Privacy Policy
Official version in Georgian: ქართული (authoritative)
Data Controller: ნივი (Nivi)
Registration No.: [TODO]
Address: [TODO: full address], Akhalkalaki, Georgia
Data protection contact: [email protected]
1. Scope
This Privacy Policy describes how NIVI ("we", "Platform") collects, processes, and protects personal data of users and visitors of the NIVI marketplace (nivi.ge). This Policy is adopted in compliance with the Law of Georgia on Personal Data Protection (2012, as amended through 2024).
2. Personal Data We Collect
| Category | Data | Legal basis | Purpose |
|---|---|---|---|
| Account | Phone number | Contract performance | OTP authentication |
| Account | Display name | Contract performance | User identification |
| Account | Profile photo | Contract (optional) | Public profile display |
| Account | Business details (name, address, description, website) | Contract (optional) | Business profile display |
| Listings | Photos, titles, descriptions, prices, location | Contract performance | Publishing listings |
| Technical | IP address | Legitimate interest | Security, anti-fraud |
| Technical | Browser and device info | Legitimate interest | Service stability |
| Technical | Session and CSRF cookies | Legitimate interest | Authentication and security |
| Preferences | Language cookie | Legitimate interest | Service personalisation |
3. How We Use the Data
- Authenticating users via OTP (one-time password) delivered by SMS
- Publishing and displaying your listings to other users and visitors
- Displaying your phone number on your listing pages
- Sending in-app notifications about listing status changes
- Moderating content to ensure quality and compliance
- Detecting and preventing fraud, spam, and abuse
- Ensuring technical stability and security of the Platform
4. Visibility of Your Phone Number
Your phone number is displayed on your active listing pages and is visible to all visitors of NIVI, including unauthenticated visitors. This is an intentional core feature of the marketplace, enabling buyers to contact sellers directly. If you do not wish your phone number to be publicly visible, do not post listings on NIVI.
5. Third-Party Data Processors
| Processor | Purpose | Country | Safeguard |
|---|---|---|---|
| SMSOffice.ge | OTP delivery by SMS | Georgia | Georgian law applies |
| Cloudflare, Inc. (R2) | Media file storage | USA / EU | Standard Contractual Clauses (Module 2) |
We do not sell personal data. We do not share personal data for advertising or marketing purposes.
6. Cross-Border Data Transfers
Media files are stored with Cloudflare R2 (Cloudflare Inc., USA). The transfer is covered by Standard Contractual Clauses adopted under EU Regulation 2016/679 (Module 2), providing an equivalent level of protection. Copies of the applicable SCCs are available on request: [email protected].
7. Data Retention
| Data | Retention period |
|---|---|
| Account data (name, phone, profile) | Until account deletion; deleted within 30 days thereafter |
| Listing photos | Deleted within 30 days of listing deletion |
| Security and access logs | 12 months from creation |
| Blocked account records (fraud prevention) | 3 years from blocking date |
| SMS delivery logs | 90 days |
8. Your Rights
Under the Law of Georgia on Personal Data Protection, you have the following rights:
- Right of access — Request information about what data we hold about you and receive a copy.
- Right to rectification — Request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — Request deletion of your data, subject to exceptions (e.g., fraud-prevention records).
- Right to restriction of processing — Request that we limit processing while a dispute is resolved.
- Right to data portability — Receive your data in a structured, machine-readable format.
- Right to object — Object to processing based on legitimate interest. We will cease unless compelling legitimate grounds exist.
- Right to withdraw consent — Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
To exercise any right: [email protected]. We respond within 30 calendar days. Identity verification may be required. Most data can be edited directly in account settings.
9. Right to Lodge a Complaint
You have the right to lodge a complaint with the Personal Data Protection Service of Georgia (PDPS):
- Website: www.pdp.ge
- Address: 2 Aleksandre Kazbegi Ave., Tbilisi 0160, Georgia
- Phone: +995 (32) 242-12-42
10. Cookies
| Cookie | Purpose | Expiry |
|---|---|---|
sessionid | Keeps you logged in | 30 days (or browser session) |
csrftoken | Protects against CSRF attacks | 1 year |
nivi_lang | Remembers your language preference | 1 year |
We do not use advertising, third-party analytics, or tracking cookies.
11. Age Restriction
NIVI is intended for users aged 18 and over. We do not knowingly collect data from persons under 18. If you believe a minor has registered: [email protected].
12. Changes to This Policy
We may update this Policy. The current version is always available at nivi.ge/privacy/. We will notify users of material changes via SMS or in-app notification. Continued use of the Platform after the effective date constitutes acceptance of the updated Policy.
13. Contact
Data protection: [email protected]
General inquiries: [email protected]
Effective: 12 May 2026 · Version 1.0 · © 2026 NIVI Marketplace