Customer data

Data Processing Addendum

Effective August 29, 2026. This Addendum applies when Faris Akroush, operating as Made by Auren, processes personal information on behalf of a business customer through hosted website tools. It supplements the Terms and project checkout summary.

Roles and instructions

The customer is the business, controller, or equivalent party that determines why visitor information is processed. Made by Auren is the service provider, contractor, processor, or equivalent party for that customer data. Made by Auren processes it only to provide, secure, support, restore, and improve the contracted service; follow documented customer instructions; or comply with law. Made by Auren will notify the customer when an instruction appears unlawful unless prohibited from doing so.

Covered data

Covered data may include visitor contact details, inquiries, appointment requests, wholesale details, newsletter consent, first-party analytics events, order and delivery information, membership information, support communications, and related security identifiers. The service is not approved for protected health information, complete payment-card data, government identity records, bank credentials, children’s data, or other sensitive categories unless a separate written agreement expressly approves them.

Confidentiality and security

Access is limited to people and providers who need it and are subject to confidentiality duties. Controls include transport encryption, restricted server-side credentials, role-based access, multi-factor owner administration, input validation, rate limits, bot controls, signed payment events, audit records, non-cacheable authenticated pages, backup review, retention jobs, and incident escalation. No control eliminates all risk.

Subprocessors

The customer authorizes the subprocessors below for the stated functions. Made by Auren remains responsible for selecting providers with appropriate contractual and security commitments and will update this list before adding a materially new processing category.

Requests, incidents, and cooperation

Made by Auren will reasonably assist with verified data-subject requests, security assessments, legally required records, and customer breach duties in light of the processing and information available. After confirming a security incident involving customer data, Made by Auren will notify the affected customer without undue delay, provide known material facts, take reasonable containment and remediation steps, and update the customer as the investigation develops.

Deletion, return, and legal holds

Customers may export eligible account records and request reviewed deletion. At termination, customer-site data follows the Privacy Policy and 180-day restore/archive workflow. Billing, tax, consent, suppression, dispute, fraud, security, backup, and legal-hold records may be retained when reasonably necessary or required. Data no longer needed is removed through controlled provider and application retention cycles.

Location and transfers

Providers may process data in the United States and other locations where they operate. A customer requiring a specific international transfer mechanism, data-residency commitment, sector agreement, or regulator-specific term must obtain written approval before using the affected feature.

Audits and priority

Made by Auren will provide reasonable current security and subprocessor information. Any extraordinary on-site audit requires advance agreement on scope, confidentiality, timing, cost, and protection of other customers. If this Addendum conflicts with the Terms solely about processing customer data, this Addendum controls for that issue.

Contact

Privacy and processing requests may be sent to support@madebyauren.com.