Privacy Policy
Last Updated: 10 February 2026
Introduction
Harnex AI Limited, trading as AuraScope (we, us, our) is committed to complying with the New Zealand Privacy Act 2020 and other applicable privacy laws (together, the Laws) when dealing with personal information. Personal information is information about an identifiable individual (a natural person).
This policy sets out how we will collect, use, disclose and protect your personal information.
This policy does not limit or exclude any of your rights under the Laws.
Changes to This Policy
We may change this policy by uploading a revised policy onto the website. The change will apply from the date that we upload the revised policy.
Who Do We Collect Your Personal Information From
We collect personal information about you from:
- You, when you provide that personal information to us, including via the website and any related service, through any registration or subscription process, through any contact with us (e.g. telephone call or email), or when you sign up for our beta waitlist or use our services and products
- Third parties where you have authorised this or the information is publicly available
- AI platforms and search engines that we monitor as part of our service delivery
If possible, we will collect personal information from you directly.
Personal Information We Collect
We collect personal information that you provide directly to us, including:
- Account information (name, email address, company name)
- Brand and website information you provide for visibility monitoring, including website URLs, industry, and geographic targeting preferences
- Website content that we retrieve from URLs you provide, including page text and metadata, to power our analysis features
- Usage data related to your use of the AuraScope platform (e.g. audit history, feature interactions)
- Communications and correspondence with our support team
How We Use Your Personal Information
We will use your personal information:
- To verify your identity and manage your account
- To provide services and products to you, including AI visibility monitoring and Answer Engine Optimisation (AEO) analytics
- To send you platform updates, visibility reports, and AEO recommendations
- To improve the services and products that we provide to you
- To respond to communications from you, including support requests and complaints
- To conduct research and statistical analysis (on an anonymised basis) to improve our AI monitoring algorithms
- To protect and/or enforce our legal rights and interests, including defending any claim
- For any other purpose authorised by you or the Laws
Disclosing Your Personal Information
We may disclose your personal information to:
- Another company within our group (Harnex AI Limited and its subsidiaries)
- Any business that supports our services and products, including:
- Supabase (authentication, database hosting, and transactional email such as login confirmations and magic links)
- AI platform APIs (including OpenAI, Google Gemini, and Perplexity) for monitoring how your brand appears in AI-generated responses
- OpenRouter (API routing service used to relay queries to AI platforms on your behalf)
- Web content retrieval services (including Firecrawl and Crawl4AI) used to analyse website content you provide for monitoring
- Other third parties (for anonymised statistical information only)
- A person who can require us to supply your personal information (e.g. a regulatory authority)
- Any other person authorised by the Laws (e.g. a law enforcement agency)
- Any other person authorised by you
A business that supports our services and products may be located outside New Zealand. This may mean your personal information is held and processed outside New Zealand, including in the United States and European Union.
We may transfer your information in the case of a sale, merger, consolidation, liquidation, reorganisation or acquisition.
Data Retention
We retain your personal information for as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. When you close your account, we will initiate deletion of your personal information. Deletion is carried out progressively and is typically complete within 90 days, except where we are required to retain data by law. Some data may be retained in anonymised or aggregated form for statistical purposes.
Your Rights
Subject to certain grounds for refusal set out in the Laws, you have the right to:
- Access your personal information that we hold
- Request correction of your personal information
- Request deletion of your personal information
- Object to processing of your personal information
- Request restriction of processing your personal information
- Request transfer of your personal information to another service provider
Before you exercise these rights, we will need evidence to confirm that you are the individual to whom the personal information relates.
In respect of a request for correction, if we think the correction is reasonable and we are reasonably able to change the personal information, we will make the correction. If we do not make the correction, we will take reasonable steps to note on the personal information that you requested the correction.
If you want to exercise any of the above rights, email us at hello@harnex.ai. Your email should provide evidence of who you are and set out the details of your request.
We may charge you our reasonable costs of providing to you copies of your personal information or correcting that information.
Protecting Your Personal Information
We will take reasonable steps to keep your personal information safe from loss, unauthorised activity, or other misuse. These steps include:
- Use of modern cloud infrastructure and security best practices to protect customer data.
- Row-level security controls ensuring users can only access their own data
- Access controls and authentication measures, including secure HttpOnly cookies
- Regular backups and disaster recovery procedures
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.
Internet Use
While we take reasonable steps to maintain secure internet connections, if you provide us with personal information over the internet, the provision of that information is at your own risk.
If you post your personal information on the website, you acknowledge and agree that the information you post is publicly available.
If you follow a link on our website to another site, the owner of that site will have its own privacy policy relating to your personal information. We suggest you review that site's privacy policy before you provide personal information.
Third-Party Services
Our Service integrates with and relies on the following categories of third-party services: AI Platforms Monitored — We query AI platforms including OpenAI (ChatGPT), Google (Gemini), and Perplexity to monitor how they describe and recommend your brand. Queries contain brand-related prompts and do not include your personal account information. API Routing — We use OpenRouter as an intermediary to route queries to certain AI platforms. OpenRouter processes the query content but does not receive your personal account information. Authentication and Database — We use Supabase for user authentication (including login, email verification, and magic links) and as our primary database host. Supabase stores your account information and audit data on secure infrastructure. Web Content Retrieval — We use services such as Firecrawl and Crawl4AI to retrieve content from website URLs you provide for analysis. These services access publicly available web pages on our behalf. Each third-party service is subject to its own privacy policy and terms. We select service providers that maintain appropriate security and privacy standards.
Children's Privacy
Our services are not directed to children. If you are under 18 years old, you may only use the Service with the involvement of a parent or guardian. For users in the European Economic Area, you must be at least 16 years old to use the Service. If you become aware that a child has provided us with personal information, please contact us at hello@harnex.ai.
International Data Transfers
As AuraScope operates globally and uses service providers located in various countries, your personal information may be transferred to, stored, and processed in countries other than New Zealand, including the United States and European Union. We will take appropriate measures to ensure that transfers of personal information are in accordance with applicable law and carefully managed to protect your privacy rights and interests.
Changes to This Privacy Policy
We may update this privacy policy from time to time. We will notify you of any material changes by posting the new privacy policy on this page and updating the "Last Updated" date. You are advised to review this privacy policy periodically for any changes.
Contact Us
If you have any questions about this privacy policy, our privacy practices, or if you would like to request access to or correction of, your personal information, you can contact us at:
Email: hello@harnex.ai
Complaints
If you have a complaint about our handling of your personal information, please contact us at hello@harnex.ai. We will investigate your complaint and respond to you within a reasonable timeframe.
If you are not satisfied with our response, you may contact the New Zealand Privacy Commissioner:
Office of the Privacy Commissioner
PO Box 10094, Wellington 6143, New Zealand
Phone: 0800 803 909
Email: enquiries@privacy.org.nz
Website: www.privacy.org.nz
