1. Who We Are
This Privacy Policy applies to the website zakeratin.com, operated by ZAKERATIN Europe LTD (hereinafter “ZaKeratin”, “we”, “us”, or “our”).
Contact details of the data controller:
Company: ZAKERATIN Europe LTD
Country of registration: Georgia
Email: info@zakeratin.com
WhatsApp: +995 599 554 150
2. Applicable Law
We process personal data in accordance with:
The Law of Georgia on Personal Data Protection (enacted 14 June 2023, in force from 1 March 2024) — for customers located in Georgia and for data processed using technical means in Georgia.
Regulation (EU) 2016/679 (GDPR) — for customers located in the European Economic Area (EEA).
3. What Data We Collect and Why
3.1 Order fulfilment
When you place an order, we collect: first and last name, email address, phone number, delivery address, country. Legal basis: performance of a contract (Art. 6(1)(b) GDPR; Georgian Data Protection Law). This data is required to process and deliver your order. Without it, we cannot fulfil your purchase.
3.2 Customer support
If you contact us via email or WhatsApp, we process the data you provide (name, contact details, message content) to respond to your enquiry. Legal basis: legitimate interest (Art. 6(1)(f) GDPR; Georgian Data Protection Law).
3.3 Marketing communications
We only send promotional messages if you have given explicit consent by ticking the relevant checkbox during checkout or sign-up. Legal basis: consent (Art. 6(1)(a) GDPR; Georgian Data Protection Law). You may withdraw consent at any time by emailing info@zakeratin.com or clicking “Unsubscribe” in any message.
3.4 Website analytics (cookies)
Our website is built on the Tilda platform, which may set technical and analytical cookies. We display a cookie banner on your first visit and process analytical cookies only with your consent. See Section 8 for details.
4. How Long We Keep Your Data
Order data (name, address, contact details): 5 years from the date of order fulfilment, to comply with accounting and tax obligations.
Marketing consent and related data: until you withdraw consent.
Customer support messages: up to 2 years after the issue is resolved.
After the retention period, data is securely deleted or anonymised.
5. Who We Share Data With
We do not sell your personal data. We share it only with the following categories of recipients, solely to fulfil your order or operate the service:
Delivery and logistics providers — to ship your order to the specified address.
Payment service providers (e.g. Stripe, Georgian Bank acquiring) — to process your payment securely. We do not store card details.
Tilda Publishing — our website platform, which processes technical data (IP address, browser type) under its own privacy policy.
Competent authorities — if required by applicable law.
6. International Data Transfers
Some of our service providers (including Tilda and Stripe) may process data on servers located outside Georgia and the EEA. Where such transfers occur, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, or we rely on adequacy decisions where applicable.
7. Your Rights
Under Georgian data protection law and GDPR, you have the following rights:
Right of access — to obtain a copy of the personal data we hold about you.
Right to rectification — to correct inaccurate or incomplete data.
Right to erasure (“right to be forgotten”) — to request deletion of your data, where no legal obligation requires us to retain it.
Right to restriction — to request that we limit processing in certain circumstances.
Right to data portability — to receive your data in a structured, commonly used format.
Right to object — to object to processing based on legitimate interest.
Right to withdraw consent — at any time, without affecting prior processing.
To exercise any of these rights, please email us at info@zakeratin.com. We will respond within 10 business days. If you are an EEA resident and believe we have not addressed your concern, you have the right to lodge a complaint with the data protection authority in your country of residence.
8. Cookies
We use the following types of cookies:
Strictly necessary cookies — required for the website and shopping cart to function. These do not require consent.
Analytical cookies — used to understand how visitors interact with the site (e.g. Tilda built-in analytics). Activated only after you accept via the cookie banner.
You can withdraw your cookie consent at any time by clearing your browser cookies or adjusting your browser settings.
9. Data Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. The website uses HTTPS encryption. Payment transactions are processed by certified payment providers and we do not store card details on our servers.
10. Children
Our website and services are not directed at children under the age of 16. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us at info@zakeratin.com and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The current version is always available at zakeratin.com/policy. Material changes will be communicated by updating the “Last updated” date at the top of this page. Continued use of the website after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us:
Email: info@zakeratin.com
WhatsApp: +995 599 554 150
Working hours: Monday – Friday, 09:00–19:00 (Tbilisi time, GET)