms, privacy notices, and trust resources for any third-party platforms they directly purchase, own, or administer.

Data location and international transfers

Personal data may be processed in the Cayman Islands and in other jurisdictions where Aurora MSP, our vendors, service providers, or subprocessors operate.

Where required by applicable law, Aurora MSP will use or cooperate in implementing appropriate safeguards for cross-border transfers. This may include contractual terms, vendor due diligence, technical safeguards, access controls, or other suitable measures depending on the service and the relevant processing activity.

Third-party dependencies

Some services depend on third-party platforms, vendors, suppliers, internet service providers, cloud providers, hardware manufacturers, software vendors, distributors, or client-selected systems. Aurora MSP is not responsible for third-party outages, vendor policy changes, supplier delays, platform limitations, or third-party support timelines, but will cooperate reasonably where those dependencies affect service delivery.

Website, Cookies & Analytics

Website enquiries and contact forms

Aurora MSP may collect personal data when you use our website, submit a form, request information, contact us by email, use a scheduling link, or enquire about our services.

This may include your name, company name, job title, email address, phone number, preferred contact method, enquiry details, and information you choose to provide about your organisation, service needs, technology environment, or support requirements.

Microsoft Forms and enquiry tools

Some enquiry forms, questionnaires, or service intake processes may be delivered using Microsoft Forms, Microsoft 365 services, or other approved form and workflow platforms. When you submit a form, the information you provide may be processed through those services and used by Aurora MSP to review, respond to, triage, or progress your enquiry.

Cookies, analytics, LinkedIn, and embedded content

Aurora MSP’s website may use cookies, analytics technologies, and third-party embedded content to help operate the site, understand how visitors use it, improve performance, maintain security, and present relevant information.

This may include Google Analytics or similar analytics tools, LinkedIn-related features, embedded Credly certification badges, website security tools, hosting or content delivery services, forms, scheduling links, and other third-party website services.

Technical website data

Website services may process technical information such as IP address, browser type, device information, approximate location, referring pages, pages visited, session activity, cookie identifiers, tracking identifiers, and security or performance logs.

Where required, Aurora MSP will provide cookie controls or obtain consent before using non-essential cookies.

Sensitive information warning

Please do not submit passwords, payment card details, private keys, recovery keys, MFA codes, seed phrases, administrative credentials, or other sensitive secrets through public website forms or general enquiry channels.

If Aurora MSP requires sensitive operational information to deliver a service, we will provide or agree an appropriate secure method for sharing that information.

Security, Retention & Rights

Security controls

Aurora MSP applies reasonable technical and organisational measures designed to protect personal data and client service information from unauthorised access, accidental loss, misuse, alteration, or disclosure.

Depending on the service, system, and agreed scope, these controls may include role-based access, least-privilege administration, multi-factor authentication, secure credential handling, logging, encryption, patching, staff confidentiality obligations, approval workflows, time-bound access, elevated access controls, and documented operational procedures where feasible.

No website, email system, cloud service, or online platform can be guaranteed to be completely secure. Clients and users should also follow appropriate security practices, including protecting passwords, using MFA, keeping devices secure, and promptly reporting suspected security issues.

Retention and deletion

Aurora MSP keeps personal data and service records only for as long as reasonably necessary for the purpose for which they were collected, including service delivery, legal and regulatory obligations, security, audit, billing, dispute management, insurance, legitimate recordkeeping, and operational continuity.

Where Aurora MSP holds personal data on behalf of a client, retention and deletion may also be governed by the applicable client agreement, service schedule, offboarding process, legal requirements, backup retention cycles, vendor retention rules, and technical feasibility.

Security incidents and breach notification

If Aurora MSP confirms a security incident affecting personal data processed for a client, we will notify the client without undue delay where required by the applicable agreement or law.

Notifications may be provided in phases as information becomes available and may include the nature of the incident, affected data categories, likely impact, containment steps, remediation actions, and recommended next steps.

Where required by applicable law, Aurora MSP will take appropriate steps in relation to notifications to affected individuals, regulators, or other required parties.

Your rights and requests

Individuals may have rights under applicable data protection laws, which may include rights to access, correct, delete, restrict, or object to the use of their personal data.

Where Aurora MSP processes personal data on behalf of a client, Aurora MSP may need to refer the request to that client as the relevant controller or authorised organisation. Where Aurora MSP acts as controller, we will review and respond to privacy requests in accordance with applicable law.

Marketing communications

Aurora MSP may use business contact information to communicate with clients, prospective clients, and business contacts about relevant services, updates, events, or information. Individuals can ask Aurora MSP to stop sending direct marketing communications where applicable.

SMS / text messaging

When you provide your mobile number during a call and agree to receive a text, Aurora MSP (Cayman) Limited uses that number solely to send the link you requested. Messages are sent on request only and are service-related, not marketing. We do not sell or share mobile numbers or SMS consent with third parties for their marketing. Reply STOP to opt out, HELP for help. Standard message and data rates may apply. Full details are set out in our SMS Messaging & Consent policy.

Contact

Questions about privacy, data protection, or service records?

Privacy enquiries, documentation access questions, and service-record requests can be sent to Aurora MSP using the contact details below. Where a request relates to a client-controlled environment, Aurora MSP may need to coordinate with the relevant client contact or authorised representative.

Aurora MSP (Cayman) Limited
Email: enquiries@aurora-msp.com

Last updated: June 2026
Version: 1.1