Privacy & data protection
Privacy Policy
Effective date: · v3
How polisi.ge handles the personal data of users and leads who submit insurance requests.
1. Who processes data
The operator of polisi.ge is LLC INAVI, identification code 404815875, registered at Guram Rcheulishvili Street N17, Apt. N28, Mtatsminda District, Tbilisi, Georgia.
For questions or data-protection requests, write to corporate@inavi.ge.
2. What data we collect
We may collect: full name, phone, email, preferred language and preferred contact channel.
When a visitor sends a Contact-page message, we collect the submitted name, email address, message text and selected language.
We may collect request data: insurance category, company/person details, field of activity, description of the insured object or risk, location, desired limits, deductible, existing insurance, claims history, turnover, number of employees, security measures, files/photos if uploaded, and other details entered by the user.
We may collect technical and analytics data: IP address, device type, browser, language, cookie/analytics identifiers, UTM and source data.
At MVP stage the platform may allow photos/files of the object or risk to better describe the request, while final document requests, inspection, risk assessment and underwriting are carried out by the selected insurance partner.
3. Why we process data
Data is used to operate the request form, prepare comparison results, route the user's request to the insurance providers assessed for it, create a PDF summary, support, security, fraud prevention, analytics, and legal/audit purposes.
Contact-page message data is used to review and respond to the question and provide support.
The platform must not use the data to make the final insurance underwriting or policy-issuance decision about the user.
Automated processing notice: the platform may use automated processing and comparison logic to prepare estimated categorization, a request summary, partner-fit indicators and informational matching outputs. These processes are used for informational purposes only.
4. Who data may be shared with
With the consent given at the contact step, an administrator routes the request to insurance providers whose products fit it. More than one provider — in some cases every active provider in the relevant category — receives the request so that comparable terms can be offered. Providers that are not chosen still receive the request data they needed in order to quote.
Providers receive the request details and the answers given in the funnel. They do NOT receive the name, phone number or email address until the user accepts that provider's offer.
Data is also processed by the technical providers listed in "Technical providers" below.
Data may be disclosed to a public authority or court where required by applicable law.
5. Technical providers
Google Cloud (Ireland/Belgium, region europe-west3) — application hosting and the database in which requests, accounts and offers are stored.
Google Cloud Vertex AI, Gemini models (regions europe-west4 and europe-west1) — generates the informational assistant answers and the plain-language policy summaries. Questions typed into the assistant are sent to this service.
Brevo (France) — transactional email: verification codes, offer notifications, account messages and internal notifications about Contact-page messages.
smsoffice.ge (Georgia) — SMS delivery of verification codes.
Meta Platforms Ireland (WhatsApp Business Cloud API) — where a user or provider continues a conversation over WhatsApp.
Sentry (Ireland) — error monitoring. Diagnostic data is scrubbed of personal identifiers before it is sent.
S3-compatible object storage — documents uploaded by providers and administrators.
Plausible Analytics — cookieless usage statistics, where enabled.
Google Tag Manager and Google Analytics (Google Ireland Limited / Google LLC) — consent-gated usage analytics. The Google tag does not load unless the user accepts analytics cookies.
Each provider acts on our instructions under a data-processing agreement and may use the data only to deliver its service to us.
6. Consent and withdrawal
At the contact step the user separately confirms that their request may be shared with insurance providers, and — where the funnel collects health answers — separately again for that special-category data.
Consent may be withdrawn by writing to corporate@inavi.ge. Withdrawal does not affect processing already carried out based on consent before withdrawal, and it does not reach a provider that has already received the request — that provider must be contacted directly.
7. Retention
Requests that are started but never completed, and that are not attached to an account, are deleted 90 days after they were last changed. This includes any names, personal identification numbers, dates of birth and health answers entered before the contact step.
Verification codes are deleted once they expire and are swept at least daily.
Sign-in sessions and single-use links are deleted when they expire.
Questions asked of the assistant are retained for service quality and abuse prevention; the IP address recorded alongside them is anonymised.
Messages submitted through the Contact page are deleted after 365 days.
Consent records are kept as evidence that consent was given, including the exact text shown and the version accepted. The IP address and browser identifier stored with a consent record are erased after 365 days; the record itself is kept for the period required to defend a legal claim.
Account data is kept while the account exists. Deleting the account removes the account, its requests, its leads and its uploaded documents; consent records are retained as legal evidence with the link to the deleted account removed.
Data already transferred to an insurance provider is retained by that provider under its own policy, which we do not control.
8. Security
The platform uses reasonable technical and organizational measures to protect data, including access control, logging, encrypted connection and least-privilege access.
No online system is absolutely secure; users should not enter unnecessary or unrequested sensitive information.
9. User rights
Within applicable law, users may have the right to receive information about data processing and to request access, correction, deletion, restriction, objection, or the exercise of other rights.
Requests are sent to corporate@inavi.ge. The operator responds within the period set by applicable law.
A user who considers that their data has been handled unlawfully may complain to the Personal Data Protection Service of Georgia (personaldata.ge) or apply to a court.
10. Cookies and analytics
The platform uses necessary cookies for service functionality. Plausible may provide cookieless usage statistics where enabled.
Google Tag Manager and Google Analytics are disabled by default through Google Consent Mode v2. Google Analytics may set analytics cookies only after the user accepts them in the cookie banner; declining keeps Google analytics disabled.
The choice is stored for 12 months in the first-party polisi-consent cookie. A user can change it by deleting the site cookie in their browser, after which the banner is shown again.
This implementation does not enable advertising or marketing cookies: ad_storage, ad_user_data and ad_personalization remain denied.
If JavaScript is disabled, the consent banner cannot operate. The standard Tag Manager fallback may contact Google, but it cannot execute analytics tags or set analytics cookies.
11. International transfers
Application hosting and the database are located in the European Union (Google Cloud, region europe-west3). The assistant and policy-summary models run in the European Union (regions europe-west4 and europe-west1).
Brevo, Sentry and Meta Platforms process data in the European Union. smsoffice.ge processes data in Georgia.
If the user accepts analytics cookies, site-usage data is processed through Google Tag Manager and Google Analytics and may be processed on Google servers in the European Union and the United States.
Transfers outside Georgia are made to countries with an appropriate level of data protection and under data-processing agreements with each provider, in accordance with the Law of Georgia on Personal Data Protection.
12. Minors
The platform is intended for adults researching insurance products. Minors should not use the platform without a parent/legal representative.
13. Changes
This policy may be updated. The new version will be published on the website or app with its effective date.
Electronic records notice: electronic consent records, timestamps and communication logs may be retained for audit and compliance purposes.