Privacy Policy
Effective 4 August 2026 · Version 2.0
1. Introduction
1.1 This notice explains how Aurifex Digital (“Aurifex”, “we”, “us”) processes personal data in connection with Varian (the “Service”), a project cost-tracking application.
1.2 It applies to visitors to varianpm.app, to individuals who hold a Varian account, and to individuals whose personal data is contained in data submitted to the Service by a subscribing organisation.
1.3 Terms defined in the Terms of Service have the same meaning in this notice.
2. Controller and processor roles
2.1 Aurifex is the controller of Account Data, being the personal data required to create and administer an account: identity, contact and authentication data, and organisation membership and role.
2.2 Aurifex is a processor in respect of Customer Data, being the content submitted to the Service by a subscribing organisation, including any personal data relating to that organisation’s personnel, clients or suppliers. The subscribing organisation is the controller of that data and determines the purposes and means of its processing. Aurifex processes it only on the documented instructions of that organisation.
2.3 Where an individual asks Aurifex to exercise a data subject right in respect of Customer Data, Aurifex will refer that request to the relevant controller and act on its instructions. Requests should be directed to the organisation’s Owner or Administrator in the first instance.
2.4 Aurifex is not required to appoint a Data Protection Officer under Article 37 UK GDPR. Enquiries should be sent to the address in clause 12.
3. Categories of personal data
3.1 Aurifex processes the following categories:
- Identity and contact data — email address and, where supplied, display name.
- Authentication data — a cryptographic hash of the account password. Passwords are not stored or accessible in plaintext and cannot be recovered.
- Authorisation data — organisation and project membership, and assigned role.
- Customer Data — content submitted to the Service, which may include names of client and supplier personnel, references, amounts, dates and narrative notes.
- Activity data — records of changes to financial records, comprising the acting account, the timestamp, and the prior and resulting values.
- Technical data — IP address, browser and device characteristics, and diagnostic information generated when an error occurs.
- Usage data — named product events indicating which features are used.
3.2 The Service is not designed to process special category data within the meaning of Article 9 UK GDPR, or personal data relating to criminal convictions and offences. Such data should not be submitted to the Service.
3.3 Personal data is obtained directly from the data subject, from the subscribing organisation that holds the account, or is generated by the Service in the course of its operation. No personal data is obtained from public sources or acquired from third parties.
4. Purposes and lawful bases
| Purpose | Categories | Lawful basis |
|---|---|---|
| Providing the Service and administering accounts | Identity, contact, authentication, authorisation | Article 6(1)(b) — performance of a contract |
| Sending service, invitation and alert messages | Identity, contact | Article 6(1)(b) — performance of a contract |
| Hosting and processing Customer Data | Customer Data | Article 6(1)(b) as against the subscribing organisation; processed on its instructions under Article 28 |
| Maintaining an attributable record of changes to financial records | Activity | Article 6(1)(f) — legitimate interests in the integrity and accountability of cost records |
| Maintaining security and availability, and diagnosing faults | Technical | Article 6(1)(f) — legitimate interests in network and information security |
| Measuring feature adoption to improve the Service | Usage | Article 6(1)(f) — legitimate interests in product development |
4.1 Where processing relies on legitimate interests, Aurifex has assessed those interests against the rights and freedoms of data subjects. A summary of that assessment is available on request.
4.2 No decision producing legal or similarly significant effects is taken solely by automated means, and no profiling is carried out.
5. Recipients
5.1 Personal data is disclosed to the sub-processors listed in Annex A, each engaged under a written contract meeting the requirements of Article 28 UK GDPR.
5.2 Personal data may be disclosed to professional advisers, or to a competent authority where disclosure is required by law. Aurifex does not sell personal data and does not disclose it for advertising purposes.
5.3 In the event of a merger, acquisition or transfer of the business, personal data may be transferred to the acquirer subject to this notice.
6. International transfers
6.1 The sub-processors in Annex A process personal data within the United Kingdom or the European Economic Area. Aurifex does not, in the ordinary operation of the Service, transfer personal data to a country outside the UK or EEA.
6.2 Should such a transfer become necessary, it will be made under an adequacy decision or subject to appropriate safeguards under Article 46 UK GDPR, and this notice will be updated.
7. Retention
| Data | Retention period |
|---|---|
| Account Data and Customer Data | Duration of the account |
| Deleted projects and records | 30 days from deletion, then erased |
| Activity data (audit records) | Duration of the organisation’s account |
| Diagnostic and error data | 90 days |
| Closed accounts | Erased within 30 days of confirmed closure |
7.1 Aurifex may retain personal data beyond these periods where required to comply with a legal obligation, or to establish, exercise or defend legal claims.
7.2 Activity data is retained for the life of the organisation’s account and is not erased on individual request, its integrity being necessary for the purpose identified in clause 4. This does not affect the right to object under clause 9.
8. Security
8.1 Aurifex implements appropriate technical and organisational measures under Article 32 UK GDPR, having regard to the state of the art, the costs of implementation, and the nature, scope and purposes of processing. These measures include:
- encryption of personal data in transit and at rest;
- logical separation of each organisation’s data, enforced at the data layer rather than solely within the application;
- role-based access control within each organisation;
- restriction and logging of privileged operations;
- maintenance of an attributable record of changes to financial records.
8.2 No method of transmission or storage is entirely secure. Aurifex does not warrant that these measures will prevent every unauthorised access, and account holders remain responsible for the security of their credentials.
8.3 Where a personal data breach is likely to result in a risk to the rights and freedoms of data subjects, Aurifex will notify the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours of becoming aware of it, and will notify affected controllers without undue delay.
9. Rights of data subjects
9.1 Subject to the conditions in the applicable legislation, data subjects have the right to request access to their personal data; rectification of inaccurate data; erasure; restriction of processing; a portable copy of data processed by automated means on the basis of contract or consent; and to object to processing carried out on the basis of legitimate interests.
9.2 Requests should be sent to aurifex.digital@gmail.com. Aurifex will respond within one month of receipt. That period may be extended by two further months where a request is complex, in which case the data subject will be informed within the first month.
9.3 Where Aurifex acts as a processor, requests will be referred to the relevant controller in accordance with clause 2.3.
9.4 Data subjects have the right to lodge a complaint with the Information Commissioner’s Office (ico.org.uk) or, in the European Economic Area, with their local supervisory authority.
10. Cookies and similar technologies
10.1 The Service sets cookies that are strictly necessary for its operation: authentication cookies that maintain a signed-in session, and preference cookies that store display settings selected by the user. These are exempt from the consent requirement under regulation 6(4) of the Privacy and Electronic Communications (EC Directive) Regulations 2003.
10.2 No advertising, cross-site tracking or profiling cookies are set. Session replay and automatic capture of user interactions are disabled.
11. Children
11.1 The Service is intended for use by businesses and is not directed at children. Aurifex does not knowingly process the personal data of any person under 16.
12. Changes and contact
12.1 This notice may be amended from time to time. The effective date and version above will be revised, and account holders will be notified by email in advance of any change that materially affects their rights.
12.2 Enquiries and requests: Aurifex Digital, aurifex.digital@gmail.com.
Annex A — Sub-processors
The following sub-processors are engaged in the provision of the Service. Aurifex will give notice of any intended addition or replacement, and the subscribing organisation may object on reasonable data protection grounds.
| Sub-processor | Processing activity | Location |
|---|---|---|
| Supabase | Database hosting and authentication | United Kingdom (London) |
| Vercel | Application hosting and delivery | United Kingdom (London) |
| Resend | Transactional email delivery | Ireland |
| Sentry | Error and performance monitoring | Germany |
| PostHog | Product analytics | European Economic Area |
| Cloudflare | Domain name resolution only; no Customer Data is processed | Global anycast network |
The Service also retrieves published foreign exchange reference rates from a public feed. That request transmits no personal data.