Legal
Privacy notice
Last updated: 16 August 2026
This notice describes which personal data are processed when you use Goldthread, for what purpose, on what legal basis, who receives them and how long they are kept. A separate notice applies to the aurinexis.com website.
1. Controller
Aurinexis Ltd, a private company limited by shares under the Companies Act 2001 (Mauritius).
Registered Office: 20 Vandermeersch Street, Rose-Hill 71367, Republic of Mauritius.
Data protection contact: legal@aurinexis.com
Goldthread is a working platform that Aurinexis operates for the delivery of consulting projects. For the content a client records on its project board, Aurinexis acts on that client's behalf; the client is then the controller, and the data processing addendum from the consulting contract applies in addition. For account, sign-in and log data, Aurinexis is itself the controller.
The Mauritius Data Protection Act 2017 applies. Where processing has a sufficient link to the EU, the EEA or Switzerland, we additionally observe the GDPR and the revised Swiss Federal Act on Data Protection.
2. What data are processed
Account data — Email address, password (only as a cryptographic hash), time of the most recent sign-in and of the invitation being confirmed.
Profile data — Display name, chosen language, time zone.
Content you enter yourself — Board, list and card titles, descriptions, checklists, comments, due dates and uploaded attachments (images and PDF). These fields are free text: what goes into them is your decision. Please do not enter special categories of personal data (such as health or identity document data) or confidential third-party data.
Activity history — Who created, moved or changed which card and when, including the display name valid at the time of the action.
Security log — For sign-ins, permission changes and certain administrative operations we store the time, the person acting and the type of operation. The IP address and browser identification (user agent) are stored for successful and for refused sign-in attempts, and for calendar-feed reads. For a refused attempt we do not store the address that was typed in clear text, only an irreversible checksum of it; if it belongs to an existing account, that account is named, otherwise the address stays unreadable. Refused sign-in attempts are deleted after 90 days.
Calendar feeds — If you generate a calendar link and subscribe to it in a calendar application, we log every retrieval with time, IP address and browser identification of the retrieving application. This also affects people you pass the link on to — they need no account, and their retrievals are logged in the same way.
Cookies — Two technically necessary cookies: the session cookie for sign-in and a cookie named “locale” for your language choice. We do not use analytics, tracking or marketing cookies.
3. Purposes and legal bases
Providing the platform — Account, profile, content, activity history. Legal basis: Article 6(1)(b) GDPR (performance of the contractual relationship under which access was granted to you) or (f) (legitimate interest in collaborating on the project); section 28(1)(b) and (f) Mauritius DPA 2017.
Security and accountability — Security log including IP address. Legal basis: Article 6(1)(f) GDPR. The legitimate interest is investigating unauthorised access and keeping permission changes traceable. That includes recognising repeatedly refused sign-in attempts — without this record, systematic password guessing could not be told apart from a forgotten password. For anonymous calendar retrievals, the IP address is the only attribute that makes misuse of the link detectable at all.
AI features — See section 4.
Account email — Invitations, confirmation and reset links. These messages are required for access itself. Legal basis: Article 6(1)(b) GDPR.
Notifications — Email notices when a card is assigned to you, a comment is added, or a due date approaches. Legal basis: Article 6(1)(f) GDPR — legitimate interest in letting you learn what happens on your boards without keeping the application open; section 28(1)(f) Mauritius DPA 2017. Unlike account email, this processing is not necessary to perform the contract, and you may object to it at any time (section 8). In practice you exercise that objection through the switches in your profile: you turn each of the three occasions off individually and choose how often notices are bundled. The message itself contains no card, list or comment text — only the name of the board, the number of occasions, and a link into the application.
4. AI features
Goldthread offers two features that transmit text to a language model: generating cards from a description of a goal, and suggesting categories for an existing card. Both run only when explicitly triggered — nothing happens in the background.
What is transmitted is exactly the text the feature needs. For card generation, that is your input. For category suggestions, it is the title and description of the card concerned, the category names present on the board, the titles of all lists on the board, and the titles of up to 15 further cards from the same board — that context is what lets the model see which categories fit this board. Your name, your email address, the descriptions of other cards, comments, checklists and attachments are not transmitted.
Processing runs through a gateway in Frankfurt and a model in the Google Cloud data centre in Belgium (europe-west1). Neither provider uses the transmitted content to train its models. The gateway operator stores requests and responses encrypted within the EU for up to 30 days to enable billing, troubleshooting and abuse detection.
The features may be switched off for individual boards and individual accounts. Where they are, no content from that board leaves the platform towards an AI provider.
Legal basis: Article 6(1)(f) GDPR — legitimate interest in supporting project work. You may object to this use (section 8); the features are not required in order to work with a board.
The output of a language model can be incorrect. Only suggestions are produced, and a human decides on them; we make no automated individual decisions producing legal or similarly significant effects within the meaning of Article 22 GDPR.
5. Recipients
| Recipient | Task | Place of processing |
|---|---|---|
| Vercel Inc. | Application hosting, access logs | Dublin, Ireland (EU); corporate seat United States |
| Supabase Pte. Ltd | Database, authentication, file storage, realtime updates | Ireland (EU); corporate seat Singapore |
| Requesty Ltd | AI gateway — routing and logging (only where the AI features are used) | Frankfurt, Germany (EU); corporate seat United Kingdom |
| Google LLC | Execution of the language model (only where the AI features are used) | Belgium (EU); corporate seat United States |
| Infomaniak Network SA | Delivery of system email | Switzerland |
Beyond this we disclose data only where a legal obligation requires it. With every provider named above we have the data processing agreements required under applicable data protection law.
International transfers — The data is stored exclusively in data centres in the EU and in Switzerland. That does not settle the question, however: several of the providers have their corporate seat outside the EU, and administrative access from there is, in data protection terms, processing at that location and at the same time a transfer to it — safeguarded by EU Standard Contractual Clauses. For Switzerland, an adequacy decision of the European Commission is in place. Aurinexis itself is seated in Mauritius, for which no adequacy decision exists; transfers there are based on EU Standard Contractual Clauses. Section 36 of the Mauritius Data Protection Act 2017 applies in addition to transfers out of Mauritius.
6. Retention
| Data | Duration |
|---|---|
| Account and profile data | until the account is deleted |
| Content and attachments | until you delete them; at the latest on completion of the project, as set out in the consulting contract |
| Activity history | 90 days |
| Security log including IP address | 12 months; refused sign-in attempts 90 days |
| Log of calendar retrievals | 12 months |
| Notification dispatch log (who was told about what — without content) | 30 days from dispatch; the cleanup job runs daily. Entries that were never dispatched — for instance because notifications were switched off before their turn came — and entries that could not be delivered remain as a record and as error diagnostics; they fall away as soon as the board they belong to, or the account, is deleted |
| Session cookie | until sign-out or expiry of the session |
| Language cookie | until deleted in the browser |
When the project ends, content is returned or deleted according to the rules agreed in the consulting contract. Backup copies expire with the ordinary backup cycle.
7. Security
Access is encrypted throughout (HTTPS). Boards are isolated from one another at database level: every query checks the permission of the requesting person, independently of the interface. Attachments are held in non-public storage and are reachable only through time-limited links. Administrative access is limited to what is necessary and is logged.
8. Your rights
You have the right of access, rectification, erasure, restriction of processing and data portability, as well as the right to object to processing based on a legitimate interest. You may withdraw consent at any time with effect for the future.
To exercise these rights, contact legal@aurinexis.com. We reply within the statutory deadlines, ordinarily within 30 days.
Where access was granted to you by your employer or client, requests concerning the content of the boards go to them first; we support them in this and forward your request.
9. Right to complain
You can contact us at any time: legal@aurinexis.com. Independently of that, you may turn to a supervisory authority:
- Mauritius — Data Protection Office: dataprotection.govmu.org
- EU/EEA — the data protection supervisory authority competent for your residence, your place of work or the place of the alleged infringement.
- Switzerland — Federal Data Protection and Information Commissioner: edoeb.admin.ch
10. Changes
We update this notice when the data processed, the purposes, the recipients, the storage locations or the legal bases change. The current version is available at this address; the date above indicates the last change.