Privacy Policy

Last updated: June 2026

1. General Provisions

This Privacy Policy (hereinafter — the 'Policy') governs the collection, processing, storage, and protection of personal data of users (hereinafter — 'User' or 'you') of the website emgpost.com (hereinafter — the 'Website'), operated by Express Mail Georgia LLC (hereinafter — 'EMG', 'we', 'us', or 'our'), a company registered and operating under the laws of Georgia.

By accessing or using the Website, registering an account, placing an order, or submitting any form on the Website, you expressly and unconditionally consent to the collection, processing, storage, and use of your personal data in accordance with this Policy. If you do not agree to this Policy, please discontinue use of the Website immediately.

This Policy complies with: (i) the Law of Georgia on Personal Data Protection (No. 5669-RS, as amended); and (ii) Regulation (EU) 2016/679 of the European Parliament (GDPR), to the extent applicable to data subjects located in the European Economic Area.

2. Data Controller

Express Mail Georgia LLC

Registered office: Tbilisi, Georgia

Email: [email protected]

Phone: +995 577 03 03 33

For GDPR-related inquiries, the above contacts serve as the Data Protection contact point.

3. Categories of Personal Data Collected

3.1 Data provided directly by the User:

Full name (first name, last name, patronymic if applicable)
Date of birth and/or identification document number (for customs clearance purposes)
Residential and/or delivery address (including country, city, postal code, street)
Email address
Phone number
Payment data (card number — processed exclusively via certified payment gateways; EMG does not store raw card data)
Information about shipments: contents, declared value, weight, dimensions
Any additional information voluntarily provided by the User in forms, messages, or communications

3.2 Data collected automatically:

IP address and approximate geolocation
Browser type and version, operating system
Pages visited, time spent, referral sources
Device identifiers
Cookies and similar tracking technologies (see Section 9)

3.3 Data received from third parties:

Information from payment processors and banking institutions
Data from partner courier services and customs authorities
Information from social networks if you use social login features

4. Purposes and Legal Bases for Processing

EMG processes personal data for the following purposes and on the following legal bases:

Order fulfilment and logistics services — performance of a contract (Art. 6(1)(b) GDPR)
Customs declaration and compliance with legal obligations — legal obligation (Art. 6(1)(c) GDPR)
User account management and authentication — performance of a contract
Payment processing and fraud prevention — legitimate interest and legal obligation
Customer support and dispute resolution — legitimate interest
Sending transactional notifications (shipment status, tracking) — performance of a contract
Marketing communications and newsletters — with your prior explicit consent (Art. 6(1)(a) GDPR). You may withdraw consent at any time
Website analytics and improvement — legitimate interest
Legal claims and compliance — legal obligation and legitimate interest

5. Consent to Processing of Personal Data

By using the Website and/or its services, by ticking the relevant checkbox during registration or order placement, you provide your freely given, specific, informed, and unambiguous consent to the processing of your personal data as described in this Policy.

Where processing is based on consent, you have the right to withdraw such consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. To withdraw consent, contact us at [email protected].

6. Data Retention

Personal data is retained for as long as necessary for the purposes set out in this Policy, and in any case:

Order and transaction records: 7 (seven) years from the date of the transaction, in compliance with Georgian tax and accounting legislation
Account data: until account deletion, plus 1 year
Customs and shipping documents: 5 years, per applicable Georgian and international customs law
Marketing consent records: until consent is withdrawn, plus 3 years for record-keeping
Server logs: up to 12 months

7. Data Sharing and Transfers

EMG may share personal data with the following categories of recipients:

Partner courier and logistics companies (DPD, Georgian Post, and other carriers) — for shipment fulfilment
Customs authorities of Georgia and destination countries — as legally required
Payment processing providers — for secure payment handling
IT service providers, hosting companies, and analytics platforms — as data processors under appropriate agreements
Legal, financial, and auditing advisors — where necessary
Law enforcement and public authorities — when required by law

For transfers outside the European Economic Area, EMG applies appropriate safeguards including Standard Contractual Clauses (SCCs) as approved by the European Commission, or relies on adequacy decisions where applicable.

8. Rights of Data Subjects

You have the following rights under Georgian law and GDPR:

Right of access — to obtain confirmation of whether your data is processed and receive a copy
Right to rectification — to correct inaccurate or incomplete data
Right to erasure ('right to be forgotten') — to request deletion of data where legally permissible
Right to restriction of processing — to limit how your data is used
Right to data portability — to receive your data in a structured, machine-readable format
Right to object — to processing based on legitimate interest, including direct marketing
Right to withdraw consent — at any time, without affecting prior processing
Right to lodge a complaint — with the Personal Data Protection Service of Georgia (www.pdps.ge) or a relevant supervisory authority in your EU Member State

To exercise any of these rights, submit a written request to: [email protected]. We will respond within 30 days.

9. Cookies Policy

The Website uses cookies and similar technologies. We use:

Strictly necessary cookies — essential for the Website to function; cannot be disabled
Analytical/performance cookies — to understand how users interact with the Website (e.g., Google Analytics)
Functional cookies — to remember your preferences
Targeting/marketing cookies — to deliver relevant advertisements; used only with your consent

You may manage cookie preferences through your browser settings or our cookie consent banner. Disabling certain cookies may affect Website functionality.

10. Data Security

EMG implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or disclosure, including SSL/TLS encryption, access controls, and regular security assessments. However, no method of electronic transmission or storage is 100% secure.

11. Children's Data

The Website is not directed to persons under the age of 16. EMG does not knowingly collect personal data from minors. If you believe we have inadvertently collected such data, please contact us immediately for deletion.

12. Amendments to this Policy

EMG reserves the right to amend this Policy at any time. Material changes will be communicated via the Website or by email. Continued use of the Website after the effective date of changes constitutes acceptance of the updated Policy.

13. Governing Law and Dispute Resolution

This Policy is governed by and construed in accordance with the laws of Georgia. Any disputes arising from this Policy shall be subject to the jurisdiction of the courts of Georgia. For users in the EU, applicable EU data protection law shall also apply.

14. Contact

Express Mail Georgia LLC

Email: [email protected] | Phone: +995 577 03 03 33