Skip to content

Privacy policy

Last updated: 25 August 2026. This privacy policy explains how Giorgi Tkhinvaleli EF processes personal data under the EU GDPR and Swedish data-protection law.

1. Controller

The controller is Giorgi Tkhinvaleli EF, org. no. 9011079176, email george@gfg.life, phone 073-723 31 20. The practice is presented as George from Georgia (gfg.life).

2. Data we process

Depending on how you use our services, we may process: name, email, phone number, booking dates and selected treatments, home-visit address, payment status and booking reference, allergy or nail/skin information you choose to give us, technical website data (such as IP address, device and cookie identifiers), and messages you send us.

We do not store full card numbers. Card payments are handled by Stripe. Salon bookings are handled in BokaDirekt.

3. Purposes and legal bases

Booking, performing and confirming treatments and home visits: contract (GDPR Art. 6(1)(b)).

Payment, accounting, tax and other legal duties: legal obligation (Art. 6(1)(c)), including the Swedish Bookkeeping Act.

Customer service, incident handling, security and running the website: legitimate interests (Art. 6(1)(f)) in operating and protecting the business.

Non-essential cookies and similar technologies: consent (Art. 6(1)(a)). See our cookie policy.

We do not send newsletters or other direct marketing without your consent.

4. Health data

Allergies and similar information you provide are special-category data (Art. 9). We process them only to perform the treatment safely and with your explicit consent (Art. 9(2)(a)). You may withdraw consent at any time; this does not affect treatment already given. If you prefer not to share this information, we may need to decline certain treatments.

5. Recipients

Data may be shared with: BokaDirekt (salon booking), Stripe (payments), hosting and IT providers that run gfg.life, the cookie-banner provider (e.g. Complianz), and public authorities where the law requires it. Salon treatments take place at Nail Democracy, Drottninggatan 82; booking details may appear in the salon system. Providers may process data only under contract and applicable law.

6. Transfers outside the EU/EEA

Stripe and some IT providers may process data outside the EU/EEA. Where that happens, transfers rely on appropriate safeguards such as the European Commission Standard Contractual Clauses or another lawful mechanism.

7. Retention

Booking and contact data are kept for as long as needed for the contract and then up to 24 months for follow-up and complaints, unless a longer period is required by law. Accounting records are kept for seven years under the Bookkeeping Act. Payment data held by Stripe follows Stripe’s policy. Cookies are deleted according to the cookie policy. When the purpose ends, data are deleted or anonymised.

8. Your rights

You have the right of access, rectification, erasure, restriction, data portability, and to object to processing based on legitimate interests. Where we rely on consent, you may withdraw it at any time. You also have the right not to be subject to automated decisions with legal effects; we do not use such profiling. Contact george@gfg.life to exercise your rights. We may need to verify your identity.

9. Cookies

Necessary cookies are required for the site to work. Other cookies are used only after consent via the banner. Details are in the cookie policy.

10. Children

The website and services are not directed at children under 13. Bookings for minors should be made by a parent or guardian.

11. Complaints

If you are unhappy with how we process your data, you may lodge a complaint with the Swedish Authority for Privacy Protection (IMY), imy.se.

12. Terms and changes

Service terms are set out in our terms and conditions. We may update this policy. The current version is published on this page.