Privacy Policy
This Privacy Policy explains how Easy Business Ltd. ("Easy Business", "IzziGo", "we", "us" or "our") collects, uses, stores, shares and protects personal data in connection with IzziGo, including IzziMap, our websites, mobile applications, traveler services, business services, offers, communications and related platform features.
This Policy applies to visitors, registered travelers, business representatives, programme participants, persons contacting IzziGo and other individuals whose personal data we process in connection with IzziGo.
This Policy provides information about our processing under applicable data-protection laws, including the EU General Data Protection Regulation ("GDPR") where it applies and the Law of Georgia on Personal Data Protection.
This Privacy Policy is a transparency notice. Using IzziGo or accepting the IzziGo Terms of Use does not mean that you consent to every type of processing described here. Where consent is legally required, we request it separately.
1. Who is responsible for your personal data
The controller responsible for IzziGo is:
Easy Business Ltd.
Identification Code: 400371842
Teimuraz Bochorishvili N3
Tbilisi, Georgia
Website: izzigo.eu
Privacy contact: info@izzigo.eu
You can contact us at this address regarding privacy questions, data-protection rights or concerns relating to our processing of personal data.
Further company information is available in our Imprint / Legal Notice.
2. Personal data we process
The personal data we process depends on how you interact with IzziGo.
2.1 Account and identity data
This may include:
- name and surname;
- email address;
- internal user identifier;
- account type or role;
- profile information;
- profile image or avatar;
- language preferences;
- account creation information;
- email-verification status; and
- authentication-provider identifiers where supported social login is used.
2.2 Authentication and security data
This may include:
- authentication records;
- password-related security information;
- email-verification information;
- password-reset information;
- login and session information;
- security events;
- fraud-prevention signals;
- rate-limit information; and
- technical information reasonably necessary to protect accounts and the platform.
2.3 Traveler information
If you use traveler features, we may process information such as:
- travel preferences;
- preferred languages;
- saved places;
- followed places;
- collections;
- trip information;
- offer interactions;
- notification preferences; and
- other choices you intentionally save through traveler features.
2.4 Location information
If you enable location-based functionality, IzziGo may process location information to provide features such as nearby-place discovery and map functionality.
Depending on the feature and device, this may include:
- approximate location;
- device-provided location;
- map position;
- location-derived search context; or
- an approximate region derived from technical information where appropriate.
Access to precise device location is subject to the permissions and settings provided by your browser, operating system or device.
You can disable location access through your device or browser settings.
2.5 Business representative data
For business accounts and representatives, we may process:
- name;
- email address;
- telephone number;
- business role;
- relationship to the listed business;
- authority or verification information where reasonably necessary;
- Business Dashboard activity; and
- business-related communications with IzziGo.
2.6 Business listing information
Business listings may contain information such as:
- business name;
- address and geographic coordinates;
- business category;
- business description;
- public business telephone number;
- public business email address;
- website;
- social-media links;
- opening or practical information;
- languages;
- accessibility information;
- photographs, logos and media;
- offers; and
- other information relevant to the public profile.
Information relating only to a legal entity is not necessarily personal data. Business information may, however, be personal data where it identifies or relates to an individual, such as a sole trader, guide, owner or named business representative.
2.7 Publicly available business information
IzziGo may collect limited professional or business information from publicly accessible sources where permitted and reasonably necessary for legitimate platform purposes.
Sources may include:
- official business websites;
- public business directories;
- official business social-media pages;
- tourism or institutional directories;
- public map and location information; and
- other legitimate publicly accessible professional sources.
This information may include business names, professional names, public business contact information, business websites, addresses, categories and other information that a business has made publicly available for professional purposes.
2.8 Offers and traveler inquiries
If you contact a business through an IzziGo inquiry or offer feature, we may process:
- your name;
- email address;
- your message;
- the selected business or offer;
- submission date and time;
- delivery or status information; and
- limited evidence of the privacy notice displayed when the inquiry was submitted.
The information necessary for the inquiry is shared with the business you selected so that it can respond.
2.9 Plans, payments and orders
When a business purchases a paid IzziGo service, we may process:
- business identity;
- customer or account information;
- order number;
- purchased plan or visibility product;
- price and currency;
- payment status;
- transaction references;
- invoice or accounting information where applicable;
- activation and expiry information; and
- refund or cancellation information where applicable.
Payment information may also be processed directly by the relevant payment provider. IzziGo does not necessarily receive the full payment credentials used to complete a transaction.
2.10 Visibility and promotional services
If a business purchases or receives a visibility entitlement, we may process information concerning:
- the relevant business;
- visibility product;
- purchase or grant source;
- activation;
- duration;
- expiry;
- status; and
- performance information where such analytics are available.
2.11 Website Partner Programme
Where a business applies to or participates in the IzziGo Website Partner Programme, we may process:
- business identity;
- application information;
- eligibility information;
- programme status;
- website or partnership information;
- warnings or compliance status;
- programme benefits; and
- programme communications.
2.12 Referrer Programme
Where a user or business participates in the IzziGo Referrer Programme, we may process:
- referrer identity;
- referral code;
- referral attribution;
- referred business information;
- programme status;
- credits or rewards;
- limits or expiry information; and
- programme communications.
Optional browser-based referral attribution is subject to the applicable cookie and consent settings.
2.13 Communications and support
When you contact us or receive service communications, we may process:
- email address;
- message content;
- support requests;
- communication category;
- delivery status;
- notification preferences;
- unsubscribe status;
- communication history; and
- relevant troubleshooting information.
2.14 Notifications and push services
If you enable app or web notifications, we may process:
- user or account identifier;
- notification type;
- notification status;
- device or platform information;
- push-delivery identifiers or tokens; and
- notification preferences.
Push-delivery tokens are technical identifiers and are not displayed publicly.
2.15 Reports, moderation and appeals
If you report content, receive a moderation decision or submit an appeal, we may process:
- reporter contact information where provided;
- reported URL or content;
- report category;
- report explanation;
- affected account or business;
- moderation decision;
- reason for the decision;
- appeal information;
- appeal outcome;
- decision and appeal references; and
- audit or integrity information associated with those records.
2.16 Technical and usage information
Depending on the service being used and your consent choices, we may process technical information such as:
- browser type;
- operating system;
- device type;
- application version;
- IP address;
- pages or features accessed;
- referring URL;
- language;
- cookie or service identifiers;
- error or diagnostic information; and
- security events.
3. How we obtain personal data
We may obtain personal data:
- directly from you;
- when you create or manage an account;
- when you create, claim or manage a business listing;
- when you use traveler features;
- when you submit an inquiry or offer;
- when you purchase a business plan or visibility product;
- when you participate in an IzziGo programme;
- when you contact support;
- from your browser, device or application where technically necessary or permitted by your settings;
- from supported authentication providers;
- from payment and technical service providers;
- from another person where they legitimately provide information concerning you; or
- from publicly accessible professional or business sources where permitted.
4. Why we process personal data
We process personal data only where we have an appropriate purpose and legal basis under applicable law.
4.1 Contract and requested services
We may process personal data where necessary to provide a service you request, take steps requested before entering into a contract, or perform our contractual relationship.
This may include:
- account creation and operation;
- authentication;
- traveler dashboard functionality;
- saved places and trips;
- business listing management;
- business offers;
- traveler inquiries;
- paid business plans;
- visibility purchases;
- programme administration;
- support relating to requested services; and
- account export or deletion functionality.
4.2 Legitimate interests
Where permitted by applicable law, we may process personal data where necessary for legitimate interests pursued by Easy Business Ltd. or another party, provided those interests are not overridden by the rights and freedoms of the affected person.
Relevant interests may include:
- operating and improving IzziGo;
- maintaining platform and account security;
- preventing fraud and abuse;
- protecting platform integrity;
- moderating content;
- handling complaints and disputes;
- establishing, exercising or defending legal claims;
- measuring service performance;
- maintaining relevant business-directory information;
- using appropriate publicly available professional information;
- communicating with businesses concerning their IzziGo listing or professional relationship;
- limited business-to-business outreach where permitted by applicable law; and
- improving discovery, relevance and usability.
Where we rely on legitimate interests, you may have a right to object depending on the circumstances.
4.3 Consent
We use consent where it is the appropriate or legally required basis, including where applicable for:
- optional analytics or statistics technologies;
- optional marketing technologies;
- optional external-media technologies;
- promotional marketing where consent is required;
- certain location functions; and
- other optional processing for which we specifically ask permission.
You may withdraw consent at any time through the relevant settings or contact method.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
4.4 Legal obligations
We may process personal data where necessary to comply with legal obligations relating to matters such as:
- tax;
- accounting;
- payment records;
- data-protection requests;
- security incidents;
- lawful authority requests;
- regulatory requirements; and
- other applicable legal duties.
5. Information obtained from public or third-party sources
Some business-related personal data displayed or used by IzziGo may not have been collected directly from the individual concerned.
This can occur where publicly available professional information identifies a sole trader, guide, business owner, responsible person or business representative.
Such information may include:
- name;
- professional role;
- business name;
- public business email;
- public business telephone number;
- business website;
- professional social-media information;
- business address; and
- other publicly available professional information.
Sources may include official business websites, public professional profiles, tourism or institutional directories, public business directories and other legitimate publicly accessible sources.
We may use such information to create or maintain relevant business information, enable claiming or correction of a listing, contact a business about its IzziGo presence, or conduct limited professional outreach where permitted by applicable law.
Where applicable data-protection law requires us to provide information because personal data were obtained from another source, we provide the required information within the applicable timeframe.
You may contact us to ask about the source of personal data relating to you.
6. Traveler inquiries and businesses
IzziGo does not provide businesses with general access to traveler accounts or unrelated traveler personal data.
Where a traveler intentionally sends an inquiry to a selected business, we share the information reasonably necessary for that business to respond.
This may include:
- traveler name;
- email address;
- message;
- selected business or offer; and
- information relevant to delivery of the inquiry.
Once the selected business receives the inquiry, that business may have its own responsibilities concerning its subsequent use of the information.
Businesses must not use traveler inquiry information for unrelated unsolicited marketing without an appropriate legal basis.
7. Marketing communications
Promotional marketing is separate from essential service communications.
Where required by applicable law, we obtain consent before sending promotional marketing.
Where applicable law permits another legal basis for particular professional or existing-customer communications, we may rely on that basis subject to applicable safeguards and opt-out rights.
You may stop promotional marketing using:
- the unsubscribe link included in an applicable marketing email;
- available account communication preferences; or
- contacting us.
Opting out of marketing does not prevent communications that are necessary for your account, security, transactions, privacy requests, legal notices, moderation matters, programme administration or support.
8. Cookies and similar technologies
IzziGo uses cookies and similar technologies for different purposes.
These may include:
- necessary platform operation;
- security;
- preference storage;
- statistics and analytics;
- marketing;
- external media; and
- referral attribution.
Optional technologies are controlled according to your saved consent choices where consent is required.
Detailed information is available in our Cookie Policy.
You can review or change optional choices through our Cookie Settings.
9. Who may receive personal data
We do not sell personal data to advertisers.
Personal data may be disclosed to recipients where reasonably necessary for the purposes described in this Privacy Policy.
Recipient categories may include:
- hosting and infrastructure providers;
- email-delivery providers;
- push-notification providers;
- authentication providers;
- payment-service providers;
- mapping or location-service providers;
- analytics providers where enabled;
- marketing technology providers where permitted and enabled;
- security and anti-abuse providers;
- technical support providers;
- professional advisers such as lawyers and accountants where necessary;
- competent public authorities where legally required;
- businesses selected by travelers for an inquiry; and
- a successor or acquiring organisation in connection with a lawful corporate transaction, subject to applicable safeguards.
Where a provider processes personal data on our behalf, we seek to use providers offering appropriate data-protection and security commitments.
10. Authentication providers
If you use a supported third-party authentication method, such as Google or Apple sign-in, the authentication provider may provide IzziGo with information necessary to identify and authenticate your account.
This may include:
- provider account identifier;
- email address;
- name where made available; and
- authentication confirmation.
The authentication provider separately processes information under its own terms and privacy information.
11. Payment providers
Where a business purchases a paid IzziGo service, a payment provider may process information necessary to complete the transaction.
IzziGo may receive information such as:
- payment status;
- transaction reference;
- amount;
- currency;
- payer information where provided; and
- refund or payment-failure information.
Payment providers may act independently for some of their processing and may provide their own privacy information.
12. International processing and transfers
Easy Business Ltd. is established in Georgia. Personal data relating to IzziGo may therefore be processed in Georgia.
Our service providers may also process personal data in other countries depending on their infrastructure and the services used.
Where applicable data-protection law requires safeguards for an international transfer, we use an appropriate lawful transfer mechanism where required.
Depending on the circumstances, this may include:
- an applicable adequacy decision;
- approved contractual safeguards such as Standard Contractual Clauses;
- another legally recognised transfer mechanism; or
- a statutory derogation where its requirements are satisfied.
You may contact info@izzigo.eu for further information concerning safeguards relevant to your personal data.
13. How long we retain personal data
We retain personal data only for as long as reasonably necessary for the purpose for which it is processed, subject to applicable legal requirements.
Retention periods or criteria may depend on:
- how long an account remains active;
- the duration of a business relationship;
- the duration of a plan, order or programme;
- the need to provide a requested feature;
- tax or accounting requirements;
- security and fraud-prevention needs;
- applicable limitation periods;
- pending disputes or claims;
- data-protection accountability requirements; and
- whether information can instead be deleted or anonymised.
13.1 Account information
Core account information is generally retained while the account remains active.
After account deletion, limited information may remain for a period where necessary for legal, contractual, security, fraud-prevention or dispute purposes.
13.2 Business listing information
Public listing information may remain while the relevant listing is active.
Following removal, limited historical records may remain where reasonably necessary to document previous publication, contractual relationships, rights requests, disputes or compliance actions.
13.3 Orders and payments
Order, transaction, invoice and accounting information may be retained for periods required by applicable tax, accounting and legal obligations.
13.4 Legal acceptance records
Records showing acceptance of IzziGo Terms or Business Terms may be retained for as long as reasonably necessary to demonstrate the contractual relationship, maintain legal accountability and establish or defend legal claims.
13.5 Reports, decisions and appeals
Governance and moderation information may be retained for a period reasonably necessary for complaint handling, platform integrity, repeat-abuse prevention, legal accountability and the establishment or defence of legal claims.
13.6 Marketing preferences
Marketing preference and opt-out information may be retained as necessary to respect your choice and demonstrate that we have acted on it.
13.7 Referral attribution
Where permitted by the user's consent choice, the IzziGo referral attribution cookie currently uses a 30-day attribution period.
Programme records may be retained longer where reasonably necessary to administer credits or rewards, prevent abuse and maintain programme or accounting evidence.
14. Account deletion
Registered users can request account deletion using available IzziGo account controls.
Following deletion, information that is no longer necessary will normally be deleted or anonymised as appropriate.
Limited information may nevertheless remain where reasonably necessary for:
- legal obligations;
- accounting or transaction evidence;
- security;
- fraud prevention;
- contractual evidence;
- moderation or appeal evidence;
- the establishment, exercise or defence of legal claims; or
- respecting marketing suppression or opt-out choices.
Information retained for these purposes is not retained merely so that promotional marketing can continue after deletion or opt-out.
15. Your data-protection rights
Depending on the law applicable to you and the circumstances of the processing, you may have rights including:
- the right to receive information about processing;
- the right to access personal data concerning you;
- the right to correct inaccurate data;
- the right to request deletion;
- the right to request restriction of processing;
- the right to data portability where applicable;
- the right to object to certain processing;
- the right to withdraw consent where processing is based on consent;
- the right to object to direct marketing; and
- the right to lodge a complaint with a competent supervisory authority.
These rights may be subject to conditions, exceptions or restrictions provided by applicable law.
16. Accessing and exporting your data
Where available, registered users can use IzziGo privacy and account tools to obtain information associated with their account.
An account export may include information from multiple IzziGo systems, such as:
- account information;
- preferences;
- legal acceptance evidence;
- communications records;
- notification information;
- governance records; and
- other account-linked information supplied by participating IzziGo components.
Confidential security information, credentials, secrets or personal data belonging to another person may be excluded where necessary.
17. Right to object
Where we rely on legitimate interests, applicable law may give you the right to object to processing based on your particular situation.
We will consider an objection in accordance with the applicable legal requirements.
You may object to direct marketing at any time.
18. Withdrawing consent
Where processing is based on consent, you may withdraw that consent at any time.
Depending on the processing, consent may be managed through:
- Cookie Settings;
- account communication preferences;
- unsubscribe controls;
- browser or device permissions; or
- contacting us.
Withdrawal does not affect the lawfulness of processing performed before consent was withdrawn.
19. Privacy requests
To exercise a data-protection right or ask a privacy question, contact:
Easy Business Ltd.
Email: info@izzigo.eu
We may need to take reasonable steps to verify your identity before disclosing, deleting or changing personal data.
We will respond within the period required by applicable law.
20. Complaints
If you have a privacy concern, we encourage you to contact us first at info@izzigo.eu so that we can investigate the matter.
If the GDPR applies to your processing, you may have the right to lodge a complaint with a competent data-protection supervisory authority in the European Union or European Economic Area.
Under Georgian personal-data protection law, data subjects may also have the right to apply to the State Audit Office of Georgia, a competent court and/or another competent body in accordance with applicable law.
21. Automated processing, recommendations and profiling
IzziGo may use automated processing to support functions such as:
- search relevance;
- content ordering;
- recommendations;
- nearby-place discovery;
- fraud or security signals;
- spam prevention;
- platform analytics; and
- personalisation where applicable.
Based on the current IzziGo service model, we do not use solely automated processing to make traveler decisions intended to produce legal effects or similarly significant effects within the meaning of GDPR Article 22.
Technical signals may support business listing, offer, security or governance processes, but administrative or human review may also be used where appropriate.
Information about business ranking and visibility is available in our Ranking & Visibility Transparency document.
22. Children
IzziGo accounts are intended for persons aged 16 or older.
We do not knowingly permit persons under 16 to create an IzziGo account.
If we become aware that an account belonging to a person under the minimum age was created contrary to our rules, we may restrict or delete the account and associated personal data as appropriate, subject to lawful retention requirements.
23. Security
We use technical and organisational measures intended to protect personal data against unauthorised access, disclosure, loss, alteration, destruction and other unlawful processing.
Depending on the relevant system, measures may include:
- access controls;
- authentication controls;
- role-based permissions;
- protected communications;
- secure password handling;
- security monitoring;
- rate limiting;
- data minimisation;
- audit and integrity records;
- backup procedures; and
- recovery measures.
No internet-based service can guarantee absolute security. Users should also protect their credentials, email accounts and devices.
24. Personal-data incidents
We maintain procedures intended to identify, assess and respond to personal-data security incidents.
Where applicable law requires notification of a personal-data breach, we will notify the competent authority and/or affected individuals within the applicable legal timeframe.
25. Changes to this Privacy Policy
This Privacy Policy is maintained as a version-controlled legal document.
We may update it because of:
- changes to IzziGo services;
- new processing activities;
- changes to service providers;
- legal or regulatory developments;
- changes to retention or security practices; or
- clarification of existing information.
Where a change materially affects how personal data is processed, we may provide an appropriate notice through the website, application, account notification or email depending on the circumstances.
Continued use of IzziGo does not itself constitute consent to processing for which applicable law requires consent.
Where consent is necessary, it is requested separately.
26. Related privacy information and controls
This Privacy Policy should be read together with relevant IzziGo information and controls, including:
- Cookie Policy;
- Cookie Settings;
- Terms of Use;
- Business Terms & Listing Agreement;
- Platform & Content Rules; and
- privacy notices displayed within individual IzziGo features where appropriate.
27. Contact
For privacy questions, requests or concerns, contact:
Easy Business Ltd.
Identification Code: 400371842
Teimuraz Bochorishvili N3
Tbilisi, Georgia
Email: info@izzigo.eu
Website: izzigo.eu
