PRIVACY POLICY
Effective date: 7 October 2026
This Privacy Policy explains how the Georgian Institute of Financial Crime Prevention — GIFCP — collects, uses, stores and protects personal data.
1. Data Controller
The controller of personal data is:
Georgian Institute of Financial Crime Prevention (GIFCP)
Privacy contact email:
2. Scope
This Policy applies to personal data processed by GIFCP in connection with:
- use of the website;
- registration for training or other professional programmes;
- registration of participants by an organisation;
- enquiries submitted to GIFCP;
- invoicing, payment and registration administration;
- other services connected with GIFCP's professional activities.
3. Personal Data We Process
Depending on the relevant interaction, GIFCP may process:
- first and last name;
- email address;
- telephone number;
- employer or organisation;
- job title or professional position;
- organisation name and identification/tax number;
- training and registration information;
- for organisational registrations, participant names, email addresses and, where relevant, job titles;
- invoice and payment-administration information;
- correspondence with GIFCP;
- technical and log information necessary for system operation and security.
GIFCP does not intentionally request special-category personal data unless processing such information is lawfully necessary for a specific service.
Please do not provide such information voluntarily where it is not required.
4. Purposes of Processing
Personal data may be processed to:
- receive and review training applications;
- administer registrations;
- communicate with participants and organisations;
- prepare and send invoices;
- administer bank-transfer and payment status;
- confirm participation;
- organise and deliver training;
- administer a certificate or proof of participation where provided by the relevant programme;
- respond to enquiries;
- comply with legal, accounting and other mandatory obligations;
- establish, exercise or defend GIFCP's legal rights and claims;
- protect the security and reliability of GIFCP systems.
5. Legal Bases
GIFCP processes personal data only where an appropriate legal basis exists.
Depending on the circumstances, processing may be necessary:
- to take steps requested by a data subject before entering into a contract;
- to perform obligations under a contract;
- to review a data subject's request and provide a service;
- to comply with obligations imposed by Georgian law;
- to pursue an important legitimate interest of GIFCP or a third party, where that interest is not overridden by the rights and interests of the data subject;
- where applicable, on the basis of lawfully obtained consent.
Processing of the core information necessary for training registration is not based solely on consent where that processing is necessary to review the application, prepare the service or perform the relevant contractual relationship.
6. Acknowledgement of the Privacy Policy
The registration form requires the user to confirm that they have read this Privacy Policy.
This acknowledgement is not blanket consent to every form of personal-data processing.
Where GIFCP relies on consent for an additional purpose, including direct marketing where applicable, that consent will be requested separately, clearly and voluntarily.
7. Participants Registered by Organisations
Where an organisation registers one or more participants, GIFCP may obtain participant data from the organisation's authorised contact rather than directly from the participant.
GIFCP will provide the relevant participant with the information required by applicable law in accordance with the applicable requirements and time limits.
The registering organisation is responsible for providing GIFCP only with personal data that it has an appropriate basis to disclose and for the accuracy of the information provided.
8. Recipients and Service Providers
GIFCP may use trusted technical and professional service providers that process data on GIFCP's instructions or another appropriate legal basis.
Relevant categories may include:
- hosting and infrastructure providers;
- database and storage providers;
- transactional email providers;
- IT and security providers;
- accounting, legal or other professional advisers where necessary;
- public authorities where disclosure is required by law.
GIFCP does not sell personal data to third parties for commercial purposes.
9. International Data Transfers
Some technical services used by GIFCP may involve processing or transfer of data outside Georgia.
Any such transfer will take place only where permitted by applicable law and subject to appropriate safeguards.
10. Retention
GIFCP does not retain personal data for longer than necessary for the relevant purpose.
Retention may be determined by reference to:
- the period required to administer the relevant training or service;
- the duration of a contractual relationship;
- applicable invoicing, accounting, tax or other statutory obligations;
- periods necessary for the establishment, exercise or defence of legal claims;
- a data subject request, where it can lawfully be fulfilled.
Once no legal or legitimate need for retention remains, personal data will be deleted, destroyed or, where appropriate, anonymised.
11. Security
GIFCP applies appropriate technical and organisational measures designed to protect personal data against unauthorised access, unlawful processing, accidental loss, alteration, disclosure, damage or destruction.
Access to administrative and registration information is restricted to authorised persons.
Invoices and other non-public documents are not stored in publicly accessible storage.
12. Your Rights
Subject to applicable Georgian law, a data subject may have the right to:
- obtain information about the processing of their personal data;
- access their personal data and obtain a copy;
- request correction, updating or completion of inaccurate or incomplete information;
- request cessation of processing, deletion or destruction where provided by law;
- request restriction/blocking of data where provided by law;
- withdraw consent where processing is based on consent;
- exercise other rights provided by applicable Georgian law.
Requests may be submitted to:
GIFCP may take reasonable steps to verify the identity of the requester before acting on a request.
13. Complaints
If you believe your personal data has been processed unlawfully, you may first contact:
You also have the right, in accordance with applicable law, to apply to the competent Georgian data-protection supervisory authority — the State Audit Office of Georgia — or to a court.
14. Direct Marketing
Personal data submitted for a training registration is not used for direct marketing merely because an individual registered for a programme.
If GIFCP introduces direct marketing, it will use an appropriate legal basis and provide the opt-out mechanism required by applicable law.
15. Cookies and Similar Technologies
The website may use technical cookies or similar technologies necessary for functionality and security.
If GIFCP later introduces analytics, advertising or other non-essential tracking technologies, this Policy and any required consent mechanism will be updated before those technologies are activated where consent is required by applicable law.
16. Changes to this Policy
GIFCP may update this Policy to reflect changes in law, technology or its services.
The current version will be published on the website together with its effective date.
17. Contact
Georgian Institute of Financial Crime Prevention (GIFCP)
Website:
Email: