Legal

Privacy Policy

Effective 16 July 2026

Introduction

1.1. This Privacy Policy describes how Getintoto Software ("Getintoto", "we", "us", or "our") collects, uses, discloses, and protects personal data through getintoto.com, client engagements, and other interactions. This Policy applies to individuals worldwide, including users in Nepal, Australia, the European Union, and the United States.

1.2. By using our website, entering into an SOW, or otherwise providing personal data to Getintoto, you consent to the processing described in this Policy, subject to any required local consents and rights under applicable law.

 

Data Controller and Data Processor Roles

2.1. Where Getintoto determines the purposes and means of processing personal data collected directly from individuals on our website or as a service provider to clients, Getintoto is the data controller in respect of that processing. For data processed on behalf of a Client under an SOW (e.g., software that stores end-user data), the Client will generally be the data controller and Getintoto will act as a data processor. A Data Processing Agreement (DPA) will be provided on request to define roles and obligations.

2.2. For EU data subjects, the DPA will include required GDPR terms including processing instructions, subprocessors, security measures, data subject rights assistance, and breach notification obligations.

 

Information We Collect

3.1. Personal Data You Provide: contact details (name, email, phone), company information, billing and payment information, project requirements, employment or recruitment-related information, and other information submitted through forms, emails, or SOWs.

3.2. Usage and Technical Data: IP addresses, browser and device identifiers, pages visited, cookies and similar tracking technologies, error logs, and analytics data collected when you visit getintoto.com or use demo/staging environments.

3.3. Third-Party Data: information received from third-party services such as integration partners, social login providers, payment processors, or public sources.

 

How We Use Your Information

4.1. To provide services and fulfill SOW obligations, including development, hosting coordination, deployment, and support.

4.2. For billing, invoicing, tax compliance, and collection of fees owed to Getintoto.

4.3. To communicate about projects, support requests, account notices, marketing (with consent where required), and administrative matters.

4.4. To improve our websites, Services, security, and for analytics, testing, and research.

4.5. To comply with legal obligations, respond to lawful requests by public authorities, and to enforce our rights under contracts and these Terms.

 

5.1. Where applicable (e.g., for EU data subjects), Getintoto relies on one or more lawful bases for processing: 

(a) performance of a contract (to provide Services); 

(b) compliance with legal obligations; 

(c) legitimate interests (improving services, fraud prevention, security), after balancing interests against the rights of the data subject; and 

(d) consent where required (for marketing communications and non-essential cookies). 

Specific processing activities and bases will be documented in any DPA or privacy addendum.

 

Data Sharing and Disclosure

6.1. Service Providers and Subprocessors: Getintoto uses third-party service providers (e.g., cloud hosting, analytics, payment processors, communication tools) who process personal data on our behalf under contract and confidentiality obligations.

6.2. Affiliates and Professional Advisors: We may share data with our affiliates, legal advisors, auditors, and insurers where necessary.

6.3. Legal Requirements and Protection: We may disclose personal data to comply with legal obligations, respond to lawful requests by public authorities, or to protect Getintoto's rights, property, or safety.

6.4. Business Transfer: In the event of a merger, acquisition, or sale of assets, personal data may be transferred to a successor, subject to notice to data subjects where required.

 

International Data Transfers

7.1. Getintoto may transfer personal data to, and store it in, countries outside your jurisdiction, including Nepal, Australia, the EU, and the USA, where our systems, service providers, or subprocessors operate.

7.2. Where transfers involve EU personal data, Getintoto will implement appropriate safeguards, such as Standard Contractual Clauses (SCCs), DPAs, or other lawful transfer mechanisms, and will provide copies of such safeguards on request.

7.3. By using our Services or providing data, you consent to such transfers as necessary to provide the Services.

 

Data Security

8.1. Getintoto implements organizational, technical, and administrative measures designed to protect personal data against unauthorized access, loss, or destruction, including access controls, encryption where appropriate, secure development lifecycle practices, and regular security assessments.

8.2. While we use reasonable measures, no method of transmission or storage is completely secure; Getintoto cannot guarantee absolute security.

 

Data Retention

9.1. Getintoto retains personal data only for as long as necessary to provide Services, to comply with legal obligations, resolve disputes, and enforce agreements. Specific retention periods will be defined in the SOW or DPA as applicable.

9.2. For recruitment-related data or marketing consents, retention periods will be stated in applicable forms and will comply with local law.

 

Cookies and Tracking Technologies

10.1. Getintoto uses cookies and similar technologies to operate the website, authenticate users, analyze usage, and provide targeted content; users may control cookies through browser settings and consent mechanisms where required.

10.2. A cookie banner or settings page will explain cookie categories, purposes, and opt-out instructions where required by law.

 

Your Rights (EU/GDPR and similar rights)

11.1. Data subjects in applicable jurisdictions have rights including access, rectification, erasure ("right to be forgotten"), restriction of processing, objection to processing, and data portability.

11.2. To exercise these rights, data subjects may contact Getintoto at the contact details below; Getintoto will respond within applicable legal timeframes and may require identity verification.

11.3. Where processing relies on consent, data subjects may withdraw consent at any time without affecting processing based on consent prior to withdrawal.

11.4. EU data subjects have the right to lodge a complaint with a supervisory authority in their member state.

Children’s Privacy

12.1. Our Services are not directed to children under 14 (or higher age if required by local law), and we do not knowingly collect personal data from children without parental consent; if we learn that we have collected such data, we will delete it promptly.

 

13.1. Our website may include links or embedded content from third parties; Getintoto is not responsible for third-party privacy practices and encourages users to review the privacy policies of such third parties.

 

Data Breach Notification

14.1. In the event of a security incident that is likely to result in a risk to the rights and freedoms of individuals (including EU data subjects), Getintoto will notify affected data subjects and relevant supervisory authorities in accordance with applicable law and without undue delay.

 

Changes to This Privacy Policy

15.1. Getintoto may update this Privacy Policy from time to time; material changes related to how we process personal data will be communicated via getintoto.com or direct notice to Clients where required by law. Continued use after updates constitutes acceptance.

 

Contact and Data Protection Officer

16.1. For questions, to exercise rights, or to request a DPA or information about subprocessors, contact: Getintoto Software: info@getintoto.comcontact@getintoto.com 

16.2. If required by law or upon reasonable request, Getintoto will designate or provide contact details for a Data Protection Officer (DPO) or privacy contact for EU data subjects.

 

Additional Provisions for Specific Jurisdictions

17.1. European Economic Area (EEA): For EEA data subjects, Getintoto will honor GDPR rights, provide DPAs, implement transfer safeguards (e.g., SCCs), and cooperate with supervisory authorities.

17.2. Australia: Getintoto will comply with the Australian Privacy Principles (APPs) for Australian personal data and will provide a local contact where required by law.

17.3. United States: For US persons, processing will comply with applicable federal and state privacy laws; exceptions or additional disclosures may apply in states with specific privacy laws.

 

Service Providers and Subprocessors (Transparency)

18.1. Getintoto maintains a list of subprocessors (e.g., cloud infrastructure providers, analytics, payment processors). Clients may request an up-to-date list and any material changes; Getintoto will provide prior notice of onboarding material subprocessors where required by contractual commitments.

 

How to Exercise Rights and Make Requests

19.1. To access, correct, port, restrict, or delete personal data, or to object to processing, or to request a copy of safeguards used for transfers, Contact: info@getintoto.comcontact@getintoto.com  with sufficient information to locate the relevant data.

19.2. Getintoto may require verification and will respond within applicable statutory timeframes; where requests are manifestly unfounded or excessive, Getintoto reserves the right to charge a reasonable fee or refuse to act.

 

Effective Date

20.1. This Privacy Policy is effective as of the date posted on getintoto.com and supersedes prior privacy statements.