Last Updated: [01-07-2026]
This Personal Data Protection Policy (hereinafter – the Policy) describes how LLC “Gold Avenue” (ID: 420004499, Address: Georgia, Tbilisi, Dzmebi Zubalashvili St. No. 1) (hereinafter – the Company) collects, processes, stores, and protects your personal data during your use of the gold.ge website and the gold purchasing process.
Our data processing practices are in full compliance with the applicable Law of Georgia “On Personal Data Protection”, international best practices, and the Law of Georgia “On Facilitating the Suppression of Money Laundering and Terrorism Financing” (AML/CFT).
We process data strictly observing the principles of lawfulness, fairness, transparency, purpose limitation, minimization, accuracy, and security.
1. Data Controller and Contact Information
The entity responsible for processing your personal data is:
- Company Name: LLC “Gold Avenue”
- Identification Code (ID): 420004499
- Legal Address: Georgia, Tbilisi, Dzmebi Zubalashvili St. No. 1
- Email: info@gold.ge
- Phone Number: +995 032 2800002
2. Types of Personal Data We Collect
We process only the volume of data strictly necessary to achieve our purposes:
- Identification data: First name, last name, personal number, copy of an identity document (Passport/ID card) (only in mandatory cases defined by AML legislation).
- Contact data: Email address, phone number.
- Financial and transactional data: Payment details, bank account number, volume of investment gold purchased, price, and order history.
- Technical and Cookie data: IP address, browser type, device information, and website navigation history (for details, see Section 10).
3. Purposes and Legal Bases for Data Processing
We process your data for the following purposes and legal bases:
- Conclusion and execution of a contract: To process your order, issue an invoice/waybill, and deliver products.
- Fulfillment of a legal obligation (AML/CFT): For tax and financial accounting purposes. Additionally, under anti-money laundering legislation, we are an accountable entity. Upon exceeding statutory limits or in the event of a suspicious transaction, we are obligated to strictly identify/verify you and, if necessary, provide information to the Ministry of Finance of Georgia and/or its subordinate institutions.
- Direct marketing: To provide news, discounts, and investment offers (Legal basis: your prior, voluntary, and revocable consent).
- Legitimate interest of the Company: To ensure website security, prevent fraud, and improve service quality.
- Automated decisions (Profiling): Gold prices on our platform change in real-time (live mode), tied to international exchange prices. We declare that the Company does not use analysis of the user’s economic situation, behavior, or personal interests (profiling) to determine an individual price.
4. Data Sharing and International Transfer
Your data is strictly confidential. We share it with third parties only when necessary:
- Service providers: Hosting and IT providers, and payment systems.
- State authorities: The Financial Monitoring Service, investigative, or tax authorities – only in cases directly stipulated by law.
- International transfer: To ensure the proper functioning of the gold.ge website, hosting, IT support, and analytical services, user personal data may be transferred to and processed on servers located outside of Georgia.
- Consent: By agreeing to this Privacy Policy, the user declares written consent (in electronic form) to the international transfer of their data, including to countries that may not have the same data protection guarantees as Georgia (this may create risks of unauthorized data access or processing).
- Security measures: Regardless of the country to which the data is transferred, the Company takes all reasonable organizational and technical measures for the secure transfer of data and the protection of its confidentiality.
Note: The user is informed that the transfer of their personal data to countries lacking adequate data protection guarantees is carried out exclusively on the basis of a separate, specific, and voluntary written (electronic) consent expressed by the user on the website, which is separate from the general text of this Policy, in strict compliance with legal requirements. The user has the right to withdraw this consent at any time.
5. Data Retention Periods
- AML obligations: Identification data, copies of documents, and transaction details are stored for 5 years after the termination of the business relationship or the execution of a one-time transaction, in compliance with the mandatory requirement of the law.
- Tax purposes: Primary documentation reflecting the transaction is stored for the period established by tax legislation.
- Marketing: Data is stored until you withdraw (cancel) your consent, while records confirming the fact/time of granting and withdrawing consent are stored for 1 year after the termination of marketing in accordance with legal requirements.
6. Video Monitoring at the Service Location
Since the physical pickup of our products and service provision takes place at a stand located in a shopping center, the video monitoring process and responsibility for it, for the purpose of security and property protection, are delineated as follows:
- Monitoring conducted by the shopping center: The administration of the shopping center independently conducts video monitoring in the common area/perimeter. The administration is fully responsible for processing this data, storing the recordings, and ensuring their security, acting as an independent data controller. Accordingly, warning signs belonging to the shopping center are placed in this area.
- Monitoring conducted by the Company (Stand perimeter): The Company reserves the right to independently conduct video monitoring directly at its stand location for property protection and incident prevention. If the Company exercises this right, it will act as the data controller and, prior to starting video monitoring, will ensure: (a) the placement of a warning sign in a visible place on the stand, containing a easily recognizable image denoting video monitoring along with the name and contact details of our Company; (b) the protection of video recordings from unauthorized access, strict control over access, and systematic logging of each access instance.
Note: The user is informed that if the Company conducts video monitoring at its own stand, the recordings will be processed solely to achieve the aforementioned legitimate purposes and will be strictly protected as required by law.
7. Your (Data Subject) Rights
In accordance with the legislation of Georgia, you have the right to:
- Request information about the processing of your data and receive copies free of charge. If the data subject’s request is repeated with unreasonable frequency, the Company reserves the right to refuse fulfillment or set a reasonable fee for issuing copies, of which you will be notified immediately.
- Request correction or completion of incorrect or incomplete data.
- Request data erasure. Please note: this right is limited and does not apply to data the Company is legally obligated to keep under AML/CFT legislation (5-year mandatory period). The Company may also refuse erasure if the data is processed to fulfill a legal obligation or establish a legal claim.
- Request temporary suspension of data processing (except storage), such as during data accuracy verification or dispute periods.
- Request receipt of data you provided in a structured and machine-readable format or its transfer to another controller (where technically feasible).
- Withdraw your consent at any time (e.g., for direct marketing) using the method indicated in the sent email.
The data subject has the right, in case of a violation of rights and rules stipulated by the Law of Georgia “On Personal Data Protection”, to appeal to the personal data protection supervisory authority (the State Audit Office) and/or the court in accordance with the law.
Contact for Rights Realization: You can contact us via email at info@gold.ge. We will review your request and notify you of our response within the statutory timeframe, specifically: (a) for information/copies, data correction, erasure, and consent withdrawal requests – no later than 10 working days (can be extended by an additional 10 working days if necessary, with immediate notification); (b) for direct marketing termination – no later than 7 working days; (c) for data blocking requests – no later than 3 working days.
8. Data Security and Incident Response
- We employ adequate and reasonable technical and organizational measures appropriate to the potential risks of data processing. These ensure the protection of information security mechanisms (confidentiality, integrity, and availability) against unauthorized or unlawful processing, accidental loss, destruction, or disclosure. The Company ensures systematic logging of all actions performed on electronic data (including access, modification, disclosure, or erasure).
- In the event of a data security incident that is highly likely to pose a significant risk to your rights and freedoms, we will notify you without undue delay regarding the incident, the expected damage, and the measures taken to address it. Furthermore, in strict compliance with the law, a notification will be submitted to the personal data protection supervisory authority (the State Audit Office of Georgia) no later than 72 hours after discovering the incident, unless the incident is unlikely to cause significant harm or pose a threat to human rights.
- The Company maintains internal records of all data security incidents, their consequences, and the mitigation measures taken.
9. Amendments to the Policy
We reserve the right to update this Policy in accordance with changes in legislation or our services. In the event of significant changes, we will notify you by email or by posting a notice on the website.
10. Cookie Policy
10.1. What is a Cookie? A cookie is a small text file stored on your device (computer, tablet, or mobile phone) when you open our website. It helps the website remember your actions and preferences (e.g., language, authorization details) over a period of time, so you do not have to re-enter them upon every new visit to the site.
10.2. What types of cookies do we use? Our platform uses the following categories:
(a) Strictly necessary (technical) cookies: Critically important for the website’s proper functioning. They enable secure user authorization, session management, and the technical execution of the checkout process (including fraud prevention). Disabling these will cause service disruptions. Their use does not require prior consent.
(b) Analytical and statistical cookies: Used only with your prior consent. They help us understand how visitors interact with our website (e.g., longest-viewed pages, traffic sources). This data is anonymous and used solely to improve platform design and functionality.
(c) Functional cookies: Used only with your prior consent. They allow the website to remember your choices (e.g., preferred language or currency) and provide a personalized experience.
(d) Marketing (advertising) cookies: Used to deliver advertisements relevant to your interests, both on and off our website. These are used only based on your prior, active consent (Opt-in).
10.3. Cookie management and consent withdrawal: During your first visit to the website, a special information window (Cookie Banner) allows you to choose which cookies you consent to (excluding strictly necessary files). You can change your preferences, delete stored cookies, or completely block them at any time from your browser Settings. Please note that blocking technical cookies may limit your ability to purchase investment gold and manage your profile.
10.4. Data Retention for Cookies: Your active consent regarding the use of cookies and the associated data are stored for 24 months. After this period expires, the old data is deleted, and you will be prompted to renew/confirm your consent again upon visiting the website