🌱 TL;DR — Key Takeaways
- SmartPay collects only the data necessary to provide payment services and comply with legal requirements.
- Your card data is tokenised and never stored in plain text on our servers.
- We never sell your personal data to third parties.
- You can exercise your data rights at any time by contacting support@eservicii.md
- We comply with the Republic of Moldova Law No. 133/2011 on Personal Data Protection and the EU General Data Protection Regulation (GDPR).
01Introduction & Controller
This Privacy Policy describes how "Intelectsoft" SRL ("SmartPay", "we", "us", or "our") collects, uses, stores, and protects your personal data when you use our payment services, website, and mobile applications.
By using SmartPay services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with its terms, please refrain from using our services.
| Company Name | „Intelectsoft" SRL |
| Headquarters | str. Alba Iulia 113, MD-2071, mun. Chișinău, Republica Moldova |
| IDNO | 1008600024770 |
| Phone | +373 22 83 53 12 |
| Email (Privacy) | support@eservicii.md |
02Definitions
For the purposes of this Privacy Policy, the following terms have the meanings set out below:
| Term | Meaning |
|---|---|
| Personal Data | Any information relating to an identified or identifiable natural person, such as name, email, phone number, or payment data. |
| Processing | Any operation performed on personal data, including collection, recording, storage, adaptation, retrieval, consultation, use, disclosure, or erasure. |
| Controller | The natural or legal person who determines the purposes and means of processing personal data. In this case, SmartPay. |
| Processor | A natural or legal person who processes personal data on behalf of the Controller. |
| User / Data Subject | The identified or identifiable natural person whose personal data is being processed. |
| Tokenization | The process of replacing sensitive card data with a unique, non-reversible token for secure storage and processing. |
03What Data We Collect
We collect different categories of personal data depending on how you interact with our services:
Account & Identification Data
When you create a SmartPay account, we collect:
- Email address / Phone number — Used for account login, communication, and sending verification codes.
- Full name — Used for identification and compliance with anti-money laundering (AML) regulations.
- Password — Stored in encrypted (hashed) form using BCrypt. We cannot retrieve your original password.
- Account identifiers — Internal unique IDs, account creation date, and session tokens.
Technical & Usage Data
When you use our website or app, we automatically collect:
- IP address and approximate geolocation
- Device type, operating system, browser version
- Application identifiers and crash reports
- Pages visited, features used, and time spent
- Cookies and similar tracking technologies (see Section 10)
Transaction Data
When you make a payment, we record:
- Date and time of the transaction
- Amount and currency
- Beneficiary name and identifier
- Transaction status (completed, pending, failed, reversed)
- Unique transaction reference number
Payment Card Data
When you link a card to your SmartPay account, the following is collected:
- Last 4 digits of the card number (for display purposes only)
- Card type (Visa, Mastercard, etc.)
- Card expiration date
- Cardholder name
- Tokenised card reference (the full card number is never stored on our servers)
Recurring Payment & Template Data
If you set up recurring payments or save payment templates, we store:
- Template name you assign
- Payment schedule (frequency, next execution date)
- Notification and reminder preferences
Data Shared with Third Parties
We may share your data with the following categories of recipients, strictly as necessary:
- Payment networks (Visa, Mastercard, etc.) — For transaction authorisation and settlement.
- Partner banks and financial institutions — For fund transfers and account verification.
- Service providers — Hosting, analytics, customer support, and identity verification services, bound by data processing agreements.
- Regulatory and law enforcement authorities — When required by law, court order, or to prevent fraud.
04How We Use Your Data
We process your personal data for the following purposes and on the following legal bases:
| Purpose | What It Means |
|---|---|
| Service provision | Processing payments, managing your account, and providing customer support. (Legal basis: contract performance) |
| Security & authentication | Verifying your identity, sending OTP codes, and preventing unauthorised access. (Legal basis: legitimate interest & contract performance) |
| Regulatory compliance | Anti-money laundering (AML), know-your-customer (KYC), and tax reporting obligations. (Legal basis: legal obligation) |
| Transaction notifications | Sending email and SMS confirmations for completed, pending, or failed transactions. (Legal basis: contract performance) |
| Analytics & improvement | Aggregated and anonymised analytics to improve our services, website performance, and user experience. (Legal basis: legitimate interest) |
| Fraud prevention | Monitoring transactions for suspicious activity and preventing payment fraud. (Legal basis: legitimate interest & legal obligation) |
| Communications | Sending service-related emails (receipts, security alerts) and, with your consent, marketing communications. (Legal basis: consent for marketing; legitimate interest for service communications) |
05Legal Bases for Processing
We rely on the following legal bases as defined by the GDPR and the Republic of Moldova Law No. 133/2011:
- Contract performance — Processing is necessary to fulfil the terms of service you have agreed to.
- Legal obligation — Processing is required by applicable laws (AML, tax, reporting).
- Legitimate interest — Processing is necessary for our legitimate business interests (security, analytics), provided those interests are not overridden by your rights.
- Consent — You have given explicit consent for a specific purpose (e.g., marketing emails). You may withdraw consent at any time.
06Your Rights
Under applicable data protection laws, you have the following rights regarding your personal data:
- Right of access — Request a copy of all personal data we hold about you.
- Right to rectification — Request correction of inaccurate or incomplete data.
- Right to erasure — Request deletion of your data where there is no overriding legal retention obligation.
- Right to restrict processing — Request that we limit how we use your data in certain circumstances.
- Right to data portability — Receive your data in a structured, machine-readable format.
We will respond to all data rights requests within 30 calendar days. If we need more time, we will notify you of the extension and the reason.
07Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes described in this policy:
Retention Periods
- Account data — Retained for the lifetime of your account plus 5 years after account closure (AML requirement).
- Transaction records — Retained for 5 years from the date of the transaction (tax and regulatory requirement).
- Technical logs — IP addresses and session data retained for 12 months for security monitoring.
- Marketing consent — Retained until you withdraw consent.
- Cookie data — See Section 10 for cookie-specific durations.
- Support tickets — Retained for 2 years after the last interaction for quality assurance.
After Retention
- Secure deletion from production databases
- Anonymisation so data can no longer be linked to you
- Archiving in encrypted form only where required by law
- Deletion of backups within 90 days of the main deletion
- Certificate of destruction issued upon request
Some data may be retained longer in encrypted backups for disaster recovery. Such data is inaccessible for normal operations and is purged according to the backup rotation schedule.
08Exercising Your Rights
You may exercise any of your data protection rights by contacting us using the details below. We will verify your identity before processing any request:
To exercise any of these rights, email us at support@eservicii.md. We will respond within 30 calendar days.
If you believe your data protection rights have been infringed, you have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANPDCP) in Romania, or the National Centre for Personal Data Protection (CNPDCP) in the Republic of Moldova.
09Data Retention Periods
The following table summarises how long we retain each category of data:
| Data Type | Retention Period |
|---|---|
| Account profile data | Account lifetime + 5 years |
| Transaction records | 5 years from transaction date |
| Payment card tokens | Until deleted by user or account closure + 30 days |
| Technical / log data | 12 months |
| Marketing consent records | Until withdrawal of consent |
| Support tickets | 2 years after last interaction |
| Cookie data | Up to 24 months (see Section 10) |
After the applicable retention period, data is securely deleted or anonymised so that it can no longer be associated with you.
10Cookies & Tracking Technologies
We use cookies and similar technologies to enhance your experience:
- Strictly necessary cookies — Required for authentication, security, and basic site functionality. Cannot be disabled.
- Analytics cookies — Help us understand how visitors interact with our website. Data is aggregated and anonymised.
- Preference cookies — Remember your settings (language, theme) to provide a personalised experience.
11International Data Transfers
Your data is primarily stored and processed within the European Economic Area (EEA) and the Republic of Moldova.
If data is transferred outside the EEA or Moldova, we ensure appropriate safeguards are in place, including:
- EU Standard Contractual Clauses (SCCs)
- Adequacy decisions by the European Commission
- Binding Corporate Rules approved by the relevant supervisory authority
12Data Security
We implement industry-standard technical and organisational measures to protect your data, including TLS/SSL encryption in transit, AES-256 encryption at rest, BCrypt password hashing, role-based access control, and regular penetration testing and security audits.
In the event of a personal data breach that poses a high risk to your rights, we will notify you without undue delay and, where required, inform the relevant supervisory authority within 72 hours.
13Children's Privacy
SmartPay services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children.
If we become aware that we have collected data from a minor without parental consent, we will take immediate steps to delete that information.
If you believe a minor has provided us with personal data, please contact us at support@eservicii.md.
14Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or through a prominent notice on our website at least 30 days before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.
Questions? Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data rights, reach out to us:
MD-2071, Chișinău
Republica Moldova