How Aurora MSP handles personal data and service information.
This Privacy & Data Protection Notice explains how Aurora MSP handles personal data across our website, client service delivery, documentation portals, support systems, and third-party service platforms.
Aurora MSP (Cayman) Limited, trading as Aurora MSP, respects privacy and is committed to handling personal data and client service information responsibly, securely, and transparently.
This notice is intended to give website visitors, clients, authorised users, suppliers, partners, and other relevant individuals a clear explanation of the personal data Aurora MSP may process, why it is processed, how it is protected, and how privacy-related enquiries can be raised.
This notice should be read alongside any applicable client agreement, service schedule, order form, data processing terms, support policy, acceptable use terms, or other written agreement between Aurora MSP and the relevant client.
Privacy information for website visitors, clients, and authorised users.
The sections below are designed so they can be linked directly from IT Glue, client portal notes, service desk tickets, onboarding materials, proposals, and other client-facing documentation.
General Privacy Notice
Who this notice applies to
This notice applies to visitors to the Aurora MSP website, prospective clients, client contacts, authorised users, suppliers, partners, and individuals whose information may be processed while Aurora MSP delivers IT support, consultancy, documentation, project, procurement, or managed service activities.
Where Aurora MSP provides services to an organisation, information relating to that organisation’s users, contacts, systems, devices, service records, tickets, documentation, and authorised representatives may be processed as part of delivering, securing, documenting, supporting, or improving those services.
Who we are
Aurora MSP (Cayman) Limited, trading as Aurora MSP, provides IT managed services, support services, consultancy, technical delivery, technology solutions, documentation services, and hardware and software sourcing services.
In this notice, “Aurora MSP”, “we”, “us”, and “our” refer to Aurora MSP (Cayman) Limited.
Our role when handling personal data
For client service delivery, Aurora MSP will usually process personal data as a service provider or data processor acting on behalf of the client. In that context, the client is normally responsible for determining why personal data is processed, what personal data is made available to Aurora MSP, who is authorised to access it, and the lawful basis for that processing.
Aurora MSP processes client personal data only to the extent reasonably necessary to deliver, administer, support, secure, document, improve, monitor, troubleshoot, transition, or offboard the agreed services, or where otherwise required by applicable law or written client instructions.
For Aurora MSP’s own website, administration, marketing, finance, security, supplier management, and general business operations, Aurora MSP may act as a controller of the relevant personal data.
Client responsibility for data
The client remains responsible for the personal data, business data, user information, system information, and service information it provides to Aurora MSP or makes accessible through client systems, third-party platforms, integrations, documentation portals, support channels, or administrative access.
This includes responsibility for ensuring that personal data is lawful, accurate, appropriate for the services, subject to any required internal notices or consents, and shared only by authorised users or representatives. Aurora MSP may rely on the client’s instructions, approvals, access permissions, user lists, system records, and authorised contacts when delivering services.
Aurora MSP supports clients by applying reasonable security controls, maintaining service records, documenting relevant information, and providing visibility where appropriate; however, the client remains responsible for its own internal data governance, user lifecycle processes, access approvals, and decisions about how its systems and data are used.
Personal data we handle
Depending on the relationship and service scope, Aurora MSP processes personal data and technical information that may include names, business contact details, job titles, organisation names, email addresses, phone numbers, user account information, device and asset records, service ticket information, access records, approval records, configuration information, billing and procurement details, website enquiry information, and technical data required to support, secure, document, monitor, or administer client systems.
Aurora MSP may also process technical or operational information such as IP addresses, device names, usernames, email addresses, system logs, alert data, asset identifiers, network information, configuration records, support notes, diagrams, service history, and related information where this is required for service delivery, security, documentation, monitoring, troubleshooting, or reporting.
How we use personal data
Aurora MSP uses personal data to provide, administer, support, secure, improve, monitor, document, troubleshoot, onboard, transition, and offboard services. We also use personal data for service management, client communication, vendor coordination, billing, procurement, legal compliance, security, audit, reporting, insurance, dispute management, and operational recordkeeping.
We do not sell personal data. We use personal data only where there is a lawful and legitimate reason to do so, including where processing is necessary to respond to enquiries, take steps before entering into a contract, perform a contract, comply with legal obligations, protect our rights and systems, administer services, or where consent has been provided.
Client Services & Documentation
Client documentation portals
As part of Aurora MSP’s transparency, clarity, and service documentation approach, authorised client users may be given access to selected documentation and service information relating to their organisation’s IT environment.
This may include approved documentation, configuration records, knowledge articles, passwords or credential records, diagrams, network information, asset records, service records, ticket references, vendor information, and other client-facing documentation maintained by Aurora MSP.
Access is role-based and permission-controlled. The information available to each user may vary depending on their role, organisation, approved access level, business need, and applicable security controls. Access may be increased, reduced, suspended, or removed where appropriate, including where a user changes role, leaves the organisation, no longer requires access, or where Aurora MSP or the client identifies a security or confidentiality concern.
The client is responsible for confirming which users are authorised to access client documentation and for notifying Aurora MSP when access should be changed or removed. Aurora MSP will use reasonable efforts to apply role-based access, multi-factor authentication where supported, and secure access controls within the relevant documentation or portal platform.
Client visibility and transparency
Aurora MSP’s documentation approach is designed to give clients clearer visibility of the information used to support their environment. Where appropriate and approved, clients may be able to review selected documentation, service records, assets, configurations, diagrams, credentials, vendor details, and support information through client-facing portals or documentation platforms.
This visibility supports Aurora MSP’s values of clarity, accountability, and practical service delivery. It also helps clients understand what is documented, identify missing or outdated information, and request corrections where records no longer reflect their environment.
Some information will remain restricted where access could expose privileged credentials, security controls, internal operational procedures, third-party confidential information, information relating to other users, or information that is not appropriate for a user’s role.
Support tickets and service records
Aurora MSP records service requests, incidents, alerts, changes, approvals, notes, actions, outcomes, evidence, and related communications in our service management systems. These records form part of the service history and help us provide support, maintain accountability, track activity, identify trends, support reporting, and improve service quality over time.
Service records may include information provided by the client, authorised users, client systems, monitoring tools, vendors, suppliers, or Aurora MSP personnel. These records may also include technical notes, troubleshooting steps, business impact information, user contact information, device information, screenshots, logs, timestamps, approvals, and closure notes.
Administrative access and credentials
Where required to deliver services, Aurora MSP may hold, use, or access administrative credentials, delegated access, privileged access records, recovery information, tokens, configuration records, service accounts, vendor portal access, or other sensitive operational information.
Aurora MSP applies reasonable access controls for administrative and sensitive information, including role-based access, least-privilege principles, multi-factor authentication where supported, secure credential handling, logging, approval workflows for significant changes, and time-bound or elevated access controls where feasible.
Access to client systems is used for service delivery purposes only, including support, administration, monitoring, documentation, troubleshooting, project work, vendor coordination, security review, backup administration, and approved changes. The client remains responsible for maintaining accurate authorised contacts, internal approvers, user lifecycle information, and any client-side access governance requirements.
Monitoring, telemetry, and service tools
Aurora MSP may use internal systems and third-party tools to collect telemetry, inventory, configuration records, documentation outputs, alerts, health information, backup status, endpoint information, network information, change-awareness data, and service visibility information.
These tools support visibility, documentation, monitoring, troubleshooting, security review, reporting, and service improvement. They do not guarantee detection of every event, vulnerability, misconfiguration, outage, unauthorised change, or security issue.
Accuracy of documentation and access requests
Aurora MSP aims to maintain clear, useful, and accurate service documentation. However, documentation may change over time as systems, users, devices, suppliers, vendors, and business requirements change.
If an authorised client user believes documentation is missing, inaccurate, outdated, or no longer appropriate for their role, they should contact the Aurora MSP Service Desk so the relevant access or records can be reviewed.
Third-Party Platforms
Third-party systems and service providers
Aurora MSP uses third-party platforms and service providers to operate our business, deliver managed services, provide support, maintain documentation, manage security, process billing, communicate with clients, host website services, coordinate vendors, and support service improvement.
These platforms may include systems for documentation, ticketing, remote support, monitoring, endpoint management, identity administration, cloud administration, backup and disaster recovery, email, collaboration, billing, accounting, scheduling, analytics, website hosting, content delivery, secure credential management, procurement, and vendor support.
Subprocessors and vendor controls
Aurora MSP may use third-party service providers, software vendors, hosting providers, distributors, subcontractors, and other platforms as subprocessors where reasonably necessary to deliver services, operate our business, support clients, maintain documentation, manage security, process billing, or coordinate service delivery.
Aurora MSP remains responsible for subprocessors as required by applicable law and the relevant client agreement, and uses reasonable care when selecting third-party providers that process personal data on Aurora MSP’s behalf.
Some third-party products, cloud services, SaaS platforms, hardware vendors, and distributors operate under their own terms, privacy notices, security practices, support processes, retention rules, and data locations. Where a client directly selects, owns, or contracts with a third-party platform, that platform may also process personal data under its own terms and the client’s own relationship with that provider.
SMS and messaging providers
Where Aurora MSP sends a requested text message, the recipient’s mobile number is processed through a third-party messaging provider (for example, Twilio) acting as a service provider to Aurora MSP. The number is used solely to deliver the message the recipient requested on the call. Mobile numbers and SMS consent are not sold or shared with third parties for their own marketing.
Vendor trust and assurance resources
For transparency, Aurora MSP may link to official vendor trust, privacy, security, or compliance resources for key platforms used in our website, service delivery, documentation, support, analytics, or client service workflows. These links are provided for reference only and may not represent every vendor, service, subprocessor, or tool used for every client.
Vendor trust portals and privacy resources are maintained by the relevant third parties and may change over time. Clients should review the applicable vendor terms, privacy notices, and trust resources for any third-party platforms they directly purchase, own, or administer.
- Microsoft Service Trust Portal
- Microsoft Trust Center
- Kaseya Trust Center
- Google Analytics — Safeguarding Your Data
- Google Analytics — Privacy Controls
- Credly Data Security & Privacy
- Credly Privacy Policy
Data location and international transfers
Personal data may be processed in the Cayman Islands and in other jurisdictions where Aurora MSP, our vendors, service providers, or subprocessors operate.
Where required by applicable law, Aurora MSP will use or cooperate in implementing appropriate safeguards for cross-border transfers. This may include contractual terms, vendor due diligence, technical safeguards, access controls, or other suitable measures depending on the service and the relevant processing activity.
Third-party dependencies
Some services depend on third-party platforms, vendors, suppliers, internet service providers, cloud providers, hardware manufacturers, software vendors, distributors, or client-selected systems. Aurora MSP is not responsible for third-party outages, vendor policy changes, supplier delays, platform limitations, or third-party support timelines, but will cooperate reasonably where those dependencies affect service delivery.
Security, Retention & Rights
Security controls
Aurora MSP applies reasonable technical and organisational measures designed to protect personal data and client service information from unauthorised access, accidental loss, misuse, alteration, or disclosure.
Depending on the service, system, and agreed scope, these controls may include role-based access, least-privilege administration, multi-factor authentication, secure credential handling, logging, encryption, patching, staff confidentiality obligations, approval workflows, time-bound access, elevated access controls, and documented operational procedures where feasible.
No website, email system, cloud service, or online platform can be guaranteed to be completely secure. Clients and users should also follow appropriate security practices, including protecting passwords, using MFA, keeping devices secure, and promptly reporting suspected security issues.
Retention and deletion
Aurora MSP keeps personal data and service records only for as long as reasonably necessary for the purpose for which they were collected, including service delivery, legal and regulatory obligations, security, audit, billing, dispute management, insurance, legitimate recordkeeping, and operational continuity.
Where Aurora MSP holds personal data on behalf of a client, retention and deletion may also be governed by the applicable client agreement, service schedule, offboarding process, legal requirements, backup retention cycles, vendor retention rules, and technical feasibility.
Security incidents and breach notification
If Aurora MSP confirms a security incident affecting personal data processed for a client, we will notify the client without undue delay where required by the applicable agreement or law.
Notifications may be provided in phases as information becomes available and may include the nature of the incident, affected data categories, likely impact, containment steps, remediation actions, and recommended next steps.
Where required by applicable law, Aurora MSP will take appropriate steps in relation to notifications to affected individuals, regulators, or other required parties.
Your rights and requests
Individuals may have rights under applicable data protection laws, which may include rights to access, correct, delete, restrict, or object to the use of their personal data.
Where Aurora MSP processes personal data on behalf of a client, Aurora MSP may need to refer the request to that client as the relevant controller or authorised organisation. Where Aurora MSP acts as controller, we will review and respond to privacy requests in accordance with applicable law.
Marketing communications
Aurora MSP may use business contact information to communicate with clients, prospective clients, and business contacts about relevant services, updates, events, or information. Individuals can ask Aurora MSP to stop sending direct marketing communications where applicable.
SMS / text messaging
When you provide your mobile number during a call and agree to receive a text, Aurora MSP (Cayman) Limited uses that number solely to send the link you requested. Messages are sent on request only and are service-related, not marketing. We do not sell or share mobile numbers or SMS consent with third parties for their marketing. Reply STOP to opt out, HELP for help. Standard message and data rates may apply. Full details are set out in our SMS Messaging & Consent policy.
Questions about privacy, data protection, or service records?
Privacy enquiries, documentation access questions, and service-record requests can be sent to Aurora MSP using the contact details below. Where a request relates to a client-controlled environment, Aurora MSP may need to coordinate with the relevant client contact or authorised representative.
Aurora MSP (Cayman) Limited
Email: enquiries@aurora-msp.com
