1Who we are

Zusti Solutions LLC, identification code 416396509, Tbilisi, Georgia. Questions: [email protected].

2Two different roles

ZUSTI handles two kinds of data, and the difference matters.

Your account data – name, email, phone, sign-in history. Here we are the controller: we need this data in order to provide the service.

The data in your books – your counterparties, employees, salaries, bank transactions, uploaded documents. Here we are only the processor: you are the controller. We process this data solely on your instruction, in order to run the service.

3What we store

Passwords are stored only as hashes. RS.GE and bank credentials are stored encrypted (AES-GCM) and are never returned to the interface.

4Who else processes it

We do not sell your data and we do not use it for advertising. We use these sub-processors:

Note: when you upload a document for AI recognition, the full content of that document is sent to Anthropic's servers in the United States. If that is not acceptable to you, do not use AI document recognition – the rest of the system works completely without it.

5How long we keep it

Your accounting records are kept for as long as your account exists. That is deliberate: Georgian law requires accounting documents to be retained, and read access continues even when a subscription lapses, so that your books stay reachable.

Backups are retained for up to 30 days. After you ask for deletion, data is removed from the live database immediately and disappears from backups as those backups expire on their normal schedule.

6Your rights

You may ask for a copy of your data, for it to be corrected or deleted, and you may object to the processing. Write to [email protected]; we answer within 30 calendar days. You may also complain to the Personal Data Protection Service.

If you are an employee of one of our customers and your data was entered into ZUSTI by your employer, please approach that employer directly: for this data they are the controller, not us.

7Security

Each company's data is isolated at the database level. Every change is written to an audit trail. Connections are encrypted. Nobody can promise perfect security and we will not pretend otherwise – but if we discover a breach, we notify the customers affected.

8Changes

We will tell you in the app about any material change to this policy before it takes effect.

9Language

This policy is available in Georgian and in English. Where the two differ, the Georgian text prevails.