Privacy Policy

How GTO Gecko handles your information.

Last Updated: 14 August 2026

GTO SOLUTIONS AS (Norwegian organisation number 935 325 579), trading as GTO Gecko, is the controller responsible for the processing described in this policy. This policy covers the GTO Gecko website, applications, accounts, purchases, requested resources, and email communications.

1. Information We Collect

1.1 Account and purchase information

When you create an account or purchase a subscription, we may process your name, email address, account identifier, subscription status, purchase and entitlement records, and support history. Payment card details are processed by our payment provider and are not stored by GTO Gecko.

1.2 Product and device information

We may process IP address, device and app information, security logs, feature usage, training activity, and performance data needed to provide, secure, and improve the service.

1.3 Email, consent, and requested resources

When you request a resource or subscribe to email, we process your email address, optional first name, the resource requested, your privacy-notice acknowledgement, any marketing-consent choice and the wording shown to you, server and client timestamps, delivery status, and an unsubscribe or suppression record. We store keyed hashes of limited request metadata, such as IP address and user agent, to document the choice and prevent abuse rather than storing those values in plain text in the consent record.

Resource delivery is separate from marketing consent. Selecting the optional marketing checkbox creates a pending request; marketing starts only after you use the signed confirmation link and explicitly confirm on the confirmation page. Newsletter signup requires an affirmative, unchecked-by-default choice. Recipient-level open and click tracking is disabled in current Loops marketing messages and in landing-page emails sent through SendGrid.

1.4 Affiliate referrals and promotion codes

When you follow an affiliate link, enter a promotion code, or complete an eligible referred purchase, we may process the referral token or code, campaign and promoter relationship, a pseudonymous customer or subscription identifier, and the related purchase, refund, dispute, currency, and commission status. We do not send your raw email address to FirstPromoter on the consent-independent referral path.

2. Cookies and similar technologies

Our cookie banner offers Accept All, Only Obligatory, and Decline All choices. Necessary storage supports security and core functionality. Analytics and advertising technologies are activated only according to the choice shown in the banner. You can reopen cookie settings from the website footer.

A first-party gg_affiliate_offer cookie can retain a validated referral token for up to 60 days so we can preserve an advertised price and determine whether a later web purchase qualifies for affiliate commission. It is not a FirstPromoter visitor or device identifier. FirstPromoter browser tracking and its measurement cookies remain disabled unless the applicable analytics or advertising consent has been granted. Declining that tracking does not erase the separate first-party commercial offer.

3. Purposes and legal bases

  • Provide the service and requested resources: performance of a contract or steps you ask us to take before entering one.
  • Marketing email: your consent. You can withdraw it at any time without affecting processing that occurred before withdrawal.
  • Payments, accounting, and legal obligations: compliance with applicable law.
  • Affiliate offer and commission administration: taking steps you request to apply a referred offer and our legitimate interests in honoring partner agreements, preventing fraud, resolving attribution disputes, and maintaining accurate commercial records.
  • Security, fraud prevention, suppression, and service reliability: our legitimate interests in protecting users and operating a safe service, balanced against your rights.
  • Optional analytics and advertising: consent where consent is required.

4. Service providers and recipients

We use service providers under contract for hosting and storage, authentication, payments, customer support, analytics, affiliate-program administration, and email delivery. FirstPromoter administers affiliate referrals and commissions; Stripe processes eligible web payments. Email-related providers include Loops and Twilio SendGrid; consent and suppression evidence for the landing-page resource flow is stored using Netlify. Providers receive only the data needed for their role. We do not sell personal data.

5. International transfers

Some providers process data outside Norway or the European Economic Area, including in the United States. Where required, we rely on an adequacy decision, the European Commission's Standard Contractual Clauses, and appropriate supplementary safeguards.

6. Retention

We retain account, purchase, and tax records for the periods required by law. The first-party affiliate-offer cookie expires after no more than 60 days; related purchase, refund, dispute, commission, and payout evidence is retained as needed for accounting, fraud prevention, partner disputes, and legal obligations. An unconfirmed newsletter request expires after 48 hours, after which we remove its raw email address and first name unless they remain necessary for a suppression or provider duty. For a website resource request with no pending or active marketing consent, we remove those direct identifiers 90 days after the latest reliable consent or delivery activity. We retain limited consent and delivery evidence for as long as needed to demonstrate the choice, resolve disputes, and protect the signup flow. We keep a minimal suppression record for as long as needed to honor an unsubscribe request and avoid sending marketing again. Other data is deleted or anonymized when those purposes no longer apply.

7. Your rights and choices

Depending on applicable law, you can request access, correction, deletion, restriction, or portability of your personal data, and object to processing based on legitimate interests. You can withdraw consent at any time. Every marketing email includes an unsubscribe control. The public email preferences page is also available for marketing sent through this website.

You may complain to the Norwegian Data Protection Authority (Datatilsynet) or the supervisory authority where you live or work. We will not discriminate against you for exercising a privacy right.

8. Security

We use access controls, provider secrets, signed download links, suppression checks, rate limits, and other technical and organizational safeguards appropriate to the risk. No transmission or storage system can be guaranteed completely secure.

9. Children

GTO Gecko is not intended for individuals under 18. We do not knowingly collect personal data from children.

10. Changes to this policy

We may update this policy as our services or legal obligations change. The current version and revision date are published on this page. Material changes will be communicated where required.

11. Contact

To exercise a right or ask a privacy question, contact:

This website uses cookies to enhance the user experience. See our Privacy Policy for details.