1. General Provisions
This Privacy Policy explains how LLC "Samu Georgia" (ID 402323240, address: 6 Giorgi Tovstonogov St., Didube District, Tbilisi, Georgia) — brand "Appy.ge" (hereinafter — the "Company") collects, processes and protects users' personal data in accordance with the Law of Georgia on Personal Data Protection. The Company acts as the data controller.
By using the website, registering or placing an order, the User confirms that they have read this Policy.
2. Data We Collect
- Identification and contact data: first name, last name, personal/identification number, email, phone, address;
- Account data: username, hashed password, account settings;
- Transaction data: invoices, order contents, payment status, date and amount, the last four digits and type of the card (the Company does not store the full card number, expiry date or CVV);
- Technical and security data: IP address, browser and device data (User-Agent), authentication attempts, request logs, incidents detected by the security system and blocking records;
- Consent and delivery records: the fact of acceptance of the Terms, Return and Delivery Policies, together with the date, time and IP address, as well as system logs of service activation and handover;
- Communication data: correspondence by email, in the personal dashboard or through any other official channel.
3. Purposes and Legal Basis of Processing
- Provision of services, fulfilment of orders and operation of the personal dashboard — performance of the contract;
- Settlement, invoicing, tax and accounting records — legal obligation;
- Communication with the User, support and handling of complaints — performance of the contract and the Company's legitimate interest;
- Ensuring the security of the website and user accounts, prevention of unauthorised access, attacks and automated scanning — the Company's legitimate interest;
- Fraud prevention and submission of evidence to the bank, payment system or competent authority in disputed transactions and payment disputes (chargebacks) — the Company's legitimate interest and legal obligation;
- Sending news and marketing messages — the User's consent, which may be withdrawn at any time.
4. Card Data and Payments
Payments are processed through a licensed payment service provider. Full card data (number, expiry date, CVV/CVC) is entered directly on the secure page of the payment system and is neither transmitted to nor stored on the Company's servers. The Company receives only the transaction result, identifier, amount and the last four digits of the card.
In accordance with the requirements of the payment system, data related to a transaction is retained for at least 6 (six) months for the purpose of handling disputed operations.
5. Retention Periods
- Account and profile data — for the period the account is active and for 12 months after its deletion;
- Invoices, payment and accounting documentation — for the period established by Georgian legislation (as a rule, 6 years);
- Transaction-related data — at least 6 months;
- Consent and delivery records (including IP address) — for 3 years from completion of the service, taking into account the limitation period;
- Security logs and incident records — 12 months;
- Marketing consent — until the consent is withdrawn.
Upon expiry of the relevant period, data is deleted or irreversibly anonymised.
6. Data Sharing
The Company does not sell personal data. Data may be transferred only to the following categories, to the extent necessary:
- The payment service provider and the acquiring bank — for the purpose of executing payments, refunds and handling disputed transactions;
- Hosting and infrastructure providers — for the operation of the website;
- Email and messaging delivery services;
- The Revenue Service of Georgia — for the issuance of tax documents;
- Accounting, audit or legal advisers — subject to a confidentiality obligation;
- the software manufacturer (e.g. Microsoft) and its authorised distributor — to purchase and activate licences: organisation name and identification code, address, domain, and the contact person's name, email and phone;
- Competent state authorities — in cases provided for by law.
7. International Transfers
Certain technical services (hosting, email, analytics) may be provided from servers located outside Georgia. In such cases the Company ensures that the transfer is carried out in compliance with the requirements established by legislation and on the basis of appropriate contractual safeguards.
8. Data Protection
The Company applies organisational and technical measures: encryption of data in transit (HTTPS/TLS), password hashing, access restricted to authorised persons only, system logging, mechanisms for detecting and blocking automated attacks and unauthorised access, and regular backups.
9. User Rights
The User has the right to request information about the processing of their data, to obtain a copy of it, to request correction, updating, blocking, deletion or destruction of the data, and to withdraw consent at any time.
Requests must be submitted to the Company's official email address. The Company will respond within 10 (ten) working days. In order to identify the User, the Company is entitled to request additional information; during that period the time limit is suspended.
A deletion request does not extend to data which the Company is required to retain by law (including tax and accounting documentation) or which is necessary for bringing or defending a legal claim or for handling a disputed transaction.
10. Right to Lodge a Complaint
If the User considers that their data is being processed in breach of the law, they have the right to apply to the supervisory authority for personal data protection. As of 3 March 2026, the Personal Data Protection Service has been abolished and its functions have been transferred to the State Audit Office of Georgia (website: sao.pdp.ge). The User is also entitled to apply to the court.
The Company asks that the matter be raised with us directly in the first instance — the majority of cases are resolved at the internal review stage.
11. Cookies
The website uses cookies for the following purposes: maintaining the session and authentication, security (including CSRF protection), remembering language and user settings, and recording website usage statistics.
Without cookies that are strictly necessary for functioning, certain parts of the website (login, cart, payment) will not work. Cookies can be managed through the browser settings.
12. Analytics and Third Parties
The website uses Google Analytics 4 (provider: Google Ireland Limited) to measure visits and improve the website. The service is enabled only after your consent — by pressing the accept button in the cookie notice. Without consent no request is sent to Google and the corresponding cookies are not created.
Data processed: the date and duration of the visit, the pages viewed, the device and browser type, an approximate geographic location (country and city) and the source you arrived from. The IP address is anonymised. The data is processed on Google's servers and may be transferred outside the European Union on the basis of Google's standard contractual clauses.
You may withdraw consent at any time by clearing this website's data (cookies and localStorage) in your browser — the notice will appear again on your next visit. Further information: Google's Privacy Policy.
13. Changes to the Policy
The Company is entitled to amend this Policy. The updated version enters into force from the moment of its publication on the website. In the event of a material change, the User will be notified by email or by a notice placed on the website.
14. Contact
For any matter related to data protection, please contact us at the official email address or telephone number indicated on the website.