Skip to main content

Privacy Policy

Last updated: 15 August 2026

This Privacy Policy explains how personal and technical data is processed in connection with GetAISet (https://www.getaiset.com). We are committed to transparency, data minimization, and honoring your data protection rights under the EU General Data Protection Regulation (GDPR).

1. Data Controllers and Responsibilities

Personal data processed in connection with GetAISet is handled under distinct, separate data controller responsibilities based on the specific processing activity:

Website-Level Controller: Oberhauser Péter Zoltán

Oberhauser Péter Zoltán (private individual, Hungary) acts as the independent data controller for GetAISet's own website-level processing operations where he determines the purposes and essential means. This includes:

• Technical operation, hosting infrastructure management, and temporary server access log processing.

• Performance and analytics measurement via Google Analytics 4 (strictly consent-gated).

• Management of user consent preferences (stored in localStorage under "learnai_consent") and language preferences (stored via the "learnai_locale" cookie).

• Handling general, support, and privacy-related user inquiries received via contact@getaiset.com, support@getaiset.com, or privacy@getaiset.com.

Commercial & Affiliate Activity Controller: Forray Gyöngyi e.v.

Forray Gyöngyi (Hungarian individual entrepreneur) acts as a separate, independent data controller solely for personal data she independently processes in connection with her commercial and affiliate business activities. This includes:

• Managing commercial affiliate partnership accounts, network agreements, and direct business communications.

• Fulfilling statutory accounting, tax, and commercial recordkeeping obligations relating to affiliate commissions received.

Forray Gyöngyi does NOT automatically receive, process, or control personal data of visitors navigating to third-party merchant or course provider websites.

Official business registration and tax details are available on our dedicated Legal Notice page.

Separate Areas of Controller Responsibility

For the processing activities described in this policy, the two operators act independently within their respective areas of responsibility and separately determine the purposes and essential means of the processing for which they are responsible.

Third-Party Affiliate Destinations and Networks

When you click an outbound affiliate link on GetAISet, you are directed to an external third-party website (such as an AI tool provider, online course platform, or affiliate network). Those independent third parties process personal data in accordance with their own separate privacy policies. GetAISet does not control and is not responsible for data processing conducted by third-party destination platforms.

Privacy Inquiries and Contact Point

For all privacy questions, data subject rights requests, or inquiries regarding website-level data processing, please contact: privacy@getaiset.com. Complete service-provider identification and official addresses are available on our dedicated Legal Notice page.

2. Categories of Data We Process

We collect and process only the minimal data necessary to deliver, secure, and improve our educational directory and platform.

Technical Server Logs

When you access GetAISet, our edge hosting infrastructure automatically processes standard HTTP request headers and access logs. This technical data includes your IP address, browser type and version, operating system, referring URL, date and time of access, and requested pages. This information is processed temporarily to ensure system stability, prevent malicious activity, and mitigate DDoS attacks.

Analytics Data (Google Analytics 4 — Consent-Gated Only)

GetAISet sends sanitized analytics event parameters that are designed not to include direct identifiers, raw search terms, or unnecessary sensitive URL data. After analytics consent is granted, Google Analytics may nevertheless process pseudonymous identifiers, cookies, and device/browser information in accordance with Google's service configuration and policies.

The Google Analytics script is strictly consent-gated: it is not loaded or initialized unless and until you provide affirmative, explicit consent via our cookie consent banner. If you decline or make no choice, no analytics scripts load and no tracking requests or cookies are dispatched.

Local Browser Storage

We store your cookie consent choice ("granted" or "denied") in your browser’s localStorage under the key "learnai_consent" to remember your preference. We also use a functional cookie ("learnai_locale") to persist your selected interface language across sessions.

Affiliate and Outbound Interactions

When you click outbound links to partner platforms, educational providers, or tools, our platform records sanitized telemetry events (such as the target host and category) to measure aggregate interest in specific resources. We do not construct individual cross-site tracking profiles.

Direct Communications

If you contact us voluntarily via email (e.g., to contact@getaiset.com, support@getaiset.com, or privacy@getaiset.com), we process your name, email address, and message content solely to respond to your inquiry and address your request.

5. Data Retention Principles

Personal and technical data is retained only for as long as necessary to fulfill the purposes for which it was collected:

• Technical server logs are retained temporarily by edge infrastructure (typically up to 30 days) for security diagnostics and are automatically purged.

• Analytics data collected via Google Analytics 4 is retained in accordance with standard Google Analytics retention settings (up to 14 months) in aggregated reporting format.

• Email correspondence is retained for as long as necessary to resolve your request and for up to 3 years thereafter to maintain records of communications and legal compliance.

• Commercial accounting records maintained independently by the commercial operator are retained in accordance with mandatory statutory tax and accounting retention requirements.

6. Third-Party Infrastructure Providers

We rely on select, reputable infrastructure providers to operate the platform:

  • Hosting & Edge Delivery: Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA) provides hosting, serverless compute, and content delivery network (CDN) services.
  • Analytics (Strictly Consent-Gated): Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) / Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) provides Google Analytics 4 only upon explicit user consent.

7. International Data Transfers

Where data is processed by service providers based outside the European Economic Area (EEA), such transfers are governed by appropriate safeguards recognized under the GDPR, including the EU-U.S. Data Privacy Framework adequacy decision and Standard Contractual Clauses (SCCs) approved by the European Commission.

8. Your Data Subject Rights Under GDPR

Under Chapter III of the GDPR, you have the following fundamental rights regarding your personal data:

  • Right of Access (Art. 15 GDPR): You may request confirmation of whether your data is being processed and receive a copy of that data.
  • Right to Rectification (Art. 16 GDPR): You may request the correction of inaccurate or incomplete personal data.
  • Right to Erasure (Art. 17 GDPR): You may request the deletion of your personal data where retention is no longer necessary or lawful.
  • Right to Restriction of Processing (Art. 18 GDPR): You may request that we temporarily restrict processing in certain circumstances.
  • Right to Data Portability (Art. 20 GDPR): You may request to receive your provided data in a structured, commonly used, machine-readable format.
  • Right to Object (Art. 21 GDPR): You may object to data processing based on legitimate interests.
  • Right to Withdraw Consent (Art. 7(3) GDPR): You may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

9. Right to Lodge a Complaint

If you believe that the processing of your personal data infringes applicable data protection laws, you have the right to lodge a complaint with a competent supervisory authority.

In Hungary, the competent supervisory authority is:

Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary Postal address: 1363 Budapest, Pf.: 9. Website: https://www.naih.hu Email: ugyfelszolgalat@naih.hu Telephone: +36 (1) 391-1400

You may also lodge a complaint with the data protection supervisory authority in your EU Member State of habitual residence, place of work, or place of the alleged infringement.

10. Security and Integrity

We implement modern technical and organizational security measures, including HTTPS/TLS encryption for all data in transit, strict access controls, and regular infrastructure reviews. While we make every reasonable effort to protect your data, no method of transmission over the internet or electronic storage is completely infallible.

11. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our platform practices, technical architecture, or legal requirements. Any modifications will be posted on this page with an updated revision date.