Privacy policy
Effective date: From the date of publication on www.greygeo.com
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when you access or use the website www.greygeo.com, create an account, place an order, contact customer support, subscribe to communications, or otherwise interact with the website.
The data controller responsible for the processing of personal data is:
Individual Entrepreneur Zinaida Amoeva
Identification Number: 302359418
Legal Address: 43 Paliashvili Street, Tbilisi, Georgia
Website: www.greygeo.com
Email: greysupport@gmail.com
For the purposes of this Privacy Policy, Individual Entrepreneur Zinaida Amoeva may also be referred to as “Greygeo,” “the Company,” “we,” “us,” or “our.”

1. Definitions
For the purposes of this Privacy Policy, the following terms shall have the meanings set out below.

1.1. Website
“Website” means the online store available at www.greygeo.com, including its pages, functions, forms, services, and related digital content.

1.2. User
“User,” “you,” or “your” means any natural person who visits, accesses, browses, registers on, places an order through, or otherwise uses the Website.

1.3. Customer
“Customer” means a User who places or attempts to place an order through the Website.

1.4. Personal Data
“Personal Data” means any information relating to an identified or identifiable natural person.
A person may be identifiable directly or indirectly, including by reference to a name, identification number, contact details, online identifier, location data, account information, or other characteristics specific to that person.
1.5. Processing
“Processing” means any operation or set of operations performed on Personal Data, whether by automated or non-automated means, including collection, recording, organisation, structuring, storage, adaptation, modification, retrieval, consultation, use, disclosure, transmission, restriction, erasure, anonymisation, or destruction.
1.6. Data Controller
“Data Controller” means the person who determines the purposes and means of processing Personal Data.
For the purposes of this Privacy Policy, the Data Controller is Individual Entrepreneur Zinaida Amoeva.
1.7. Data Processor
“Data Processor” means a third party that processes Personal Data on behalf of and under the instructions of the Data Controller, such as a payment provider, hosting provider, courier service, IT service provider, or communications platform.
1.8. Cookies
“Cookies” are small text files or similar technologies stored on a User’s device when the User visits the Website. Cookies may enable the Website to recognise a browser, remember preferences, maintain a shopping cart, analyse traffic, and improve Website functionality.
1.9. IP Address
“IP Address” means a numerical identifier assigned to a device connected to a network using the Internet Protocol.
1.10. Consent
“Consent” means a freely given, specific, informed, and unambiguous indication of the User’s wishes by which the User agrees to the processing of Personal Data for one or more specified purposes.
2. General Provisions
2.1.
This Privacy Policy applies to Personal Data processed in connection with the Website, including data collected when the User:
  • visits or browses the Website;
  • creates or uses an account;
  • places or pays for an order;
  • requests delivery;
  • communicates with customer support;
  • submits a form or request;
  • subscribes to marketing communications;
  • interacts with cookies or similar technologies;
  • otherwise uses the Website or its services.
2.2.
By using the Website and providing Personal Data, the User confirms that they have read and understood this Privacy Policy.
Where processing is based on consent, the Company will request such consent in an appropriate form.
2.3.
If the User does not agree with this Privacy Policy, the User should discontinue use of the Website and should not provide Personal Data through the Website.
2.4.
This Privacy Policy applies only to the Website and the services operated by the Company.
The Website may contain links to third-party websites, payment platforms, social media services, delivery services, or other external resources. The Company does not control the privacy practices of such third parties and is not responsible for their privacy policies, security measures, or processing activities.
Users should review the privacy policies of third-party services before providing Personal Data to them.
3. Personal Data We May Collect
Depending on how the User interacts with the Website, the Company may collect and process the following categories of Personal Data.
3.1. Identification and contact information
This may include:
  • first name;
  • last name;
  • telephone number;
  • email address;
  • delivery address;
  • billing address;
  • country, city, or region;
  • information provided in communications with the Company.
The Company generally does not require a personal identification number unless it is necessary for a specific transaction, delivery, customs, tax, accounting, legal, or regulatory purpose.
3.2. Account information
Where account registration is available, the Company may process:
  • account username;
  • encrypted or protected login credentials;
  • account preferences;
  • order history;
  • saved addresses;
  • communication preferences;
  • account activity.
Users are responsible for maintaining the confidentiality of their login credentials.
3.3. Order and transaction information
This may include:
  • products ordered;
  • order number;
  • order value;
  • transaction status;
  • payment confirmation;
  • delivery instructions;
  • order history;
  • refund or cancellation information, where applicable;
  • communications relating to an order.
3.4. Payment information
Payments may be processed by third-party banks, payment processors, or payment service providers.
The Company does not ordinarily receive or store full payment card numbers, card verification codes, or complete banking credentials.
The Company may receive limited payment-related information, such as:
  • payment status;
  • transaction identifier;
  • payment method;
  • masked card information;
  • payment date and amount;
  • confirmation or failure information.
Payment providers process payment information under their own privacy and security policies.
3.5. Technical and usage information
When the User visits or uses the Website, certain technical information may be collected automatically, including:
  • IP Address;
  • browser type and version;
  • device type;
  • operating system;
  • language settings;
  • approximate location derived from technical data;
  • date and time of access;
  • pages viewed;
  • time spent on pages;
  • referring website or source;
  • navigation and interaction data;
  • error logs;
  • cookie identifiers;
  • session information.
3.6. Customer support and communications
When the User contacts the Company, the Company may process:
  • the contents of emails and messages;
  • contact details;
  • complaint or request information;
  • photographs or documents submitted by the User;
  • records of correspondence;
  • support history.
3.7. Marketing preferences
Where the User subscribes to marketing communications, the Company may process:
  • email address;
  • telephone number;
  • marketing consent status;
  • subscription date;
  • communication preferences;
  • information about whether communications were opened or interacted with, where such tracking is used lawfully.
3.8. Information from third parties
The Company may receive Personal Data from:
  • payment providers;
  • courier and delivery companies;
  • technical service providers;
  • social media platforms;
  • analytics providers;
  • fraud prevention providers;
  • business partners;
  • public authorities, where permitted or required by law.
The Company will only process such information where there is a lawful basis to do so.
4. Purposes of Processing Personal Data
The Company may process Personal Data for the following purposes.
4.1. Website operation
To:
  • provide access to the Website;
  • maintain Website functionality;
  • enable navigation and shopping cart functions;
  • remember User preferences;
  • maintain technical security;
  • diagnose and resolve technical issues.
4.2. Account management
To:
  • create and manage User accounts;
  • authenticate Users;
  • maintain account security;
  • provide access to personalised features;
  • store order history and preferences.
4.3. Order processing
To:
  • receive and confirm orders;
  • verify order information;
  • process payment status;
  • prepare and fulfil orders;
  • contact the Customer regarding an order;
  • provide order updates;
  • maintain transaction records.
4.4. Delivery
To:
  • organise shipment or delivery;
  • share necessary information with courier or logistics providers;
  • verify delivery details;
  • resolve delivery issues;
  • provide delivery status information.
4.5. Customer support
To:
  • respond to questions;
  • process requests or complaints;
  • provide technical assistance;
  • resolve order-related issues;
  • maintain records of customer communications.
4.6. Fraud prevention and security
To:
  • verify transactions;
  • prevent fraudulent, unlawful, or abusive activity;
  • protect the Website, Users, and Company systems;
  • detect suspicious behaviour;
  • enforce Website rules and legal rights.
4.7. Legal and regulatory compliance
To:
  • comply with Georgian law;
  • satisfy accounting, tax, consumer protection, and reporting obligations;
  • respond to lawful requests from public authorities;
  • establish, exercise, or defend legal claims;
  • maintain records required by law.
4.8. Website improvement and analytics
To:
  • understand Website use;
  • analyse performance;
  • improve Website design, navigation, products, and services;
  • measure technical effectiveness;
  • develop new functions;
  • identify errors and usability issues.
4.9. Marketing communications
Where permitted by law and, where required, based on the User’s consent, to:
  • send news;
  • send information about products;
  • send promotions and special offers;
  • send newsletters;
  • provide personalised marketing communications.
The User may unsubscribe from marketing communications at any time.
4.10. Business administration
To:
  • maintain internal business records;
  • manage service providers;
  • audit transactions;
  • protect business interests;
  • administer contracts and commercial relationships.
5. Legal Bases for Processing
The Company processes Personal Data only where a lawful basis exists.
Depending on the circumstances, processing may be based on one or more of the following grounds:
5.1. Performance of a contract
Processing may be necessary to:
  • process an order;
  • collect or confirm payment;
  • arrange delivery;
  • provide customer support;
  • perform obligations arising from a transaction.
5.2. Steps taken at the User’s request before entering into a contract
Processing may be necessary to:
  • respond to product inquiries;
  • provide order information;
  • prepare an order;
  • communicate before purchase.
5.3. Compliance with a legal obligation
Processing may be necessary to comply with:
  • tax obligations;
  • accounting obligations;
  • consumer protection requirements;
  • regulatory requirements;
  • court orders;
  • lawful requests from public authorities.
5.4. Consent
Processing may be based on the User’s consent, including for:
  • certain marketing communications;
  • optional cookies;
  • certain analytics or advertising technologies;
  • other optional processing activities.
The User may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
5.5. Legitimate interests
Where permitted by law, the Company may process Personal Data for legitimate interests, including:
  • preventing fraud;
  • securing the Website;
  • improving services;
  • maintaining business records;
  • protecting legal rights;
  • managing customer relationships;
  • ensuring operational efficiency.
The Company will consider the impact of such processing on the User’s rights and interests.
5.6. Protection of important interests or other grounds provided by law
In exceptional circumstances, Personal Data may be processed where necessary to protect important interests or where another lawful basis under Georgian law applies.
6. Cookies and Similar Technologies
6.1.
The Website may use cookies, pixels, local storage, tags, and similar technologies.
6.2.
Cookies may be used for the following purposes:
  • enabling essential Website functions;
  • maintaining a shopping cart;
  • remembering User preferences;
  • maintaining login sessions;
  • improving Website security;
  • measuring Website performance;
  • analysing Website traffic;
  • supporting marketing activities, where permitted.
6.3.
Cookies may be categorised as:
  • Strictly Necessary Cookies — required for the Website to operate;
  • Functional Cookies — used to remember settings and preferences;
  • Analytics Cookies — used to understand how the Website is used;
  • Advertising Cookies — used to support or measure marketing activities.
6.4.
Where required by law, optional cookies will only be used after the User has provided consent.
6.5.
The User may control or delete cookies through browser settings or through the Website’s cookie settings, where available.
Disabling certain cookies may affect Website functionality, but disabling optional cookies should not prevent access to the main informational content of the Website.
7. Disclosure of Personal Data
The Company does not sell Personal Data.
The Company may disclose Personal Data only where necessary, lawful, and proportionate.
Recipients may include the following.
7.1. Payment service providers
Banks, acquiring institutions, and payment processors may receive information necessary to process payments and prevent fraud.
7.2. Courier and logistics providers
Courier, postal, customs, or logistics providers may receive information such as:
  • Customer name;
  • telephone number;
  • delivery address;
  • delivery instructions;
  • order or shipment details.
7.3. Technology and hosting providers
Hosting providers, cloud service providers, website developers, IT support providers, security providers, email providers, and analytics platforms may process Personal Data where necessary to provide their services.
7.4. Professional advisers
The Company may disclose information to accountants, auditors, lawyers, consultants, insurers, and other professional advisers where necessary.
7.5. Public authorities
Personal Data may be disclosed to courts, law enforcement bodies, tax authorities, regulators, or other authorised bodies where disclosure is required or permitted by Georgian law.
7.6. Business transfers
If the business, Website, assets, or relevant operations are sold, transferred, reorganised, or merged, Personal Data may be disclosed to potential or actual successors, advisers, or transaction parties, subject to appropriate safeguards.
7.7. Protection of rights
The Company may disclose information where reasonably necessary to:
  • protect the rights or property of the Company;
  • protect Users or third parties;
  • prevent fraud or security incidents;
  • establish, exercise, or defend legal claims.
Service providers receiving Personal Data are expected to process it only for authorised purposes and to apply appropriate confidentiality and security measures.
8. International Transfers
Some service providers used by the Company may store or process Personal Data outside Georgia.
Where Personal Data is transferred internationally, the Company will take reasonable and legally required measures to ensure that the transfer complies with applicable Georgian data protection law.
Such measures may include:
  • transferring data to a jurisdiction recognised as providing appropriate protection;
  • using contractual safeguards;
  • obtaining consent where legally appropriate;
  • relying on another lawful transfer mechanism.
9. Data Retention9.1.
The Company does not retain Personal Data indefinitely unless continued retention is required by law or is necessary for a lawful purpose.
9.2.
Personal Data is retained only for as long as reasonably necessary to:
  • fulfil the purposes described in this Privacy Policy;
  • complete orders and deliveries;
  • provide customer support;
  • comply with tax and accounting requirements;
  • resolve disputes;
  • establish, exercise, or defend legal claims;
  • prevent fraud;
  • enforce agreements;
  • comply with legal obligations.
9.3.
Different categories of Personal Data may be retained for different periods.
For example:
  • account data may be retained while the account remains active and for a reasonable period thereafter;
  • order and transaction records may be retained for the period required by tax, accounting, and commercial law;
  • customer support records may be retained for as long as necessary to resolve issues and protect legal interests;
  • marketing data may be retained until consent is withdrawn or the User unsubscribes, unless another lawful basis applies;
  • technical logs may be retained for a limited period necessary for security, fraud prevention, and troubleshooting.
9.4.
When Personal Data is no longer required, it will be securely deleted, destroyed, or anonymised, unless continued storage is required by law.
10. Data Security
10.1.
The Company applies reasonable organisational and technical measures designed to protect Personal Data against:
  • unauthorised access;
  • unlawful processing;
  • accidental loss;
  • alteration;
  • disclosure;
  • destruction;
  • misuse.
10.2.
Security measures may include:
  • access controls;
  • password protection;
  • secure connections;
  • restricted staff access;
  • data minimisation;
  • monitoring and technical safeguards;
  • service-provider confidentiality obligations;
  • backup and recovery procedures where appropriate.
10.3.
No method of online transmission or electronic storage is completely secure. Therefore, the Company cannot guarantee absolute security.
However, the Company will take reasonable steps to protect Personal Data in accordance with applicable law.
10.4.
Users are responsible for protecting their account credentials and should not share passwords or authentication information with third parties.
Users should notify the Company promptly if they suspect unauthorised access to their account.
11. Personal Data Breaches
If the Company becomes aware of a Personal Data breach, it will assess the nature and potential consequences of the incident.
Where required by applicable law, the Company will:
  • take measures to contain and remedy the breach;
  • document the incident;
  • notify the competent authority;
  • notify affected Users where the breach is likely to create a significant risk to their rights and freedoms.
12. User Rights
Subject to applicable Georgian law, the User may have the following rights.
12.1. Right to information
The User may request information about:
  • whether the Company processes their Personal Data;
  • what categories of data are processed;
  • the purposes of processing;
  • the legal basis for processing;
  • the source of the data;
  • recipients or categories of recipients;
  • applicable retention periods;
  • automated decision-making, where applicable.
12.2. Right of access
The User may request access to their Personal Data and, where provided by law, obtain a copy.
12.3. Right to rectification
The User may request the correction, updating, or completion of inaccurate or incomplete Personal Data.
12.4. Right to erasure or destruction
The User may request deletion or destruction of Personal Data where:
  • the data is no longer necessary;
  • consent has been withdrawn and no other lawful basis exists;
  • processing is unlawful;
  • deletion is otherwise required by law.
The right to erasure may not apply where retention is necessary to comply with a legal obligation, resolve disputes, prevent fraud, or establish, exercise, or defend legal claims.
12.5. Right to restriction or blocking
The User may request that processing be restricted or data be blocked where permitted by law, including while the accuracy or lawfulness of processing is being reviewed.
12.6. Right to withdraw consent
Where processing is based on consent, the User may withdraw consent at any time without providing a reason.
Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
12.7. Right to object
Where provided by law, the User may object to processing based on legitimate interests or to processing for direct marketing purposes.
12.8. Right relating to direct marketing
The User may unsubscribe from direct marketing communications at any time by:
  • using the unsubscribe link in an email;
  • following the instructions in the communication;
  • contacting the Company at greysupport@gmail.com.
12.9. Rights relating to automated decisions
Where applicable, the User may have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except where permitted by law and subject to appropriate safeguards.
The Company does not currently intend to make legally significant decisions solely through automated processing.
12.10. Right to complain
If the User believes that their Personal Data has been processed unlawfully, the User may contact the Company, apply to the competent Georgian data protection authority, or seek judicial protection in accordance with applicable law.
13. Exercising User Rights13.1.
To exercise any privacy right, the User may contact:
Email: greysupport@gmail.com
The request should clearly describe:
  • the User’s identity;
  • the right the User wishes to exercise;
  • the Personal Data or processing activity concerned;
  • any relevant order or account information.
13.2.
The Company may request additional information reasonably necessary to verify the identity of the requester and protect Personal Data from unauthorised disclosure.
13.3.
Requests will be handled within the time limits prescribed by applicable Georgian law.
13.4.
The exercise of privacy rights is generally free of charge. However, the Company may refuse manifestly unfounded, repetitive, or excessive requests where permitted by law.
13.5.
Where a request is denied or restricted, the Company will provide an explanation where required by law and inform the User of available complaint or appeal mechanisms.
14. Marketing Communications14.1.
The Company may send marketing communications only where permitted by law and, where required, after obtaining the User’s consent.
14.2.
Marketing communications may include:
  • product announcements;
  • promotions;
  • special offers;
  • newsletters;
  • brand updates;
  • invitations or campaigns.
14.3.
The User may withdraw marketing consent or unsubscribe at any time.
Unsubscribing from marketing communications will not prevent the Company from sending transactional or service-related messages, such as:
  • order confirmations;
  • payment notifications;
  • delivery updates;
  • security notifications;
  • responses to customer support requests.
15. Children’s Privacy
The Website is not intended to knowingly collect Personal Data directly from children who are not legally permitted to enter into online transactions independently.
If a child uses the Website, the involvement and consent of a parent or legal representative may be required in accordance with applicable law.
If the Company becomes aware that Personal Data has been collected from a child without an appropriate legal basis, the Company will take reasonable steps to delete or otherwise lawfully address that information.
16. User Responsibilities
The User is responsible for:
  • providing accurate, complete, and current information;
  • updating Personal Data when it changes;
  • protecting account credentials;
  • ensuring that information provided about another person is provided lawfully;
  • avoiding the submission of unnecessary sensitive information;
  • notifying the Company of suspected unauthorised account access.
The User should not provide false, misleading, or unlawfully obtained Personal Data.
17. Limitation of Responsibility
The Company is responsible for processing Personal Data in accordance with applicable Georgian law.
The Company is not responsible for:
  • privacy practices of third-party websites or services;
  • data processing independently carried out by payment providers, courier companies, social networks, or other third-party controllers;
  • disclosure resulting from the User voluntarily publishing information;
  • disclosure caused by the User sharing account credentials;
  • events outside the Company’s reasonable control, provided the Company has taken measures required by law.
Nothing in this Privacy Policy excludes or limits liability that cannot lawfully be excluded or limited under Georgian law.
18. Dispute Resolution and Complaints18.1.
Users are encouraged to first contact the Company regarding any privacy-related concern.
18.2.
A complaint may be submitted by email to:
greysupport@gmail.com
18.3.
The Company will review the complaint and respond within a reasonable period and within any mandatory period established by law.
18.4.
If the matter cannot be resolved, the User may apply to the competent Georgian authority or court in accordance with the legislation of Georgia.
18.5.
This Privacy Policy and disputes arising from it are governed by the laws of Georgia.
19. Changes to This Privacy Policy19.1.
The Company may amend or update this Privacy Policy from time to time to reflect:
  • changes in law;
  • changes in Website functionality;
  • changes in business operations;
  • changes in service providers;
  • changes in data-processing practices;
  • security or compliance requirements.
19.2.
The revised Privacy Policy becomes effective when published on www.greygeo.com, unless a different effective date is specified.
19.3.
Where changes materially affect the rights or interests of Users, the Company may provide additional notice where reasonably appropriate or legally required.
Users are encouraged to review this Privacy Policy periodically.
20. Contact Information
For questions, requests, complaints, or concerns relating to this Privacy Policy or the processing of Personal Data, please contact:
Data Controller: Individual Entrepreneur Zinaida Amoeva
Identification Number: 302359418
Legal Address: 43 Paliashvili Street, Tbilisi, Georgia
Website: www.greygeo.com
Email: greysupport@gmail.com
21. Final Provisions
By continuing to use the Website, the User confirms that they have had the opportunity to review this Privacy Policy.
Where a specific processing activity requires consent, continued Website use alone will not replace consent if Georgian law requires a separate, freely given, specific, informed, and unambiguous consent.
If any provision of this Privacy Policy is held to be invalid or unenforceable, the remaining provisions will continue to apply to the extent permitted by law.
This Privacy Policy takes effect from the date of its publication on www.greygeo.com and remains effective until replaced by an updated version.
Ask question
Our besties
Contact us
greysupport@gmail.com
Vake-Paliashvili 43
Vera-Tarkhnishvili 9
11:00-20:00
Contact us
greysupport@gmail.com
Vake-Paliashvili 43
Vera-Tarkhnishvili 9
11:00-20:00
© All Rights Reserved.
Created by: KPS.GE
CONTACTS