communities.md Privacy Policy
Version dated 22.09.2026. Effective from that date.
Controller and scope
The personal data controller for communities.md is WEB TEAM S.R.L. (IDNO 1022600023783), 44 A. Pushkin Street, Chișinău, Republic of Moldova. For questions about your data or to exercise your rights, write to inbox@webteam.email.
We process personal data in accordance with the Republic of Moldova's Law No. 195/2024 on personal data protection.
This policy describes how we process data about website visitors, account holders, people making submissions, subscribers and people whose information is published in the directory and news. On external websites, their operators' privacy policies govern data processing.
Website visits and necessary cookies
When you visit the website, we process your IP address, browser and device information, the date and time, the address of the page requested and the outcome of the request. These data are used to provide the website, secure sign-in, prevent spam and resolve errors. The legal basis is our legitimate interest in maintaining the security and availability of the service.
Necessary cookies enable account sign-in and protect forms. If you select “Remember me”, a separate cookie keeps you signed in for up to 30 days. You can delete or block cookies in your browser; blocking necessary cookies limits the operation of the corresponding website features.
Web analytics and consent management
We use Google Analytics 4, deployed through Google Tag Manager, to analyse website traffic and the use of pages and features, and to improve the service. Google Tag Manager manages the loading of analytics tags.
Analytics processes cookie and session identifiers, information about pages viewed and actions on the website, referral sources, browser, device, language and approximate location. Your IP address is also processed when your browser connects to Google's servers. We do not send names, email addresses, passwords, the contents of requests or forms, or personal access links to analytics. We do not use analytics data for personalised advertising.
The legal basis for processing web analytics data is your consent. Until you give consent, analytics cookies are not set and neither Google Analytics 4 nor the Google Tag Manager container is loaded. Declining analytics does not limit your ability to browse the directory, create an account, make submissions or subscribe to the digest.
You can change your choice or withdraw consent at any time through the website's cookie settings panel. After withdrawal, analytics is disabled in that browser. Withdrawal does not affect the lawfulness of processing carried out before it. To access or delete previously collected data, contact the controller using the contact address provided in this policy.
GA4 user-level and event-level data are retained for 2 months. New activity resets the retention period for user-level data; it does not extend the retention period for individual events. Google deletes data after the retention period expires as part of its monthly process. This setting does not apply to standard aggregated reports. The lifetimes of analytics cookies are shown in the table below.
Information about how Google services process data is available in the Google Privacy Policy.
Accounts
For registration and sign-in, we process your email address, password hash, email confirmation status and sign-in time. You can choose to add your name, profile description, image and links. We publish your sign-in email as a contact address only if you separately specify it for publication.
The processing of data necessary to create and maintain an account is based on the performance of a contract to provide the service features you request. An account cannot be created without the required data; the directory is available without registration. Email confirmation and account recovery messages are service messages and do not constitute a subscription to the digest.
Submissions, materials and complaints
When you add or amend a listing, claim the right to manage a community, propose a news item or submit a complaint, we process contact details, the content of the submission, your connection to the community, language, date and time, IP address and browser information. The editorial team reviews the materials and records its decision.
We review an organiser's submission on the basis of performing a contract to provide the requested features. To verify authority and handle complaints, we rely on our legitimate interest in maintaining an accurate directory and preventing abuse. A submission does not guarantee publication. Contact details provided for a reply, non-public contents of the request and internal editorial notes are not published in the community listing.
If a submission, material or complaint contains data about other people, share only what is needed for review and only if you are entitled to do so. The legal basis is our legitimate interest in checking the request, maintaining an accurate directory and protecting rights. We do not publish special categories of data from the non-public part of a request, such as information about other people's health or beliefs. We use them only to review the request where a ground under Article 9 of Law No. 195/2024 applies. We disclose the requester's identity and non-public information only as needed to review the request or comply with the law.
The editorial team reviews submissions and complaints. To prevent abuse, the website automatically limits how often requests can be sent. If an editor approves one of several competing claims to manage a community, the system rejects the other such claims. You can ask the controller to review the outcome.
Do not send passwords, personal access links or scans of identity documents. We do not request information about health, beliefs or other private circumstances for an ordinary account or submission.
Rights to submitted materials and how they may be used are set out in the Terms of Use.
Public information and its sources
Published listings and news are accessible to all visitors and search engines. They may contain descriptions, images, links, ways to join and public contact details. Amending or deleting our publication does not automatically delete independent copies made by others.
Materials come from organisers, people making submissions and public sources, including community websites and public pages. We use the community's name, description, ways to join and the contact details it has published for enquiries. We publish a representative's name and role only as needed to describe their public activity in the community, taking into account the source's context and the person's reasonable expectations. We do not publish personal contact details that are not intended for contacting the community. The legal basis is our legitimate interest in an accurate directory, taking into account these people's rights and interests.
We publish photographs of people with their consent to publication in the public directory, where the photograph is supplied by the person themselves or by an organiser who has confirmed that consent. We do not publish photographs of people taken from publicly available sources.
We publish information revealing health, political opinions or religious beliefs, ethnic origin, sexual orientation or other special categories of personal data only with the person's explicit consent to that publication or where the person themselves has manifestly made the information public, under Article 9(2)(a) or (e) of Law No. 195/2024.
You can find out the source of your data and object to publication: write to the controller or use the link to report a problem on the listing. If we did not obtain the data from you, we inform you about the processing through an available contact channel within one month of obtaining them. If we contact you or disclose the data earlier, we inform you no later than that first action. We do not send an individual notice in the cases covered by Article 14(5) of Law No. 195/2024.
Digest subscriptions
To send the digest, we process your email address, selected mailing lists, topics, communities and language. We retain records of subscription requests, confirmation, changes to preferences, unsubscription and delivery. Your IP address is also processed when you request and confirm a subscription.
The legal basis for sending the digest is your separate consent. Issues are sent after you confirm your email address. Registering an account or making a submission does not create a subscription. You can change your preferences or unsubscribe using the links in an email or by contacting the controller.
After you withdraw consent, we stop the corresponding mailing. Withdrawal does not affect the lawfulness of processing before it is received. Information necessary to demonstrate consent, its withdrawal and compliance with an instruction not to send further messages is retained only for those purposes.
We retain records of consent and its withdrawal to fulfil our duty to demonstrate that consent was given and that your choice was respected. We process data necessary to establish, exercise or defend claims in a specific dispute on the basis of our legitimate interest in protecting our rights.
Data recipients and international processing
The controller and authorised editorial staff can access requests and materials within their duties. We use hosting, email delivery and cloud storage services. Providers process the account, submission and technical data needed for these services and, for email delivery, the recipient's address and message contents. Google receives the analytics data described above. Public materials are accessible to visitors and search engines. We disclose data to competent authorities where required by law.
Data may be processed outside the Republic of Moldova. Google processes data on servers in various countries, including the United States.
When processing data outside the Republic of Moldova, we comply with Law No. 195/2024. Transfers to countries of the European Economic Area are made under Article 44(2), without special authorisation; the other data protection obligations remain applicable. When transferring data to other countries, including onward transfers from the EEA, we ensure data protection in accordance with Chapter V of that law. Information about recipients, countries of processing, the ground for a specific transfer and a copy of the applicable safeguards can be requested from the controller.
Retention periods
| Category | Retention period |
|---|---|
| Ordinary web server and application logs | 30 days from the event. |
| Unconfirmed subscription requests | 7 days from the most recent accepted request for confirmation. Records of a previously confirmed subscription are retained only where there is an independent legal basis. |
| Full contents of a finally rejected submission | 90 days from the final rejection, except for data necessary for an unresolved dispute. This period does not apply to published materials. |
| Closed account data | Deleted or anonymised within 30 days after closure, except for information retained on a separate basis. |
| History of decisions on submissions and requests | 12 months from the final decision on a submission or closure of a request, except for data relating to a specific unresolved dispute. |
| Correspondence and records of how requests were handled | 12 months after the request is closed, except for data relating to a specific unresolved dispute. |
| Minimum evidence of consent to the mailing and its withdrawal | For the duration of the mailing and for 3 years after it ends, except for data relating to a specific unresolved dispute. |
| Minimal records of acceptance of terms, licences and consent to publication | While the material is published and for 3 years after publication ends, except for records relating to a specific unresolved dispute. This period applies only to minimal records and does not extend retention of the full contents of a rejected submission. |
| Copy of data prepared at your request | Deleted after confirmed delivery to you, and no later than 7 days after the first working copy is created, including if delivery fails. |
| Residual backups | Until the relevant backup reaches the end of its retention period, and no more than 400 days after it is created. |
Account data and active subscription data are retained while the account or subscription remains active. Public information is retained while the basis for its publication remains valid.
Minimal records of an opt-out are retained while it remains in effect; a new subscription requires fresh consent. Email delivery information is retained until the delivery outcome is established and related errors or complaints have been resolved. Security incident materials are retained until the incident review is complete. Data relating to a specific dispute are retained until its final resolution and the resulting decision has been implemented. Once the relevant period expires, the data are deleted or anonymised.
Data deleted from the live system may remain in backups until those backups reach the end of their retention period. Access to backups is restricted; they are used only to restore the service.
Data protection and security breaches
Connections to the website are protected by HTTPS, passwords are stored as hashes, access to data is limited by staff responsibilities, and backups are maintained. The measures are reviewed in light of the risks of processing.
We notify the CNPDCP of personal data breaches that may pose a risk to people's rights and freedoms without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach; if notification is delayed, we give the reasons. Where a breach is likely to result in a high risk, we also inform the affected individuals without undue delay, subject to the exceptions in Article 34 of Law No. 195/2024.
Your rights and how to make a request
You have the right to request access to and a copy of your data, rectification, erasure, restriction of processing and, where provided for by law, data portability. You may object to processing based on legitimate interests and withdraw consent at any time where processing is based on consent.
Write to inbox@webteam.email, describe your request and include a public link if it concerns a publication. Where possible, use your account or subscription email. If we have reasonable doubts about the requester's identity, we ask only for information needed to confirm it. Do not include your password, personal access links or an identity document with your initial request.
We respond without undue delay, within one month of receiving your request. Where the law allows, the complexity and number of requests may require an extension of a further two months. We explain the extension and its reasons within the first month. If we cannot fulfil the request in full, we explain why and how to challenge the decision. We provide a copy of your data while respecting others' rights and without disclosing access credentials. We process requests and necessary records of how they are handled to fulfil our duty to protect your rights.
You can exercise your rights free of charge. A fee or refusal to act on a manifestly unfounded or excessive request is permitted only in the circumstances provided for by law, with reasons given.
You have the right to lodge a complaint with National Centre for Personal Data Protection of the Republic of Moldova — CNPDCP: 48 Serghei Lazo Street, Chișinău, MD-2004; telephone +373 22 820 801; email centru@datepersonale.md. You also have the right to take legal action. Contacting us does not limit these rights.
Changes to this policy
When our processing practices change, we update this policy and state the version date. We notify you of material changes through an available channel before they take effect. If new processing requires consent, we request it separately.
This policy is available in Romanian, Russian and English. If the language versions differ, the Romanian text prevails. You can report a translation error to the controller; it does not limit the rights granted by applicable law.