Privacy Policy

Aurora by Heylixir (product of Aurora Vicci LLC)

Last Updated: April 2026

This Privacy Policy explains how Aurora collects, uses, and protects your personal information when you use the Aurora Website, and related services ("Services").

By using our Services, you agree to this Privacy Policy. If you do not agree, you should not use Aurora.

We process personal data in accordance with applicable data protection laws, including GDPR where applicable. The data controller is Aurora Vicci LLC, 8 The Green, STE B, Dover, Delaware, USA.

1. Data Governance Roles

  • The User (Patient): The Data Owner.
  • The Institution: The Data Controller (determines the purpose of the data collection).
  • Aurora by Heylixir The Data Processor (handles data on behalf of the Controller).

2. Data Transmission & "Zero-Knowledge" Philosophy

Aurora employs a partitioned database architecture:

  • In-Transit: Data is transmitted via TLS 1.2+ protocols.
  • Access: Institutional access to unmasked patient data is only possible via a cryptographically signed DSR token generated by the User. Aurora employees do not have access to identifiable patient health information (PHI) without explicit, time-limited authorization for support purposes.

3. Compliance Framework

  • HIPAA: Aurora maintains administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of PHI.
  • GDPR: We honor the "Right to Portability" and the "Right to be Forgotten." When an institution or user requests data deletion, Aurora executes a cryptographic erasure, rendering the data unrecoverable.
  • Standardization (FHIR/HL7): Data is processed into standardized formats to ensure interoperability while maintaining strict data provenance logs.

4. Data Retention and Purging

Institutional Control: Upon completion of a clinical trial or care program, the Institution is responsible for exporting required records or deleting if no longer required.

Automatic Erasure: Aurora provides tools for the "Zero-Data Persistence" model, allowing institutions to purge datasets from Aurora servers once they have been ingested into the Institution’s internal EHR/EDC systems.

5. Segmented Data Architecture

Tier 1 (Anonymized Aggregate): Data used by Aurora to improve the Intelligence Layer (non-identifiable).

Tier 2 (PHI/PII): Identifiable health data that is only visible to the Institution via the DSR. Aurora acts as a "Blind Vault" for Tier 2 data.

6. Breach Notification Protocol

In the event of a suspected security incident, Aurora commits to notifying the Institution within 24 to 72 hours (aligning with GDPR/HIPAA mandates). This section must detail:

  • The nature of the breach.
  • The steps taken to mitigate it.
  • The point of contact for the Institution’s Data Protection Officer (DPO).

7. Cookies and Tracking

We use cookies (upon consent) and similar technologies to understand usage, improve performance, and enhance user experience. You can disable cookies in your browser, but some features may not work properly.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of significant changes through email or in-app notices.

12. Contact Us

If you have any questions, contact us at mailto:aurora@heylixir.com or write to: Aurora Vicci LLC., 8 The Green, STE B, Dover, Delaware, USA.