TERMS AND CONDITIONS

Last Updated: January 13, 2026
These Terms and Conditions of Payment (“Payment Terms”) govern all transactions made through payment gateway at https://stlegal.ge (the “Platform”). By initiating a payment, you (“the User”) agree to be bound by these terms.

1. LEGAL IDENTITY & CONTACT INFORMATION
The service provider is:
• Company Name: ST LEGAL LLC
• Registered Address: 32-34 Gogebashvili str., build. 2, apt. 21
• Identification Number: 204955726
• Email: [email protected]
• Phone: +995 595 11 6006

2. ACCEPTED PAYMENT METHODS
We offer the following secure payment options:
• Credit/Debit Cards: Visa, Mastercard.
• Digital Wallets: Apple Pay and Google Pay.
• Payment Gateway: All transactions are processed via flitt.com, an authorized Payment Service Provider (PSP) regulated by the National Bank of Georgia (NBG).

3. CURRENCY AND PRICING
• Transaction Currency: All prices are displayed and processed in GEL.
• Exchange Rates: If your account is in a different currency, the final amount will be determined by your issuing bank's exchange rate at the time of the transaction. We are not responsible for any foreign transaction fees or conversion spreads charged by your bank.
• Taxation: Prices include all applicable taxes unless otherwise stated during the checkout process.

4. SECURITY AND DATA PROTECTION
• PCI-DSS Compliance: We do not store your full card number or CVV code. All sensitive data is handled by our PCI-compliant gateway.
• Strong Customer Authentication (SCA): To comply with NBG regulations and PSD2 standards, you may be required to complete "3D Secure" verification (via your banking app or SMS OTP) to authorize the transaction.
• Biometrics: When using Apple Pay or Google Pay, you authorize the transaction using the biometric security (FaceID, TouchID) or passcode on your personal device.

5. RIGHT OF WITHDRAWAL (14-DAY REFUND POLICY)
Under the Georgian Law on the Protection of Consumer Rights (Article 13):
• 14-Day Window: You have the right to withdraw from a distance contract (online purchase) within 14 calendar days without providing a reason.
• Commencement: This period begins from the day the contract is concluded (for digital services) or the day you receive the physical product.
• Exceptions: This right does not apply to:
(a) Digital content already accessed or downloaded with your prior express consent.
(b) Services fully performed before the 14-day period expires.
• Refund Process: Upon a valid withdrawal, we will refund all payments received within 14 days using the same payment method used for the initial transaction.

6. ORDER CONFIRMATION
Upon successful payment, an automated confirmation will be sent to your registered email address immediately. This confirmation serves as your digital receipt and proof of transaction.

7. LIMITATION OF LIABILITY
We are not liable for:
• Technical failures of Apple Pay, Google Pay, or the Payment Gateway.
• Unauthorized use of your digital wallet due to your failure to secure your device.
• Refusal of a transaction by your issuing bank for any reason (e.g., insufficient funds, fraud blocks).

8. GOVERNING LAW AND DISPUTE RESOLUTION
• Governing Law: These terms are governed by and construed in accordance with the Laws of Georgia.
• Dispute Resolution: In the event of a dispute, the parties shall first attempt to reach an amicable settlement. If no agreement is reached, the dispute shall be submitted to the courts of Tbilisi, Georgia.
• Regulatory Body: You have the right to contact the National Competition Agency of Georgia for consumer rights violations.

CONFIDENTIALITY & DATA PROTECTION POLICY
1. SCOPE AND COMPLIANCE
This policy describes how ST LEGAL LLC (“the Company”) collects, uses, and protects your personal and financial data. We operate in full compliance with the Law of Georgia on Personal Data Protection and, where applicable, the General Data Protection Regulation (GDPR).

2. DATA WE COLLECT
To provide payment services and maintain your account, we collect:
• Identity Data: Full name, date of birth, and personal identification number (where required for KYC).
• Contact Data: Email address, phone number, and billing address.
• Financial Data: We process payments via flitt.com. While we see your card type and the last 4 digits, your full card details are encrypted and handled exclusively by the Payment Service Provider (PSP).
• Technical Data: IP address, device type and browser data used to access our platform.

3. PURPOSES OF PROCESSING
We process your data only under the following legal grounds:
• Contractual Necessity: To provide service to you.
• Legal Obligation: To comply with Anti-Money Laundering (AML) and "Know Your Customer" (KYC) regulations in Georgia.
• Legitimate Interest: To prevent fraud and ensure the security of our trading environment.
• Consent: For marketing communications (which you may withdraw at any time).

4. THIRD-PARTY DISCLOSURES
We only share data with third parties necessary to provide our services:
• Payment Processors: Apple Pay, Google Pay, and our banking partners in Georgia.
• Regulators: Only when legally compelled by the National Bank of Georgia or other authorized state bodies.

5. DATA SECURITY
We implement industry-standard technical and organizational measures:
• Encryption: All data transmitted between your device and our servers is protected by 256-bit SSL encryption.
• Access Control: Access to personal data is restricted to authorized employees on a "need-to-know" basis.
• Breach Notification: In the event of a data breach, we will notify the Personal Data Protection Service of Georgia and the affected users within the timeframes required by law.

6. YOUR RIGHTS
Under Georgian law, you have the following rights:
• Access & Portability: Request a copy of your data in a structured format.
• Rectification: Correct any inaccurate or incomplete information.
• Erasure ("Right to be Forgotten"): Request deletion of your data once the legal retention period (usually 5–6 years for financial records) has expired.
• Withdrawal of Consent: You can opt-out of all non-essential data processing at any time.

7. CONTACT OUR DATA PROTECTION OFFICER
For any questions regarding your privacy or to exercise your rights, please contact:
• DPO Name: Joseph Tugushi
• Email: [email protected]