Privacy Policy

Effective date: 21 July 2026
Last updated: 21 July 2026

1. Introduction

Aupy E.A.S., trading as AUPY Consultoria E.A.S. (“AUPY”, “we”, “us” or “our”), operates the website at aupy.consulting (the “Website”) and provides consultancy, business advisory, engineering and project services, local business support, and Employer of Record (EOR) services (together, the “Service”).

This page informs you of our policies regarding the collection, use, and disclosure of Personal Information when you use our Service, and the choices you have about that information. We are committed to handling your Personal Information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs); the EU and UK General Data Protection Regulation (GDPR) where it applies to you; and the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and the California Online Privacy Protection Act (CalOPPA), where you are a California resident.

If you choose to use our Service, you agree to the collection and use of information in accordance with this Policy. We will not use or share your information with anyone except as described here. For the purposes of the GDPR, AUPY is the data controller of your Personal Information. Terms used in this Policy have the same meanings as in our Terms & Conditions unless otherwise defined here.

2. Information Collection and Use

For a better experience while using our Service, and to provide and improve it, we may collect the following personally identifiable information, including but not limited to:

  • Identity and contact details — first name, last name, email address, phone / WhatsApp number, and postal address including street, city, state or province, postal / ZIP code, and country;
  • Business details — company or organisation name, job title, industry, seniority, and company size;
  • Social media information — profile information and interactions where you engage with us via social media platforms such as LinkedIn, or connect a social profile;
  • Enquiry and correspondence content — the type of enquiry and any information you include in a form, email, or message to us;
  • EOR and client engagement data — where we act as your Employer of Record or deliver services, information necessary to do so, which may include the details of your personnel (such as names, contact details, identification and payroll-related information) and your business, financial, project and contractual information; and
  • Technical data — as described in “Log Data” and “Cookies” below.

The information we collect will be used to contact or identify you, to respond to your enquiries, to provide and improve the Service, and for the purposes set out in section 8.

We do not seek to collect “sensitive information” (under the Privacy Act) or GDPR “special category” data through the Website. Where we handle such information in the course of EOR or client work, we do so only where necessary and with an appropriate lawful basis or your consent.

3. Log Data

Whenever you visit our Service, we collect information that your browser sends to us called Log Data. This Log Data may include information such as your computer’s Internet Protocol (“IP”) address, browser type and version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, approximate location derived from your IP address, and other diagnostic and statistical data.

4. Cookies

Cookies are files with a small amount of data that are commonly used as anonymous unique identifiers. They are sent to your browser from the websites you visit and stored on your device. Our Website uses cookies and similar technologies to operate the site, remember your preferences, measure performance, and support our analytics and advertising described below.

We categorise cookies as: strictly necessary (required for the site to function), analytics/performance, and advertising/targeting. Strictly necessary cookies are always active. We set analytics and advertising cookies only where you have given consent, and you can accept, refuse, or manage them at any time through our cookie banner / preference tool or your browser settings. If you refuse certain cookies, some portions of the Service may not function properly.

5. Analytics

We use third-party analytics tools to understand how visitors use our Service so we can improve it. These tools may collect information such as Log Data and set cookies. The providers we use may include:

Where consent is required, we load these tools only after you have consented via our cookie controls.

6. Marketing and Advertising

We use third-party advertising and marketing platforms to promote our Service and to measure the effectiveness of our campaigns. These platforms may place cookies or pixels on your device and may combine the data they collect with information they already hold, including to show you our ads on other websites and platforms (retargeting) and to measure conversions. The platforms we use may include:

You can control interest-based advertising through each platform’s ad settings, your browser or device settings, and our cookie preference tool. Note that the use of these advertising cookies and pixels may be considered a “sale” or “sharing” of Personal Information under California law — see section 12.

7. Email Communications and Marketing Consent

You can opt in to receive newsletters and marketing emails from us — for example, by subscribing on the Website. We manage our email communications through Brevo (Sendinblue), a third-party email marketing platform; information you provide when subscribing (such as your name and email address) is stored and processed by Brevo on our behalf. See Brevo’s Privacy Policy.

We only send marketing emails where you have opted in or where otherwise permitted by law. Every marketing email contains an unsubscribe link, and you can withdraw your consent at any time by using that link or emailing info@aupy.consulting. We handle marketing in accordance with the Privacy Act, the Spam Act 2003 (Cth), and, where applicable, the GDPR and applicable US laws (including the CAN-SPAM Act). We do not sell your Personal Information for money.

8. How We Use Your Information and Our Legal Basis

We use Personal Information to: respond to enquiries and provide requested information; deliver, administer and improve the Service (including EOR services); send communications you have opted in to receive; manage our business relationship with you, including invoicing and records; secure and maintain the Website; comply with legal, tax and regulatory obligations; and establish, exercise or defend legal claims.

Where the GDPR applies, our lawful bases are: your consent (e.g. newsletters, non-essential cookies, advertising); performance of a contract or pre-contract steps at your request; our legitimate interests in operating, promoting and securing our business (balanced against your rights); and compliance with a legal obligation. You may withdraw consent at any time.

9. Service Providers

We may employ third-party companies and individuals to: facilitate our Service; provide the Service on our behalf; perform Service-related services (such as hosting, email delivery, payment, and CRM); or assist us in analysing how our Service is used. These third parties — which include our website host, Brevo, and the analytics and advertising providers named above — have access to your Personal Information only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

10. Overseas Disclosure and International Transfers

AUPY is based in Paraguay, and our service providers may store or process Personal Information in Paraguay, the United States, the European Union and Australia. Your Personal Information may therefore be transferred to, and handled in, countries other than the one in which you live.

Under APP 8, before disclosing Personal Information overseas we take reasonable steps to ensure the recipient handles it consistently with the APPs, or we rely on an applicable exception (such as your consent). Under the GDPR, where we transfer personal data outside the EEA or UK to a country without an adequacy decision (including Paraguay), we put in place appropriate safeguards such as the European Commission’s Standard Contractual Clauses; you may request a copy by contacting us.

11. Data Retention

We keep Personal Information only for as long as necessary for the purposes described in this Policy, or as required to meet legal, tax, accounting or regulatory obligations. When it is no longer needed, we take reasonable steps to securely destroy or de-identify it.

If you leave a comment on the Website, the comment and its metadata are retained indefinitely so that we can recognise and approve any follow-up comments automatically instead of holding them in a moderation queue.

For users who register on the Website (if registration is enabled), we also store the personal information they provide in their user profile. Registered users can see, edit, or delete their personal information at any time (except that they cannot change their username). Website administrators can also see and edit that information.

12. Your California Privacy Rights (CCPA / CPRA and CalOPPA)

This section applies to residents of California and supplements the rest of this Policy.

Categories of Personal Information we collect. In the past 12 months we may have collected the following CCPA categories: identifiers (e.g. name, email, phone, postal address, IP address, online identifiers); California customer records (name, address, phone number); commercial information (services enquired about or received); internet or network activity (browsing and interaction with our site and ads); geolocation data (approximate, derived from IP); professional or employment information (company, job title, industry, seniority, and, for EOR, employee-related data); and inferences drawn to create a profile about preferences. We collect these from you directly, automatically through your device, and from analytics and advertising partners.

How we use and disclose it. We use these categories for the business purposes in section 8, and disclose them to the service providers and advertising partners described above.

“Sale” and “sharing”. We do not sell your Personal Information for money. However, our use of advertising and analytics cookies and pixels (Google, LinkedIn, Meta) may be considered a “sale” or “sharing” (for cross-context behavioural advertising) under the CCPA/CPRA. You have the right to opt out of this — you can do so via our cookie preference tool and by disabling advertising cookies. We do not knowingly sell or share the Personal Information of consumers under 16.

Your CCPA/CPRA rights. Subject to verification, California residents have the right to: (a) know the categories and specific pieces of Personal Information we have collected; (b) access a copy of it; (c) request deletion; (d) request correction of inaccurate information; (e) opt out of the sale or sharing of Personal Information; (f) limit the use of sensitive Personal Information; and (g) not receive discriminatory treatment for exercising these rights. You may use an authorised agent to submit a request on your behalf.

Shine the Light. California Civil Code § 1798.83 permits California residents to request information about disclosure of Personal Information to third parties for their direct marketing purposes. We do not disclose Personal Information to third parties for their own direct marketing.

Do Not Track (CalOPPA). Some browsers offer a “Do Not Track” (DNT) signal. There is no consistent industry standard for responding to DNT signals; our Website does not currently respond to DNT signals. You can still control tracking through our cookie preference tool. As required by CalOPPA, this Policy identifies the categories of Personal Information we collect (above), the third parties with whom we share it (above), and the process by which we notify you of material changes (section 16).

How to exercise your rights. Submit a request by emailing info@aupy.consulting. We will verify your identity and respond within the timeframes required by law.

13. Your Rights (Australia, EU and UK)

Australia. Under the Privacy Act you may request access to the Personal Information we hold about you and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading.

EU / UK (GDPR). Where the GDPR applies, you also have the right to access, rectification, erasure, restriction of processing, objection to processing, data portability, and to withdraw consent at any time without affecting the lawfulness of prior processing.

To exercise any right, email info@aupy.consulting. We may need to verify your identity, and we will respond within a reasonable time and within any period required by law.

14. Security

We value your trust in providing us your Personal Information and use commercially acceptable technical and organisational means to protect it — including access controls, encrypted connections (HTTPS), restricting access to authorised personnel, and confidentiality obligations with our service providers. However, no method of transmission over the internet or method of electronic storage is 100% secure and reliable, and we cannot guarantee its absolute security.

15. Automated Decision-Making

We do not use your Personal Information to make decisions that are solely automated and produce legal or similarly significant effects on you. If this changes, we will update this Policy in line with our obligations, including the automated decision-making transparency requirements taking effect under the Australian Privacy Act from 10 December 2026.

16. Links to Other Sites

Our Service may contain links to other sites. If you click a third-party link, you will be directed to that site. These external sites are not operated by us, so we strongly advise you to review their privacy policies. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party sites or services.

17. Children’s Privacy

Our Service is directed at businesses and professionals and does not address anyone under the age of 13. We do not knowingly collect personally identifiable information from children under 13. If we discover that a child under 13 has provided us with Personal Information, we immediately delete it from our servers. Where the GDPR applies, we do not knowingly collect data from children under 16 without parental consent. If you are a parent or guardian and believe your child has provided us with Personal Information, please contact us so we can take the necessary action.

18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time, so we advise you to review this page periodically. We will notify you of any changes by posting the new Policy on this page and updating the “Last updated” date; where changes are material, we will take reasonable steps to notify you. Changes are effective immediately after they are posted on this page.

19. Contact Us and Complaints

If you have any questions, suggestions, requests, or complaints about this Privacy Policy, do not hesitate to contact us:

Aupy E.A.S. (trading as AUPY Consultoria E.A.S.)
Email: info@aupy.consulting
Location: Paraguay

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. If the GDPR applies to you, you may also lodge a complaint with your local EU/UK data protection supervisory authority.