We respect your right to privacy. This policy describes what data we collect, why we collect it, with whom we share it, and what your rights are.
1. Data Controller
The controller of the personal data collected through the platform proaici.com (hereinafter referred to as the "Platform") is:
Pro Aici
Chișinău, Republic of Moldova
Email: dpo@proaici.com (Data Protection Officer)
General email: contact@proaici.com
Our processing activities are governed by Law No. 133/2011 on the Protection of Personal Data of the Republic of Moldova and, where applicable, by Regulation (EU) 2016/679 (GDPR).
2. What Data We Collect
2.1 Data Provided Directly by You
- Account — name, email, password (encrypted), phone number. When we collect: upon registration.
- Profile — photograph, bio, social networks, gender, address. When we collect: when editing your profile.
- Business — information about the establishment (name, address, hours, menu, images). When we collect: when creating a listing.
- Payments — billing details, transaction history. When we collect: when subscribing to a paid plan.
- Communications — chat messages, reviews, correspondence with support. When we collect: when you interact on the Platform.
2.2 Data Collected Automatically
- Technical data: IP address, browser type, operating system, device identifier;
- Usage data: pages visited, session duration, listings opened;
- Approximate location: determined from your IP address or, with your consent, from GPS (for the map feature).
2.3 Data from Third Parties
If you sign in through Google or Apple (when this option becomes available), we receive your name, email, and avatar from those providers. We do not store the passwords of these accounts.
3. Purposes of Processing
We use your data for:
- Providing the service — authentication, reservations, chat with owners, displaying listings;
- Personalization — recommendations of establishments based on your history and location;
- Communication — notifications related to reservations, new messages, account updates;
- Payments and billing — processing subscriptions, issuing invoices, preventing fraud;
- Improvement and analytics — aggregated statistics, troubleshooting, performance optimization;
- Legal compliance — fulfilling tax obligations, responding to authorized requests.
4. Legal Basis for Processing
- Performance of a contract — creating the account, processing reservations, providing the subscription;
- Legitimate interest — fraud prevention, security, improving the service;
- Consent — marketing emails, non-essential cookies, geolocation;
- Legal obligation — accounting records, responding to requests from authorities.
You may withdraw your consent at any time — withdrawal does not affect the lawfulness of processing carried out previously.
5. Cookies and Similar Technologies
We use the following types of cookies:
- Essential — authentication (Sanctum), CSRF fraud prevention. These cannot be disabled.
- Preferences — language, city, preferred theme.
- Analytics — anonymous statistics about the use of the Platform (number of visitors, popular pages).
You can manage your cookie preferences from your browser settings or from the consent banner displayed on your first visit.
6. Data Sharing
We do not sell your data. We share it only in the following situations, with entities subject to strict confidentiality obligations:
- Establishment owners — your name, contact details, and the content of messages / reservations are visible to the owner of the listing you contact;
- Infrastructure providers — hosting, CDN, transactional email (under a processing agreement pursuant to Article 28 GDPR);
- Payment processors — for subscriptions (we do not store full card details — these remain with the processor, PCI-DSS certified);
- Public authorities — only on the basis of a legally justified request, in accordance with applicable procedures.
7. International Transfers
The main servers are located in the Republic of Moldova and/or the European Union. If we use providers outside the EEA (for example, certain analytics services), we ensure that the transfer is protected by:
- adequacy decisions of the European Commission;
- standard contractual clauses (SCC);
- or your explicit consent.
8. Data Retention Period
- Active account — for the duration of the account's existence;
- Account deleted at your request — immediately, with the exceptions below;
- Inactive account — automatically deleted after 24 months of inactivity;
- Invoices and accounting records — 5 years (legal obligation);
- Security logs — 12 months;
- Messages and reviews — for the duration of the account; reviews may remain anonymously on listings after deletion.
9. Your Rights
As a data subject, you have the following rights:
- Right to information and access — you may request a copy of the data we hold about you;
- Right to rectification — correcting inaccurate data directly from your profile page or by request;
- Right to erasure ("the right to be forgotten") — you may delete your account from the settings;
- Right to restriction of processing — for example, while the accuracy of the data is being verified;
- Right to portability — to receive your data in a structured, commonly used format (JSON);
- Right to object — in particular for processing based on legitimate interest;
- Right not to be subject to automated decisions — we do not make decisions that produce legal effects solely on the basis of algorithms;
- Right to lodge a complaint — with the National Center for Personal Data Protection of the Republic of Moldova (datepersonale.md) or, for EU residents, with the national supervisory authority.
To exercise any right, write to dpo@proaici.com. We will respond within a maximum of 30 calendar days.
10. Security Measures
We apply appropriate technical and organizational measures:
- TLS/HTTPS encryption for all connections;
- passwords stored with modern hashing algorithms (bcrypt);
- two-factor authentication (2FA) available for all accounts;
- database access limited to authorized personnel, with logging;
- daily backups, stored encrypted;
- periodic security testing.
11. Protection of Minors
The Platform is not intended for persons under 16 years of age. We do not knowingly collect data from minors. If you become aware that a minor has provided us with data without the consent of a parent or guardian, please notify us at dpo@proaici.com so that the data may be deleted.
12. Changes to the Policy
This policy may be updated. Substantial changes will be communicated by email (to registered users) or through a visible notice on the Platform, at least 15 days before they take effect.
13. Contact
Data Protection Officer:
Email: dpo@proaici.com
Postal address: Chișinău, Republic of Moldova
For other requests, you can write to us at contact@proaici.com.
See also: Terms and Conditions for the rules of using the Platform.