PRIVACY POLICY

Effective date: 7 October 2026

This Privacy Policy explains how the Georgian Institute of Financial Crime Prevention — GIFCP — collects, uses, stores and protects personal data.

1. Data Controller

The controller of personal data is:

Georgian Institute of Financial Crime Prevention (GIFCP)

Privacy contact email:

info@gifcp.ge

2. Scope

This Policy applies to personal data processed by GIFCP in connection with:

3. Personal Data We Process

Depending on the relevant interaction, GIFCP may process:

GIFCP does not intentionally request special-category personal data unless processing such information is lawfully necessary for a specific service.

Please do not provide such information voluntarily where it is not required.

4. Purposes of Processing

Personal data may be processed to:

5. Legal Bases

GIFCP processes personal data only where an appropriate legal basis exists.

Depending on the circumstances, processing may be necessary:

Processing of the core information necessary for training registration is not based solely on consent where that processing is necessary to review the application, prepare the service or perform the relevant contractual relationship.

6. Acknowledgement of the Privacy Policy

The registration form requires the user to confirm that they have read this Privacy Policy.

This acknowledgement is not blanket consent to every form of personal-data processing.

Where GIFCP relies on consent for an additional purpose, including direct marketing where applicable, that consent will be requested separately, clearly and voluntarily.

7. Participants Registered by Organisations

Where an organisation registers one or more participants, GIFCP may obtain participant data from the organisation's authorised contact rather than directly from the participant.

GIFCP will provide the relevant participant with the information required by applicable law in accordance with the applicable requirements and time limits.

The registering organisation is responsible for providing GIFCP only with personal data that it has an appropriate basis to disclose and for the accuracy of the information provided.

8. Recipients and Service Providers

GIFCP may use trusted technical and professional service providers that process data on GIFCP's instructions or another appropriate legal basis.

Relevant categories may include:

GIFCP does not sell personal data to third parties for commercial purposes.

9. International Data Transfers

Some technical services used by GIFCP may involve processing or transfer of data outside Georgia.

Any such transfer will take place only where permitted by applicable law and subject to appropriate safeguards.

10. Retention

GIFCP does not retain personal data for longer than necessary for the relevant purpose.

Retention may be determined by reference to:

Once no legal or legitimate need for retention remains, personal data will be deleted, destroyed or, where appropriate, anonymised.

11. Security

GIFCP applies appropriate technical and organisational measures designed to protect personal data against unauthorised access, unlawful processing, accidental loss, alteration, disclosure, damage or destruction.

Access to administrative and registration information is restricted to authorised persons.

Invoices and other non-public documents are not stored in publicly accessible storage.

12. Your Rights

Subject to applicable Georgian law, a data subject may have the right to:

Requests may be submitted to:

info@gifcp.ge

GIFCP may take reasonable steps to verify the identity of the requester before acting on a request.

13. Complaints

If you believe your personal data has been processed unlawfully, you may first contact:

info@gifcp.ge

You also have the right, in accordance with applicable law, to apply to the competent Georgian data-protection supervisory authority — the State Audit Office of Georgia — or to a court.

14. Direct Marketing

Personal data submitted for a training registration is not used for direct marketing merely because an individual registered for a programme.

If GIFCP introduces direct marketing, it will use an appropriate legal basis and provide the opt-out mechanism required by applicable law.

15. Cookies and Similar Technologies

The website may use technical cookies or similar technologies necessary for functionality and security.

If GIFCP later introduces analytics, advertising or other non-essential tracking technologies, this Policy and any required consent mechanism will be updated before those technologies are activated where consent is required by applicable law.

16. Changes to this Policy

GIFCP may update this Policy to reflect changes in law, technology or its services.

The current version will be published on the website together with its effective date.

17. Contact

Georgian Institute of Financial Crime Prevention (GIFCP)

Website:

https://www.gifcp.ge

Email:

info@gifcp.ge