Privacy Policy
Datero.md processes personal data in accordance with the legislation of the Republic of Moldova, including Law No. 195/2024 on personal data protection, aligned with Regulation (EU) 2016/679 (GDPR). This document explains what data we process, on what legal basis, how long we keep it, and what rights you have.
Last updated: August 23, 2026 (version 2026-08-23)
1. Data controller
The controller of personal data processed through the Datero.md platform is KERNEXIT S.R.L., IDNO 1026023040248, registered at MD-2008, Chișinău, Buiucani district, 20 Ștefan Neaga St., office 4 (hereinafter "Datero", "we"). For any questions regarding personal data processing or to exercise your rights, you can contact us using the details below.
Email: [email protected]
Phone: +373 68 508 886
2. Platform user data
If you use the platform or create an account, we process the following categories of data:
- Account data: email address and password (stored only as a hash) when creating an account, together with the date you accepted the Terms and the privacy-policy version you acknowledged
- Usage data: pages visited, searches performed, access timestamps
- Technical data: IP address, browser type, operating system
- Payment data: processed exclusively through secure third-party payment providers (we do not store card data)
- Contact-form data: name, email, subject, message, together with proof of consent (policy version, date and time, IP address) — kept for at most 12 months after the request is handled
Legal bases for processing user data: performance of the service contract (art. 6 (1) (b)), compliance with legal obligations ((c)), legitimate interest in platform security and abuse prevention ((f)), and your consent ((a)) — for analytics cookies and for messages sent through the contact form. Consent may be withdrawn at any time without affecting the lawfulness of prior processing.
3. Data about founders and administrators
The platform publishes information about natural persons who own or manage companies in the Republic of Moldova. This information constitutes personal data, which we process as a controller. Published categories:
- First and last names of founders and administrators
- Position held (administrator, founder) and ownership share
- Associated company (name, IDNO) and links between companies through common persons
- Historical records of changes in founders and administrators, as reflected in the state register
We do not publish: personal identification numbers (IDNP), home addresses, phone numbers, or personal email addresses of these persons.
Processing purposes: business environment transparency, verification of business partners (due diligence), credit risk assessment, fraud prevention, journalistic and research purposes.
The legal basis for this processing is legitimate interest (art. 6 (1) (f) of Law No. 195/2024). This data is public by operation of law: it originates from state registers intended to inform the public, primarily the State Register of Legal Entities maintained by the Public Services Agency under Law No. 220/2007.
4. Data sources
Datero.md aggregates information exclusively from official public sources:
- State Register of Legal Entities — dataset.gov.md (Public Services Agency)
- Public Repository of Financial Reports — National Bureau of Statistics
- Public Procurement System MTender — mtender.gov.md
- Other official public sources of the Republic of Moldova (National Bank, government open data portals)
Individually notifying each data subject (hundreds of thousands of founders and administrators) would involve disproportionate effort within the meaning of art. 14 (5) (b) of Law No. 195/2024. For this reason, information is provided by making this privacy policy publicly available.
5. Data retention and recipients
Account data is kept for as long as the account exists, plus periods required by legal obligations (e.g., accounting). Data from public registers is displayed for as long as it appears in the source registers; historical records (e.g., former administrators) are retained further, as company history is of legitimate public interest for business transparency.
Recipients of published data: platform visitors, users of the Datero API and AI agent tools. Data is hosted on servers located in the European Union. We do not sell personal data to third parties.
Processors and providers handling data on our behalf: OVH (hosting, France/EU), Cloudflare (CDN and attack protection), Resend (transactional email), Google — reCAPTCHA (bot protection, on the basis of legitimate interest in security) and Google Analytics 4 (only with your consent). Transfers to providers outside the Republic of Moldova and the EU rely on the appropriate safeguards provided by art. 46 of Law No. 195/2024 (standard contractual clauses).
6. Rights of data subjects
In accordance with Law No. 195/2024 on personal data protection, you have the following rights:
- Right of access — you can request a copy of your data that we process
- Right to rectification — you can request correction of inaccurate data
- Right to erasure — under the conditions of art. 17 of Law No. 195/2024
- Right to restriction of processing
- Right to data portability (for account data)
- Right to object — you may object to processing based on legitimate interest, on grounds relating to your particular situation
- The right to withdraw consent — at any time via "Cookie settings" (for cookies) or by email; withdrawal does not affect processing carried out before
Specifics for public register data: upon an erasure request or objection, we assess each case individually, balancing the grounds invoked against the public interest in business transparency (see also art. 17 (3) (a) — freedom of information). We correct display or processing errors on our side; corrections to the state register itself must be requested from the Public Services Agency — once the register is updated, the platform will automatically reflect the corrected data.
You also have the right to lodge a complaint with the National Center for Personal Data Protection (datepersonale.md) and the right to apply to a court.
7. How to submit a request
Send your request to the email address below, indicating: the right you wish to exercise, the data or pages concerned (e.g., a link to the company or person page), the grounds — in the case of an objection — and information allowing us to verify your identity (so we do not disclose data to someone else).
We respond free of charge, within one month of receiving the request. If the request is complex, the deadline may be extended in accordance with the law, with notice to you.
Email: [email protected]
Phone: +373 68 508 886
8. Cookies
We use cookies and similar technologies (localStorage) in two categories. Nothing in the "Analytics" category loads before you make a choice in the consent banner. Your choice is stored on your device for at most 12 months, together with the policy version it refers to, and can be changed at any time via "Cookie settings" (in the footer of every page or the button below).
- Strictly necessary — account sign-in, chosen language, watchlist, remembering your cookie choice and Google reCAPTCHA bot protection (cookie _GRECAPTCHA). Basis: providing the requested service and legitimate interest in security; no consent required.
- Analytics (consent only) — Google Analytics 4, loaded via Google Tag Manager: the _ga and _ga_* cookies (up to 2 years), aggregated statistics on pages visited, searches and usage events. Google Analytics 4 does not log or store the IP address. Provider: Google Ireland Ltd. / Google LLC.
Withdrawing consent deletes the analytics cookies from your device and stops Google Analytics from loading. You can also block cookies in your browser settings; disabling the strictly necessary ones may affect how the platform works.
9. Data security
We apply appropriate technical and organizational measures: connection encryption (TLS), encrypted password storage, system access control, monitoring and limiting abusive automated access. In the event of a data security breach likely to pose a risk to your rights, we will notify the supervisory authority and, where applicable, the affected persons, in accordance with art. 33 and 34 of Law No. 195/2024.
10. Legal framework
Data processing is carried out in accordance with the following legal framework:
- Law No. 195/2024 on personal data protection (in force since 23.08.2026)
- Law No. 284/2004 on electronic commerce (information on cookies and similar technologies)
- Law No. 148/2023 on access to information of public interest
- Law No. 220/2007 on state registration of legal entities and individual entrepreneurs
- Regulation (EU) 2016/679 (GDPR) — reference standard
11. Changes and contact
We may update this policy periodically; the current version and the date of the last update are published on this page. For any questions regarding this policy or the processing of your data, you can contact us:
Email: [email protected]
Phone: +373 68 508 886