Privacy Policy
I.Identity and contact details of the controller
This Privacy Policy describes how TAFI SOLUTIONS S.R.L. (limited liability company) collects, uses, stores and protects personal data in the service to which this document relates — the tafisolutions.com corporate website and the online booking portal made available to our clients. It is drawn up in accordance with Law No. 195/2024 on the Protection of Personal Data, published in the Official Gazette of the Republic of Moldova No. 367-369 of 23 August 2024, art. 574, in force since 23 August 2026, which transposes Regulation (EU) 2016/679 (GDPR) and replaced Law No. 133/2011.
- Personal data controller
- TAFI SOLUTIONS S.R.L. (limited liability company)
- IDNO
- 1025600051060
- Registered office
- 17 Ciocirliei str., office 7, Centru, MD-2021 Chisinau, Republic of Moldova
- Administrator
- FINCIUC ANDRIAN
- [email protected]
- Telephone
- +373 69 130 410
- Data protection contact
- [email protected]
All requests concerning the processing of personal data, including those exercising your rights under arts. 13–22, should be addressed to [email protected]. We will acknowledge receipt and reply within the statutory one-month period.
II.Scope
This Policy applies to every natural person whose data is processed in the service concerned — the tafisolutions.com corporate website and the online booking portal made available to our clients — whether you are a visitor, a client, a representative of a client company, or an authenticated user.
III.Categories of personal data processed
Data submitted through contact forms
- The name you provide in the form
- E-mail address and/or telephone number
- The name of the company you represent
- The content of your message and enquiry
- Date and time of submission
Identification and account data
- First and last name
- E-mail address
- Telephone number
- Position/role within the organisation
- Authentication data (username; password stored solely as an irreversible hash)
- Language and time-zone preferences
- External identity-provider account identifier (Google, Apple) where you choose that sign-in method
Client company data
- Company name and IDNO/tax identification code
- Registered office and place-of-business addresses
- Contact details of legal representatives
- Bank details (IBAN, bank name) required for invoicing
- VAT registration certificate, where applicable
Appointment data
- Name of the client making the booking
- Telephone number and e-mail address
- Service requested, specialist selected, appointment date and time
- History of bookings, cancellations and no-shows
- Notes and preferences recorded by the provider
- Reviews and ratings left after the service
Technical and log data
- IP address
- Browser type and version, operating system (user agent)
- Session date, time and duration
- Pages accessed and actions performed within the account
- Authentication logs (successful and failed), for security and evidential purposes
Marketing and commercial communications data
- E-mail address used to subscribe to commercial communications
- Communication preferences and consent history (date, time, mechanism of expression)
- Delivery and open statistics for messages sent
- Date and method of consent withdrawal
We do not deliberately collect special categories of data (racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health, sex life or sexual orientation) within the meaning of art. 9 of Law No. 195/2024, save where transport legislation requires verification of drivers' medical fitness, in which case we process only the "fit/unfit" conclusion and its validity date, not the diagnosis.
IV.Purposes of processing and legal basis
Every processing operation rests on at least one of the grounds set out in art. 6 of Law No. 195/2024 and complies with the principles in art. 5 — lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.
| Purpose of processing | Legal basis (Law No. 195/2024) | Retention period |
|---|---|---|
| Receiving and handling enquiries submitted through contact forms | Pre-contractual steps at the data subject's request — art. 6(1)(b); for general enquiries, the legitimate interest in answering correspondence — art. 6(1)(f) | 12 months from the last communication, where no contractual relationship follows |
| Creating and administering accounts, delivering contracted services, technical support | Performance of a contract or pre-contractual steps — art. 6(1)(b) of Law No. 195/2024 | For the duration of the contract and 3 years thereafter (general limitation period) |
| Booking, confirming and reminding of reserved services; managing cancellations | Performance of the contract with the data subject — art. 6(1)(b) of Law No. 195/2024 | 24 months from the last appointment, unless earlier erasure is requested |
| Fulfilling tax, accounting and archiving obligations | Legal obligation — art. 6(1)(c) of Law No. 195/2024 | Periods imposed by tax and accounting legislation, in principle 5 years (art. 43 of Accounting Law No. 287/2017) |
| Ensuring system security, preventing fraud and unauthorised access, logging actions | Legitimate interest — art. 6(1)(f) of Law No. 195/2024; security obligation — art. 32 | 12 months for access logs; 24 months for audit logs of sensitive operations |
| Sending commercial communications, newsletters and information about new services | Consent — art. 6(1)(a) and art. 7 of Law No. 195/2024, read with art. 8 of Law No. 284/2004 on electronic commerce | Until consent is withdrawn; proof of consent is kept for 3 years after withdrawal |
| Establishing, exercising or defending a legal claim and handling complaints | Legitimate interest — art. 6(1)(f) of Law No. 195/2024 | 3 years from the accrual of the cause of action, or until final resolution of the dispute |
Where we rely on legitimate interest, we first carry out a balancing test between our interest and your fundamental rights and freedoms. You may request a summary of that assessment at the contact address indicated.
V.Recipients of personal data
We do not sell or rent personal data. We disclose it only to the following categories of recipients, strictly within the limits of the purpose pursued:
| Recipient / category of recipients | Purpose of disclosure | Location |
|---|---|---|
| Furnizorii de găzduire și infrastructură cloud | Hosting of application servers and databases, backups | European Union (Germany, the Netherlands) |
| Furnizorul serviciului de poștă electronică tranzacțională | Delivery of confirmation, notification and password-reset e-mails | European Union / United States, under standard contractual clauses |
| Furnizorul widgetului de asistență prin chat | Handling support messages sent from the page | European Union |
| Contabilii, auditorii și consultanții juridici ai operatorului | Fulfilling accounting obligations and defending rights in court | Republic of Moldova |
| Autoritățile publice competente | Only upon the written and reasoned request of the authority, within the limits provided by law | Republic of Moldova |
Each processor acts under a processing agreement containing the mandatory clauses required by art. 28(3) of Law No. 195/2024, including obligations of confidentiality, security, and deletion or return of the data when the services end.
VI.International transfers of data
Data is hosted principally on servers located in the European Union. Where a transfer to a third country is necessary, it takes place only in compliance with Chapter V of Law No. 195/2024 (arts. 44–49), on one of the following grounds:
- an adequacy decision adopted under art. 45
- standard contractual clauses approved by the National Centre for Personal Data Protection, under art. 46
- binding corporate rules, under art. 47
- the derogations for specific situations set out in art. 49, including explicit consent given after prior information about the risks
You may request a copy of the safeguards applied to a particular transfer by writing to the contact address given in section I.
VII.Data retention
We keep data only for as long as necessary for the purpose for which it was collected, in accordance with the storage limitation principle in art. 5(1)(e). Specific periods are set out in the table in section IV. On expiry of the applicable period, data is permanently deleted or irreversibly anonymised so that it no longer permits your identification.
Backups are retained on cycles of at most 90 days; an erasure request is executed immediately in live systems, and removal from backups follows at the end of the current cycle.
VIII.Security measures
In accordance with art. 32 of Law No. 195/2024 we apply technical and organisational measures appropriate to the risk, taking into account the state of the art, the cost of implementation, and the nature, scope and purposes of the processing:
Technical measures
- Encryption of traffic in transit via TLS 1.2 or above, with mandatory redirection to HTTPS
- Encryption at rest of databases and backups
- Storage of passwords solely as hashes computed with brute-force-resistant functions
- Network segmentation, application firewall and request rate limiting
- Two-factor authentication available for administrative accounts
- Logging of access and sensitive operations, with logs held in separate systems
- Automated backups, periodically tested through restoration exercises
- Systematic patching of software components and vulnerability scanning
Organisational measures
- Access to data is granted strictly on a need-to-know basis, by role
- Employees and contractors sign confidentiality undertakings
- Periodic staff training on data protection
- Maintenance of records of processing activities under art. 30 of Law No. 195/2024
- A documented security incident response procedure
- Data protection impact assessments for processing likely to result in a high risk, under art. 35
- Periodic review of contracts with processors
IX.Personal data breaches
In the event of a personal data breach we proceed as follows:
- we notify the National Centre for Personal Data Protection (NCPDP) within 72 hours at the latest of becoming aware of the breach, under art. 33 of Law No. 195/2024, unless the breach is unlikely to result in a risk to your rights and freedoms
- we inform you without undue delay where the breach is likely to result in a high risk to your rights and freedoms, under art. 34
- we document every breach, its effects and the remedial action taken, so that the supervisory authority can verify compliance
X.Your rights
As a data subject, Law No. 195/2024 grants you the following rights:
| Right | Content |
|---|---|
| Right to be informed | To be informed, in a concise, transparent, intelligible and easily accessible form, about how your data is processed (art. 13 and art. 14) |
| Right of access | To obtain confirmation that your data is being processed, a copy of it, and information on purposes, categories, recipients and storage period (art. 15) |
| Right to rectification | To obtain the correction of inaccurate data and the completion of incomplete data, without undue delay (art. 16) |
| Right to erasure (‘right to be forgotten’) | To obtain erasure where the data is no longer necessary for the purpose, you have withdrawn consent, you have objected, or the data was processed unlawfully (art. 17) |
| Right to restriction of processing | To obtain restriction of processing, for example while the accuracy of the data or an objection is being verified (art. 18) |
| Right to notification | To have each recipient to whom the data was disclosed notified of any rectification, erasure or restriction carried out (art. 19) |
| Right to data portability | To receive the data you provided in a structured, commonly used and machine-readable format, and to transmit it to another controller (art. 20) |
| Right to object | To object at any time to processing based on legitimate interest and, unconditionally, to processing for direct marketing purposes (art. 21) |
| Rights regarding automated decisions | Not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you (art. 22) |
| Right to withdraw consent | To withdraw consent at any time, as easily as it was given, without affecting the lawfulness of processing carried out before the withdrawal (art. 7(3)) |
| Right to lodge a complaint | To lodge a complaint with the National Centre for Personal Data Protection and to bring proceedings before the competent court |
How to exercise your rights
Send a request to [email protected] or in writing to the address given in section I. We reply within one month at the latest of receiving the request. That period may be extended by up to two further months for complex or numerous requests, in which case we inform you within the first month of the extension and its reasons. Exercising your rights is free of charge; we may charge a reasonable fee or refuse to act only where a request is manifestly unfounded or excessive, in particular because of its repetitive character. Where we have reasonable doubts about the identity of the person making the request, we may ask for additional information strictly necessary to confirm it.
Complaint to the supervisory authority
If you consider that the processing infringes the law, you have the right to lodge a complaint with the National Centre for Personal Data Protection (NCPDP), 48 Serghei Lazo str., MD-2004, Chisinau, Republic of Moldova, tel. +373 22 820 801, e-mail [email protected], datepersonale.md, and to bring proceedings before the competent court. We would ask you, however, to contact us first — in most cases we can resolve the matter directly.
XI.Automated decisions and profiling
We do not take decisions based solely on automated processing which produce legal effects concerning you or similarly significantly affect you, within the meaning of art. 22 of Law No. 195/2024.
XII.Cookies and similar technologies
We use cookies and similar technologies, described in detail in our Cookie Policy. Cookies that are not strictly necessary are set only after obtaining your consent through the banner displayed on your first visit, and consent may be withdrawn at any time just as easily.
XIII.Children's data
Our services are not directed at minors and we do not knowingly collect data from persons under 16. In relation to information society services offered directly to a child, processing based on consent is lawful only where the child is at least 16; below that age, consent must be given or authorised by the holder of parental responsibility. If we learn that such data has been collected without a basis, we delete it without delay. If you are a parent or guardian and believe a minor has provided us with data, please contact us.
XIV.Changes to this Policy
We may update this Policy to reflect changes to our services, our practices or applicable law. The version in force is always the one published at this address, with the date of last update shown in the header. Material changes — for example a new purpose of processing or a new category of recipient — are communicated to you in advance, by e-mail or through a prominent notice in the service, at least 15 days before they take effect. Current version: 2026-08-26-r1.
XV.Applicable law
This Policy is governed by the law of the Republic of Moldova, in particular:
- Law No. 195/2024 on the protection of personal data
- Law No. 284/2004 on electronic commerce
- Law No. 105/2003 on consumer protection
- Law No. 982/2000 on access to information
- The Civil Code of the Republic of Moldova
- Decisions and recommendations of the National Centre for Personal Data Protection
Law No. 133/2011 on the protection of personal data was repealed upon the entry into force of Law No. 195/2024 on 23 August 2026; references to it in earlier documents are to be read as references to the corresponding provisions of Law No. 195/2024.