Privacy Policy
University of Georgia LLC is an institution registered in accordance with the legislation of Georgia (hereinafter referred to as the "University").
Identification Code: 205037137
Address: 77a Kostava St., Saburtalo District, Tbilisi, Georgia
Website: https://ugshop.ug.edu.ge/en
Protection of Personal Data
1.1. The Privacy Policy of the University of Georgia LLC (hereinafter referred to as the "Policy") defines the purposes, main conditions, and rules for processing personal data of the University's users in order to protect the principle of user confidentiality and integrity.
Terms Used in the Document
Personal Data - Any information related to an identified or identifiable natural person. A person is identifiable when their identity can be established, directly or indirectly, including by reference to a name, surname, identification number, geolocation data, electronic communication identification data, or to one or more physical, physiological, mental, psychological, genetic, economic, cultural, or social characteristics.
Data Processing - Any operation performed on data, including collection, acquisition, access, photography, video monitoring and/or audio monitoring, organization, grouping, interconnection, storage, alteration, restoration, retrieval, use, blocking, erasure, or destruction, as well as disclosure of data by transmission, dissemination, publication, or otherwise making them available.
University - Determines the purposes and means of data processing, methods, forms, organizational and technical security measures, as well as the ways to exercise the rights of the data subject.
Data Subject - Any natural person whose data is being processed.
Consent of the Data Subject - The freely given, specific, informed, and unambiguous indication of the data subject's wishes by which they signify agreement to the processing of personal data relating to them, expressed by an active action, in writing, or orally, after receiving relevant information.
Data Controller - A natural person, legal entity, or public institution which, independently or jointly with others, determines the purposes and means of data processing, and processes data directly or through a data processor.
Data Protection Officer - A person determined/appointed by the data controller or data processor who performs the functions provided by law.
Direct Marketing - The direct and immediate delivery of information to a data subject by telephone, mail, email, or other electronic means regarding a natural person and/or legal entity, goods, ideas, services, or work.
Incident - A breach of data security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, transmission, storage, or otherwise processing of personal data.
What Data We Process
The University collects the following data:
Name and surname
Contact information (email, phone number)
Personal Number
Address
Payment information
Information regarding "Cookies"
Purposes of Data Processing
Personal data processing is carried out for the proper functioning of the online store and for the following purposes:
Order Management: Processing, payment, and delivery of products.
Communication: User support and feedback.
Service Improvement: Analysis of service quality and ensuring security.
Data Processing Principles
The University is guided by the following principles when processing data:
Legality and Transparency: Data is processed fairly, transparently, and in full compliance with user rights.
Purpose Limitation: Data is collected only for specific, legitimate purposes and is not processed in a manner incompatible with those purposes.
Data Minimization: We process only the volume of information necessary to achieve the stated purpose.
Accuracy: We ensure the accuracy of data and prompt correction or deletion of inaccurate information.
Storage Limitation: Data is stored only for the period necessary to achieve the purpose or as required by law, after which it is securely deleted or anonymized.
Security: We apply technical and organizational measures to protect data from unauthorized access, loss, or damage.
Rights of the Data Subject
The data subject enjoys the rights provided by Chapter 3 of the Law of Georgia on "Personal Data Protection," which includes, but is not limited to:
Right of Access - To receive information on what personal data is processed and for what purpose, including information on the person performing video monitoring, the purpose, and the legal basis of the monitoring.
Right to Rectification/Update - To request the correction or updating of inaccurate or incomplete data.
Right to Erasure ("Right to be Forgotten") - To request the deletion of data if its processing is no longer necessary for achieving the purpose or if consent has been withdrawn, except for exceptions established by law.
Right to Restriction of Processing - To request the restriction of data processing in cases defined by law.
Right to Withdraw Consent (Opt-out) - To withdraw previously given consent.
In case of violation of rights, to apply to the Audit Service or the Court.
Rules for Fulfilling Requests:
Response Period: The University is obliged to correct, update, add, delete, or destroy data within 10 calendar days of receiving a request from the data subject, or to notify the user in writing of the grounds for refusal.
Automatic Correction: If the University itself discovers that the data in its possession is inaccurate, it is obliged to correct it and notify the user immediately.
Data Processing for Direct Marketing Purposes
Consent: Data processing for direct marketing purposes is carried out only based on the user's prior consent. Written consent is required for processing additional personal data (other than name, address, phone number, and email).
Right to Opt-out: The user has the right to withdraw their consent at any time in the same form in which the marketing is carried out (e.g., Unsubscribe button).
Response Period: The University is obliged to cease data processing for marketing purposes no later than 7 working days from receiving the request.
Record Keeping: Information regarding consent to data processing and its withdrawal is stored during the period of direct marketing and for 1 year after its termination.
Data Transmission
Basis for Transmission: The University is authorized to transfer personal data to partner companies, contractors, and service providers only to the extent necessary for website functionality, order fulfillment, and security purposes.
Obligation of Third Parties: Any third party that gains access to data is obliged to protect its confidentiality and security based on the legislation of Georgia and the relevant agreement.
Specific Cases: Data transfer is carried out in the following necessary instances:
Courier Services: To ensure delivery of the order to the location.
Payment Systems: For secure processing and authorization of transactions.
Technical Support: To obtain proper operation of the website and analytical services.
Data Processing and Storage Periods
Targeted Storage: The University processes personal data only for the period necessary to achieve the purpose of its collection or as defined by the applicable legislation of Georgia.
Rules of Destruction: After the expiration of the storage period or the elimination of the basis for data processing, the information is deleted or destroyed in an irreversible manner (anonymization), excluding any subsequent identification of the person.
Specific Periods:
User Profile Data: Stored until the user cancels their personal account.
Order and Transaction History: Stored for 1 years from the execution of the order.
Marketing Communication Data: Stored until the user withdraws consent.
Claims and Correspondence History: Stored for 1 years from the final resolution of the issue (taking into account potential statutes of limitations for legal disputes).
Cookies: Stored according to their type, until the end of the browser session or for a period of 1 years (details can be found in the "Cookie Policy").
Cookies Policy
Definition: "Cookies" are small text files stored on your device when visiting a website. Through them, technical information is processed (e.g., IP address), which is necessary for the proper operation and security of the site.
Purpose: Essential cookies ensure the functioning of the website, while other types of records (analytical, functional) help us improve the quality of service and remember user preferences.
Management and Restrictions: The user has the right to change or withdraw consent to the use of cookies at any time. Please note that blocking or deleting them may cause restrictions on individual functions of the website.
Full Terms: Detailed information regarding cookie types, storage periods, and management is given in our (Cookie Policy), which is an integral part of this document.
Data Security Measures
Technical and Organizational Protection: The University uses modern security mechanisms to prevent unauthorized access, loss, destruction, alteration, or unlawful disclosure of personal data.
Access Control: Access to data is restricted to unauthorized persons. Information is available only to employees who need it to perform their official duties and are bound by confidentiality obligations.
Incident Response: In case of a data security breach (incident), the University acts in accordance with the rules established by law, which implies taking immediate measures and, if necessary, informing the supervisory authority and the data subject.
Personal Data Protection Officer
Supervision over the compliance of the University's personal data processing processes with the legislation and the protection of data subjects' rights is carried out by the Personal Data Protection Officer.
In case of any questions, claims, or recommendations, you can contact the officer at the following address:
Safe Data Solutions LLC
Email: [email protected]
Final Provisions
Consent and Familiarization: By using the website, the user confirms that they have read this Policy. Personal data processing is carried out solely on the grounds established by law and for the purposes defined by this document.
Changes to the Policy: The University reserves the right to periodically update the privacy policy. Information about changes will be posted on the website, after which the new edition of the document will enter into force.
Communication: For any questions related to the policy or data processing, the user is authorized to contact the University email address.
Legal Regulation: Issues not regulated by this Policy shall be governed in accordance with the applicable legislation of Georgia.