Privacy Policy
Last Updated: 10.07.2026
IO Consulting (“we,” “us,” “our”) operates the website ioconsulting.ge (the “Site”). This Privacy Policy explains what personal data we collect, how we use it, where it is stored, and what rights you have regarding your data.
By using this Site, you agree to the collection and use of information in accordance with this policy.
Who We Are
IO Consulting is a cybersecurity and digital audit consultancy based in Tbilisi, Georgia, providing ISO 27001/22301/20000-1 implementation and audit, IT audit, cybersecurity framework compliance, and related consulting services.
Contact:
IO Consulting
Tbilisi, Georgia
Email: info@ioconsulting.ge
Website: www.ioconsulting.ge
What Information We Collect
We collect the following categories of personal data, depending on how you interact with the Site:
Information You Provide Directly
- Newsletter/Marketing Signup (if applicable) – email address, and name if provided, when you subscribe to updates from IO Consulting.
Information Collected Automatically
- Log Data – IP address, browser type, device information, pages visited, referring URL, and timestamps, collected automatically by our web server and hosting infrastructure.
- Cookies and Similar Technologies – see Section – Cookie Policy, for full details.
We do not knowingly collect sensitive categories of personal data (such as health, biometric, or financial account information) through this Site.
How We Use Your Information
We use the information we collect to:
- Respond to inquiries submitted through our contact form
- Provide, maintain, and improve the Site
- Communicate with you about our services, upon request
- Moderate and display blog comments
- Analyze Site usage to improve content and user experience
- Comply with legal obligations and protect against fraudulent or unauthorized activity
We do not sell, rent, or trade your personal data to third parties for their marketing purposes.
Legal Basis for Processing
Where the General Data Protection Regulation (GDPR) applies to you (e.g., if you are located in the European Economic Area), we process your personal data on the following legal bases:
- Consent – for newsletter subscriptions, non-essential cookies, and comment submissions
- Legitimate interest – for responding to inquiries, maintaining Site security, and analyzing Site usage
- Contractual necessity – where processing is required to provide services you have requested
- Legal obligation – where processing is required to comply with applicable law
If you are located in Georgia, this processing is additionally governed by the Law of Georgia on Personal Data Protection, and IO Consulting acts as the data controller with respect to personal data collected through this Site.
Where Your Data Is Stored and Hosting
This Site is hosted on infrastructure provided by Hetzner Online GmbH, located in Germany (European Union). As a result, personal data submitted through this Site (including contact form and comment data) may be stored and processed on servers located in the EU, and is subject to the data protection standards applicable in that jurisdiction, in addition to Georgian data protection law.
We take reasonable technical and organizational measures to protect data during transfer and storage, consistent with our own professional standards as an information security consultancy.
Third-Party Services
The Site may use the following third-party services, which may process limited personal data on our behalf:
- Hosting Provider (Hetzner) – stores Site data and infrastructure logs on servers in Germany.
- Email/Contact Form Processing – form submissions are transmitted via the Site’s contact form and delivered to our email systems for response.
Each third-party service processes data according to its own privacy policy, in addition to the safeguards described here.
Cookie Policy
What Are Cookies
Cookies are small text files stored on your device when you visit a website. They help websites function properly, remember preferences, and understand how visitors use the Site.
Types of Cookies We Use
| Cookie Type | Purpose | Duration |
|---|---|---|
| Strictly Necessary | Required for core Site functionality (e.g., security, navigation, WordPress session management) | Session / up to 1 year |
| Functional | Remember preferences (e.g., language selection via Polylang) | Up to 1 year |
| Comment Cookies | Remember your name/email if you leave a blog comment, so you don’t have to re-enter it | Up to 1 year |
Managing Cookies
You can control or delete cookies through your browser settings at any time. Most browsers allow you to:
- View what cookies are stored and delete them individually
- Block third-party cookies
- Block cookies from specific or all websites
- Delete all cookies when you close your browser
Please note that blocking strictly necessary cookies may affect the functionality of the Site (e.g., language switching, form submission).
Do Not Track
The Site does not currently respond to “Do Not Track” browser signals, as no universal standard for interpreting these signals has been adopted.
Data Retention
We retain personal data only as long as necessary for the purposes described in this policy:
- Contact form submissions – retained for as long as necessary to respond to and follow up on your inquiry, and thereafter as required for legitimate business or legal purposes.
- Blog comments – retained indefinitely unless you request deletion, as they form part of the public discussion on the Site.
- Server/log data – typically retained for a limited period for security and troubleshooting purposes.
Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access – request a copy of the personal data we hold about you
- Rectification – request correction of inaccurate or incomplete data
- Erasure – request deletion of your personal data, subject to legal exceptions
- Restriction – request that we limit how we use your data
- Objection – object to certain types of processing, including direct marketing
- Data Portability – request your data in a portable format, where applicable
- Withdraw Consent – where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, contact us at info@ioconsulting.ge. We will respond within the timeframe required by applicable law (Law of Georgia on Personal Data Protection).
If you are located in the EU and believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local data protection authority. If you are located in Georgia, you may contact the Personal Data Protection Service of Georgia.
Data Security
As a cybersecurity consultancy, we apply industry-standard technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
Children’s Privacy
This Site is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The “Last Updated” date at the top of this page indicates when this policy was last revised. We encourage you to review this page periodically.
Contact Us
If you have questions about this Privacy Policy or how we handle your personal data, please contact us:
IO Consulting
Tbilisi, Georgia
Email: info@ioconsulting.ge
