Legal.geLegal.geLegal.ge
СпециалистыБиблиотекаБлог
Ещё
О насЦеныКонтакты
LegalTools
Загрузка аккаунтаВойти
О насСпециалистыБиблиотекаБлогЦеныКонтакты
LegalTools
Загрузка аккаунтаВойти
Legal.ge

Юридическая платформа Грузии.

Загрузить в App StoreLegal.ge для iPhone

Быстрые ссылки

  • О нас
  • Специалисты
  • Открытые задачи
  • Услуги
  • Законы и кодексы
  • Компании
  • Организации
  • Ивенты
  • Блог
  • Контакты

Правовая информация

  • Юридическая библиотека
  • Политика конфиденциальности
  • Условия использования
  • Политика использования файлов cookie

Контакты

contact@legal.ge+995 551 911 961Нужен юрист? Найдите специалиста

Тбилиси, Грузия

© 2026 Legal.ge. Все права защищены.

Made with in Georgia

Последнее обновление: 13 мая 2026 г.· Версия 2.0

Политика использования файлов cookie

Этот документ описывает, как LegalGE использует файлы cookie для улучшения вашего опыта.

Legal.ge

Содержание

Содержание

COOKIE POLICY

Legal Sandbox Georgia LLC

Version: 2.0 Effective Date: Upon Publication Last Updated: [Date] Document Language: English (Georgian version prevails in case of conflict)


VERSION 2.0 — MAJOR REFRESH

This Cookie Policy v2.0 is a major refresh that brings the Cookie Policy into alignment with the actual cookie collection and tracking mechanisms operating in the production codebase as of the publication date.

Material changes from v1.1:

  • New Marketing consent category (4th category — Strictly Necessary, Functional, Analytics, Marketing) reflecting the actual four-category consent model in production code.
  • Meta Pixel cookies disclosed: _fbp (browser identifier, 90 days) and _fbc (click identifier, 90 days). Both are gated behind marketing consent.
  • Meta Conversions API disclosed (§7): server-side transmission of event data, IP address, user agent, and Pixel identifiers from Platform servers to Meta Platforms, Inc. (United States); gated behind marketing consent; supplements client-side Meta Pixel.
  • Cookie list corrected to match actual codebase: cookie_consent_session (consent audit linking) added; cookies that do not exist in production removed (session_id, csrf_token, last_viewed, language).
  • Theme cookie disclosure (set by inline initialisation script in [locale]/layout.tsx) added.
  • Vercel Analytics disclosed as cookieless performance monitoring; not consent-gated because Vercel Analytics does not set cookies and uses anonymised request metadata only.
  • Cookie Policy version constant disclosed (§9): a code-level COOKIE_POLICY_VERSION constant triggers re-consent flow when the policy materially updates, via an isPolicyOutdated() mechanism.
  • Server-side consent audit disclosed (§8): consent decisions are persisted server-side via /api/consent and linked to authenticated user IDs when available.
  • Removed false denial from prior v1.1 §4.3 ("we do not use Social media tracking pixels") — this denial was inaccurate because Meta Pixel was operating in production.
  • DNT handling removed from prior v1.1 §6 — DNT is not implemented in code.

v2.0 corrects misrepresentation: Earlier versions of the Cookie Policy did not disclose Meta Pixel, Meta Conversions API, or the marketing consent category, and contained an explicit denial of social media tracking. These tracking mechanisms have been operating in production gated behind marketing consent. v2.0 brings the Cookie Policy into alignment with the actual cookie collection and tracking activities of the Platform.


VERSION 1.1 — PRIOR VERSION (PRESERVED FOR HISTORY)

v1.1 was a minor refresh adding Google Calendar OAuth disclosure, updated supervisory authority reference (PDPS), encoding cleanup, and cross-references to Privacy Policy v2.0. v1.1's representation that the Platform did not use social media tracking was inaccurate and is corrected in v2.0.


COOKIES AT A GLANCE

QuestionAnswer
Do we use cookies?Yes
Do we need your consent?Yes, for non-essential cookies (Functional, Analytics, Marketing)
Can you refuse cookies?Yes, except strictly necessary cookies
What happens if you refuse?The Platform will still work, but some features may be limited
Can you change your mind?Yes, anytime via our cookie settings or your browser
Who sets cookies?We do (first-party) and some service providers (third-party)
What about marketing tracking?Meta Pixel + Meta Conversions API; gated behind explicit marketing consent. See §3.5, §4.4, and §5.
What about Google Calendar OAuth?Server-side tokens, not browser cookies. See §4.5
Supervisory authority?Personal Data Protection Service of Georgia

1. INTRODUCTION

1.1 About This Policy

This Cookie Policy explains how Legal Sandbox Georgia LLC ("we," "us," "our," or the "Platform"), operator of legal.ge, uses cookies and similar tracking technologies when you visit our website.

This Policy should be read together with our Privacy Policy v2.1, which explains how we handle personal data collected through cookies, and the applicable Function Rulebooks which govern specific Platform features.

1.2 What Are Cookies?

Cookies are small text files that are stored on your device (computer, tablet, or mobile phone) when you visit a website. They help the website recognise your device and remember certain information about your visit, such as your preferences or login status.

1.3 Similar Technologies

In addition to cookies, we may use similar technologies including:

  • Local Storage: Data stored in your browser that persists until cleared;
  • Session Storage: Data stored temporarily for a single browser session;
  • Pixels/Beacons: Small invisible images that track page visits and actions.

Throughout this Policy, "cookies" refers to all these technologies unless otherwise specified.

1.4 Distinction from Server-Side Storage

Cookies and browser-side technologies described in this Policy are distinct from server-side data storage (such as OAuth tokens stored in our database for Google Calendar integration). Server-side data storage is governed by the Privacy Policy v2.0 and the applicable Function Rulebook (e.g., Calendar Function Rulebook §7.5 for Google Calendar OAuth tokens).


2. OUR COOKIE CONSENT APPROACH

2.1 Strict Opt-In

We operate a strict opt-in cookie policy in compliance with the 2023 Georgian Personal Data Protection Law (No. 3144) and applicable European requirements. This means:

  • Essential cookies are placed automatically (required for the website to function);
  • All other cookies are placed only after you give explicit consent;
  • We will not track you or collect analytics data until you consent.

2.2 Cookie Consent Banner

When you first visit our website, you will see a cookie consent banner that allows you to:

  • Accept all cookies — enables all cookie categories;
  • Reject non-essential cookies — only essential cookies will be used;
  • Customise settings — choose which cookie categories to enable.

2.3 Changing Your Preferences

You can change your cookie preferences at any time by:

  • Clicking the "Cookie Settings" link in the website footer;
  • Clearing cookies through your browser settings (see Section 5).

If you change your preferences, the new settings will apply from that point forward. Cookies already placed may remain until they expire or you delete them.


3. TYPES OF COOKIES WE USE

3.1 Cookie Categories

We use the following four categories of cookies:

CategoryConsent Required?Purpose
Strictly NecessaryNoEssential for website operation
FunctionalYesEnhanced features and preferences
AnalyticsYesUnderstanding how visitors use our site
MarketingYesConversion tracking and remarketing via Meta Pixel and Meta Conversions API

Each non-essential category is independently controlled by the user via the cookie consent banner. The user may grant consent for some categories and decline others.

3.2 Strictly Necessary Cookies

These cookies are essential for the website to function properly. Without them, services you have requested cannot be provided. You cannot opt out of these cookies.

Cookie NameProviderPurposeDurationSameSite
cookie_consentlegal.geStores your selected consent preferences for the four categories (Necessary, Functional, Analytics, Marketing)365 daysLax
cookie_consent_sessionlegal.geAnonymous consent session identifier; used to link consent decisions to authenticated user IDs when available, for audit purposes365 daysLax
sb-access-tokenSupabaseAuthentication token (managed by Supabase auth system)SessionPer Supabase configuration
sb-refresh-tokenSupabaseAuthentication refresh tokenPer Supabase configurationPer Supabase configuration

3.3 Functional Cookies

These cookies enable enhanced functionality and personalisation. They may be set by us or by third-party providers whose services we use.

Cookie NameProviderPurposeDurationSameSite
themelegal.geRemembers light/dark mode preference; set by inline initialisation script in the page layout365 daysLax

Note on language preference: Language is determined by the URL path segment (e.g., /ka/, /en/, /ru/) rather than by a browser cookie. Language selection persists across visits via URL routing, not cookie storage.

3.4 Analytics Cookies

These cookies help us understand how visitors interact with our website by collecting and reporting information anonymously. Analytics cookies are placed only after the user grants explicit consent in the Analytics category via the cookie banner.

Cookie NameProviderPurposeDuration
_gaGoogle Analytics 4Distinguishes unique users2 years
_gidGoogle Analytics 4Distinguishes unique sessions24 hours (typical)
_ga_<container>Google Analytics 4Stores additional configuration and traffic data2 years
_gatGoogle Analytics 4Throttles request rateSession
_gac_<container>Google Analytics 4Campaign attribution when URL campaign parameters are present90 days

Important: We use Google Analytics 4 configured to:

  • Store and process data within the European Union only;
  • Not share data with Google for advertising purposes;
  • Anonymise data where possible.

The Google Analytics script is loaded only after the user grants analytics consent. Until consent is granted, no GA4 cookies are placed and no analytics data is transmitted to Google.

3.5 Marketing Cookies

These cookies are used for conversion tracking and remarketing via Meta Pixel and the server-side Meta Conversions API. They are placed only after the user grants explicit consent in the Marketing category via the cookie banner.

Cookie NameProviderPurposeDuration
_fbpMeta (Facebook)Anonymous browser identifier set by Meta Pixel; used for conversion attribution and remarketing90 days
_fbcMeta (Facebook)Click identifier set when a user arrives at the Platform from a Meta-served advertisement; used for click-to-conversion attribution90 days

Server-side complement (Meta Conversions API): In addition to the _fbp and _fbc cookies set by the client-side Meta Pixel, the Platform operates a server-side Meta Conversions API integration which transmits conversion event data, IP address, user agent, and Pixel identifiers from Platform servers to Meta. This server-side path complements the client-side Pixel and is described in detail in Section 7.

Marketing consent gate: The Meta Pixel script is loaded only after the user grants marketing consent. The Meta Conversions API server-side calls are similarly gated behind marketing consent. Without marketing consent, neither client-side Pixel cookies nor server-side Conversions API events are activated for the user.

Withdrawal effects: If you withdraw marketing consent, the Platform ceases new Pixel and Conversions API activity for your subsequent activity. Data already transmitted to Meta is subject to Meta's own retention and deletion policies; the Platform cannot recall data already transmitted.

Additional Meta cookies: The loaded Meta Pixel script may set additional Meta-controlled cookies beyond _fbp and _fbc. These additional cookies operate under Meta's own privacy policies. The Platform's source code explicitly references only _fbp and _fbc.


4. THIRD-PARTY COOKIES AND SERVICES

4.1 Overview

Some cookies are placed by third-party services that appear on our pages. We do not control these cookies. The third parties set their own cookies according to their privacy policies.

4.2 Third-Party Services We Use

ServicePurposeConsent Required?Their Privacy Policy
Google Analytics 4Website analytics (EU-only configuration)Yes (Analytics category)https://policies.google.com/privacy
Google OAuthLogin authenticationNo (Strictly Necessary)https://policies.google.com/privacy
Google Calendar (OAuth)Calendar synchronisation for Specialists at Expert/Enterprise tiersSpecialist OAuth granthttps://policies.google.com/privacy
Bank of GeorgiaPayment processing (on payment pages)No (Strictly Necessary on payment pages)https://bankofgeorgia.ge/privacy
SupabaseBackend services and authenticationNo (Strictly Necessary)https://supabase.com/privacy
Meta Platforms, Inc. (Facebook/Meta Pixel)Conversion tracking and remarketing — client-side PixelYes (Marketing category)https://www.facebook.com/privacy/policy
Meta Platforms, Inc. (Conversions API)Server-side conversion event transmissionYes (Marketing category)https://www.facebook.com/privacy/policy
Vercel AnalyticsCookieless page-view and performance monitoringNo (cookieless; legitimate interest)https://vercel.com/legal/privacy-policy

4.3 Cookies We Do NOT Use

For transparency, we want to confirm that we do not use:

  • LinkedIn, Twitter/X, TikTok, or other social-platform tracking pixels (only Meta/Facebook Pixel is in use, gated behind marketing consent — see §3.5);
  • Session recording tools (Hotjar, FullStory, Microsoft Clarity, etc.);
  • A/B testing cookies;
  • Cookies from data brokers or third-party advertising networks beyond Meta;
  • Cross-site behavioural tracking beyond what is performed by Meta Pixel and Meta Conversions API under marketing consent.

Correction note: Earlier versions of this Cookie Policy stated that we do not use any social media tracking pixels. That representation was inaccurate — Meta Pixel and Meta Conversions API have been operating in production behind marketing consent. v2.0 of this Cookie Policy corrects this disclosure.

4.4 Vercel Analytics — Cookieless Performance Monitoring

Vercel Analytics provides page-view and performance monitoring for the Platform. It is included in the page layout via the @vercel/analytics/next package and operates without setting cookies and without creating persistent identifiers. It uses anonymised request metadata (path, response time) for operational performance monitoring.

Because Vercel Analytics is cookieless and does not track users across visits or sites, it operates under legitimate interest (operational monitoring) and is not gated by the cookie consent banner. The Platform discloses Vercel Analytics here for transparency.

If Vercel Analytics is determined in the future to set persistent identifiers or otherwise constitute tracking, the Platform will gate it behind analytics consent and update this Policy accordingly.

4.5 Google Calendar OAuth — Server-Side, Not Cookies

Where a Specialist (at Expert tier for Solo Specialists or Enterprise tier for Company Specialists) authorises Google Calendar synchronisation, the resulting OAuth tokens are stored server-side in our database (not as browser cookies).

This is governed by:

  • Calendar Function Rulebook §7.5 — token persistence and encryption;
  • Privacy Policy v2.0 §3.1.4 — Calendar Data category;
  • Privacy Policy v2.0 §6.1.1 — third-party services (Google Calendar);
  • Calendar Function Rulebook §8 — disconnection and token deletion.

OAuth tokens are not cookies and are not affected by browser cookie settings. They are managed through the Specialist's Calendar Tab on the Platform.

For all browser-side cookies set during the OAuth handshake (state parameter, redirect tokens), these are session cookies that expire upon completion of the OAuth flow.


5. SERVER-SIDE META CONVERSIONS API

5.1 What the Conversions API Does

In addition to the client-side Meta Pixel, the Platform operates a server-side Meta Conversions API integration. The Conversions API transmits conversion event data directly from Platform servers to Meta Platforms, Inc. infrastructure in the United States.

The Conversions API exists to improve conversion measurement reliability when client-side Pixel data is incomplete (e.g., due to browser tracking-prevention features, ad-blockers, or network failures).

5.2 What Data Is Transmitted

For each conversion event (e.g., subscription purchase, role registration), the Platform's Conversions API integration transmits to Meta:

  • Event name and event timestamp;
  • Event-specific parameters (e.g., subscription tier, currency);
  • The user's IP address;
  • The user's browser user agent string;
  • The _fbp cookie value (if available from the same request);
  • The _fbc cookie value (if available from the same request);
  • Other request metadata as configured in the Conversions API integration.

5.3 Marketing Consent Gate

The Conversions API is gated behind marketing consent. Until the user grants marketing consent via the cookie consent banner, no Conversions API events are transmitted for that user.

When the user grants marketing consent, the Conversions API begins transmitting events for the user's subsequent activities. When the user withdraws marketing consent, transmissions cease for subsequent activities; events already transmitted remain at Meta.

5.4 International Data Transfer

Meta's servers are located in the United States. Transmission via the Conversions API constitutes an international data transfer outside the European Economic Area.

The Platform's lawful basis for this transfer is dual:

(a) Explicit user consent (marketing category) — granted via the cookie consent banner;

(b) Standard Contractual Clauses (SCCs) — Meta's data processing terms incorporate Standard Contractual Clauses approved by the European Commission as the safeguard for international transfers.

The Privacy Policy v2.1 §6.3.1 contains additional detail on the lawful basis.

5.5 Data Recall Limitation

Once data has been transmitted to Meta via the Conversions API, the Platform cannot recall the transmitted data. Subsequent withdrawal of marketing consent prevents new transmissions but does not delete data already at Meta. Users wishing to delete data already received by Meta should contact Meta directly through Meta's data subject rights mechanisms.

5.6 Source

The Conversions API integration is implemented in the codebase at src/lib/analytics/meta-capi.ts. It complements the client-side Meta Pixel implementation at src/components/analytics/MetaPixel.tsx.


6. MANAGING COOKIES

6.1 Through Our Website

The easiest way to manage cookies on our website is through our cookie consent controls:

  1. Click "Cookie Settings" in the website footer;
  2. Adjust your preferences for each cookie category;
  3. Click "Save Preferences".

6.2 Through Your Browser

You can also control cookies through your browser settings. Here's how for popular browsers:

BrowserInstructions
ChromeSettings → Privacy and Security → Cookies and other site data
FirefoxSettings → Privacy & Security → Cookies and Site Data
SafariPreferences → Privacy → Manage Website Data
EdgeSettings → Cookies and site permissions → Manage and delete cookies

For detailed instructions, visit your browser's help documentation.

6.3 Effects of Disabling Cookies

If you disable or delete cookies:

Cookie Type DisabledEffect
Strictly NecessaryWebsite may not function properly; you may not be able to log in
FunctionalPreferences (language, theme) will reset each visit
AnalyticsNo impact on your experience; we simply won't collect analytics data

6.4 Mobile Devices

For mobile apps or mobile browsers, cookie settings are typically found in:

  • iOS: Settings → Safari → Privacy & Security
  • Android: Chrome → Settings → Site Settings → Cookies

7. POLICY VERSIONING AND RE-CONSENT

7.1 Cookie Policy Version Constant

The Platform's codebase contains a constant representing the current Cookie Policy version (COOKIE_POLICY_VERSION). When this version constant is incremented (typically when material changes are made to this Policy), the Platform's isPolicyOutdated() mechanism detects that previously-recorded user consent corresponds to an older policy version.

7.2 Re-Consent Trigger

Where a user has previously granted cookie consent under an older policy version, and the current policy version constant indicates a material update:

(a) The user is shown the cookie consent banner again on next visit;

(b) The prior consent record is preserved as historical audit evidence but no longer treated as current consent;

(c) The user must affirmatively grant consent under the new policy version before non-essential cookies are placed;

(d) The strictly-necessary cookies remain in effect throughout (per §3.2).

7.3 Material vs. Non-Material Updates

(a) Material updates (e.g., addition of a new cookie category, change of consent mechanics, addition of a new cross-border data transfer) → version constant incremented → re-consent required;

(b) Non-material updates (e.g., typo correction, clarifying language without operational change) → version constant not incremented → continued use under prior consent acceptable.

This approach implements the principle that consent must be informed: where the underlying processing changes materially, prior consent does not validly cover the new processing.


8. SERVER-SIDE CONSENT AUDIT

8.1 Audit Trail

In addition to storing consent decisions in the user's browser via the cookie_consent cookie, the Platform persists consent decisions on the server for audit purposes:

(a) Consent decisions are saved server-side via the Platform's /api/consent endpoint;

(b) The cookie_consent_session cookie provides an anonymous identifier linking consent decisions to specific browsers/sessions;

(c) Where the user is authenticated, the Platform links anonymous consent records to the authenticated user identity for full audit traceability.

8.2 Purpose of Server-Side Audit

The server-side audit trail enables the Platform to:

(a) Demonstrate compliance with the 2023 Georgian Personal Data Protection Law's consent record-keeping requirements;

(b) Respond to user requests to verify their consent history;

(c) Investigate consent-related disputes or audit inquiries.

8.3 Retention of Consent Audit Records

Consent audit records are retained per the Privacy Policy retention table (account lifetime + 2 years for active accounts; longer where required for legal compliance).


9. COOKIE RETENTION

9.1 Retention Periods

Different cookies have different lifespans:

TypeDuration
Session cookiesDeleted when you close your browser
Persistent cookiesRemain until expiry date or manual deletion

Specific retention periods for each cookie are listed in Section 3.

9.2 Our Retention Principle

We set cookie expiration periods based on their purpose:

  • Essential functionality: As short as practical;
  • Preferences: Long enough to be useful (typically 1 year);
  • Analytics: Industry standard (up to 2 years for Google Analytics).

10. UPDATES TO THIS POLICY

10.1 Changes

We may update this Cookie Policy to reflect changes in:

  • The cookies we use;
  • Legal or regulatory requirements;
  • Our website functionality.

10.2 Notification

If we make significant changes to this Policy, we will:

  • Update the "Last Updated" date;
  • Reset cookie consent for affected users where appropriate;
  • Post a notice on our website for material changes.

10.3 Review

We encourage you to review this Policy periodically.


11. SUPERVISORY AUTHORITY

If you believe we have not handled cookies in compliance with applicable law, you have the right to lodge a complaint with:

Personal Data Protection Service of Georgia (PDPS)

Address: 7 Vachnadze Street, 0105, Tbilisi, Georgia (Branch office: Bako Street No. 48, Batumi, Georgia)

Email: office@pdps.ge Phone: +995 032 242 10 00 Website: https://personaldata.ge/en

For EU residents, you may also complain to your local data protection authority.


12. CONTACT US

If you have questions about our use of cookies, please contact us:

Legal Sandbox Georgia LLC

Email: contact@legal.ge

Address: Tbilisi, Agmashenebeli Alley N240 Georgia

Data Protection Contact: Vakhtang Baramashvili (CEO)


13. RELATED DOCUMENTS

  • Master Terms and Conditions v2.0 — Rules for using our Platform;
  • Privacy Policy v2.1 — Details on how we handle personal data;
  • Calendar Function Rulebook v1.0 — Specific provisions for Google Calendar OAuth integration;
  • Function Rulebooks — Feature-specific binding rules incorporated by reference;
  • Role Terms and Conditions — Role-specific obligations.

TECHNICAL REFERENCE

For developers and technical users, here is a complete list of cookies actually set by the production codebase as of v2.0:

STRICTLY NECESSARY (no consent required)
├── cookie_consent (legal.ge) — 365 days — User's consent preferences for 4 categories
├── cookie_consent_session (legal.ge) — 365 days — Anonymous consent session ID for audit
├── sb-access-token (Supabase) — Session — Auth token
└── sb-refresh-token (Supabase) — Per Supabase config — Auth refresh

FUNCTIONAL (Requires Functional consent)
└── theme (legal.ge) — 365 days — Light/dark mode preference

ANALYTICS (Requires Analytics consent)
├── _ga (Google Analytics 4) — 2 years — User distinction
├── _gid (Google Analytics 4) — 24 hours — Session distinction
├── _ga_<container> (Google Analytics 4) — 2 years — Configuration / traffic data
├── _gat (Google Analytics 4) — Session — Throttling
└── _gac_<container> (Google Analytics 4) — 90 days — Campaign attribution

MARKETING (Requires Marketing consent)
├── _fbp (Meta) — 90 days — Browser identifier for Meta Pixel
├── _fbc (Meta) — 90 days — Click identifier (set when arriving from Meta ad)
└── (Additional Meta cookies may be set by the loaded Meta Pixel script)

SERVER-SIDE STORAGE (NOT BROWSER COOKIES)
├── Google Calendar OAuth tokens — managed per Calendar Rulebook §7.5 — Specialist Expert/Enterprise tier only
├── Supabase session/refresh tokens — managed by authentication system
├── Server-side consent audit records — saved via /api/consent endpoint
└── Meta Conversions API events — transmitted server-side to Meta (US); not stored as cookies

LANGUAGE PREFERENCE (NOT A COOKIE)
└── Language is determined by URL path segment (/ka/, /en/, /ru/), not by cookie

THIRD-PARTY UNCONDITIONAL (NOT COOKIE-BASED)
└── Vercel Analytics (@vercel/analytics/next) — cookieless; uses anonymised request metadata only; legitimate interest

SCHEDULE A: ITEMS FLAGGED FOR LEGAL AND TECHNICAL REVIEW

The following provisions warrant review by qualified Georgian legal counsel and the technical team before final publication:

  1. §3.2-§3.5 — Cookie Lists Match Production: Technical team should confirm that: (a) All cookies set by the production Platform are listed in the appropriate category; (b) Cookie names, providers, durations, and purposes are accurate; (c) The Meta Pixel script does not set significant additional cookies beyond _fbp and _fbc that warrant disclosure; (d) The Supabase auth cookie names and durations match the actual Supabase configuration in production.

  2. §3.4 — Google Analytics 4 EU-Only Configuration: Technical team should confirm that GA4 is configured for EU-only data residency as represented.

  3. §3.5 — Meta Pixel Cookies: Technical team should confirm _fbp and _fbc cookie behavior; counsel should confirm disclosure is sufficient.

  4. §4.4 — Vercel Analytics Cookieless: Technical team should verify Vercel Analytics genuinely operates without setting cookies or persistent identifiers as represented. If Vercel Analytics in fact tracks users, consent gating must be added.

  5. §4.5 — Google Calendar OAuth: Technical team should confirm that OAuth tokens are stored server-side only (no equivalent browser-side cookies) per the Calendar Function Rulebook §7.5 design.

  6. §5 — Meta Conversions API: Critical flag. Counsel should confirm: (a) The disclosure of server-side conversion event transmission is sufficient under the 2023 Georgian Personal Data Protection Law; (b) That marketing consent gating provides valid lawful basis for the server-side transmission; (c) That the dual lawful basis (consent + SCCs) for international transfer to Meta in the United States is correctly stated; (d) DPIA requirement. Article 33 of the 2023 Georgian Law mandates Data Protection Impact Assessments for processing posing high risk to data subject rights. Marketing tracking with international transfer to a US ad platform is the textbook trigger for DPIA. A DPIA is required and has not yet been performed. This is a separate workstream.

  7. §2.1 — Strict Opt-In Consent: Counsel should confirm that the strict opt-in consent banner implementation complies with the 2023 Georgian Personal Data Protection Law's requirements for explicit cookie consent.

  8. §7 — Policy Versioning and Re-Consent: Counsel should confirm that the version-constant-driven re-consent flow satisfies the 2023 Georgian Law's requirements for valid consent where processing materially changes.

  9. §8 — Server-Side Consent Audit: Counsel should confirm that the server-side audit trail satisfies the 2023 Georgian Law's record-keeping requirements for consent. Counsel should also review whether the link between anonymous consent session IDs and authenticated user identities raises any data protection concerns.

  10. §10 — Supervisory Authority Details: Counsel should verify current PDPS contact details are accurate as at publication date.

  11. General — Cookie Categorisation: Counsel should confirm that the four-category model (Strictly Necessary / Functional / Analytics / Marketing) and the "Strictly Necessary" exemption from consent align with the 2023 Georgian Personal Data Protection Law and applicable European requirements.

  12. General — Meta Standard Contractual Clauses: Counsel should obtain and review Meta's current Data Processing Terms incorporating SCCs, and verify that the SCCs cover the specific data transfers performed by the Platform (both client-side Pixel and server-side Conversions API).


LEGAL SANDBOX GEORGIA LLC

Version 2.0 — Effective Upon Publication


This document should be reviewed by qualified Georgian legal counsel and the technical team before publication. Schedule A items above identify specific provisions warranting attention.


END OF DOCUMENT

© 2026 Legal.ge. Все права защищены.