How we use information submitted through this website.

This policy explains what LegalTech Georgia collects, why and on what legal basis it is processed, who may have limited access to it and how you can exercise your rights.

1. Who is responsible for processing

The purposes and means of personal-data processing within LegalTech Georgia are determined by project lead Luka Shakhkulashvili. For privacy questions, use the contact form on this website.

2. Information we collect

Depending on the form, we may process your name, email, organisation, title, professional role, sector, country and city, time zone, topics of interest, preferred involvement, LinkedIn URL, product or partnership information, submitted text and campaign-source parameters. A membership application may also record profile visibility, member-message and communications choices. An organisational application includes the organisation description, activity and expertise, website, work contact details and the choice to display a representative. An organisation account may additionally record team members’ work emails, names, roles, access levels, invitation status and activation status. When you enter the member space, we process the authenticated account email and professional information used in your profile.

3. Purposes and legal bases

We use information to register and respond to an expression of interest or application, review applications, plan events, provide requested information and operate member-space features. Depending on the processing activity, the legal basis may be your consent; the need to review an application you submitted and provide a service you requested; an important legitimate interest in securely administering the platform, accounts and information where that interest is not overridden by your rights; or compliance with a legal obligation. Marketing updates are sent only on the basis of separate consent.

4. Consent to updates

Receiving updates is voluntary. You can withdraw consent at any time through the method shown in a message or through the website contact form. Withdrawal does not affect processing lawfully carried out before it.

5. Who may receive information and where it is processed

We do not sell personal information or share it with partners for their own marketing. An individual profile is shown only according to the member’s visibility choices. An organisation’s public profile shows only information designated for public display. Team members’ emails and account-management information are not public. Our technical providers may have limited access where needed to provide their services: Microsoft Azure for application hosting; Supabase for database, authentication and storage; and Resend for service and authentication email. Depending on their infrastructure, information may also be processed outside Georgia. Any such transfer and processing must be handled in accordance with the conditions and safeguards required by applicable Georgian law.

6. Retention

Interest and application information is kept for the period needed to manage the relevant process and is reviewed periodically. A member profile is kept for the duration of membership; after membership ends it is deleted or restricted unless retention is required by law or needed to protect legal claims. Communications data is kept until consent is withdrawn.

7. Your rights

Where Georgian law applies, you may request information about processing, access, a copy, correction, updating, deletion or cessation of processing. You may also withdraw consent and, where provided by law, contact the State Audit Office of Georgia, which exercises supervisory powers in the field of personal-data protection.

8. Technical site data

The site stores your language preference using a cookie and local storage. Session cookies support sign-in. These records support the relevant site functions. When a form is submitted, we may record campaign-source parameters and the referring page to understand which communications generate genuine interest. We do not currently use advertising cookies or behavioural analytics.

9. Security and changes

We use reasonable technical and organisational measures to protect information, including authentication, role-based access and database access controls. If this policy changes materially, the updated date on this page will change.

10. Retention management

Retention is managed by purpose and status: incomplete or unsuccessful applications, resolved enquiries, service-email records, active member profiles and security/audit records are reviewed separately. Information is deleted or anonymised when no longer needed for its purpose unless a legal obligation, security incident or defence of a legal claim requires longer retention. You may use the contact form to ask about the basis and current retention period for a particular record.

11. Requests and complaints

We may need to verify your identity reasonably before acting on a rights request. We will respond within the period required by applicable law and explain the outcome or any lawful restriction. If you are not satisfied, you may use the complaint mechanisms available under law and contact the State Audit Office of Georgia.