Privacy Policy of the website www.inprint.md
Effective date: August 23, 2026
Last updated: October 04, 2026
1. General Provisions
This Privacy Policy (hereinafter referred to as the “Policy”) defines the procedure for processing and protecting the personal data of users of the website www.inprint.md (hereinafter referred to as the “Website”).
The personal data controller is S.C. “INPRINT-COM” S.R.L., registered in accordance with the legislation of the Republic of Moldova, legal address: MD-2044, CHIȘINĂU CIOCANA, mun. Chișinău, Alecu Russo, 59/3, ap.(of.) 4 (hereinafter referred to as the “Controller”, “we”).
Personal data processing is carried out in accordance with:
-
Law of the Republic of Moldova No. 195/2024 “On the Protection of Personal Data” (entered into force on August 23, 2026);
-
Law of the Republic of Moldova No. 133/2011 “On the Protection of Personal Data” (until August 23, 2026);
-
Other normative acts of the Republic of Moldova in the field of personal data protection.
This Policy applies to all personal data that the Controller receives from users of the Website or about users of the Website.
2. Basic Concepts
Personal data — any information relating to an identified or identifiable natural person (data subject).
Data subject — a natural person whose personal data is processed by the Controller (Website user).
Personal data processing — any action or set of actions performed with personal data, including collection, recording, systematization, accumulation, storage, updating, use, transfer, anonymization, blocking, deletion, destruction.
Controller — the person who determines the purposes and means of personal data processing.
3. Principles of Personal Data Processing
The Controller processes personal data based on the following principles:
-
Lawfulness and fairness — processing is carried out on lawful grounds and is fair in relation to the data subject.
-
Purpose limitation — data is collected for specific, explicit, and legitimate purposes and is not further processed in purposes incompatible with these purposes.
-
Data minimization — only the data necessary to achieve the declared purposes is processed.
-
Accuracy — data must be accurate and, where necessary, up to date.
-
Storage limitation — data is stored no longer than necessary for the purposes of processing.
-
Integrity and confidentiality — appropriate data security is ensured.
-
Accountability — the Controller is responsible for complying with the above principles and must be able to demonstrate this.
4. Categories of Personal Data Processed
The Controller may process the following categories of personal data of Website users:
-
Identification data: first name, last name.
-
Contact data: email address, phone number.
-
Delivery data: delivery address (when placing an order).
-
Payment data: payment information (processed by payment systems).
-
Technical data: IP address, browser type, device type, data on visited pages, access time.
Special categories of data (race, ethnic origin, political views, religious beliefs, health data, etc.) are not processed by the Controller.
5. Purposes and Legal Grounds for Processing
The Controller processes personal data for the following purposes:
| Purpose of processing | Legal ground |
|---|---|
| Processing orders and providing services | Performance of a contract |
| Communication with the user (responses to requests, notifications) | Performance of a contract / Consent |
| Sending marketing messages | Consent of the data subject |
| Improving the operation of the Website and analyzing statistics | Legitimate interest of the Controller |
| Compliance with legal requirements | Legal obligation |
The legitimate interest of the Controller consists in ensuring the operation of the Website, improving the quality of services, and preventing fraud. Processing on this ground is carried out with respect for the rights and freedoms of the data subject.
6. Rights of the Personal Data Subject
In accordance with Law No. 195/2024, the user has the following rights:
-
Right of access — to obtain confirmation of the processing of their data and a copy of the processed data.
-
Right to rectification — to request correction of inaccurate or incomplete data.
-
Right to erasure (“right to be forgotten”) — to request deletion of data where certain grounds exist.
-
Right to restriction of processing — to request restriction of data processing.
-
Right to data portability — to receive their data in a structured, commonly used format and to transfer it to another controller.
-
Right to object — to object to data processing based on legitimate interest or for marketing purposes.
-
Right not to be subject to an automated decision — including profiling that has legal consequences.
-
Right to be informed — to be informed about data processing at the time of collection.
-
Right to lodge a complaint — with the National Center for Personal Data Protection (CNPDCP).
To exercise their rights, the user may send a request to: office @ inprint.md or in writing to the address: str. Sarmizegetusa, 24/1, Chișinău, MD2032.
The Controller is obliged to review the request and provide information on the actions taken no later than one month from the date of receipt of the request. Where necessary, the term may be extended by two months, with notification to the data subject of the reasons for the extension.
Information is provided free of charge. However, in the case of manifestly unfounded or excessive requests, the Controller has the right to charge a reasonable fee or refuse to satisfy the request.
7. Transfer of Personal Data to Third Parties
The Controller may transfer personal data to the following categories of third parties:
-
Service providers: hosting providers, IT companies, delivery services.
-
Payment systems: for processing payments.
-
State bodies: upon lawful requests in accordance with legislation.
Third parties process data exclusively for the purposes determined by the Controller and on the basis of contracts ensuring the confidentiality and security of the data.
Transfer of data outside the Republic of Moldova is carried out only subject to ensuring an adequate level of personal data protection in the recipient country or in the presence of other guarantees provided by law.
8. Personal Data Storage Period
The Controller stores personal data no longer than necessary for the purposes of processing:
-
Data for order processing: for the period necessary to perform the contract and comply with accounting and tax legislation requirements (up to 5 years).
-
Marketing data: until withdrawal of consent by the data subject.
-
Technical data (logs): up to 12 months.
-
Data processed on the basis of consent: until withdrawal of consent.
Upon expiry of the storage period, the data shall be deleted or anonymized.
9. Personal Data Security
The Controller takes the necessary technical and organizational measures to protect personal data from unauthorized access, modification, disclosure, destruction, or other unlawful actions:
-
Encryption of data during transmission (HTTPS/SSL).
-
Restriction of access to personal data to authorized employees only.
-
Regular updating of security systems.
-
Training of employees on the rules for working with personal data.
-
Regular audit of data processing processes.
In the event of a personal data breach that may create a risk to the rights and freedoms of data subjects, the Controller will notify the National Center for Personal Data Protection within 72 hours from the moment of detecting the incident and, where necessary, the data subjects themselves.
10. Cookies
The Website uses cookies for:
-
Ensuring the operation of the Website.
-
Analyzing traffic and improving the operation of the Website.
-
Personalizing content.
The user can manage cookie settings in their browser. Disabling cookies may limit the functionality of the Website.
11. User Consent
By using the Website and providing their personal data, the user confirms that they have read this Policy and gives consent to the processing of their personal data in accordance with the described purposes and conditions.
Consent may be withdrawn at any time by sending a notification to: office @ inprint.md. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
12. Changes to the Privacy Policy
The Controller has the right to make changes to this Policy. The current version of the Policy is always available on the Website. In the event of significant changes, the Controller will notify users through the Website or by email.
13. Contact Information
For questions related to personal data processing, the user may contact:
-
Email: office @ inprint.md
-
Address: MD-2044, CHIȘINĂU CIOCANA, mun. Chișinău, Alecu Russo, 59/3, ap.(of.) 4
-
Phone: +373 22 86 50 50
National Center for Personal Data Protection of the Republic of Moldova (CNPDCP):
-
Address: MD-2004, Republica Moldova, mun. Chisinau, str. Serghei Lazo nr. 48
-
Website: www.datepersonale.md




