Privacy Policy
This policy explains how Aurexa Technologies Pte. Ltd. ("Aurexa", "we") collects, uses, and protects personal data across the Aurexa ecosystem: aurexa.tech, accounts.aurexa.tech, and the applications Counterpartly (counterpartly.com), Escrowz (escrowz.com), and AssessFit (assessfit.com). One Aurexa account works across all three applications, and this one policy covers them all.
1. Who we are
Aurexa Technologies Pte. Ltd.
68 Circular Road, #02-01, Singapore 049422
Contact: support@aurexa.tech
2. Data we collect
- Account data — name, email address, and sign-in identifiers, managed through our authentication provider.
- Company data — legal name, country, website, and registry information for the organization you represent.
- Business verification (KYB) data — when you choose to verify your company, our verification provider processes company registry records, corporate documents you submit, and details of key people (such as directors or beneficial owners), including screening against sanctions and watchlists. Verification is optional and free of charge; it is initiated only when you press the verification button.
- Transaction and activity data — records of deals, escrow transactions, assessments, and similar business activity conducted in the applications, including counterparty identifiers, amounts, statuses, and timestamps.
- Technical data — IP address, browser information, and logs necessary to operate and secure the services.
3. The trust profile
The core of Aurexa is a portable trust profile: a score and tier computed from your company's completed activity across the ecosystem (for example, completed escrow transactions or verified company status). By design, your company's trust score, tier, transaction count, and dispute rate are visible to prospective counterparties inside the applications — that visibility is the product's purpose. The underlying documents and personal details from verification are not shared with counterparties; only the resulting verified status is.
4. How we use data
- To provide the services: matching, escrow, assessments, and cross-app sign-in.
- To verify companies (KYB) and maintain the integrity of the trust ledger.
- To prevent fraud and abuse, and to comply with legal obligations.
- To communicate about transactions and account matters (e.g. escrow invitations, verification results).
We do not sell personal data, and we do not use it for third-party advertising.
5. Service providers
We use a small number of processors to run the services:
| Provider | Purpose |
|---|---|
| Clerk | Authentication and single sign-on (accounts.aurexa.tech) |
| Didit | Business verification (KYB), registry and sanctions screening |
| Vercel | Hosting and content delivery |
| Neon | Database infrastructure (Singapore region) |
| Inngest | Background job processing |
| Resend | Transactional email |
| Stripe | Payments, where applicable |
Each provider processes data only as needed to deliver its function, under its own contractual and security obligations. Some providers operate internationally; where data leaves Singapore, we rely on the providers' standard safeguards for international transfers.
6. Retention
- Account and company data are kept for as long as your account is active.
- A successful company verification is valid for one year; verification records are retained as required for compliance and audit purposes.
- Transaction records that feed the trust ledger are retained while the ledger operates, since deleting history would falsify reputations that counterparties rely on.
7. Your rights
Subject to the Singapore Personal Data Protection Act (PDPA) and other applicable law, you may request access to, correction of, or deletion of your personal data, and you may withdraw consent to further processing. Write to support@aurexa.tech and we will respond within a reasonable time. Note that deleting data that other parties' trust records depend on (e.g. completed transactions) may be replaced by anonymization rather than erasure.
8. Security
Data is encrypted in transit, access to production systems is restricted and key-based, verification webhooks are cryptographically signed, and API access between our applications requires per-application keys. No system is perfectly secure; if we become aware of a breach affecting your data, we will notify you as required by law.
9. Changes
We may update this policy as the services evolve. Material changes will be announced in the applications or by email. The effective date above always reflects the current version.