← Aubora

Aubora: Privacy Policy

Last updated: August 12, 2026

Publisher: Arthur Franco, acting on behalf of Aubora, a company in formation (société en formation), Paris, France
Contact: contact@aubora.co

This policy covers the aubora.co website and the role Aubora plays behind its products. Each product also has its own privacy policy, and that policy is the one that governs the product itself.

The short version

This site sets no cookies and has no accounts. Visiting it produces at most two things: hosting logs at Vercel, and cookieless aggregate audience statistics on the pages that carry the measurement script. The fonts are served from this site itself, so no font request reaches a third party. No form on this site is wired to a server: if you write to us, we process your email in order to reply. Our products are built so that, in normal use, your data does not reach Aubora. There is one exception: the private alpha of Cerno, where we hold tester accounts and the CVs testers upload, governed by Cerno’s own privacy policy.

The sections below set out the legal detail.

1. Who is responsible (the controller)

The controller for this website is Arthur Franco, acting on behalf of Aubora, a company in formation (société en formation), Paris, France. Aubora is not yet registered and has no legal personality of its own, so the controller’s obligations are carried personally by its founder.

Article 13(1)(a) of the GDPR requires the controller’s identity and contact details: a named natural person, the city where he operates, and three working email addresses that reach him directly (section 11). Once the company is registered, we will update this page with its registered name and SIREN number, and the company will take over the processing described here.

No data protection officer is designated, and none is required. The thresholds in article 37(1) of the GDPR are not met: we are not a public authority, and our core activities consist neither of regular and systematic monitoring of data subjects on a large scale nor of large-scale processing of special categories of data or of data relating to criminal convictions and offences. privacy@aubora.co is our privacy contact point. It is not a data protection officer address.

2. Visiting aubora.co

(a) Hosting and server logs. The site is a set of static pages hosted by Vercel Inc., which acts as our processor. Serving a page produces a server log entry containing your IP address, the request method, the path and query string requested, the timestamp, the HTTP status returned, your browser’s user agent string, the referring page, the Vercel edge region that handled the request, and a request identifier. We use these logs to deliver the site, keep it secure, prevent abuse, and debug problems. The legal basis is our legitimate interest under article 6(1)(f) of the GDPR, and that interest is keeping the site available and secure. Logs are kept only for the limited period necessary for those purposes, then deleted. Article 13(2)(a) of the GDPR asks for the storage period or, where that cannot be given, the criteria used to determine it. Retention here is set by Vercel’s log windows rather than by a period we choose, so we state the criterion. Vercel also processes limited operational data as an independent controller, under its own privacy notice, which you can read at vercel.com/legal/privacy-notice.

(b) Audience measurement. We use Vercel Web Analytics, a cookieless measurement script served from /_vercel/insights/script.js. It stores nothing at all on your device: no cookies, no local storage. For each page view it sends the page URL, the route pattern, filtered query parameters, the referrer when you arrive from another site, a timestamp and the script version. When you click a Verto download button it also sends a named event (“download”) with the platform you chose, Apple Silicon or Intel. From the request itself, Vercel additionally derives and stores an approximate location (country, region, city), your device type, and your operating system and browser versions. Visitors are distinguished by a hash computed from the incoming request, which is discarded after 24 hours. The result is aggregate statistics about our own site, for our own use alone, with no cross-site tracking.

On consent, the position is this. Article 82 of the French loi Informatique et Libertés requires consent before information is read from or written to a visitor’s terminal, except where the operation has the sole purpose of carrying out or facilitating an electronic communication, or is strictly necessary to supply an online service expressly requested by the user. In its guidelines the CNIL treats trackers limited to audience measurement as falling within that second statutory exception, so no consent is required for them (CNIL Deliberation No. 2020-091, article 5). Our measurement falls within that exemption: it serves only to measure audience on our own site, its results are anonymous and aggregate, and the data is neither cross-referenced with other processing nor passed on to anyone. The processing of the resulting data rests on our legitimate interest under article 6(1)(f), which is understanding aggregate traffic to our own site.

3. Writing to us

Three addresses reach us: contact@aubora.co, privacy@aubora.co and security@aubora.co, with the roles set out in section 11. When you write, we process your email address, the content of your message and any attachments, and the history of our correspondence.

We use this to reply to you, to handle requests about your rights, and to handle security reports. For ordinary correspondence the basis is our legitimate interest under article 6(1)(f), which is answering the people who write to us. For requests about your data protection rights, the basis is our legal obligation under article 6(1)(c), since the GDPR requires us to respond.

Our mailboxes run on Google Workspace, and Google acts as our processor for their content. We delete ordinary correspondence after 24 months. We keep data protection requests and our answers for 3 years, as evidence that we handled them properly.

4. International transfers

Vercel Inc. and Google LLC are established in the United States, so the flows described in sections 2 and 3 involve a transfer outside the European Economic Area. Both companies are certified under the EU-U.S. Data Privacy Framework. Those transfers therefore rest on the European Commission’s adequacy decision of 10 July 2023, under article 45 of the GDPR. As a fallback, the standard contractual clauses adopted by the European Commission apply under each provider’s data processing agreement.

5. Aubora behind the products

Each product has its own privacy policy, which governs that product. This section says only where Aubora stands.

6. Special categories of data

The aubora.co website collects no special categories of personal data within the meaning of article 9 of the GDPR: no data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, and no genetic data, biometric data used to identify a person uniquely, data concerning health, or data concerning a person’s sex life or sexual orientation. This statement is about the website only. For the products, and for Cerno in particular, see the product policies listed in section 5.

7. Your rights

Under articles 15 to 21 of the GDPR you have the rights of access, rectification, erasure, restriction of processing, objection, and portability: you can ask what we hold, have it corrected or deleted, have its use limited, object to it, or receive it in a portable form.

The right to object deserves particular attention here. Almost everything described on this page rests on our legitimate interest: server logs, audience measurement, fonts, and ordinary correspondence. Article 21 of the GDPR lets you object to that processing on grounds relating to your particular situation, and if you do, we stop unless we can show compelling legitimate grounds that override your interests, rights and freedoms. The one exception is handling a data protection rights request, which rests on a legal obligation.

To exercise any of these rights, write to privacy@aubora.co. We answer within one month of receiving your request, as article 12(3) of the GDPR requires.

8. Complaining to a supervisory authority

You can lodge a complaint with the French supervisory authority, the Commission nationale de l’informatique et des libertés (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr, or with the supervisory authority of the country where you live.

9. No automated decision-making

This website takes no decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you, within the meaning of article 22 of the GDPR.

10. Changes to this policy

When our practices change, we update this page and the date shown at the top. Where a change is material, we note it on this page. We will also update it when Aubora is registered, to give the company’s registered name and SIREN number.

11. Contact