Public Authority Data Request Policy

Effective Date: September 20, 2026
Data Controller: Aquarea LLC, Identification No. 406514703
Country: Georgia

Aquarea LLC is committed to protecting the privacy and personal data of its customers. This Policy describes how Aquarea LLC handles requests from government authorities, law enforcement agencies, regulatory bodies, courts, and other public authorities seeking access to personal data or platform data processed by the Company.

1. Review of the Legality of Requests

Before disclosing any personal data, Aquarea LLC reviews the legality and validity of the request submitted by a public authority.

Where appropriate, the Company verifies:

  • the identity and authority of the requesting body;
  • the legal basis for the request;
  • whether the requesting authority has the relevant jurisdiction;
  • whether the request is sufficiently specific;
  • whether disclosure of the requested data is required under applicable law.

Aquarea LLC does not disclose personal data solely because a public authority has requested it. Data will only be disclosed where there is a valid legal basis or a legal obligation to do so.

2. Challenging Unlawful or Excessive Requests

To the extent permitted by law, Aquarea LLC may refuse, challenge, seek clarification of, or request modification of a public authority request if the request:

  • lacks a valid legal basis;
  • exceeds the legal authority of the requesting body;
  • is excessively broad or disproportionate;
  • seeks information unrelated to the stated legal purpose;
  • otherwise conflicts with applicable law.

Where appropriate, Aquarea LLC may seek legal advice before responding to such a request.

3. Data Minimization

If Aquarea LLC is legally required to disclose personal data, only the minimum amount of information necessary to satisfy the specific and legally valid request will be provided.

For this purpose, the Company seeks to:

  • disclose only the data specifically covered by the request;
  • exclude unrelated customer or business information;
  • limit the relevant time period where appropriate;
  • avoid disclosing additional information that is not legally required.

4. Documentation of Requests

Unless prohibited by law, Aquarea LLC maintains appropriate internal records of public authority requests for access to personal data and the Company’s responses to such requests.

Where appropriate, such records may include:

  • the name of the requesting authority;
  • the date the request was received;
  • the legal basis cited in the request;
  • the categories of information requested;
  • details of the review performed by Aquarea LLC;
  • any clarification, objection, or challenge relating to the request;
  • the information disclosed, if any;
  • the date and method of the response;
  • information regarding the personnel involved in reviewing and responding to the request.

Such records are protected against unauthorized access and retained in accordance with applicable legal, security, and operational requirements.

5. Confidentiality and Security

Access to public authority requests and related personal data is restricted to authorized Aquarea LLC personnel who require such access for legal, compliance, security, or operational purposes.

Aquarea LLC applies appropriate technical and organizational security measures to protect such information.

6. No Unrestricted or Bulk Access to Personal Data

Aquarea LLC does not voluntarily provide public authorities with unrestricted or bulk access to customers’ personal data.

7. Updates to This Policy

Aquarea LLC may update this Policy where necessary to reflect changes in applicable law, regulatory requirements, or internal data protection practices.

Contact Information

Aquarea LLC
Identification No.: 406514703
Tbilisi, Georgia
Website: www.aquarea.ge