Effective and last reviewed: 17 August 2026
This notice explains how ASSIO LEX & ASSOCIATES LLC collects and uses personal data through ITResidency.ge, how long information is kept, when it may be shared and how an individual may exercise data-protection rights.
1. Controller and scope
ASSIO LEX & ASSOCIATES LLC operates ITResidency.ge and is the controller of personal data collected through the public website, enquiry forms and preliminary eligibility tools. Where a professional engagement is accepted, the company also processes information needed to deliver the agreed legal or business service, subject to the engagement terms and applicable professional duties.
This notice applies to website visitors, prospective and current clients, applicants, family members, company owners and representatives, employees, contractors and other individuals whose information is provided in connection with an enquiry or matter. A person submitting information about another individual must have a lawful basis and appropriate authority to do so and should make this notice available to that individual.
Processing is governed primarily by the Law of Georgia on Personal Data Protection. Where the EU General Data Protection Regulation applies to a particular activity because of its territorial scope, we also apply the relevant additional requirements. References to an EU-style standard in this notice do not represent that the company is established in the European Union.
2. Personal data we collect
We collect information directly from the individual, from an authorised representative, through correspondence and documents, and—when required for an accepted matter—from public registers, Georgian authorities, professional advisers or service providers.
Contact and identity information
Name, email address, telephone number, citizenship, country of residence, passport or identity-document details and the identity and authority of a representative.
Case and professional information
Immigration status, travel and residence plans, profession, employment and contracting arrangements, experience, income evidence, business ownership, company and tax information, family details and the assistance requested.
Documents and communications
Information contained in optional uploads, contracts, invoices, certificates, correspondence, meeting notes and later matter records. Public enquiry forms currently accept no more than five PDF, JPG, PNG or WebP files of up to 5 MB each.
Technical and security information
Request time, basic server and security logs, form-consent record, case reference and a one-way hash derived from the connecting address for short-term abuse prevention. We do not use that hash to identify the visitor for marketing.
3. Why we use personal data
We use personal data only for specified purposes connected with the website, an enquiry, an accepted engagement or our legal and operational responsibilities. We do not sell personal data.
| Purpose | Typical legal basis |
|---|---|
| Receive an enquiry, provide a case reference, prepare a preliminary route or checklist and decide whether and how we can assist. | Steps requested before a possible contract; the individual's application to receive services; and consent where specifically requested. |
| Open, administer and perform an accepted legal or business-services engagement. | Performance of the engagement, compliance with legal and professional obligations, and legitimate interests in managing the matter. |
| Verify identity, authority, conflicts, eligibility facts and supporting evidence. | Contractual steps, legal obligations and legitimate interests in providing accurate and secure professional services. |
| Operate, secure and troubleshoot the website, prevent spam and protect the enquiry and case systems. | Legitimate interests in service security and continuity and compliance with data-security duties. |
| Maintain financial, administrative, consent and claims records. | Legal obligations and legitimate interests in accounting, audit, insurance and the establishment, exercise or defence of legal claims. |
| Send direct marketing or service updates not required for an existing matter. | Prior consent. Refusing or withdrawing marketing consent does not affect an enquiry or engaged service. |
4. Recipients and service providers
Access is limited to authorised personnel and advisers who need the information for the relevant purpose. Depending on the enquiry or engagement, information may be disclosed to secure hosting, database, file-storage, email and IT-support providers; translators, notaries, accountants, auditors, insurers, banks and other professional providers; Georgian public authorities, registries, courts or regulators; and another recipient instructed or authorised by the client.
Providers acting for us are selected with regard to confidentiality, security and data-protection requirements and receive only the information reasonably required for their function. We may disclose information when required by law, a binding authority request or the establishment, exercise or defence of legal claims. We do not disclose personal data to unrelated parties for their own advertising.
5. International transfers
Some technical or professional providers may process information outside Georgia, and a matter may require communication with a client, adviser or authority in another country. Before an international transfer, we consider the destination, purpose, information involved and the transfer mechanism required by Georgian law. Depending on the circumstances, safeguards may include a legally recognised adequacy basis, contractual protections, an authorised cross-border arrangement or a statutory exception that is applicable to the requested service.
Where the GDPR applies, any transfer outside the European Economic Area is also handled using the relevant EU transfer mechanism and supplementary safeguards where required. Information about the safeguard used for a particular transfer may be requested from the privacy contact.
6. Retention
We keep personal data only for as long as it is reasonably needed for the purpose collected, taking account of legal, professional, accounting, security and claims requirements. The principal periods and criteria are:
| Record | Retention approach |
|---|---|
| Abuse-prevention hash and rate-limit counter | Automatically eligible for deletion after 24 hours. |
| Enquiry form, correspondence and optional uploads where no engagement follows | Normally deleted or anonymised within 24 months after the last substantive contact, unless a shorter period is requested or a longer period is needed for a legal, security or claims reason. |
| Accepted client and matter records | Kept for the engagement and then for the period required by applicable law, professional duties, accounting rules, insurance requirements and limitation periods. Matter-specific holds override routine deletion. |
| Direct-marketing consent and withdrawal records | Kept while marketing continues and, as required by Georgian law, for one year after the relevant direct-marketing activity is discontinued. |
| Security logs and backup copies | Kept for a limited security or backup cycle and then overwritten or deleted unless needed to investigate an incident or comply with law. |
7. Security and confidentiality
We use proportionate technical and organisational measures designed to preserve confidentiality, integrity and availability. These include restricted staff access, authenticated administration, private object storage for uploaded documents, validation of file types and sizes, rate limiting, access logging, secure transport and provider controls. Access rights are reviewed according to role and operational need.
No internet transmission or storage system can be guaranteed to be completely secure. If a personal-data incident creates a material risk, we investigate, document and make any notification required by applicable law.
8. Preliminary automated assistance
The enquiry tools may generate a preliminary route and document checklist from the answers submitted. This output is an orientation aid, not a final legal, tax, immigration or eligibility decision. No final decision producing legal or similarly significant effects is made solely by automated processing. A member of the team reviews the enquiry before a professional recommendation or proposed engagement is issued, and the individual may ask for correction or human review.
9. Children and family information
The website is not directed to children. A parent, legal representative or appropriately authorised adult should provide information concerning a child in a family or residence matter. Under Georgian law, consent-based processing generally requires the minor's consent from age 16; below that age, the parent or other legal representative provides consent. Special-category data concerning a minor is handled only with the additional authority and safeguards required by law.
10. Your rights
Subject to the conditions and exceptions in applicable law, an individual may request information about processing; access and a copy; correction, updating or completion; termination of processing and deletion or destruction; blocking; data portability where the statutory conditions are met; withdrawal of consent; and review of a decision based solely on automated processing. Where the GDPR applies, the individual may also have rights to restrict processing and object to processing based on legitimate interests or direct marketing.
Under Georgian law, requests for processing information, access or deletion are generally answered or acted upon within 10 working days. A complex request may be extended by no more than a further 10 working days where the law permits and the individual is informed promptly. A request may be refused or limited only where an applicable legal ground allows it, including protection of another person's rights, legal retention duties or legal claims. We explain the reason and available appeal route where required.
Consent may be withdrawn at any time without affecting processing already carried out lawfully. Where no other legal basis remains, consent-based processing is terminated and the relevant data is deleted or destroyed within the period required by law.
Use the Personal Data Request page or contact us directly. Requests are normally free of charge, although the law may permit a reasonable response to manifestly unfounded or excessive repeated requests.
11. Direct marketing
We send direct marketing only with prior consent. Each marketing communication identifies a practical way to withdraw that consent. A withdrawal request is actioned within the period required by Georgian law and no later than seven working days. We do not make withdrawal more difficult or more expensive than giving consent.
12. Complaints and supervisory authority
Please contact us first so that we can investigate and respond. An individual may also appeal to the State Audit Office of Georgia, which has exercised the Georgian personal-data supervisory functions since 2 March 2026, or to a competent court. Where the GDPR applies, the individual may also complain to the competent supervisory authority in the relevant EU or EEA member state.
13. Changes to this notice
We may revise this notice to reflect changes in law, services, technology or processing. The current version is published on this page with its effective date. If a change materially affects information already collected, we provide any additional notice or obtain any consent required by law.
Contact the website operator
Please describe the information or right concerned and include enough detail for us to identify the relevant record. We may ask for proportionate proof of identity or authority before disclosing or changing personal data.
Company ID 400470566
75A Erosi Manjgaladze Street, Nadzaladevi District, 0112 Tbilisi, Georgia
info@itresidency.ge
+995 555 940 077
