Privacy Policy
Version: 3.7
Effective date: 2026-07-01
Last updated: 2026-07-27
1. General Information
This Privacy Policy explains how Aulisco collects, uses, stores, shares, and protects personal data processed through the aulisco.com website, its administrative areas, and its audit, verification, intelligence, scoring, monitoring, and Blacklist services.
This Privacy Policy applies to website visitors, registered users, clients, audit applicants, individuals or organizations submitting reports, subjects included in Blacklist cases, persons exercising a right of reply or requesting corrections, and anyone who communicates with Aulisco.
2. Data Controller
The controller responsible for processing personal data is:
TRADING COMPANY SERVICES LIMITED
Registered office: CARIOCCA BUSINESS CENTER A
Privacy email: privacy@aulisco.com
In this Privacy Policy, the controller is referred to as “Aulisco,” “we,” “us,” or “the Controller.”
3. Personal Data We Process
Depending on how you use the platform, Aulisco may process the following categories of personal data.
3.1 Identification and contact data
This may include:
first and last name;
company or organization name;
professional role;
email address;
telephone number;
postal address;
country;
account details;
information included in communications sent to Aulisco.
3.2 Account and authentication data
When an account is created or used, we may process:
username;
email address;
encrypted password;
assigned role and permissions;
account status;
login date and time;
authentication records;
IP address;
security and access logs.
Passwords are not stored in readable form.
3.3 Audit request and client data
When an audit or assessment is requested, we may process:
applicant identity and contact details;
organization details;
contractual and billing information;
audit scope;
systems, assets, websites, wallets, smart contracts, infrastructure, documents, and processes submitted for review;
communications between the client and Aulisco;
project status, findings, scores, remediation activities, and reports.
3.4 Technical, financial, compliance, and evidentiary data
Depending on the audit or investigation, we may process:
technical configurations;
source code or code excerpts;
wallet addresses and blockchain transaction data;
public financial or corporate information;
compliance documentation;
risk indicators;
security findings;
audit evidence;
reports, screenshots, files, URLs, logs, correspondence, and supporting materials.
Such information may contain personal data relating to employees, representatives, customers, contractors, counterparties, or other individuals.
3.5 Blacklist reports and risk intelligence data
When a report is submitted or a Blacklist case is created, Aulisco may process:
names of individuals, companies, websites, platforms, brokers, intermediaries, or other entities;
aliases, trading names, domains, email addresses, telephone numbers, social media profiles, wallet addresses, and other identifiers;
descriptions of alleged conduct;
documents, contracts, screenshots, payment records, correspondence, and other evidence;
information obtained from public registers, regulatory authorities, court records, sanctions lists, warning lists, news sources, websites, and open-source intelligence;
reporter contact details;
responses, objections, correction requests, and supporting documentation submitted by the subject of a report.
Aulisco distinguishes, where applicable, between official warnings, documented public information, user-submitted allegations, internal assessments, and verified findings.
Submission of a report does not automatically result in public publication.
3.6 Right of reply and correction request data
When a person or organization exercises a right of reply or requests correction, we may process:
identity and contact information;
proof of authority or representation;
the challenged publication or case;
explanations, objections, and requested actions;
supporting documents;
correspondence and review outcomes.
3.7 Publicly available data
Aulisco may collect and process information lawfully available from sources such as:
regulatory and supervisory authorities;
official warning lists;
sanctions databases;
company and professional registers;
court or administrative decisions;
public websites;
public blockchain networks;
public reports and databases;
reputable news and open-source intelligence sources.
Public availability does not remove the need for lawful, proportionate, and accurate processing.
3.8 Website and technical usage data
When you access the website, we may automatically collect:
IP address;
browser type and version;
operating system;
device information;
requested pages;
timestamps;
referrer information;
session identifiers;
technical error logs;
security events;
activity and audit logs.
4. Purposes of Processing
Aulisco may process personal data for the following purposes:
operating, maintaining, and securing the website and platform;
creating and managing user accounts;
authenticating users and enforcing permissions;
receiving and responding to contact requests;
evaluating and managing audit requests;
providing audit, scoring, compliance, monitoring, and intelligence services;
collecting and reviewing audit evidence;
preparing, issuing, verifying, updating, or revoking reports;
publishing public verification pages where authorized;
receiving, reviewing, and managing Blacklist reports;
identifying duplicates, related entities, and risk indicators;
verifying information against public and authoritative sources;
monitoring relevant sources for changes;
allowing subjects to submit replies, objections, and corrections;
preventing fraud, abuse, false reporting, unauthorized access, and security incidents;
maintaining evidentiary, integrity, and activity logs;
meeting legal, regulatory, contractual, and accounting obligations;
establishing, exercising, or defending legal claims;
improving the reliability, usability, and performance of the platform;
sending service-related or administrative communications.
Aulisco does not make public accusations solely because an unverified report has been submitted.
5. Legal Bases for Processing
Depending on the circumstances, Aulisco may rely on one or more of the following legal bases:
5.1 Performance of a contract
Processing may be necessary to:
evaluate a service request;
enter into or perform an audit agreement;
provide requested services;
manage the client relationship;
issue reports and deliverables.
5.2 Steps taken before entering into a contract
Processing may be necessary to respond to enquiries, prepare proposals, assess an audit scope, or determine whether Aulisco can provide a requested service.
5.3 Compliance with legal obligations
Processing may be required for:
accounting and tax obligations;
responding to lawful requests;
record retention;
regulatory cooperation;
security, fraud-prevention, and reporting obligations.
5.4 Legitimate interests
Aulisco may process data where necessary for legitimate interests such as:
protecting users, clients, and the public from fraud and abuse;
maintaining accurate risk intelligence;
conducting due diligence;
verifying reports and supporting evidence;
protecting the security and integrity of the platform;
preventing duplicate, malicious, or fraudulent submissions;
defending legal rights;
improving services;
publishing proportionate public-interest information supported by an appropriate legal and factual basis.
Before relying on legitimate interests, Aulisco considers the necessity and proportionality of the processing and the rights and expectations of the affected individuals.
5.5 Consent
Where required, Aulisco may rely on consent, for example for optional communications, non-essential cookies, or specific voluntary processing activities.
Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
5.6 Establishment, exercise, or defence of legal claims
Where information includes sensitive or legally protected data, processing may be necessary to establish, exercise, or defend legal claims, subject to applicable law.
6. Blacklist and Risk Registry Processing
The Aulisco Blacklist is intended to provide structured risk intelligence and documented information. It is not intended to declare that a person or organization is criminal, fraudulent, or legally liable without an appropriate and reliable basis.
Cases may be classified according to their origin and level of verification, including:
official regulatory warnings;
public authority notices;
sanctions or enforcement actions;
public judicial or administrative records;
verified documentary evidence;
open-source intelligence;
user-submitted reports under review;
disputed or corrected information;
archived or superseded records.
Before publication, Aulisco may assess:
source reliability;
relevance;
evidence quality;
public interest;
proportionality;
accuracy;
current status;
potential harm to affected persons;
availability of a right of reply.
A subject may request access, correction, contextualization, restriction, removal, or publication of a reply, as permitted by applicable law.
The absence of a person or organization from the Blacklist does not constitute certification of legitimacy, solvency, security, or trustworthiness.
7. Automated Analysis and Scoring
Aulisco may use automated tools to assist with:
data organization;
duplicate detection;
source comparison;
risk indicator identification;
monitoring;
prioritization;
preliminary scoring;
classification of audit evidence.
Automated outputs may support human review but should not, by themselves, be treated as definitive legal conclusions.
Where a decision produces legal or similarly significant effects, Aulisco will apply the safeguards required by applicable law, including human intervention where appropriate.
8. Data Sources
Personal data may be obtained:
directly from the data subject;
from clients or authorized representatives;
from reporters or complainants;
from audited organizations;
from public authorities and regulatory bodies;
from official registers;
from public blockchain networks;
from public websites and databases;
from contractual counterparties;
from service providers;
from open-source intelligence and reputable media sources.
Where data is obtained indirectly, Aulisco will provide the required information unless an applicable legal exception applies.
9. Data Sharing and Recipients
Aulisco may share personal data only where necessary with:
authorized employees, analysts, auditors, moderators, and administrators;
hosting, infrastructure, security, backup, email, and technical service providers;
professional advisers, including lawyers, accountants, and auditors;
contractors supporting an audit or investigation;
regulatory, judicial, law-enforcement, or public authorities where legally required;
business partners where necessary for a requested service and subject to appropriate safeguards;
a prospective purchaser or successor in connection with a lawful corporate transaction.
Service providers may process data only under appropriate contractual and confidentiality obligations.
Aulisco does not sell personal data.
10. Public Disclosure
Certain information may be made publicly available where necessary for:
publishing a verified audit report;
providing a public verification page;
displaying an organization’s score;
publishing a documented Blacklist record;
publishing an official warning, source, response, correction, or status update.
Before publication, Aulisco will seek to limit the information to what is necessary and proportionate.
Confidential evidence, private contact details, identification documents, internal communications, and sensitive personal data will not normally be published unless lawful, necessary, and justified.
11. International Data Transfers
Some service providers may process data outside the European Economic Area or the country in which the user is located.
Where required, Aulisco will use appropriate safeguards, such as:
adequacy decisions;
standard contractual clauses;
contractual and technical protections;
supplementary security measures.
Information about relevant safeguards may be requested using the privacy contact details provided in this Policy.
12. Data Retention
Personal data is retained only for as long as reasonably necessary for the relevant purpose, including legal, contractual, evidentiary, security, and compliance requirements.
Indicative retention periods may include:
contact enquiries: [PERIOD];
client and contractual records: [PERIOD];
billing and accounting records: as required by applicable law;
audit evidence and reports: [PERIOD];
account and security logs: [PERIOD];
rejected or incomplete reports: [PERIOD];
Blacklist cases and evidence: for as long as necessary to maintain an accurate historical and evidentiary record, subject to periodic review;
right-of-reply and correction records: for as long as the related publication or legal risk remains relevant;
consent records: for the duration necessary to demonstrate compliance.
Public records may be corrected, updated, archived, restricted, or removed where continued publication is no longer necessary, accurate, lawful, or proportionate.
13. Data Accuracy
Aulisco takes reasonable measures to ensure that personal data and public records are accurate, relevant, and current.
Because some information is received from third parties or public sources, Aulisco cannot guarantee that every submitted statement is correct at the time it is received.
Affected persons are encouraged to report inaccuracies and provide supporting evidence through the available correction or contact procedures.
14. Data Security
Aulisco applies appropriate technical and organizational measures designed to protect personal data, including:
access controls;
role-based permissions;
password hashing;
encrypted communications;
logging and monitoring;
backup procedures;
integrity controls;
security updates;
incident management;
restricted access to evidence and administrative areas.
No system can guarantee absolute security. Users should protect their credentials and notify Aulisco promptly of suspected unauthorized access.
15. Cookies and Similar Technologies
Aulisco may use cookies or similar technologies necessary for:
authentication;
session management;
security;
user preferences;
platform functionality;
fraud prevention.
Non-essential analytics or marketing cookies will be used only where permitted and, where required, after obtaining consent.
Detailed information may be provided in a separate Cookie Policy or consent interface.
16. Your Data Protection Rights
Subject to applicable law, you may have the right to:
request access to your personal data;
request correction of inaccurate or incomplete data;
request deletion of personal data;
request restriction of processing;
object to processing based on legitimate interests;
withdraw consent;
request data portability;
request information about data sources and recipients;
object to certain automated decisions;
request human review;
lodge a complaint with a competent supervisory authority.
These rights are not absolute. A request may be restricted where processing is necessary for legal obligations, freedom of expression and information, public-interest purposes, legal claims, fraud prevention, security, or the rights of others.
17. Rights Relating to Blacklist Records
A person or organization mentioned in a Blacklist record may request:
access to the relevant personal data;
identification of the categories of sources used, where disclosure is lawful;
correction of inaccurate information;
addition of contextual information;
publication of a response;
restriction of processing;
review of the classification or status;
removal or de-indexing where legally required;
notification of a material correction.
Aulisco may request proof of identity, authority, or representation before processing the request.
A request will not automatically result in removal where continued processing is lawful, accurate, necessary, proportionate, and supported by overriding grounds.
18. Exercising Your Rights
Requests may be sent to:
Privacy email: [PRIVACY EMAIL]
Please include:
your name;
sufficient information to identify the relevant data or record;
the right you wish to exercise;
supporting documentation where necessary;
proof of authority if acting for another person or organization.
Aulisco may request additional information to verify identity and prevent unauthorized disclosure.
Requests will be handled within the period required by applicable law.
19. Complaints
You may lodge a complaint with the data protection supervisory authority responsible for your country of residence, workplace, or the location of the alleged infringement.
Before submitting a complaint, you may contact Aulisco so that we can attempt to address the matter directly.
20. Children
Aulisco’s professional audit and intelligence services are not directed at children.
We do not knowingly create accounts for or collect personal data directly from children without an appropriate lawful basis and required authorization.
21. Third-Party Links
The website may contain links to third-party websites, registers, authorities, reports, or services.
Aulisco is not responsible for the privacy practices, security, availability, or content of third-party websites. Users should review the privacy policies of those services separately.
22. Changes to This Privacy Policy
Aulisco may update this Privacy Policy to reflect:
legal or regulatory changes;
changes to services;
new processing activities;
security requirements;
operational improvements.
The updated version and effective date will be displayed on this page.
Material changes may also be communicated through the website, account area, or email where appropriate.
23. Contact
For questions about this Privacy Policy or Aulisco’s processing of personal data, contact:
TRADING COMPANY SERVICES LIMITED
CARIOCCA BUSINESS CENTER A
General email: contact@aulisco.com
Privacy email: privacy@aulisco.com
Website: aulisco.com