Privacy Policy — GBK Amplification

Version 2026-07 · Effective July 24, 2026

This Privacy Policy explains what personal data GBK Amplification collects when you use gbkamps.com and Plex '87, why we collect it, who we share it with, and the rights you have over it. We built Plex '87 to process audio entirely on your machine — this policy is mostly about the account and licensing data that makes that possible.

1. Who we are (controller)

The data controller is Rodrigo Koerich Engenharia e Informática Ltda, operating as GBK Amplification, CNPJ 04.717.512/0001-24, with registered offices at Rua João Pinto, 30, sala 101, Centro, Florianópolis/SC, 88010-420, Brazil.

You can reach our data-protection contact at privacy@gbkamps.com. As a small-scale processing agent under ANPD Resolution CD/ANPD No. 2/2022, we provide this communication channel instead of appointing a named data protection officer, as art. 11 of that resolution allows.

2. What we collect

We collect the following categories of data:

What we do not collect: behavioral analytics, tracking cookies, or the audio you process through the plugin — all audio processing happens 100% locally on your device and never reaches our servers.

3. Why we process your data

We map each purpose to a legal basis under LGPD art. 7 and, for users in the EU/UK, the equivalent GDPR art. 6 basis:

Automated decisions. Our licensing system enforces limits automatically: the software stops working when a trial ends or a license fails validation, and a refund or successful chargeback automatically revokes the license it paid for (Terms of Use, Section 6). These decisions follow objective rules and are necessary to operate the licensing model you contracted. You can always request human review of an automated decision that affects you — including a chargeback-related revocation — by writing to privacy@gbkamps.com (LGPD art. 20; GDPR art. 22).

4. Cookies and local storage

We do not use analytics or tracking cookies, and we do not show a cookie banner because we do not need your consent for what we actually use: essential session storage (your authentication tokens, kept in your browser) and the strictly necessary cookies set by Paddle during checkout.

5. Who we share your data with

We work with a small number of service providers (operators/sub-processors) — and, for payments, one independent controller — to run gbkamps.com and Plex '87:

When you complete a purchase, we receive from Paddle the data we need to provision your license — your email address, country, and transaction reference — but never your card details.

Where we transfer personal data internationally, we use the safeguards available under LGPD art. 33 — in particular the standard contractual clauses approved by ANPD Resolution CD/ANPD No. 19/2024, where our providers offer them, and equivalent contractual protections otherwise. For transfers subject to the GDPR or UK GDPR, we rely on the EU standard contractual clauses and, where the provider is certified, on the EU-US Data Privacy Framework and its UK Extension.

We do not sell your personal data, and we do not share it for advertising purposes.

6. How long we keep your data

We keep your account data for as long as your account exists. After you delete your account, we delete or anonymize it, except for the minimal records we need to: (a) comply with legal obligations — tax and accounting rules, and the six-month retention of application-access logs required by Brazilian law (Marco Civil da Internet, art. 15); and (b) establish, exercise, or defend legal claims.

In particular, if you obtained a license, we keep the link between your license identifiers — including the forensic watermark identifier — and your identity for 5 years after account deletion, so that we can enforce our license terms and our copyright if a leaked copy traceable to that license surfaces. We also keep hw_identity for the same period, so that the one-account-per-device and one-trial-per-account limits keep working after an account is deleted. Legal bases: LGPD arts. 7 II, VI and IX and 16 I; GDPR arts. 6(1)(c), 6(1)(f) and 17(3)(b) and (e).

Application-access logs are kept for six months, as Brazilian law requires (Marco Civil da Internet, art. 15 — a legal obligation, not a choice), under confidentiality. Other security logs are kept for a short, proportionate period — no longer than 12 months — after which they are deleted or anonymized.

7. Your rights

If you are in Brazil (LGPD art. 18), you can ask us for: confirmation that we process your data; access to it; correction; anonymization, blocking, or deletion of unnecessary or excessive data; portability; information about who we share it with; information about the consequences of not consenting; withdrawal of consent where consent is our legal basis; and review of decisions taken solely by automated means (art. 20). Send these requests to privacy@gbkamps.com; we aim to respond within 15 days, and always within the deadlines set by your local law. You can also file a complaint with the ANPD (Autoridade Nacional de Proteção de Dados).

If you are in the EU or UK (GDPR/UK GDPR), you have the right to access, rectify, erase, restrict, or port your data, to object to our processing, not to be subject to solely automated decisions with legal or similarly significant effects, and to lodge a complaint with your local supervisory authority.

Right to object. Where we rely on legitimate interest (Section 3), you may object at any time, on grounds relating to your particular situation, by writing to privacy@gbkamps.com. We will stop the processing unless we have compelling legitimate grounds, or need it to establish, exercise, or defend legal claims.

We may ask you to verify your identity before acting on any of these requests.

8. Security

We use TLS to encrypt data in transit, store passwords using a strong cryptographic hash, and design hw_identity to be pseudonymized from the start. Server secrets are never exposed in API responses or logs, and access to production data is limited to what each system component needs.

No system is 100% secure. If a security incident affects your personal data, we will notify you and the relevant authorities as required by LGPD and, where applicable, GDPR.

9. Children

Our services are intended for people aged 18 and older. We do not knowingly collect personal data from minors. If we learn that we have, we will delete it — contact privacy@gbkamps.com if you believe this applies to you or your child.

10. International users (EU/UK)

If you are in the EU or UK, the legal bases in Section 3, the international transfer safeguards in Section 5, and the rights in Section 7 apply to you as your GDPR/UK GDPR protections. You can contact privacy@gbkamps.com in English at any time.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will give you reasonable notice of material changes. The version number and effective date are always shown at the top of this page.

12. Contact

For anything related to your personal data or this policy, write to privacy@gbkamps.com. For formal legal notices, legal@gbkamps.com.