Privacy Policy

Last updated: 3 August 2026

This Privacy Policy explains how Green Road Group LLC ("Green Road Group", "we", "us" or "our") collects, uses, shares and protects personal data when you visit greenroadgroup.com.ge (the "Site"), contact us through the Site, apply for a position with us, purchase one of our software products, or activate and use a licence for our CAD plugins (together, the "Services").

We have written this policy to be read and understood, not to be skimmed past. If anything in it is unclear, or if you want to know exactly what we hold about you, write to us at beka@greenroadgroup.com.ge and we will answer you personally.

1. Who we are and who is responsible for your data

Green Road Group LLC is the data controller for the personal data described in this policy. That means we decide why and how your personal data is processed.

  • Legal entity: Green Road Group LLC
  • Registered address: Building #1, Apartment #50, Gldani VII m/d, Tbilisi, Georgia
  • Company identification number: 406257553
  • Contact for all privacy matters: beka@greenroadgroup.com.ge

We are a small company. We have not appointed a Data Protection Officer, because we are not required to under Article 37 of the General Data Protection Regulation (GDPR) — we do not carry out large-scale systematic monitoring and we do not process special categories of data on a large scale. Privacy requests are handled directly by the founder at the address above.

2. Scope of this policy

This policy covers the Site, our contact and careers forms, our software products and their licence activation, and the email correspondence that follows from any of these. It does not cover third-party websites we link to, or the internal privacy practices of our business customers who may deploy our software inside their own organisations.

3. Summary of what we collect

In plain terms, and before the detail below:

  • If you browse the Site and do nothing else, we receive anonymised usage statistics through Google Analytics, and your browser makes requests to a small number of third-party services that deliver fonts, styling and video.
  • If you fill in the contact form, we receive your name, email address, subject and message as an email. Nothing is written to a database on our server.
  • If you apply for a job, we receive the details you type into the careers form as an email. We do not accept file uploads anywhere on the Site.
  • If you buy a licence, the purchase itself is handled by our payment provider, not by us. We receive your order and contact details from them.
  • If you activate a licence in one of our plugins, we receive your licence key, your email address and a technical identifier derived from your computer.

4. The personal data we collect

4.1 Information you give us directly

Contact form. When you use the contact form on the Site, we collect the name, email address, subject line and message you enter. The form also contains a hidden field that is invisible to human visitors and is used only to detect automated spam submissions; if that field is filled in, the submission is discarded and never reaches us.

Careers form. When you apply for a position, we collect the name, email address, telephone number, LinkedIn profile URL, the position applied for, years of experience, city, country and the covering letter you write. All of these fields except name and email are optional. The Site does not accept CV file uploads; if we wish to see a CV we will ask you for it by email.

Direct correspondence. If you email us, or reply to an email from us, we hold that correspondence and any personal data contained in it for as long as described in section 9.

Purchases. When you buy one of our products, you provide billing and contact details to our payment provider. Section 6 explains this relationship in full.

Licence activation. When you activate one of our plugins, the software transmits your licence key, the email address associated with the licence, and a machine identifier to our licence server. The machine identifier is a one-way cryptographic hash derived from characteristics of the computer. It cannot be reversed to reveal your hardware, and it does not tell us who you are, where you are, or what you use the computer for. Its only purpose is to enforce the number of installations permitted by your licence and to allow you to move a licence between machines.

4.2 Information collected automatically

Analytics. The Site uses Google Analytics 4 (measurement ID G-YJ24QKG5XY), provided by Google Ireland Limited. Google Analytics sets cookies in your browser and reports to us, in aggregate, how many people visit the Site, which pages they view, roughly which country or region they are in, which language they use, what type of device and browser they use, and how they arrived at the Site. IP addresses are truncated by Google before storage and we do not have access to full IP addresses through this tool. We use these reports to understand which of our products and articles are useful and to decide what to build next. We do not use Google Analytics to build advertising profiles, we have not enabled Google Signals or advertising features, and we do not link analytics data to any individual customer record.

Web server logs. Our hosting provider maintains standard server logs for the operation and security of the Site. These logs may contain your IP address, the time of your request, the page requested, your browser's user agent string and the referring page. These logs are generated and retained by the hosting provider under its own retention schedule and are used solely for troubleshooting, abuse prevention and security. We do not analyse them for marketing and we do not combine them with any other data about you.

Administrator access. The password-protected administration area of the Site is used only by Green Road Group staff. It records failed login attempts against the originating IP address in order to limit brute-force attacks. That record contains nothing except an IP address and the times of the failed attempts, it is not accessible from the public internet, and each entry is deleted automatically within twenty-four hours. No visitor to the public Site ever appears in this record.

4.3 Information we receive from third parties

Our payment provider passes us the information we need to fulfil an order and support you afterwards: your name, email address, billing country, the product purchased, the order reference and the transaction date. We describe this in section 6.

If you contact us through LinkedIn or another platform, we receive whatever that platform makes visible to us, in accordance with that platform's own privacy policy and your settings on it.

5. Cookies and similar technologies

A cookie is a small text file stored by your browser. Some technologies that are not technically cookies, such as browser local storage, work in a similar way. The Site uses the following:

  • Language preference (local storage, key "grg_lang"). Set by us, on your device only, to remember whether you are reading the Site in English or Georgian. It is never transmitted to our server and contains nothing but the two-letter language code. It is strictly necessary for the Site to work as you have asked it to.
  • Google Analytics cookies (_ga, _ga_YJ24QKG5XY). Set by Google Analytics to distinguish one visitor from another and to measure sessions. Typical lifetime is two years. These are analytics cookies and are not strictly necessary.
  • Administrator session cookie (PHPSESSID). Set only when a Green Road Group administrator logs into the management area. It is never set for ordinary visitors. It is a session cookie, marked HttpOnly and SameSite, and it is deleted when the browser closes.
  • Third-party cookies set by embedded content. Where a product page includes an embedded YouTube video, YouTube may set cookies on your device when the page loads. See section 12.

You can delete or block cookies through your browser settings at any time. Blocking analytics cookies will not affect your ability to use any part of the Site. Blocking all local storage may cause the Site to forget your language preference between visits.

Where the law of your country requires your consent before non-essential cookies are set, that consent is the legal basis on which we set them, and you may withdraw it at any time by clearing the cookies in your browser or by using your browser's tracking-protection settings.

6. Payments and the Merchant of Record

We sell our software through 2Checkout (Verifone), which acts as the Merchant of Record for every purchase. This is an important distinction and we want you to understand it.

When you buy a Green Road Group product, the contract of sale for the payment transaction is between you and 2Checkout, not between you and us. 2Checkout collects your payment details, processes the payment, calculates and remits any sales tax or VAT due in your country, issues the invoice and handles refunds and chargebacks. 2Checkout is the data controller for your payment card data.

We never see, receive or store your card number, expiry date, CVV or bank account details. They do not pass through our servers at any point.

What we do receive from 2Checkout, in order to deliver your licence and support you afterwards, is your name, your email address, your billing country, the product and quantity purchased, the order reference number and the date of the transaction. Where you buy as a business, we may also receive your company name and VAT identification number, which we require in order to issue correct documentation.

2Checkout's own privacy policy governs its handling of your data and is available on its website. We encourage you to read it.

7. How we use your data, and our legal basis for each use

Under Article 6 of the GDPR we must have a lawful basis for every use of your personal data. Ours are as follows.

  • To answer your enquiry. When you write to us through the contact form or by email, we use your details to reply and to keep a record of the exchange. Legal basis: our legitimate interest in responding to people who contact us, and, where your enquiry concerns a possible purchase, steps taken at your request prior to entering a contract.
  • To assess your job application. We use the details you submit through the careers form to evaluate your suitability, to contact you about the role and, if you agree, to keep your details on file for future openings. Legal basis: steps taken at your request prior to entering a contract, and our legitimate interest in recruiting staff.
  • To deliver the product you bought and to provide support. This includes issuing your licence key, sending it to you, answering support questions and providing updates. Legal basis: performance of our contract with you.
  • To operate the licence system. This includes activating, validating and deactivating licences and enforcing the installation limits of your licence. Legal basis: performance of our contract with you, and our legitimate interest in protecting our software from unlicensed use.
  • To send you service messages about a product you own. For example, notice of an important update, a compatibility issue with a new AutoCAD or Civil 3D release, or a security fix. Legal basis: our legitimate interest in keeping customers informed about the software they have paid for, and performance of our contract.
  • To send marketing emails. We send these only if you have asked to receive them. Every such message contains an unsubscribe link. Legal basis: your consent, which you may withdraw at any time.
  • To understand how the Site is used. Legal basis: your consent where required by the law of your country, otherwise our legitimate interest in improving our website and products.
  • To keep our accounting and tax records. Legal basis: compliance with a legal obligation to which we are subject under Georgian law and, where applicable, the tax law of your country.
  • To protect the Site and our customers from fraud and abuse. This includes rate-limiting login attempts and filtering spam. Legal basis: our legitimate interest in the security of our systems.
  • To establish, exercise or defend legal claims. Legal basis: our legitimate interest in defending ourselves, and compliance with a legal obligation.

Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms and concluded that our processing does not override them. You have the right to object to any processing based on legitimate interests, as described in section 11.

8. Who we share your data with

We do not sell your personal data. We have never sold it and we will not sell it. We do not share it with data brokers, advertising networks or list vendors.

We share personal data only with the following categories of recipient, and only to the extent necessary:

  • Our payment provider, 2Checkout (Verifone), as described in section 6.
  • Our hosting provider, Hostinger, which stores the Site and its data on servers under our instruction and acts as our processor.
  • Our email provider, which transmits and stores the correspondence between us.
  • Google Ireland Limited, for website analytics, as described in section 4.2.
  • Our accountant and, where required, the Revenue Service of Georgia, for the purpose of statutory accounting and tax reporting.
  • Professional advisers such as lawyers, where necessary to obtain advice or defend a claim.
  • Public authorities, where we are legally compelled to disclose data by a valid order. We will resist requests we consider unlawful or overbroad and, unless prohibited by law, we will tell you if your data is demanded.
  • A successor entity, if the business is sold, merged or reorganised. You would be told before your data became subject to a different privacy policy.

Where a recipient acts as our processor, we have a written agreement in place requiring it to process personal data only on our instructions, to keep it secure and to delete or return it at the end of the engagement.

9. How long we keep your data

We keep personal data only as long as we need it for the purpose for which it was collected, or as long as the law requires.

  • Contact form enquiries and general correspondence: up to 24 months after the last message in the exchange, then deleted, unless the correspondence relates to a purchase or a legal matter.
  • Job applications: 12 months from the date of application, so that we can consider you for later openings. If you ask us to delete your application sooner, we will do so.
  • Order and invoice records: 6 years from the end of the financial year in which the transaction took place, because accounting and tax law require it. This period cannot be shortened at your request.
  • Licence and activation records: for the lifetime of the licence plus 12 months, so that we can honour reinstallations, transfers and support requests after a reinstall.
  • Marketing consent records: for as long as you remain subscribed, plus 24 months after you unsubscribe, so that we can prove we honoured your withdrawal.
  • Failed administrator login records: deleted automatically within 24 hours.
  • Web server logs: retained by our hosting provider under its own schedule, typically no more than a few months.

When a retention period ends, data is deleted or irreversibly anonymised.

10. International transfers of data

Green Road Group LLC is established in Georgia. If you are located in the European Economic Area or the United Kingdom, your personal data will therefore be transferred outside that area when you deal with us.

Georgia is not currently the subject of an adequacy decision by the European Commission. Where we transfer personal data from the EEA or the UK to Georgia, or where our processors transfer it to other countries, that transfer is made on the basis of the European Commission's Standard Contractual Clauses, or another transfer mechanism permitted by Chapter V of the GDPR, together with the supplementary technical and organisational measures described in section 13.

Some of the processors named in section 8 store or process data in the United States or in other countries outside the EEA. Those transfers likewise rely on Standard Contractual Clauses or, where the recipient is certified, on the EU–US Data Privacy Framework.

You may request a copy of the relevant transfer safeguards by writing to us at the address in section 1.

11. Your rights

Subject to the conditions and exceptions in the applicable law, you have the following rights over your personal data. If you are in the EEA or the UK, these are your rights under Articles 15 to 22 of the GDPR. If you are in Georgia, the Law of Georgia on Personal Data Protection gives you equivalent rights. We extend the same rights to every person who contacts us, regardless of where they live, because we think that is the right way to run a business.

  • The right of access. You may ask us to confirm whether we hold personal data about you and to give you a copy of it, together with an explanation of what we do with it.
  • The right to rectification. You may ask us to correct personal data that is inaccurate, or to complete data that is incomplete.
  • The right to erasure. You may ask us to delete your personal data where it is no longer needed for the purpose we collected it, where you withdraw the consent on which we relied, or where you object and we have no overriding ground to continue. This right does not extend to records we are legally obliged to keep, such as invoices.
  • The right to restriction of processing. You may ask us to stop using your data, while continuing to store it, for example while we investigate a complaint that the data is inaccurate.
  • The right to data portability. Where we process your data by automated means on the basis of your consent or a contract, you may ask us to give you that data in a structured, commonly used, machine-readable format, or to send it directly to another controller where technically feasible.
  • The right to object. You may object at any time to processing based on our legitimate interests, on grounds relating to your particular situation. You may object to direct marketing at any time, for any reason or none, and we will stop immediately.
  • The right to withdraw consent. Where we rely on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of what we did before you withdrew it.

How to exercise your rights. Write to beka@greenroadgroup.com.ge. Tell us which right you wish to exercise and give us enough information to find your records — the email address you used with us, or your order number, is usually enough. We may need to verify your identity before we act, in order to protect you from someone else making a request in your name.

We will respond within one month. If your request is unusually complex, we may extend that by up to two further months, and we will tell you within the first month if we do. Exercising your rights is free of charge. We may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive, and we will explain our reasoning if that ever happens.

The right to complain. If you are unhappy with how we have handled your data, please tell us first — we would rather fix it than have you go elsewhere. You are nevertheless entitled to complain to a supervisory authority at any time. In Georgia, that is the Personal Data Protection Service of Georgia. In the EEA, it is the data protection authority of the country where you live, where you work, or where the alleged infringement took place. In the United Kingdom, it is the Information Commissioner's Office.

12. Third-party links and embedded content

Some pages of the Site embed video hosted by YouTube, a service operated by Google. When such a page loads, your browser connects directly to YouTube's servers, and YouTube may set cookies and receive your IP address, the address of the page you are viewing and information about your device — whether or not you press play, and whether or not you have a Google account. This processing is carried out by Google as an independent controller and is governed by Google's own privacy policy. If you do not wish this to happen, do not open product pages containing video, or use a browser configured to block third-party content.

The Site also loads its typefaces from Google Fonts and part of its styling framework from a public content delivery network. Both require your browser to make a request to a third-party server, which necessarily discloses your IP address to that server. Neither service is used by us to identify you, and we receive no personal data back from either.

The Site links to our LinkedIn company page. That is an ordinary link and nothing is loaded from LinkedIn unless you click it.

We are not responsible for the content or privacy practices of any website we link to. Please read their policies before providing them with personal data.

13. How we protect your data

We take security seriously and we apply measures proportionate to the risk:

  • The entire Site is served over encrypted HTTPS connections.
  • Payment card data never touches our infrastructure; it is handled entirely by our PCI-DSS-compliant payment provider.
  • The administration area is protected by a password stored only as a modern one-way cryptographic hash, and it is rate-limited against brute-force attacks.
  • Administrator sessions use cookies marked HttpOnly, Secure and SameSite, and the session identifier is regenerated on login.
  • Configuration files containing credentials are placed outside the reach of the public web server and are denied at both the web-server and application level.
  • Access to customer data is limited to those who need it to do their work.
  • Contact and careers submissions are delivered as email and are not written to any database on the Site.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and we will notify you directly without undue delay where the breach is likely to result in a high risk to you.

14. Children

Our Services are professional engineering tools intended for use by businesses and adult professionals. They are not directed at children, and we do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

15. Automated decision-making and profiling

We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, and we do not build behavioural profiles of visitors or customers. Licence activation involves an automated technical check of whether a licence key is valid and within its installation limit; this is a straightforward contractual check and not a decision about you as a person.

16. Personal data published on this Site

The Site displays the names, photographs and professional roles of members of the Green Road Group team, and may display the names of client organisations in project case studies. This information is published with the knowledge and agreement of the individuals concerned, on the basis of our legitimate interest in describing our business, and it can be removed on request.

17. Changes to this policy

We may update this policy from time to time, for example when we introduce a new product, change a supplier, or when the law changes. The date at the top of this page always shows when it was last revised. If we make a change that materially affects how we use data you have already given us, we will tell you by email before the change takes effect, where we hold an address for you. We encourage you to review this page occasionally.

18. How to contact us

For any question about this policy, about the data we hold, or to exercise any of the rights in section 11:

  • Email: beka@greenroadgroup.com.ge
  • Phone: +995 599 90 50 38
  • Post: Green Road Group LLC, Building #1, Apartment #50, Gldani VII m/d, Tbilisi, Georgia

We read every message and we answer personally.