Legal
Privacy policy
Last updated: 2026-08-27
Working draft. Company details are placeholders and the final text must be reviewed by a qualified lawyer before publication.
This privacy policy explains how [Legal form and company name - to be added, e.g. mrkflow LLC] ("mrkflow", "we"), identification code [Company ID - to be added], registered at [Registered address - to be added], processes personal data collected through the website mrkflow.ge (the "Site").
We process personal data in accordance with the Law of Georgia on Personal Data Protection and, where applicable to visitors from the European Economic Area, the EU General Data Protection Regulation (GDPR).
1. What data we collect
We collect only the data needed to operate the Site and respond to you:
- Data you submit through forms - name, work email address, organization, website address, and the content of your message (contact form and free-audit request form).
- Technical data - basic server logs (IP address, browser type, pages requested, timestamps) generated automatically when you visit the Site.
- Analytics and cookie data - only as described in the cookie policy, and only where consent is required and given. No analytics tools are active in the current pre-launch version of the Site.
We do not knowingly collect data from children, and we ask you not to submit sensitive categories of personal data through our forms.
2. Why we process it and on what basis
- Responding to your enquiry or audit request - processing is based on your consent given when submitting the form, and on steps taken at your request prior to entering into a contract.
- Operating and securing the Site - processing of technical log data is based on our legitimate interest in keeping the Site available and secure.
- Legal obligations - where retention or disclosure is required by applicable law.
3. How long we keep data
Form submissions are kept for as long as needed to handle your request and for up to [retention period - to be confirmed, e.g. 24 months] afterwards, unless a longer period is required by law or a contract is concluded. Server logs are kept for a short technical period and then deleted or anonymized.
4. Who can access your data
Your data is accessed only by mrkflow team members who need it to respond to you, and by service providers that host our infrastructure (website hosting, email delivery) under appropriate data-processing terms. The current list of processors will be published here before launch: [hosting provider - to be added; email provider - to be added]. We do not sell personal data and do not share it with third parties for their own marketing.
If data is transferred outside Georgia or the EEA, we ensure an adequate level of protection through appropriate safeguards.
5. Your rights
You have the right to request access to your personal data, its correction, deletion or blocking, to withdraw consent at any time, to object to processing based on legitimate interest, and to receive your data in a portable format where technically feasible. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
To exercise these rights, contact us at [contact email - to be activated, planned: [email protected]]. You also have the right to lodge a complaint with the Personal Data Protection Service of Georgia (personaldata.ge) or, for EEA residents, with your local supervisory authority.
6. Security
We apply appropriate technical and organizational measures to protect personal data against unauthorized access, alteration or loss, including encrypted transport (HTTPS), access control and minimization of collected data.
7. Changes to this policy
We may update this policy as the Site and our services develop. The date above shows the latest revision; material changes will be highlighted on this page.