TrustlexGeorgia business setup

Trustlex policy

Privacy Policy

This Policy explains what personal data Trustlex processes, for what purposes and on what legal grounds, who it is shared with, whether it is transferred internationally, how long it is kept, how it is protected, and the rights you can exercise.

Last updated: July 5, 2026

Version 2.0, effective July 5, 2026. Trustlex handles identity documents and other sensitive information; this Policy is written to meet the Law of Georgia on Personal Data Protection, the EU GDPR where it applies, and US state privacy laws such as the CCPA/CPRA. The English text governs; translations are for convenience only.

1. Controller and contact

Trustlex (www.trustlex.ge) determines the purposes and means of the processing described in this Policy and is the data controller for it. For processing carried out on your instructions within an Engagement, Trustlex may act as your processor to that extent.

Trustlex processes personal data in accordance with the Law of Georgia on Personal Data Protection and, where applicable to clients in the European Union/EEA or other jurisdictions, the EU General Data Protection Regulation (GDPR) and comparable laws — applying the principles of lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.

Privacy requests and questions can be submitted through the contact options on the Platform. We respond within the timelines required by applicable law and may need to verify your identity before acting.

2. Categories of personal data we process

Account data: name, email address, password (stored only as a salted cryptographic hash), preferred language, and residency category.

Application and case data: company names, business activity, and details of founders, directors, shareholders, and ultimate beneficial owners, including identification numbers, passport or ID copies, other uploaded documents, Power of Attorney details, delivery addresses, and case correspondence.

Special-category and identity-sensitive data: identity documents may reveal information treated as sensitive (for example, an image, nationality, or data that can be linked to health or biometric identifiers). We process such data only where necessary to deliver the Services and to meet legal, identity-verification, and anti-money-laundering obligations, and we apply enhanced safeguards to it.

Service and billing data: selected services, fee breakdowns, invoices, and payment status. Where an external payment provider is used, your full card details are processed by that provider and are not stored by Trustlex.

Communications data: consultation bookings, secure messages in the client portal, and emails exchanged with our team.

Technical data: log information necessary to operate and secure the Platform, such as session identifiers and, where privacy-friendly analytics is enabled, aggregated, non-identifying page-usage statistics.

3. Purposes and legal bases

To deliver the Services you request — preparing your application, verifying documents, coordinating notaries, translators, couriers, and Authorities, and maintaining your case record. Legal basis: performance of a contract and steps taken at your request before entering one.

To meet legal obligations — identity verification, client due diligence, and anti-money-laundering and counter-terrorist-financing requirements; accounting and tax record-keeping; and responding to lawful requests of competent authorities. Legal basis: compliance with a legal obligation, and, for special-category data, the grounds permitted for establishing, exercising, or defending legal claims and for reasons of substantial public interest.

To operate, secure, and improve the Platform — authentication, fraud and abuse prevention, audit logging of sensitive actions, and service communications about your matter. Legal basis: our legitimate interests in providing a secure and reliable service, balanced against your rights and freedoms.

To send optional marketing (such as a checklist you request by email or occasional practical tips): only where you have provided your email for that purpose or otherwise consented, and you may opt out at any time. Legal basis: consent.

4. Automated processing and the Help Me Choose tool

The Platform provides preliminary, rules-based outputs — such as the Help Me Choose recommendation, name-screening, and tax-status indications. These do not produce a decision that has legal or similarly significant effects on you by solely automated means: an authorised Trustlex professional reviews the matter before any binding step, and the outputs are informational until confirmed. You may request human review of, express your point of view on, or contest any Automated Output through the contact options on the Platform.

5. Recipients and disclosures

We disclose personal data only as needed to deliver the Services and run the business: to Georgian-qualified lawyers, notaries, and certified translators working on your matter; to couriers for document delivery; to banks and payment providers when you request bank-readiness support or make payments; to public registries, the Revenue Service, and other Authorities as required for your filings; and to our infrastructure providers (secure hosting, database, file storage, email delivery, and, where enabled, analytics) acting under contract as processors.

We do not sell or share personal data for cross-context behavioural advertising, and we do not disclose it to data brokers or advertisers. Any recipient acting on our behalf is bound by written confidentiality and data-protection obligations appropriate to the data involved. We may disclose data where required by law, court order, or regulator, or to protect the rights, safety, and property of Trustlex, our clients, or others.

6. International transfers

Because our clients are international and our infrastructure providers may store or process data in the European Union, the United States, or elsewhere, personal data may be transferred outside Georgia and outside your country. Where such transfers occur, we rely on a lawful transfer mechanism — such as a decision recognising an adequate level of protection, appropriate safeguards including Standard Contractual Clauses or equivalent contractual data-protection commitments, or a permitted derogation — and we limit transfers to what the Services require. You may request information about the safeguards applied.

7. Security

Data is encrypted in transit. Documents are stored with private, non-guessable access paths and served only to the authenticated client who owns the matter or to authorised staff, with uploads validated by file type and size and scanned for basic integrity before acceptance.

Passwords are stored only as salted scrypt hashes; sessions are cryptographically signed; staff access is role-restricted on a need-to-know basis; and sensitive actions — viewing, approving, rejecting, or replacing documents, and status changes — are recorded in audit logs. We maintain organisational and technical measures appropriate to the risk, and review them periodically.

No system is perfectly secure. If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, affected individuals, in accordance with applicable law and within the applicable deadlines.

8. Retention

We keep personal data only as long as necessary for the purposes described: case records and documents for the duration of the Engagement and thereafter for the period required for legal, accounting, audit, anti-money-laundering, and dispute-resolution purposes under Georgian law; account data for as long as your account remains active; and marketing contact details until you opt out. When retention periods expire, data is deleted or irreversibly anonymised. Where law requires retention of certain records (for example, AML and accounting records) for a minimum period, we retain them for that period even after account closure.

9. Your rights

Subject to applicable law, you have the right to: access the personal data we hold about you and receive a copy; have inaccurate or incomplete data corrected; have data erased where there is no remaining legal basis to keep it; restrict or object to certain processing, including direct marketing; receive data you provided in a portable, machine-readable format; and withdraw consent at any time where processing is based on consent, without affecting prior processing. You may also lodge a complaint with the Personal Data Protection Service of Georgia or, where applicable, your local supervisory authority.

If you are a California resident, you also have the rights under the CCPA/CPRA to know, access, correct, and delete personal information, and to opt out of “sale” or “sharing” of personal information. Trustlex does not sell or share personal information as those terms are defined, and we do not discriminate against you for exercising your rights. Comparable rights available under other US state privacy laws are honoured where they apply.

To exercise any right, contact us through the Platform. You may use an authorised agent where the law permits; we may need to verify identity before responding.

10. Cookies, children, and changes

Our use of cookies and similar technologies is described in the Cookie Policy. The Platform is intended for adults and is not directed at children under 18; we do not knowingly collect children’s data, and we will delete it if we learn we have.

We may update this Policy to reflect changes in law, technology, or our services. Material changes will be indicated by the “Last updated” date and, where appropriate, by notice on the Platform. The English text is the governing version; translations are provided for convenience only.