top of page

Sintriva - Privacy Policy

Last Updated: 28.05.2026

​

This Privacy Policy explains how Sintriva collects, uses, stores, shares, and protects personal data when you visit our website, contact us, work with us as a client, or otherwise interact with our business.

Sintriva works with clients in different countries. Our relationship with you is governed by the law of Georgia, where Sintriva is registered (see Part B). At the same time, if you are located in the European Union/EEA, or if you are a resident of certain U.S. states, additional local rules also apply to you. We have set those out in Parts C and D.

This Privacy Policy should be read together with any client agreement, proposal, order form, or project-specific terms that apply to you.

​

How this Privacy Policy is organised

  • Part A - Core Privacy Policy: applies to everyone.

  • Part B - Governing Law.

  • Part C - Additional information for the EU/EEA: applies if you are located there.

  • Part D - Additional information for U.S. residents: applies if you are a resident of California or certain other states.

Where a Part that applies to your location gives you more detail or stronger protection, that information applies to you.

​

Who we are

Sintriva (“Sintriva”, “we”, “our”, or “us”) is a studio and service-based business registered in Georgia.

 

Legal entity:

Sintriva
 

Identification code:

01027002520
 

Registered address:

Building 43, Flat/Office 118,
Zemo Plato, III Masivi, Varketili District, 0163,
Tbilisi, Georgia
 

Website:

Sintriva.com
 

Privacy contact email:

contact@sintriva.com

 

Sintriva is the data controller responsible for the personal data described in this Privacy Policy, except where this Policy says otherwise (see section 5).

​

Part A - Core Privacy Policy

​

1. Who this Privacy Policy applies to

  • Website visitors - individuals who visit or interact with the Sintriva website, landing pages, forms, or online content.

  • Prospective clients - individuals who contact Sintriva about possible services, quotes, projects, or collaborations.

  • Clients and client representatives - individuals acting on behalf of a business, brand, or organization that engages Sintriva for services.

  • Business contacts - suppliers, contractors, freelancers, partners, and other professional contacts who communicate or work with Sintriva.

Our services are intended for professional and commercial use. They are not directed to children and are not intended for personal, household, or consumer use.

​

2. The personal data we collect

Depending on how you interact with Sintriva, we may collect the following categories of personal data:

  • Contact and identification details - such as name, business name, job title, email address, phone number, and billing or invoicing information.

  • Project and communication data - such as project briefs, emails, messages, call and meeting notes, requested deliverables, feedback, approvals, and revision requests.

  • Client-provided materials - such as brand assets, logos, product images, reference images, moodboards, text copy, and other files submitted for use in delivering services.

  • Technical and website usage data - such as IP address, approximate location derived from IP address, browser and device type, operating system, and basic interaction data collected through cookies or similar technologies.

  • Transaction and payment-related data - such as payment status, invoice history, and basic payment method details made available to us by payment processors. Sintriva does not intentionally store full payment card details.

  • Marketing and business development data - such as responses to campaigns, inquiry sources, and newsletter preferences.

Sintriva does not intentionally request or require special-category or highly sensitive personal data for ordinary studio operations. Please do not submit medical, biometric, government ID, payment card, or similarly regulated sensitive data unless Sintriva has expressly requested it and there is a lawful basis and operational need to receive it.

​

3. How we collect personal data

  • Directly from you - for example when you complete a contact form, email us, submit a brief, request a quote, or otherwise communicate with us.

  • From your organization or colleagues - for example when a business representative introduces you as a contact person for a project, billing, or approvals.

  • Automatically through website technologies - such as server logs, cookies, and analytics tools, where these are enabled.

  • From third-party service providers or business tools - such as payment processors, analytics providers, file transfer services, and communication tools.

  • From publicly available professional sources - such as company websites or public social media profiles, where relevant to a business inquiry or collaboration.
     

4. Why we use personal data, and our legal basis

We use personal data for clearly defined purposes. The table below shows each purpose and the legal basis we rely on. Where more than one basis is listed, the basis that applies depends on the situation.

 

Purpose

Legal basis

Responding to your inquiries, assessing project fit, and preparing proposals

Taking steps at your request before entering into a contract; our legitimate interest in developing our business

Onboarding clients, managing projects, delivering services, and handling revisions

Performance of a contract

Keeping project records, approvals, and communications

Our legitimate interest in proper recordkeeping; compliance with legal obligations

Issuing invoices, processing payments, and managing commercial relationships

Performance of a contract; compliance with legal obligations

Operating, securing, maintaining, and improving our website and systems

Our legitimate interest in running a secure and efficient business

Preventing fraud, misuse, and unauthorised access

Our legitimate interest in protecting our business; compliance with legal obligations

Complying with legal, accounting, tax, and regulatory obligations

Compliance with legal obligations

Sending service-related messages (confirmations, delivery and billing notices, policy updates)

Performance of a contract; our legitimate interest in keeping you informed

Sending marketing communications

Your consent, where required; otherwise our legitimate interest in promoting our services

Improving our internal operations, creative processes, and service quality

Our legitimate interest in improving our business

 

We will not use your personal data for new purposes that are not compatible with the purposes above, unless the law allows it or you have given consent.

​

5. Materials our clients give us

To deliver our services, clients often give us materials that contain personal data - for example photographs, reference images, contact details, or approvals relating to identifiable people.

We use these materials only as needed to provide the requested services, manage the project, keep proper records, and meet our legal and contractual obligations.

When a client gives us such materials and we process them on the client’s instructions, the client is mainly responsible for that personal data, and Sintriva acts as a service provider. In that case the details are governed by a separate data processing agreement, and the client is responsible for having the necessary rights and permissions to give us the materials.

How we use AI tools with project materials is explained in section 6.

​

6. How we use artificial intelligence (AI)

Artificial intelligence is part of how Sintriva works. We use AI tools throughout our creative and operational activities - for example to create and develop ideas and outputs, to process and refine project materials, to organise information, and to support our day-to-day business operations.

When we use AI tools, they may process personal data. This can include data you give us and data created while we work on a project.

When we use AI, we apply the following principles:

  • Lawful basis. We use AI to process personal data only where we have a lawful basis to do so, as described in section 4.

  • Only what is needed. We provide AI tools only with the data necessary for the specific task. Where it is practical, we anonymise or remove personal data first.

  • Security and providers. We choose reputable AI providers and, where appropriate, use them under written terms that support data protection and confidentiality.

  • No public model training with your materials. We do not provide client project materials to third parties to train AI models for the general market, unless this is expressly agreed in writing.

  • Human oversight. We do not make decisions that significantly affect you based only on automated processing, without human involvement. You can contact us with any questions about how we use AI in relation to your data.
     

7. Sharing personal data

Sintriva shares personal data only where reasonably necessary, including with:

  • hosting, website, email, storage, collaboration, scheduling, analytics, file transfer, and security providers;

  • payment processors, invoicing tools, accounting advisors, legal advisors, and other professional consultants;

  • creative and technical tools, including AI-assisted tools used to create, refine, organise, edit, or deliver project outputs;

  • other service providers who help us run our business, under appropriate confidentiality or contractual terms; and

  • courts, regulators, and law-enforcement bodies, where disclosure is required by law, needed to establish or defend legal claims, or needed to protect our rights, safety, and operations.

We do not sell your personal data for money. We do use analytics and advertising tools that, under some laws, may be treated as “sharing” personal data. You can control this through our cookie settings and, if you are a U.S. resident, through the options described in Part D.

​

8. International data transfers

Because Sintriva works with clients and service providers in different countries, personal data may be stored, processed, or accessed outside the country where it was first collected.

When we transfer personal data across borders, we use appropriate safeguards required by applicable law. Depending on the situation, these may include transfers to countries recognised as providing adequate protection, contractual protections such as standard data protection clauses, or other lawful transfer mechanisms. Where required under the Law of Georgia on Personal Data Protection, we will also obtain the necessary authorisation from the Personal Data Protection Service of Georgia and/or your consent.

​

9. How long we keep personal data

We keep personal data only for as long as we reasonably need it for the purposes described in this Privacy Policy.

  • Inquiry and lead information - kept for a reasonable business-development period, unless you ask us to delete it earlier and we are not required to keep it.

  • Client records, invoices, and contracts - kept for 3 years to meet tax, accounting, and legal requirements in Georgia and to deal with possible disputes.

  • Project files and client-provided materials - kept for as long as needed for operational continuity, recordkeeping, and dispute resolution, unless we agree otherwise or delete them earlier.

We may delete files and records that we no longer need, subject to any contractual obligations and our backup cycles. Delivery links or folders may expire 30 days after delivery, so please download and keep your own copies of final deliverables.

​

10. Cookies and similar technologies

Sintriva may use cookies, pixels, analytics tools, or similar technologies on its website to support essential site functions, understand website performance, improve user experience, maintain security, and - where enabled - support marketing activities. The exact tools used may change over time.

Some of these tools - in particular advertising and analytics tools - are used only where you have given consent, where consent is required by law. Where required, Sintriva provides cookie controls and consent tools. You may also manage cookies through your browser settings, and you can use recognised opt-out preference signals such as the Global Privacy Control. Disabling certain cookies may affect website performance or functionality.

​

11. Marketing communications

Sintriva processes personal data for its own marketing purposes - for example to tell you about our services, share updates, and develop new business. We do not sell your personal data, and our marketing does not depend on selling data to others.

We may send you service-related messages where they are needed to manage inquiries, projects, billing, delivery, contracts, or policy updates.

We may also send promotional or marketing communications where this is lawful. You can opt out of marketing messages at any time - by using the unsubscribe link in the message, or by contacting us directly. Opting out of marketing does not affect essential service or transaction messages.

Where the law requires your consent before we send marketing messages, we will ask for it, and you can withdraw it at any time.

​

12. Data security

Sintriva takes reasonable technical and organizational measures appropriate to the nature of its business to protect personal data against unauthorized access, misuse, loss, alteration, or disclosure. However, no website, transmission, cloud storage environment, or electronic system can be guaranteed to be completely secure, and Sintriva cannot guarantee absolute security.

If a personal data breach occurs, Sintriva will respond as required by applicable law, including, where necessary, notifying the relevant supervisory authority and affected individuals.

​

13. Your rights

Depending on the laws that apply to you, you may have rights over your personal data, including the right to ask for access, correction, deletion, restriction, objection, data portability, and withdrawal of consent where we rely on consent.

To use your rights, please contact us using the details in section 16. We may ask for information to confirm your identity and to understand your request. We may keep limited information about a request where we need it to show compliance or to defend legal claims.

If you are in the EU/EEA, please also see Part C. If you are a U.S. resident, please also see Part D.

If you are in Georgia, you may also contact the Personal Data Protection Service of Georgia, or the courts, if you believe your rights have been breached.

​

14. Third-party links and services

Sintriva’s website, emails, or project materials may contain links to third-party websites, platforms, portfolios, tools, or services. Sintriva is not responsible for the privacy practices of third parties, and this Privacy Policy does not apply to third-party websites or services, except where Sintriva itself determines the purposes and means of processing.

​

15. Changes to this Privacy Policy

Sintriva may update this Privacy Policy from time to time to reflect operational, legal, or commercial changes. The updated version becomes effective when posted, unless a later effective date is stated. Where required by law, Sintriva will provide additional notice of material changes.

​

16. How to contact us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact Sintriva at:

 

Company:

Sintriva
 

Identification code:

01027002520
 

Registered address:

Building 43, Flat/Office 118,
Zemo Plato, III Masivi, Varketili District, 0163,
Tbilisi, Georgi

​

Enail:

contact@sintriva.com

​

Supervisory authority (Georgia):

Personal Data Protection Service of Georgia

​

Part B - Governing Law

Sintriva is registered in Georgia. Our relationship with you, and this Privacy Policy, are governed by the law of Georgia, and in particular the Law of Georgia on Personal Data Protection. Any disputes are subject to the courts of Georgia.

Choosing Georgian law does not remove protections that the mandatory law of your own country gives you. If you are located in the EU/EEA, Part C also applies to you. If you are a resident of California or certain other U.S. states, Part D also applies to you. Where those laws give you stronger protection, that protection applies.

​

Part C - Additional Information for the European Union (EU/EEA)

This Part applies if you are located in the European Union or the wider European Economic Area (EEA). It adds to Part A. If you are located in the United Kingdom, broadly similar rights apply to you under UK data protection law.

​

Controller. giorgadzeworkspace@gmail.com is the controller of your personal data. 

​

Legal bases. We process your personal data on the legal bases described in section 4. Where we rely on legitimate interests, you have the right to object. Where we rely on consent, you can withdraw it at any time, without affecting processing already carried out.

​

Your rights under the GDPR. You have the right to access your personal data; to have inaccurate data corrected; to have data deleted; to restrict processing; to object to processing; to receive your data in a portable format; and not to be subject to decisions with legal or similarly significant effects based solely on automated processing.

​

Complaints. You have the right to lodge a complaint with the data protection supervisory authority in your country.

​

International transfers. When we transfer personal data outside the EU/EEA, we use safeguards such as an adequacy decision or standard contractual clauses. You can ask us for more information or for a copy of the relevant safeguards.

​

Part D - Additional Information for United States Residents

This Part applies if you are a resident of California. It adds to Part A. Residents of certain other U.S. states with similar privacy laws may also have comparable rights - please contact us to find out more.

​

Categories of personal information. In the past 12 months, we may have collected the following categories of personal information, as defined by California law: identifiers (such as name and contact details); commercial information (such as services purchased and project history); internet or network activity (such as website usage data); approximate geolocation data (from IP address); professional or employment-related information; and other information you provide in connection with a project.

​

Sources, purposes, and recipients. We collect this information from the sources described in section 3, use it for the purposes described in section 4, and disclose it to the categories of recipients described in section 7.

​

Sale and sharing. We do not sell your personal information for money. However, our website uses third-party advertising and analytics tools (such as advertising pixels). Under California law, this may be treated as “sharing” personal information for cross-context behavioral advertising. You have the right to opt out of this sharing. You can opt out by using the “Do Not Sell or Share My Personal Information” link on our website, or by contacting us using the details in section 16. We also honor recognised opt-out preference signals, such as the Global Privacy Control (GPC), that your browser sends.

​

Sensitive personal information. We do not use or disclose sensitive personal information for purposes that would give you a right to limit such use under California law.

​

Your rights. As a California resident, you have the right to know and access the personal information we hold about you; to request its deletion; to request its correction; to opt out of the sale or sharing of personal information; to limit the use of sensitive personal information; and not to be discriminated against for exercising your rights.

​

How to exercise your rights. Please contact us using the details in section 16. You may use an authorized agent to submit a request on your behalf. We may ask for information to verify your identity before we respond.

​

bottom of page