1. Privacy roles
A salon normally determines why and how its client and staff information is processed and is the responsible party under POPIA. AuraSuite acts as operator or service provider for that information. AuraSuite is responsible for information it collects for its own website enquiries, support, security and account administration.
2. Information handled
AuraSuite may handle website enquiry details; salon user, role and security records; and salon-entered client, appointment, treatment, health, photograph, document, stock, invoice, payment, voucher and communication records. Some salon records contain special personal information. Salons must collect it lawfully and restrict access appropriately.
3. Purposes
Information is used to provide and secure the selected AuraSuite functions, maintain records and audit history, synchronise services chosen by an authorised user, prepare reviewable AI assistance, respond to support, back up and restore the installation, and meet legal obligations. AuraSuite does not sell personal information or use Google data for advertising.
4. Google user data
Google access is optional and starts only when an authorised user selects the connection control and grants access on Google's consent screen. AuraSuite requests exactly these scopes:
https://www.googleapis.com/auth/calendar— read and manage calendar lists and events for two-way salon appointment synchronisation.https://www.googleapis.com/auth/gmail.readonly— search for and read recent messages fromincontact@fnb.co.zato prepare FNB transaction suggestions for review.
Full technical details about access, storage, human access, sharing, deletion and Limited Use are in the Google User Data Disclosure.
5. Gemini and AI processing
AuraSuite uses a salon-configured Google Gemini Developer API key for optional, visible user-facing assistance. Gemini receives the user's dictated or typed command and, when relevant, a limited AuraSuite catalogue or a communication draft and its supporting AuraSuite business facts. The current code does not send raw Gmail messages, Google Calendar events or OAuth tokens to Gemini. Gemini cannot independently access Gmail, Calendar or the AuraSuite database.
Gemini proposals are not saved as business actions until an authorised user reviews and confirms them. AuraSuite records limited assistant audit information locally, including the request text, operation, outcome, source labels and usage count. Production use should be connected to a billing-enabled Gemini API project; Google's applicable paid-service terms state that prompts and responses are not used to improve Google products. AuraSuite does not use salon or Google Workspace data to train general-purpose AI models.
6. Sharing and human access
Information is available to authorised salon users and may be processed by providers needed for the selected deployment, such as Google APIs, Gemini, email, hosting, backup and support providers. AuraSuite personnel do not read Google Workspace data unless the user gives documented consent for specific support, or access is necessary for security or law. Data is not transferred to advertisers, data brokers or lenders.
7. Storage and security
The audited version is a local/private-server installation. Salon records, Google-derived records and OAuth tokens are stored in the installation's local SQLite database and may be included in its configured backups. OAuth tokens are not application-level encrypted in this audited build; protection therefore depends on operating-system access controls, named AuraSuite users, device/server security, restricted backups and secure network access. Transport to Google and Gemini uses HTTPS. No system guarantees absolute security.
8. Retention and deletion
Google-derived calendar data covers the synchronisation window from 30 days before to 365 days after a sync. Gmail searches cover the most recent 90 days. Derived suggestions and confirmed business records remain until reviewed or deleted under the salon's retention process; backups remain until rotated. Disconnecting stops new access and requests token revocation. The user may also remove cached unmatched calendar items, unconfirmed Gmail suggestions and Google link identifiers. Confirmed financial and appointment records may remain as salon records where required. See Data Deletion Instructions.
9. Rights
People may request access, correction, objection or deletion as applicable. Salon clients should normally contact the salon, which controls their record. Requests about AuraSuite-controlled information may be sent to the address below. Identity and authority may be verified. Complaints may be lodged with South Africa's Information Regulator.
10. Changes
We will update this policy when actual data flows, providers or legal requirements change. Material Google-data changes may require renewed OAuth verification before release.
11. Contact
AuraSuite Privacy
South Africa
privacy@aurasuite.co.za
https://aurasuite.co.za/
