EPETRECERE PRIVACY POLICY Version 1.2 Republic of Moldova Updated: 11 September 2026 This document forms part of the EPETRECERE Legal Pack and applies together with the other documents of the pack within the limits of its subject matter.
1. General Provisions
Controller: Societatea cu Răspundere Limitată “EPETRECERE” (EPETRECERE S.R.L.), IDNO 1026023123354, MD-3701, Strășeni, 64 Mihai Eminescu Street, office 6, Republic of Moldova. Privacy contact: privacy@epetrecere.md. This Policy applies to visitors, Clients, Partners, Venue representatives, guests and people appearing in photographs.
Processing is assessed under Law No. 133/2011 until 22 August 2026 and under Law No. 195/2024 from 23 August 2026. Regulation (EU) 2016/679 applies directly where its territorial scope so provides.
2. Principles
EPETRECERE pursues lawful, fair and transparent processing, for specified purposes, in an adequate volume, for limited periods and with appropriate security measures.
3. Categories of Data
Depending on the feature, we process account and contact data; role and preferences; Partner/Venue identity and KYC data including IDNO/IDNP, address, representative and evidence; event, offer, price, deposit, Booking, cancellation and complaint data; messages; guest lists, RSVP and voluntarily provided allergy data; photographs; reviews; IP, user-agent, session identifiers, anti-fraud signals, risk scores and moderation logs; and the name, drawn signature, time and document hash for legal acceptance.
4. Sources of Data
Data comes from the person, their representative, technical use of the service and, where necessary and lawful, public registers used to verify a supplier. Guest data, RSVP and some photographs may be received from the organizer or other participants rather than from the data subject.
For indirectly obtained data, notice is provided in the invitation or RSVP no later than the first communication and otherwise within a reasonable period not exceeding one month unless a statutory exception applies. The notice identifies source, categories, purposes, recipients and rights.
5. Purposes of Processing
Account and authentication — identity, contact, role, session and security data; basis: contract/pre-contract steps and legitimate security interest; recipients: Clerk, Supabase and Vercel; retention: account lifetime and the technical-log periods below.
Onboarding and contracting — identity/KYC, profile, authority, signature and acceptance evidence; basis: contract, legal duty and defence of rights; recipients: Supabase, Vercel Blob, Resend and authorized staff; retention: applicable statutory and limitation period.
Planning, Requests, Bookings and chat — event, offer, price, status, messages and attachments; basis: contract/pre-contract steps and legitimate interest for complaints/fraud; recipients: Booking parties, Supabase, Vercel and Resend; retention: up to 36 months after closure absent a dispute.
Guests, RSVP and allergies — name, contact, response, table, plus-one and voluntarily submitted allergies; basis: organizer-requested function and explicit consent for allergies; recipients: organizer, Supabase and Resend; retention: 90 days after the event.
Event Moments — photograph, optional caption, technical identifier and reports; basis: active confirmation of rights/consent and organizer contract; recipients: organizer and people with gallery access, Vercel Blob and Supabase; retention: 180 days.
Anti-fraud, security and moderation — pseudonymized IP, user-agent, account events, abuse signals, risk, complaints and decisions; basis: legitimate interest and security duties; recipients: Supabase, Clerk, Vercel and authorized staff; retention: 90 days for ordinary signals, separately for a justified incident/dispute.
AI — minimum prompt and context; basis: the user's request and legitimate interest in providing the feature; recipients: OpenAI or Anthropic; EPETRECERE does not persist public chat on its server and provider safety logs may be kept up to 30 days under contractual settings.
Analytics and marketing — identifiers and interactions only after consent to an optional category; recipients and retention are stated in the Cookie Policy; consent can be withdrawn.
6. Legal Bases
The basis for each purpose is identified above: contract/pre-contract steps, legal duty, assessed legitimate interest or consent. Legitimate interests in security, anti-fraud, complaints and defence of rights are subject to necessity and balancing assessments; the person may object.
Required data: an account needs name, verifiable contact and role; a supplier needs identity and requested verification evidence; a Booking needs date, service and information necessary for the offer. Refusal may prevent account creation, profile approval, an offer or Booking. Budget, allergies, photographs, marketing and fields marked optional are not required; refusal limits only the related feature.
7. Transmission Between Users
For the performance of the order, certain data may be transmitted between the Client and the relevant Partner or Venue. EPETRECERE may restrict direct contact data until the stage at which it is permitted. The recipient shall use the data only for the lawful purpose of the order, in the absence of another legal basis.
8. Recipients and Processors
Active processors at this version are Clerk for authentication; Supabase for PostgreSQL; Vercel and Vercel Blob for hosting/files; Resend for email; OpenAI and Anthropic for AI; and Google Maps for requested maps. Cloudflare may process technical network-security data where traffic passes through its services. R2, Upstash, Sentry and WhatsApp are not described as active processors unless actually enabled and this Policy is first updated.
Event suppliers receive only data needed for the relevant Request or Booking and never the complete named guest list. Consultants, auditors and authorities receive data only on a legal basis with limited access.
9. International Transfers
Supabase is configured in eu-central-1 (Frankfurt, Germany) and Vercel functions in fra1 (Frankfurt). Clerk, Vercel Blob, Resend, OpenAI, Anthropic, Google and Cloudflare may involve access or subprocessors in the EEA, United States and other countries listed in the provider's current contractual documentation.
A transfer outside Moldova occurs only under an adequacy decision or safeguards permitted by Law No. 195/2024, including appropriate contractual clauses, technical measures and minimization. The current countries, mechanism for each provider and a copy or description of safeguards may be requested at privacy@epetrecere.md.
10. Retention Periods
Guest lists, RSVP and allergies: 90 days after the event. Event Moments: 180 days. Non-contract contact enquiries: up to 24 months. Requests, Bookings and chat: up to 36 months after closure absent a dispute. Authenticated AI conversations: 30 days; public chat remains locally until reset. Read notifications: 12 months, maximum 24 months. Ordinary security signals: 90 days. Cookie choice: up to 12 months.
Account data is kept until deletion. Contract and financial evidence is kept for the statutory and limitation period, then securely destroyed. Deleted active data may remain in backups for the processor's contractual cycle, with a target maximum of 35 days, and is not restored to ordinary use.
11. Security
EPETRECERE applies reasonable organisational and technical measures, including access control, logging, backups, protection of accounts and monitoring of the infrastructure. Absolute security cannot be guaranteed.
12. Incidents
In the event of a security breach, EPETRECERE assesses the risk, limits the consequences and fulfils the obligations to notify the authority and the data subjects where the law so requires.
13. Rights of the Data Subject
Subject to law, a person has rights to information, access, correction, deletion, restriction, objection, portability, withdrawal of consent and challenge of a solely automated decision. Withdrawal does not affect prior lawful processing.
A complaint may be filed with the National Centre for Personal Data Protection (CNPDCP), https://datepersonale.md, centru@datepersonale.md, (022) 820 801, MD-2004, Chișinău, 48 Serghei Lazo Street.
14. Exercise of Rights
Requests may be sent to privacy@epetrecere.md or through account export/deletion tools. Identity is verified proportionately; we respond without undue delay, normally within one month, subject to a lawful explained extension. Searches cover active systems, files, email and relevant processors.
15. Automated Systems
Automation supports recommendations, ranking, anti-fraud and security, but AI does not determine price, contract acceptance or access through a solely automated decision with legal effect. A material restriction may be challenged at privacy@epetrecere.md; the person may request human intervention, state their position and receive a reasoned decision from authorized staff.
16. Commercial Communications
Marketing is sent only on an appropriate legal basis. The User may unsubscribe from optional messages. Operational notifications necessary for the account and for the order are not marketing.
17. Cookies and Mobile Technologies
The website may use cookies and similar technologies, and the applications may use SDKs, push tokens and local storage. The details are described in the Cookie Policy and in the application settings.
18. Minors
Commercial Accounts and contracts require legal capacity. Children's data may incidentally appear in a private-event list or photographs. The organizer must inform the parent/guardian and provide only necessary data; allergies require explicit consent. Uploading or publishing a minor's image requires confirmation from an authorized adult or another lawful basis, and a report hides the photo pending review. Images are not used for facial recognition, biometrics or model training.
19. Third-Party Services
Third-party services may act as independent operators. The User must consult their policies when using the relevant integration.
20. Amendment of the Policy
The Policy may be updated in the event of changes to the law, to the functions, to the providers or to the processes. Material changes are communicated in accordance with the law.
21. Supervision and Contact
Controller: EPETRECERE S.R.L., IDNO 1026023123354, MD-3701, Strășeni, 64 Mihai Eminescu Street, office 6; privacy@epetrecere.md. CNPDCP: https://datepersonale.md, centru@datepersonale.md, (022) 820 801, MD-2004, Chișinău, 48 Serghei Lazo Street. Version 1.2, updated 11 September 2026. Romanian prevails.
