GettaSYS Legal & Policies
Privacy Policy
This policy applies from 28 August 2026 and may be updated to reflect applicable law and payment-platform requirements.
- Status: Published policy
- Operator: GettaSYS (a trading name used by an individual operator based in the Republic of Korea)
- Operating country: Republic of Korea
- Legal notice: Legal notices and inquiries: [email protected]
- Effective date: 28 August 2026
- Contact: [email protected]
1. Personal data processed
- Registration and verification: email address, one-way password hash, email verification status, and optional display name
- Consent records: acceptance of Terms, privacy collection/use consent, marketing consent, document version, and consent time
- Device and security: device identifiers, PC authorization state, device sessions, IP address, access/request times, application version, and error codes
- Subscription and payment: Paddle customer, subscription, and transaction identifiers; plan; subscription status; start, end, and next-billing times; payment success/failure/refund/chargeback state; currency and amount. GettaSYS does not directly store card numbers or CVCs
- AI and feature usage: AI Token balance, grants, usage, reversals, feature task counts, and processing state
- Customer support: inquiry title, content, response, attachments, status, account changes, deletion, and PC change records
- Local-only data: saved email, Szwego connection information, account lists, notes, presets, settings, product data, images, videos, and CSV files, generally stored on the user’s device or selected folders
- Phone verification: mobile number, country code, SMS request/approval status, attempt count and time, and an irreversible fingerprint used to prevent duplicate registration and Free Trial abuse
2. Purposes of processing
- Registration, email verification, login, password reset, and account security
- One-PC authorization, device sessions, fraud prevention, and security incident response
- Free Trial, BASIC, and PRO authorization; subscription periods; AI Tokens; and duplicate-billing prevention
- Reflecting Paddle payment, subscription, renewal, cancellation, refund, and chargeback status in GettaSYS access rights
- Service delivery, error analysis, quality improvement, and customer support
- Sending required registration, security, subscription, and account-deletion emails
- Sending product news and offers where separate marketing consent has been given
3. Legal bases and data minimization
- The operator processes personal data for entering into and performing a contract, compliance with legal obligations, legitimate security and operational needs, or the user’s consent, as applicable.
- Date of birth, national identification number, card number, and bank account number are not collected as ordinary registration fields where they are unnecessary for registration or service delivery.
- Marketing consent is optional, and refusal does not affect registration or ordinary service use.
4. Retention
- Member account: until account deletion is completed; an approximately seven-day processing grace period may apply
- Terms and consent records: for the membership period and as needed to handle disputes
- Subscription, payment, refund, and service-supply records: for the period required by applicable law and Paddle transaction-retention policy
- Support and dispute records: up to 3 years after completion
- Security and access logs: deleted or de-identified after up to 12 months
- Where a legal dispute, chargeback, or security incident is ongoing, necessary records may be retained until the matter ends
- Local Work Data: managed and deleted by the user separately from server retention periods
- After verification, GettaSYS does not retain the full raw phone number on its server; it retains an HMAC fingerprint, country calling code, and masked last four digits. When an account is finally deleted, the active phone ownership link may be released, while an irreversible Trial-eligibility claim may be retained for as long as the anti-abuse purpose remains necessary and is reviewed periodically.
5. Third-party disclosure and processors
- The operator does not sell personal data.
- Data may be disclosed where necessary under law, at the user’s request or with consent, to protect life or property, or in response to a lawful authority request.
- Paddle, Cloudflare, Vultr, Resend, and Google/Gemini may process data as described in the processor table to provide the service. External processors handle data only as needed under their service, security, and privacy terms and this policy.
6. International processing
- The operator and external providers may store, access, or process personal data outside the user’s country.
- Where international processing occurs, this policy or a separate notice will describe the countries, data, purposes, method, retention, and user rights as required by applicable law.
- Personal data will not be sent to a new international processor without legally required notice or consent.
7. Paddle payment data
- Card numbers, CVCs, and payment authentication data are processed in Paddle Checkout and are not stored on GettaSYS servers.
- The operator receives Paddle customer, subscription, and transaction identifiers and status to apply GettaSYS access rights.
- Customers may change payment methods, view receipts, and cancel subscriptions in the Paddle customer portal.
8. Website cookies and logs
- The initial website does not use Google Analytics and uses only Cloudflare features necessary for security and traffic operation.
- Paddle Checkout and the Customer Portal may use their own cookies or similar technologies for payment, fraud prevention, and session maintenance.
- The privacy policy and cookie notice will be updated before additional analytics or advertising tools are introduced.
9. User rights
- Users may request access, correction, deletion, restriction, withdrawal of marketing consent, and account deletion.
- Requests may be made through account management or [email protected] and may require account-ownership verification.
- Rights regarding payment data independently held by Paddle must also be exercised through Paddle’s privacy information and support channels.
10. Deletion and backups
- Personal data is deleted or de-identified without undue delay when retention ends or the purpose is fulfilled.
- Legally retained records are separated from ordinary account data.
- Backup data is deleted under the backup rotation schedule and used only for recovery.
- Account deletion applies to the server account and does not automatically delete Local Work Data.
11. Security measures
- One-way password hashing and TLS communication
- Restricted and authenticated administrator access
- Account, administration, and payment-webhook processing logs
- Rate limits, abnormal-use detection, and one-PC session management
- Prevention of persistent GUI storage of passwords and access tokens
- Webhook signature verification and event_id-based duplicate-processing prevention
- No secrets in customer files, the static website, or new-chat handover bundles
12. Children and age eligibility
- The service is intended for users who are at least 18 or otherwise legally capable of entering a valid contract in their country, and does not intentionally collect personal data from children.
13. Contact
- Operator: GettaSYS (a trading name used by an individual operator based in the Republic of Korea)
- Brand: GettaSYS
- Email: [email protected]
- Address and operating country: Legal notices and inquiries: [email protected] / Republic of Korea
14. Changes and previous versions
- When this policy changes, the effective date and material changes will be announced through the website, application, or email.
- Material changes to purposes, disclosure or processing, international processing, or user rights will be subject to any separate notice or consent required by applicable law.
- Previous versions will be retained for user reference.
Appendix A. Key processors
| Provider | Purpose | Data | Countries and retention |
|---|---|---|---|
| Paddle | Payments, transaction taxes, receipts, subscriptions, refunds, fraud and chargebacks | Email, payment/subscription/transaction data, IP and device-related data | Data may be processed in countries where Paddle and its subprocessors operate and retained under Paddle policies for payment, tax, refund, fraud, dispute, and legal-obligation purposes. |
| Cloudflare | DNS, CDN, Pages, TLS, and security/traffic protection | IP address, request headers, access logs, cookies and security identifiers | Data may be processed through Cloudflare’s global network. Security and access logs separately retained by GettaSYS are generally kept for up to 12 months. |
| Vultr | Hosting Phoenix API, database, and administration services | Account, device, subscription, log, and support data | The primary application and database region is Seoul, Republic of Korea. Account, subscription, security, and support data follow the category-specific retention periods and backup rotation described in this policy. |
| Resend | Sending authentication, password, security, and account emails | Email address, message content, delivery status, and time | Email data may be processed on Resend and subprocessor infrastructure. Delivery metadata may be retained under provider policy and for GettaSYS security and support needs. |
| Google/Gemini | PRO AI and translation processing | User-selected product descriptions, images, and other inputs required for processing | Inputs selected by the user for translation or AI processing may be processed on Google infrastructure. Provider retention terms and API settings apply; GettaSYS retains only results and minimum operational records for the necessary period. |
| Twilio Verify | Sign-up SMS verification, verification-status checks, Fraud Guard, and abuse prevention | Mobile number, country code, verification request/approval status, IP/device/attempt metadata | Data may be processed through Twilio and subprocessor global infrastructure. GettaSYS does not retain the OTP value; GettaSYS verification and anti-abuse records follow the retention rules above. |