Last updated: 2026-08-15
Privacy Policy
Processing of personal data under Law No. 195/2024 of the Republic of Moldova
This Policy explains what personal data we collect on eternity.md, why, on what legal basis, and how you can control its use.
It is drafted in accordance with Law No. 195/2024 of the Republic of Moldova on the protection of personal data, which enters into force on 23 August 2026 and transposes the standards of Regulation (EU) 2016/679 (GDPR).
1. Who processes your data
The data controller is:
- Name: ETERNITY DEVELOPMENT SRL
- IDNO: 1021600036984
- Registered address: STR. NADEJDA RUSSO 14, AP.31, MUN. CHIȘINĂU, MD-2004, REPUBLICA MOLDOVA
- E-mail for data matters: [email protected]
2. What data we collect
We follow the minimisation principle and collect only what is necessary.
- Data you provide through the contact form: name, e-mail address, phone number, company name and the content of your message.
- Correspondence data, if you e-mail or call us.
- Technical data unavoidably processed by our providers when the site loads: IP address, browser and device type, date and time of access.
3. Whether you must provide the data
Providing the data is neither a statutory nor a contractual requirement. You share it voluntarily.
That said, your name and e-mail address are necessary for us to reply: without them the enquiry cannot be handled. Phone number and company name are optional — leaving them out has no consequence for you beyond our contacting you by e-mail only.
4. Purposes and legal bases
We process data only where one of the bases provided by law applies (art. 5–6 of Law No. 195/2024):
| Purpose | Data | Legal basis |
|---|---|---|
| Responding to your enquiry, preparing a proposal and negotiating a contract | Name, e-mail, phone, company, message | Pre-contractual steps taken at your request |
| Operating and securing the website, protecting the form from automated submissions | Technical data, server logs, Cloudflare Turnstile verification signals | Legitimate interest — keeping the site available and preventing abuse |
| Website usage analytics | Aggregated usage data | Your consent |
| Marketing and advertising performance measurement | Advertising service identifiers | Your consent |
| Retaining correspondence to defend legal interests | Correspondence, documents | Legitimate interest — establishing and defending legal claims |
5. Consent and its withdrawal
Where we rely on consent, it is freely given, specific, informed and unambiguous. We do not use pre-ticked boxes.
You may withdraw consent at any time, as easily as you gave it. Whenever optional tooling is active on the site, a “Cookie settings” link appears in the footer of every page; you can also always write to us. Withdrawal does not affect the lawfulness of processing carried out beforehand.
6. Who we share data with
We do not sell your data. We work with providers acting on our instructions as processors, under a data processing agreement:
| Recipient | Role | Country | Transfer basis |
|---|---|---|---|
| Telegram | Delivering your enquiry to us as a message | Outside the EEA | Your enquiry is passed to a service that offers no separate processing agreement |
| Resend | Fallback delivery by e-mail if Telegram is unavailable | EU | Processing agreement; transfers within the EEA need no additional safeguards |
| Google (Tag Manager, Analytics) | Traffic analytics and advertising measurement — only with your consent | USA | Standard contractual clauses / processing agreement |
| Cloudflare | Website hosting, access logs, protecting the form from automated submissions (Turnstile) | USA | Processing agreement, standard contractual clauses |
7. Transfers outside the Republic of Moldova
Some of our providers are located abroad. Transfers to European Economic Area states take place freely and require no special authorisation — this is expressly provided by law.
For the USA there is no decision of the National Center on an adequate level of protection. Transfers there therefore take place on the basis of standard contractual clauses approved by the National Center or adopted by the European Commission.
You have the right to obtain a copy of these safeguards: send a request to [email protected] and we will provide the relevant documents.
8. Retention periods
Data is deleted once the period expires. Where data is needed to defend a legal claim, it is kept until the claim is resolved.
| Category | Retention |
|---|---|
| Form enquiries — in the working Telegram chat and in e-mail | 24 months from the last contact |
| Record of your cookie decision | 12 months, then we ask again |
| Providers' technical logs | Per the providers' policies, as a rule up to 12 months |
9. Your rights
In relation to your data you have the right:
- to obtain confirmation of processing and a copy of your data (right of access);
- to request rectification of inaccurate or incomplete data;
- to request erasure where there is no basis for retention;
- to request restriction of processing;
- to receive your data in a structured, commonly used, machine-readable format and transmit it to another controller (portability);
- to object to processing based on legitimate interest;
- to withdraw consent previously given, at any time;
- not to be subject to a decision based solely on automated processing.
10. Right to object to direct marketing
We bring this to your attention separately, as the law requires: you have the right to object at any time to the processing of your data for direct marketing purposes.
This right is unconditional. If you object, we stop processing your data for those purposes immediately and without any conditions. A single message from you is enough.
11. How to exercise your rights
Send your request to [email protected]. We log every request and respond within one month of receipt.
Where a request is complex, or where several requests have been received, the period may be extended by at most two further months. We will tell you about the extension and its reasons within the first month.
Handling your request is free of charge. A fee may be charged only for manifestly unfounded or excessive requests, in particular repetitive ones — and the burden of demonstrating that character rests with us.
We may ask for additional information to confirm the request comes from you — solely to protect your own data.
12. Right to lodge a complaint and to go to court
If you believe your rights have been infringed, you may lodge a complaint with the National Center for Personal Data Protection (CNPDCP). Independently of that, you have the right to bring an action before the courts.
- Address: MD-2004, Chișinău, str. Serghei Lazo 48
- Phone: +373 22 820801
- Website: datepersonale.md
- E-mail: [email protected]
13. Automated decisions and profiling
We do not take decisions producing legal effects concerning you based solely on automated processing, and we do not carry out profiling.
14. Security
We apply technical and organisational measures proportionate to the risk: encrypted connections (HTTPS), need-to-know access limits, and processing agreements with all providers.
In the event of a personal data breach posing a risk to your rights, we notify the supervisory authority within 72 hours and, where the risk is high, inform you as well.
15. Changes to this Policy
For material changes we update the date at the top of the document and, where consent is affected, ask for it again.