PRIVACY POLICY AND COOKIES

GETLUG OÜ – PRIVACY POLICY AND PERSONAL DATA PROTECTION NOTICE
Effective Date: [05/07/2025]
Last Updated: [05/07/2025]
Company Name: GETLUG OÜ
Place of Registration: Estonia
Contact: [email protected]

1. INTRODUCTION

This notice is provided by Getlug OÜ (“GETLUG”) as the data controller to inform users about the collection, processing, transfer, storage, and protection of personal data on the platform. The application is prepared in accordance with Estonian Data Protection Laws and the European Union General Data Protection Regulation (GDPR).

2. TYPES OF DATA COLLECTED

GETLUG collects only the following data in a limited manner:
• Full name (used only as username)
• Phone number (for SMS verification and communication)
• Profile photo (optional)
• Languages spoken and education background (only in WORK module)
• Listing and reservation details: flight date, route, item details, etc.
• Location data: GPS data collected with explicit user consent
• Platform usage data: session duration, activity logs, messages
• Device and connection info: IP address, device ID, browser data
• Notification preferences and cookies

Note: GETLUG does not collect or store ID documents, passport information, or email addresses.

  

3. PURPOSES OF DATA PROCESSING AND LEGAL BASIS

Purpose

Legal Basis

Account creation, verification, security

Contractual obligation

Travel and Work service delivery

Contractual obligation

Matching and recommendation systems

Legitimate interest

Fraud and abuse prevention

Legitimate interest

Providing customer support

Legitimate interest

Compliance with legal obligations

Legal requirement

Analytics and development processes

Legitimate interest

Consent-based scenarios

Explicit user consent

4. DATA VISIBILITY & PROFILE BUILDING

• User’s full name, profile photo, spoken languages, and education details are shown only after a match is made.
• Profile creation and automatic matching algorithms are used to enhance user experience. Users have the right to object to this system.

5. DATA RETENTION PERIODS

Data Type

Retention Period

Reservation history

12 months

Message records

12 months

Device & usage data

6 months

Profile data (active accounts)

Until account deletion

Data is automatically deleted or anonymized after its retention period expires.
For all data processed with explicit user consent, the system logs the consent time, date, and IP address, which may be shared with authorities if required.

6. DATA SECURITY

GETLUG implements the following technical and administrative measures to protect privacy:
• End-to-end data encryption
• Authorized access control
• Firewall and intrusion prevention systems
• Periodic system updates and log audits
• Staff confidentiality agreements

GETLUG logs all access, editing, and deletion actions (audit logs), ensuring traceability and protection against unauthorized access.
All user consents, access records, and processing steps are securely logged and may be submitted to data protection authorities if necessary.

7. DATA TRANSFER AND SHARING

Data is shared only with the following entities in limited contexts:
• Cloud service providers
• Notification and messaging infrastructure providers
• Legal authorities (only when legally required)
• Cross-border data transfers occur only to countries on the secure list and with explicit user consent

GETLUG signs a Data Processing Agreement (DPA) for all data transfer processes.

8. USER RIGHTS (GDPR Articles 12–23)

Users have the right to:
• Access their processed personal data
• Correct inaccuracies or incomplete data
• Request deletion of data no longer necessary
• Request anonymization of their data
• Know who their data has been shared with
• Object to automated processing
• Exercise data portability (receive data in JSON or CSV)
• Request compensation for damages caused by unlawful processing

Requests can be submitted to [email protected] in writing. All requests are resolved free of charge within 30 days.

9. COOKIE POLICY

• Technical cookies are used for session management and preference retention.
• Cookies may collect browsing history, language settings, and device info.
• Users can disable cookies via browser settings, though some features may not function properly if disabled.

10. DATA BREACH NOTIFICATION

In the event of a data breach (e.g., hacking or unauthorized access), both users and the Estonian Data Protection Authority will be notified as soon as possible.

11. AGE LIMIT AND PARENTAL CONSENT

The GETLUG platform is intended only for individuals over the age of 18. Users under 18 are not allowed to create accounts.
If this changes in the future, a parental consent protocol will be implemented.
No data is collected from users under 13, and the application complies with international child protection laws such as COPPA.

12. UPDATES AND CHANGES

GETLUG may update this policy at any time. Changes become effective when published on the app or website. Continued use of the platform constitutes acceptance of these changes.

13. LIMITATION OF LIABILITY

GETLUG shall not be held directly liable for data loss caused by system failures, third-party service provider issues, or user errors beyond its control. Users accept these risks when using the platform.

 

14. DATA PROTECTION OFFICER (DPO) NOTIFICATION

GETLUG may appoint a Data Protection Officer (DPO) when deemed necessary to oversee security practices and will notify users accordingly.

15. PRIVACY SUMMARY (TL;DR)

• We only store name, phone number, and usage data
• We do not collect ID, passport, or email
• You can delete your data anytime
• We never sell your data
• Location data is used only for matching, no background tracking