Policy notice
Privacy Policy
GPLX publishes this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act of the Republic of Korea (PIPA), and, where applicable, the GDPR, UK GDPR, and the CCPA/CPRA. It sets out how personal information is collected, used, retained, and protected within the GPLX service.
This document is a GPLX policy notice. Wording and policy may be improved during operation; major changes will be announced separately.
Article 1. Purpose of Personal Information Processing
GPLX processes personal information only for the purposes set out below. Where the purpose changes, separate consent will be obtained in accordance with Article 18 of PIPA.
- Generating, storing, and re-displaying GPLX results based on the user's responses.
- Granting and verifying access to paid reports through email-based identification.
- Processing payments, verifying payment status, and handling refunds.
- Sending email access links and re-sending them upon delivery failure.
- Responding to inquiries and maintaining records of dispute handling.
- Improving service quality, preventing abuse, and aggregate statistical analysis.
Article 2. Categories of Personal Information Processed
GPLX collects only the minimum information necessary to operate the service. The categories below are grouped by whether they are mandatory, optional, or specific to two-person reports.
- Mandatory: email address (for access link delivery and identification), questionnaire responses, and the GPLX results calculated from those responses (8-trait activations, per-axis results, main code, sub-code).
- Mandatory (payment): payment method type, amount, currency, product ID, payment status, and transaction ID issued by the payment provider.
- Mandatory (access): type of report granted, access start and expiry timestamps, and PDF download timestamps.
- Mandatory (auto-collected): IP address, browser and device information, access logs, and cookie identifiers used for operation and security.
- Optional: nickname, voluntary feedback, and inquiry content submitted by the user.
- Relationship/compatibility report specific: with both parties' express consent, the other party's result identifier and corresponding result data are processed only to render the comparison report.
GPLX does not store resident registration numbers or other unique national identifiers, sensitive data (health, beliefs, political opinions), raw card data, or payment-authentication secrets. Payment-sensitive data is processed within the payment provider's system.
Article 3. Retention Period
GPLX retains personal information only for the period necessary to fulfill the processing purpose, or as required by applicable law (Article 21 of PIPA). Information is destroyed without delay once the retention period ends.
- Test results and access rights: until the user requests deletion, or up to three (3) years from the last access for re-display purposes.
- Payment and refund records: five (5) years, in accordance with the Act on the Consumer Protection in Electronic Commerce.
- Consumer complaint and dispute records: three (3) years, in accordance with the Act on the Consumer Protection in Electronic Commerce.
- Access logs and IP addresses: three (3) months, in accordance with the Communications Secrets Protection Act.
- Identity-verification records, including email delivery logs: six (6) months, in accordance with the Act on Promotion of Information and Communications Network Utilization.
Article 4. Provision to Third Parties
GPLX does not currently provide personal information to any third party. Information is disclosed only in the limited cases set out in Article 17 of PIPA.
- Compliance with statutory obligations or lawful requests by investigative authorities.
- With the data subject's prior express consent (for example, in a two-person comparison report, the result is shared with the other party only after both parties expressly consent).
If third-party provision arrangements change in the future, this Policy will be updated and announced before the change takes effect.
Article 5. Processing Delegation
GPLX entrusts certain processing operations to service providers. Each entrustment agreement includes the safeguards required by Article 26 of PIPA, including limitations on the purpose of use, security obligations, and the prohibition of re-entrustment without consent.
- Payment processing (domestic): Toss Payments Inc. — payment data and transaction identifiers, processed to complete domestic payments and refunds.
- Payment processing (international): Stripe, Inc. (United States) — payment data and transaction identifiers, processed to complete international payments and refunds.
- Email delivery: Resend, Inc. — email address and message content, processed to deliver access links and transactional emails.
- Hosting and infrastructure: Render Services, Inc. and Supabase, Inc. — operational data necessary to run the service.
If an entrusted provider changes, this Policy will be updated and the change will be announced on the site.
Article 6. Data Subject Rights
Data subjects may exercise the following rights at any time under Articles 35 through 37 of PIPA. Requests are submitted to the Personal Information Protection Officer listed in Article 9 below.
- Right of access to personal information.
- Right to rectification and correction of inaccurate information.
- Right to deletion of personal information.
- Right to suspension of processing.
- Right to withdraw consent at any time, without affecting the lawfulness of prior processing.
- Right to object to, or obtain an explanation of, automated decisions where applicable.
Requests are handled without undue delay, in any event within ten (10) days. Information that GPLX is required to retain by law (for example, payment records) may be excluded from deletion until the statutory retention period ends.
Article 7. Procedure and Method for Destruction
Personal information is destroyed without delay once the retention period ends, the processing purpose is achieved, or the data subject's deletion request is granted.
- Timing: upon expiry of the retention period, achievement of the processing purpose, or receipt of a valid deletion request.
- Procedure: the information to be destroyed is identified and separated, the responsible officer reviews and approves the destruction, and the destruction is executed.
- Method: electronic files are permanently deleted using a method that prevents recovery or restoration; printed materials are shredded or incinerated.
Article 8. Safeguards
GPLX maintains the administrative, technical, and physical safeguards required by Article 29 of PIPA to protect personal information from unauthorized access, alteration, loss, or disclosure.
- Administrative: minimizing the number of personnel with access to personal information, segregation of duties, internal access policies, and periodic review.
- Technical: encryption in transit using HTTPS/TLS, hashed storage of credentials and identifiers, access control, and retention of access logs.
- Physical: reliance on the security policies of the entrusted data-center providers, including controlled facility access and environmental controls.
Article 9. Personal Information Protection Officer
GPLX has designated a Personal Information Protection Officer to oversee personal information processing and to handle complaints and remediation requests from data subjects.
- Role: Personal Information Protection Officer.
- Contact: support@gplx.app (until a dedicated channel is announced).
- Response: a first reply is provided within seven (7) business days, with substantive handling completed without undue delay.
For relief in case of an infringement, users may also contact the Personal Information Infringement Report Center of the Korea Internet & Security Agency (privacy.kisa.or.kr, 118), the Supreme Prosecutors' Office, or the Cyber Investigation Division of the National Police Agency.
Article 10. International Data Transfer
GPLX transfers personal information internationally as set out below, in accordance with Article 28-8 of PIPA. Data subjects may refuse such transfers; refusal may limit certain service features (for example, international payment or transactional email delivery).
- Recipient: Stripe, Inc. — Country: United States — Items: payment amount, currency, product ID, transaction identifiers, and billing-related information — Purpose: international payment processing, refunds, and fraud prevention — Method: encrypted channel (HTTPS/TLS) at the time of the international payment request — Retention: per Stripe's retention policy and applicable law.
- Recipient: Resend, Inc. — Country: United States — Items: email address and message content — Purpose: delivery of access links and transactional emails — Method: encrypted API call — Retention: per Resend's retention policy.
- Recipient: Render Services, Inc. — Country: United States — Items: operational data necessary to run the service — Purpose: hosting — Method: encrypted channel — Retention: per the provider's retention policy.
Where required by the GDPR or UK GDPR, these transfers rely on appropriate safeguards such as Standard Contractual Clauses.
Article 11. Processing of Pseudonymized Data
Under Article 28-2 of PIPA, GPLX may process pseudonymized information for the purposes of statistical compilation, scientific research, and the improvement of service quality.
Pseudonymized information is separated from identifying information (such as email addresses) and is handled under additional safeguards. No attempt is made to re-identify pseudonymized data, and combining pseudonymized data with other data for the purpose of identifying a specific individual is prohibited.
Article 12. Children Under 14
GPLX is not directed at children under the age of 14 and does not knowingly collect personal information from them.
If a user is identified as being under 14, GPLX processes the information only after confirming the consent of the legal guardian in accordance with Article 22-2 of PIPA. If such consent cannot be confirmed, the information is destroyed without delay.
Article 13. Notice for EU/UK Users
For users in the European Economic Area or the United Kingdom, GPLX acts as the data controller for personal information processed through the service. The lawful bases for processing are the performance of a contract (for delivering paid reports and access), compliance with legal obligations (for retention of payment and complaint records), and legitimate interests (for service operation, security, and abuse prevention).
EU and UK users may exercise their rights under the GDPR and UK GDPR — including access, rectification, erasure, restriction, portability, and objection — by contacting the Personal Information Protection Officer listed in Article 9. Users also have the right to lodge a complaint with their national supervisory authority.
GPLX does not sell personal information. California residents may exercise the rights to know, delete, correct, and opt out of any sale or sharing under the CCPA/CPRA by using the same contact channel.
Article 14. Changes to the Privacy Policy
GPLX may amend this Privacy Policy from time to time to reflect changes in law, service operation, or entrusted providers.
Material additions, deletions, or modifications are announced on the site at least seven (7) days before the effective date. Where a change is materially disadvantageous to data subjects, the announcement period is at least thirty (30) days.