Home
ENEnglishPLPolskiTRTürkçe
GDPR compliant

Privacy Policy

Effective date: 18 April 2026 · Last update: 18 April 2026

This policy explains how GetUp (getup.dev) collects, processes, stores, and protects users' personal data. We commit to meeting our obligations under the EU General Data Protection Regulation (GDPR) and Polish data protection law.

Data Controller

AUTH spółka z ograniczoną odpowiedzialnością (AUTH sp. z o.o.)
Marszałkowska 58 / 15, 00-545 Warszawa, Polska
KRS: 0001043319 · NIP: 5273062913 · REGON: 525652590
privacy@getup.dev

1. Data Controller

Unless stated otherwise, the party acting as data controller for the GetUp Service is:

  • Legal name: AUTH spółka z ograniczoną odpowiedzialnością (AUTH sp. z o.o.)
  • Address: Marszałkowska 58 / 15, 00-545 Warszawa, Polska
  • KRS: 0001043319 · NIP: 5273062913 · REGON: 525652590
  • Email (DPO / Data Protection): privacy@getup.dev
  • General contact: support@getup.dev

Note: for data about the customer company's own employees or customers, the customer company is the data controller; GetUp acts as data processor.

2. Categories of Personal Data

CategoryExample data
IdentityName, email, phone, tax ID (NIP/REGON/KRS)
AccountUsername, password hash, TOTP secret, login logs
CompanyCompany name, sector, address, employee count, currency
PaymentStripe customer ID, subscription ID (card details live in Stripe, not with us)
UsageIP address, browser, event logs (Vercel Analytics)
ContentEmployee, customer, invoice, shift data you upload
CommunicationSupport emails, quote accept/reject events

3. Purposes of Processing

PurposeLawful basis (GDPR Art. 6)
Providing the Service, account managementContract (6(1)(b))
Payment collection and invoicingContract (6(1)(b)) + Legal obligation (6(1)(c))
Accounting and taxLegal obligation (6(1)(c))
Security, fraud preventionLegitimate interest (6(1)(f))
Marketing (newsletter)Consent (6(1)(a)) — only if you opt in
Product improvement, statisticsLegitimate interest (6(1)(f)), anonymized

4. Retention Periods

  • Active account data: until the account is deleted.
  • Invoices and accounting records: 5 years under Polish tax law.
  • Login logs, security events: 12 months.
  • Support correspondence: 24 months.
  • After account deletion: personal data deleted within 30 days; legally mandated records kept in encrypted archive.

5. Recipients and Sub-processors

We rely on the following sub-processors to provide the Service. A GDPR Art. 28 compliant DPA is or will be in place with each.

ProviderPurposeLocation
Google LLC (Firebase)Database, authentication, hostingUSA (SCC)
Vercel Inc.Server hosting, CDN, analyticsUSA (SCC)
Stripe, Inc.Payment processingUSA / Ireland (SCC)
Resend, Inc.Transactional emailUSA (SCC)
ImprovMXEmail forwardingUSA (SCC)

Transfers to US-based providers rely on the Standard Contractual Clauses (SCC) approved by the European Commission and/or the EU-US Data Privacy Framework.

6. Your Rights

Under GDPR you have the following rights:

  • Access (Art. 15): obtain a copy of the data we process about you.
  • Rectification (Art. 16): correct inaccurate or incomplete data.
  • Erasure (Art. 17): have your data deleted under certain conditions.
  • Restriction (Art. 18): limit processing under certain conditions.
  • Portability (Art. 20): receive your data in a structured, machine-readable format.
  • Objection (Art. 21): object to legitimate-interest processing.
  • Withdraw consent: stop consent-based processing.
  • Automated decisions (Art. 22): not be subject to solely automated decisions.
  • Complaint to UODO: uodo.gov.pl.

To exercise your rights, email privacy@getup.dev. We respond within 30 days (up to 60 for complex requests, with notice).

7. Security Measures

  • All data in transit is encrypted with TLS (HTTPS).
  • Data at rest (Firebase Firestore) is encrypted by default by Google.
  • Passwords are hashed with bcrypt and additionally encrypted with a server secret.
  • Admin login requires 2FA (TOTP).
  • Role-based access control; session tokens signed with HMAC-SHA256.
  • Regular security updates and dependency vulnerability (CVE) scans.
  • Access and activity logs are retained.

8. Breach Notification

Per GDPR Art. 33, breaches are reported to UODO within 72 hours of detection. If the breach poses a high risk to users, they are notified directly (Art. 34).

9. Cookies

GetUp uses strictly necessary cookies for session management, security, and preferences (e.g. getup_session). These do not legally require explicit consent. Vercel Analytics provides anonymous usage stats. You can disable cookies in your browser, but the Service will not function without strictly necessary ones.

10. Children's Data

The Service is not designed for persons under 16. We do not knowingly collect data from anyone under 16; any such data is deleted promptly upon discovery.

11. International Data Transfers

The sub-processors (Google, Vercel, Stripe, Resend, ImprovMX) are US-based. Transfers rely on the Standard Contractual Clauses (SCC). Where feasible, we prefer EU-region resources.

12. Changes

We may update this policy from time to time. Material changes are announced by email and the “Last update” date at the top of this page is revised.

13. Contact

Data protection: privacy@getup.dev
General support: support@getup.dev


Where this policy conflicts with applicable law, the law prevails. It is not a substitute for legal advice.

Terms of Service·DPA·Home
GetUp assistant
General info while signed out; we can point you to Log in or Register.

Ask about GetUp, sign-in, and modules.

Go to sign-inRegister