GDPR Compliance
Ayorax is fully compliant with the General Data Protection Regulation (GDPR). This page explains your rights as an EU/EEA/UK data subject and how we protect your personal data.
Data controller vs. data processor
Ayorax as Controller
For data relating to our website visitors, trial users, and paying customers (name, email, billing info), Ayorax is the data controller. We decide why and how this data is processed.
Ayorax as Processor
For the leads and contacts you process through Ayorax workflows, you are the data controller. Ayorax processes this data only as directed by you and under a Data Processing Agreement (DPA).
Our legal bases for processing
Contract performance
Processing required to provide the Ayorax service to you — running workflows, syncing integrations, processing payments.
Legitimate interests
Security monitoring, fraud prevention, product improvement using anonymized analytics, and sending service-critical communications.
Consent
Optional marketing emails, analytics cookies, and marketing cookies. You can withdraw consent at any time.
Legal obligation
Retaining billing records, responding to lawful government requests, and complying with applicable financial regulations.
Your rights under GDPR
Right of access (Art. 15)
You can request a copy of all personal data we hold about you. We will provide it in a machine-readable format within 30 days of your request.
Right to rectification (Art. 16)
If we hold inaccurate or incomplete personal data about you, you have the right to have it corrected. You can update most data directly in your account settings.
Right to erasure (Art. 17)
You can request deletion of your personal data. We will comply within 30 days, subject to our legal obligation to retain certain records (e.g., billing history for 7 years).
Right to restrict processing (Art. 18)
You can ask us to pause the processing of your data in certain circumstances — for example, while you contest its accuracy or object to processing.
Right to data portability (Art. 20)
You can request your personal data in a structured, machine-readable format (JSON or CSV) to transfer to another service provider.
Right to object (Art. 21)
You can object to certain types of processing, including processing based on legitimate interests or for direct marketing. We will stop processing unless we have compelling legitimate grounds.
Right to withdraw consent
Where we rely on your consent to process your data (e.g., marketing cookies), you can withdraw consent at any time without affecting the lawfulness of processing done before withdrawal.
To exercise your rights
Email privacy@ayorax.com with your request. We will respond within 30 days. You may be required to verify your identity.
Our data protection measures
- All data encrypted in transit (TLS 1.3) and at rest (AES-256)
- Role-based access control (RBAC), custom roles and audit logs
- Built-in contact data export and deletion (right to access & erasure)
- Consent tracking and Do-Not-Call (DNC) enforcement for outreach
- Data Processing Agreement (DPA) available for all customers
- Sub-processor list published and updated on changes
- Standard Contractual Clauses (SCCs) for data transfers outside the EEA
- GDPR-compliant Data Protection Officer (DPO) appointed
- Breach notification within 72 hours as required by Art. 33
- Privacy by design in all new product development
- Regular employee training on data protection obligations
Data Processing Agreement (DPA)
All Ayorax customers can request a signed Data Processing Agreement (DPA) that formalizes our obligations as a data processor under GDPR Article 28. Enterprise customers can also request our list of sub-processors.
Request a DPAContact our Data Protection Officer
If you have concerns about how Ayorax handles your personal data, our DPO is your first point of contact. You also have the right to lodge a complaint with your local data protection supervisory authority.
DPO email: gdpr@ayorax.com
Also see our full legal documentation: