Compliance
Last updated: July 1, 2026
1. Overview
Verify.ge is committed to operating in compliance with applicable Georgian and international regulations. This page summarizes our compliance posture for OTP messaging, data protection, and payment processing.
2. Georgian Data Protection Law
We comply with the Law of Georgia on Personal Data Protection. We act as a data processor for end-user phone numbers you submit for OTP delivery, and as a data controller for account and billing data. Customers are responsible for establishing a lawful basis for sending OTPs to their users. Privacy Policy.
3. GDPR
Where GDPR applies to you or your end users, we support data subject rights described in our Privacy Policy. Enterprise customers may request a Data Processing Agreement (DPA) by contacting [email protected]. See the detailed GDPR requirements checklist.
4. Payment Compliance
Card payments are processed by JSC Bank of Georgia (BOG), a licensed payment institution. Verify.ge is a BOG merchant and does not store cardholder data. PCI-DSS cardholder data environment requirements are met by BOG for card processing. We retain only token references and transaction records required for billing and tax compliance. Terms of Service · Security.
5. SMS and Telecommunications
OTP messages are sent through licensed telecommunications partners. Custom sender names (brands) require approval before use. Customers must not send unsolicited messages and must comply with anti-spam regulations and obtain recipient consent.
6. Account Verification
Accounts are verified via phone number. Business accounts may be subject to additional verification for high-volume or enterprise use. We reserve the right to request documentation to prevent fraud and abuse.
7. Data Processing Agreement
Enterprise customers can request a DPA covering OTP processing, data retention, sub-processors, and breach notification. Contact [email protected] for details.
[email protected]
8. Certifications
We follow industry best practices for security and data protection. Formal third-party certifications (such as SOC 2) may be pursued as the platform scales. Contact us for current audit status.
9. Regulatory Contacts
For data protection matters in Georgia, you may contact the Personal Data Protection Service of Georgia (personaldata.ge). For payment disputes, contact your card issuer or BOG through the channels provided during checkout. personaldata.ge.