Privacy Policy

Effective date: 31 August 2026

This Privacy and Data Protection Policy explains how Larry Strawson, trading as Emaginow (“Emaginow”, “we”, “us” or “our”), handles personal data in connection with emaginow.com, property enquiries, advisory communications, newsletters and related services.

3.1 Who controls your personal data

Controller: Larry Strawson, trading as Emaginow

Address: Batumi Plaza Business Center, 4 Chavchavadze St, Batumi 6010, Georgia

Website: https://emaginow.com

Privacy requests: use https://emaginow.com/contact/ and write “Privacy Request” at the start of your message, or write to the postal address above.

3.2 Scope

This policy applies to personal data handled through the website, enquiry forms, newsletter sign-ups, email, telephone, WhatsApp, Telegram, meetings and the administration of Emaginow’s advisory services. Third-party websites and communication platforms have their own privacy terms. This policy does not govern their independent processing.

3.3 Personal data we may collect

  • Identity and contact data, such as your name, email address, telephone number, country of residence and preferred communication channel.
  • Enquiry and preference data, such as the type of property or service you want, location, budget range, intended use, timing and questions you ask us.
  • Correspondence and meeting data, including messages, appointment details, documents you choose to provide and records of our advice or follow-up.
  • Client and transaction-support data where you engage us, such as identification and due-diligence information, property details, contracts, invoices and information required to coordinate with developers, owners or professional advisers.
  • Marketing preference data, including newsletter choice, the consent wording shown to you, date and source of consent, unsubscribe requests and suppression status.
  • Technical and security data, including IP address, device/browser information, timestamps, requested URLs, referring page, error information and security logs.
  • Cookie and preference data, including the choices stored by the consent tool and any analytics data collected only after valid consent, where applicable.

Please do not send passport copies, bank details, health information or other sensitive material through a general website form unless we specifically request it through an appropriate secure channel and explain why it is necessary.

3.4 How we obtain data

  • Directly from you when you contact us, subscribe, book a meeting, communicate with us or engage our services.
  • Automatically from your device and our security/hosting systems when you use the website.
  • From developers, property owners, agents, professional advisers or public sources where necessary for an enquiry or service and where the collection is lawful. Where required, we will provide the information applicable to indirectly obtained data.

3.5 Why we use data and our legal grounds

PurposeData usedLegal ground
Respond to enquiries and arrange conversationsContact details, enquiry, correspondenceSteps requested before a contract; legitimate interests in operating an advisory service
Provide agreed advisory or coordination servicesClient, preference, correspondence, property and transaction-support dataPerformance of a contract; steps requested before a contract
Administer records, invoices, disputes and complianceIdentity, client, transaction and financial-administration recordsLegal obligation; contract; legitimate interests in establishing or defending claims
Protect the site and diagnose faultsTechnical, access, error and security logsLegitimate interests in security, fraud prevention, service integrity and availability
Send newsletters or direct marketingContact details and marketing preferencesConsent
Measure site use with non-essential analytics, if enabledCookie identifiers and usage eventsConsent where required
Coordinate with a developer, owner or adviser at your requestRelevant enquiry, client and property dataContract; steps requested by you; legitimate interests, depending on context

3.6 Direct marketing

We send newsletters or other direct marketing only where we have a valid consent or another legal ground that clearly permits it. Georgian law requires consent for direct marketing. Before consent, we will explain the right to withdraw and provide a simple method to do so. You may unsubscribe using the link in a marketing email or submit a Privacy Request. We will stop direct marketing within a reasonable period and no later than seven working days after a valid request. We keep proof of consent and withdrawal for the marketing period and for one year after the marketing activity ends, as required by Georgian law. [1]

Withdrawing marketing consent does not affect service messages that are necessary to answer an enquiry, perform an agreement, provide a requested update or meet a legal obligation.

3.7 Cookies and similar technologies

We may use strictly necessary cookies or local storage to operate security, remember privacy choices and provide requested site functions. These items do not require consent where they are genuinely necessary.

We use Cloudflare Web Analytics, supplied by Cloudflare, Inc., to measure aggregated page views and real-user website performance, including Core Web Vitals. The service loads a lightweight JavaScript beacon from static.cloudflareinsights.com. Cloudflare states that Web Analytics does not use cookies or local storage, does not fingerprint individuals and does not collect or use visitors’ personal data. We do not use it for advertising, cross-site tracking or individual profiling.

If we introduce any other non-essential analytics or marketing technology, we will update this policy and obtain consent before activation where required. You can also control cookies through your browser settings.

3.8 Recipients and service providers

We disclose personal data only where necessary and lawful. Recipient categories may include:

  • website hosting, content-delivery, backup, security and technical-support providers;
  • email delivery, customer-relationship and form-processing providers, including Brevo for retained email functions and self-hosted WordPress/Fluent systems;
  • communications platforms you choose to use, such as WhatsApp or Telegram;
  • developers, property owners, agents, inspection providers, lawyers, accountants, notaries, translators or other advisers where you ask us to coordinate a matter or where it is necessary for an agreed service;
  • public authorities, courts or regulators where disclosure is required by law or necessary to protect legal rights; and
  • a buyer or successor if the business is reorganised, subject to appropriate confidentiality and data-protection safeguards.

We do not sell personal data. We do not disclose enquiry details to a developer or property seller merely because you viewed a listing; a disclosure must be connected to your request or another lawful purpose.

3.9 International transfers

Some technology or communications providers may process data outside Georgia. Before making an international transfer, we assess the destination, recipient and available safeguards and use an appropriate legal mechanism, such as an adequacy basis, a legally binding data-transfer agreement or another permitted safeguard. We record relevant transfer information and limit onward transfers to the original lawful purpose. [1]

If the GDPR applies to a particular processing activity, we also use a GDPR transfer mechanism where required, such as an adequacy decision or approved contractual safeguards.

3.10 Retention

We retain data only for as long as necessary for the stated purpose, legal obligations, security, dispute handling and the establishment or defence of legal claims. The operational schedule is:

RecordDefault period/criterionReason
General enquiries that do not become a client engagementUp to 24 months after the last meaningful contactFollow-up, service quality and dispute context
Client/service filesFor the engagement and the applicable contractual, limitation, tax and accounting periodsContract performance, compliance and legal claims
Newsletter contactUntil consent is withdrawn or the list is closedConsent-based marketing
Marketing consent/withdrawal proofDuring marketing and for 1 year after it endsExpress Georgian-law record requirement
Routine server/security logsNormally up to 90 days; longer where linked to an incident or legal needSecurity and incident investigation
Cookie-consent preferenceFor the duration stated by the consent tool, normally 6-12 monthsRemember and demonstrate privacy choice
Suppression recordAs long as reasonably needed to respect an opt-outPrevent unwanted marketing

When a period expires, we delete, anonymise or securely isolate the information unless a lawful reason requires continued retention. Backups are deleted on their normal rotation and are not restored for ordinary use after deletion.

3.11 Security

We use technical and organisational measures appropriate to the sensitivity, volume, purpose and risk of processing. Measures include access controls, least-privilege administration, secure connections, updates, malware and firewall controls, backups, processor controls, confidentiality obligations, security logging and incident response. No internet service is completely secure, so we cannot promise absolute security.

3.12 Your rights

Subject to applicable law and any lawful exceptions, you may request confirmation and information about processing, access and a copy, correction or completion, erasure or destruction, restriction/blocking, portability where technically applicable, withdrawal of consent, and review of certain solely automated decisions. You may also object or request an end to direct marketing.

Under Georgian law, many information, access, correction and erasure requests must be handled within 10 working days, with limited extensions where the law permits. Blocking decisions may have a shorter deadline. If the GDPR applies, the usual response period is one month, subject to permitted extension. We will use the shorter applicable period where the regimes overlap and the request can be verified.

To exercise a right, submit a Privacy Request through https://emaginow.com/contact/ or write to the postal address in Section 3.1. We may request proportionate information to verify identity. We will not ask for more identity data than reasonably necessary.

If you believe your rights were violated, you may apply to the State Audit Office of Georgia or a competent court. Where the GDPR applies, you may also complain to the competent EU supervisory authority. [1][3]

3.13 Automated decisions

Emaginow does not use website data to make decisions based solely on automated processing that produce legal or similarly significant effects. If this changes, we will provide the required explanation and safeguards before the processing begins.

3.14 Children

Emaginow’s property advisory services are intended for adults. We do not knowingly solicit personal data from children through the website. If you believe a child has provided personal data, contact us so that we can assess and, where appropriate, delete it.

3.15 External platforms and links

The website may link to Google Maps, WhatsApp, Telegram, property developers or other third parties. Opening or using those services may allow the third party to collect data under its own policy. A link does not make Emaginow responsible for the third party’s independent processing or content.

3.16 Changes to this policy

We may update this policy when our services, providers or legal obligations change. We will publish the updated version and effective date. If a change materially affects consent-based processing, we will request a new consent where required rather than treating continued website use as consent.

Compare Listings

TitlePriceStatusTypeAreaPurposeBedroomsBathrooms