Privacy policy

Last updated: 01.10.2026
Effective date: 01.10.2026

Table of Contents

Part I. General Provisions

  1. General Provisions
  2. The Data Controller and the Responsible Person
  3. Definitions: What Is Personal Data
  4. Principles of Processing

Part II. The Data We Process and How We Obtain It
5. What Data We Process
6. Data Provided Through Forms
7. Data Provided During Communication
8. Automatically Collected Data
9. Cookies and Similar Technologies
10. Special Categories of Data
11. Children's Data

Part III. Purposes, Legal Bases and Marketing
12. Purposes of Processing
13. Legal Bases
14. Consent
15. Commercial Communications and Marketing
16. Profiling and Automated Decisions
17. Processing for New Purposes

Part IV. Disclosure and Transfer of Data
18. Providers and Processors
19. International Transfers
20. Cooperation with Authorities
21. We Do Not Sell Personal Data
22. Links to Other Websites

Part V. Retention and Security of Data
23. Data Retention Period
24. Data After the End of the Relationship
25. Data Security
26. Access to Data
27. Personal Data Breaches
28. Authentication Data and Passwords

Part VI. Rights of Data Subjects
29. Rights of Data Subjects
30. How You Can Exercise a Right
31. Identity Verification
32. Handling of Requests
33. Manifestly Unfounded or Excessive Requests
34. Complaint to the Supervisory Authority
35. User Responsibility

Part VII. Data in Client Projects
36. Confidentiality of Project Information
37. Our Clients' Data and Our Legal Role
38. Data Processing in Shopify Projects
39. Data Protection by Design and by Default
40. Risk Assessment and Impact Assessment
41. Records of Processing

Part VIII. Final Provisions
42. Relationship with the Cookie Policy and the Terms and Conditions
43. Amendment of the Policy
44. Final Provisions
45. Contact Details


Part I. General Provisions

1. General Provisions

1.1. This Privacy and Personal Data Protection Policy ("Policy") explains how Radlux&Co. ("we", "the controller") collects, uses, stores, protects and, where applicable, transmits the personal data of persons who interact with us.

1.2. The Policy applies to the processing of data carried out in connection with:

  • the use of the Radlux&Co. website;
  • the completion of contact forms;
  • requesting a quote or a consultation;
  • communication by e-mail, telephone, WhatsApp, Viber, Telegram or other channels made available by us;
  • the conclusion and performance of contracts;
  • the provision of services, support and maintenance;
  • the management of the relationship with clients and potential clients;
  • commercial and marketing communications;
  • the handling of requests and notifications and the exercise of data subjects' rights.

1.3. We aim to process data in a lawful, fair, transparent manner that is proportionate to the purposes for which it is collected.

1.4. Processing is carried out in accordance with Law No. 195 of 25 July 2024 on the protection of personal data ("Law 195/2024"), applicable from 23 August 2026, as well as with other normative acts applicable in the Republic of Moldova, depending on the nature of the activity.

1.5. The Policy is to be read together with the Cookie Policy and the Terms and Conditions of the website.

2. The Data Controller and the Responsible Person

2.1. The Controller

Depending on the specific nature of the processing, data is processed by the controller indicated below.

Name Radlux&Co. – Ucraineț Radu, IDNP 2004042079073
Address Hristo Botev 25, Chișinău, MD-2043, Republic of Moldova
E-mail Radluxco@gmail.com
Telephone +373 67 545 918

2.2. The Person Responsible for Data Protection

For matters concerning data protection and confidentiality, the responsible person (Data Protection Officer, DPO) is Radu Ucraineț.

Within the limits of their duties, the responsible person handles:

  • questions regarding the processing of data;
  • requests regarding the exercise of data subjects' rights;
  • requests for erasure or rectification;
  • withdrawal of consent;
  • objection to certain processing;
  • requests regarding commercial communications;
  • data protection incidents;
  • communication with the competent authorities, where applicable.

Contact: Radluxco@gmail.com · +373 67 545 918

3. Definitions: What Is Personal Data

3.1. Personal data means any information relating to an identified or identifiable natural person.

3.2. Depending on the context, it may include: first name and surname; telephone; e-mail; home or delivery address; data about a company or professional activity; information communicated in a request; project information; contract data; data about communication with us; online identifiers; IP address; device and browser information; website usage data; cookie identifiers; any other information that allows the direct or indirect identification of a person.

3.3. Not all of these categories are necessarily collected. The data actually processed depends on the specific interaction with us.

4. Principles of Processing

We process data in accordance with the fundamental principles of Law 195/2024:

4.1. Lawfulness, fairness and transparency – processing has a legal basis and is clearly explained to you.
4.2. Purpose limitation – data is collected for specified and legitimate purposes and is not subsequently used in ways incompatible with them.
4.3. Data minimisation – we use only the data necessary for the purpose, without unnecessary collection.
4.4. Accuracy – we seek to ensure that data is correct and up to date, where the nature of the processing so requires.
4.5. Storage limitation – we do not keep data longer than is justified by the purpose, by legal obligations or by the need to defend rights.
4.6. Integrity and confidentiality – we apply appropriate technical and organisational security measures.
4.7. Accountability – we can demonstrate compliance with these principles.


Part II. The Data We Process and How We Obtain It

5. What Data We Process

Depending on the situation, we may process the following categories of data.

5.1. Identification data: first name; surname; company name; professional position or role, if communicated.

5.2. Contact data: telephone number; e-mail address; contact details from the communication applications used (WhatsApp, Viber, Telegram).

5.3. Project data. When you request a quote or a consultation: type of project; field of activity; indicative budget, if you communicate it; technical and commercial requirements; information about the online store; information about the platforms used; other information provided voluntarily.

5.4. Contractual data. Data necessary for: identifying the client; concluding and performing the contract; invoicing; payment; communication regarding the project; delivery of services; support and maintenance; resolution of possible disputes.

5.5. Technical data: IP address; device type; operating system; browser type; pages accessed; date and time of access; technical session information; online identifiers; information about technical errors. The technical data actually collected depends on the tools and services active on the website.

6. Data Provided Through Forms

6.1. When you complete a form, we process the data entered only to the extent necessary for the purpose of the form.

6.2. For example, a quote request form may ask for: name; telephone; preferred contact method; type of service; project information; other data necessary for preparing the quote.

6.3. Mandatory fields are limited to the information necessary for processing the request. Optional fields may be left blank.

7. Data Provided During Communication

7.1. When you contact us by telephone, e-mail, WhatsApp, Viber, Telegram or another channel, the data communicated during the conversation may be processed in order to:

  • respond to the request;
  • assess the project;
  • prepare a quote;
  • provide the services;
  • maintain the relationship with the client;
  • document relevant communications;
  • resolve a complaint;
  • protect the rights and legitimate interests of the parties.

7.2. Messaging applications are operated by third-party providers, which have their own privacy policies.

8. Automatically Collected Data

8.1. The website may use technologies that automatically collect certain data: IP address; browser, device and operating system data; pages accessed; session duration; traffic source; interactions with the website; technical identifiers.

8.2. Actual collection depends on the website configuration and the active tools. We do not state in this Policy the use of a tool that is not installed or active.

8.3. For cookies and similar technologies, the Cookie Policy applies separately.

9. Cookies and Similar Technologies

9.1. The website runs on the Shopify platform and may use cookies and similar technologies for: the technical functioning of the website; security; remembering certain preferences; analytics; performance measurement; marketing, if implemented.

9.2. Non-essential cookies (analytics, marketing) are used only with your consent, which you can manage through the preferences banner.

9.3. The details (types, purposes, duration, provider, category, necessity, management of preferences) can be found in the Cookie Policy.

10. Special Categories of Data

10.1. We do not ordinarily request special categories of data (for example, data about health, origin, religious or political beliefs, biometric data) for the mere use of the website or for our services.

10.2. Please do not submit through forms or messages sensitive information that is not necessary for the request.

10.3. If, in a particular situation, the processing of a special category of data becomes necessary, we will do so only with an appropriate legal basis and in compliance with the additional conditions provided by law.

11. Children's Data

11.1. Our website and services are not designed for the intentional collection of children's data.

11.2. Where special rules on children's data apply, we comply with them.

11.3. If a parent or legal representative considers that a child's data has been provided to us improperly, they may contact us for verification and, where applicable, erasure, under the conditions of the law.


Part III. Purposes, Legal Bases and Marketing

12. Purposes of Processing

Data may be processed for the following purposes:

12.1. Communication with users – responding to requests and questions.
12.2. Requesting and preparing quotes – analysing requirements and preparing the commercial proposal.
12.3. Provision of services – carrying out contracted projects and services.
12.4. Conclusion and performance of contracts – negotiating, concluding and performing contractual relationships.
12.5. Invoicing and accounting – fulfilling legal and tax obligations.
12.6. Support and maintenance – resolving problems and post-launch support.
12.7. Security – preventing and detecting unauthorised access, fraud, attacks, abuse and activities that affect the security of the website.
12.8. Improvement of services – analysing how services are used and identifying possibilities for improvement, within the limits of the law.
12.9. Commercial communications and marketing – under the conditions of section 15.
12.10. Legal obligations – complying with obligations imposed by applicable legislation.
12.11. Protection of rights – establishing, exercising or defending legitimate rights and interests.

13. Legal Bases

Depending on the circumstances, processing may have one or more of the legal bases below.

Legal basis When it applies Examples
13.1. Consent where the law requires or permits its use non-essential cookies, certain marketing communications
13.2. Performance of a contract processing is necessary for concluding or performing the contract performing the project, support, maintenance
13.3. Pre-contractual steps at the person's request, before concluding the contract requesting a personalised quote
13.4. Legal obligation processing is required by law invoicing, accounting, tax obligations
13.5. Legitimate interest there is a legitimate interest of ours or of a third party, not overridden by the person's rights website security, fraud prevention, defence of rights
13.6. Other legal bases where the law provides another basis –

14. Consent

14.1. Where processing is based on consent, you are free to decide whether to give it. Consent must be freely given, specific, informed and unambiguous; silence or pre-ticked boxes do not constitute consent.

14.2. Refusal of consent does not produce disproportionate effects on you.

14.3. Consent may be withdrawn at any time, as easily as it was given. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

15. Commercial Communications and Marketing

15.1. We use contact data for commercial communications only under the conditions permitted by law. These may include: information about services; offers; Shopify and e-commerce development services; information about new projects and solutions; educational or commercial content; relevant news; invitations to consultations.

15.2. Depending on the channel and the specific situation, communications may be based on your consent, on the existing contractual relationship or on another basis permitted by law.

15.3. We do not use data for marketing in a manner incompatible with the purpose for which it was collected.

15.4. You may request at any time, free of charge, the cessation of commercial communications, by e-mail to Radluxco@gmail.com or through the unsubscribe link in the message, if there is one.

15.5. Withdrawal from marketing is treated separately from processing necessary for the performance of a contract and does not prevent, for example, the carrying out of an ongoing project.

16. Profiling and Automated Decisions

16.1. We may use analytics or personalisation tools only under the conditions permitted by law.

16.2. If processing were to involve profiling or a decision based solely on automated processing, with legal effects or similarly significant effects on a person, we will respect the safeguards and rights provided by law.

16.3. In our current activity we do not make decisions of this type and we do not use automated processing to circumvent the rights of data subjects.

17. Processing for New Purposes

If we intend to use data for a new purpose that is incompatible with the original one, we assess the situation before the new processing. Depending on the circumstances, it may be necessary to: inform you; obtain your consent; identify another legal basis; apply other safeguards provided by law.


Part IV. Disclosure and Transfer of Data

18. Providers and Processors

18.1. In carrying out our activity, certain data may be processed by external providers, as applicable:

  • hosting and infrastructure providers;
  • Shopify (e-commerce platform);
  • e-mail services (for example, Google Gmail/Workspace);
  • communication services (WhatsApp, Viber, Telegram);
  • analytics and security services;
  • application providers;
  • accounting, legal and IT service providers;
  • other services necessary for the activity.

18.2. We limit providers' access to what is necessary for the service provided.

18.3. Where the law requires contractual safeguards or a data processing agreement, we apply them to the extent required.

18.4. The mentions in this section are examples of categories. We maintain internally the actual list of providers and update it when the technical infrastructure changes. You may request it at Radluxco@gmail.com.

19. International Transfers

19.1. Some providers may operate infrastructure or process data outside the Republic of Moldova.

19.2. We transfer data only in compliance with the requirements of the law on international transfers, using, as applicable, the legal mechanisms available for an adequate level of protection (for example, adequacy decisions or standard contractual clauses).

19.3. The mere use of an international provider does not represent a general authorisation for the unlimited transfer of data. You may request information about the safeguards applied.

20. Cooperation with Authorities

We may provide data to a public authority when this is required or permitted by law. Disclosure is limited to what is necessary to fulfil the legal obligation or request.

21. We Do Not Sell Personal Data

21.1. We do not trade or sell users' personal data to third parties.

21.2. Access by providers that perform services for us does not, in itself, represent a "sale" of data and takes place within the limits of the purpose for which the provider is engaged.

22. Links to Other Websites

The website may contain links to third-party websites or services whose privacy policies we do not control. When accessing an external website, we recommend that you consult the privacy and cookie policies of the respective operator.


Part V. Retention and Security of Data

23. Data Retention Period

23.1. We keep data only for the period necessary for the purpose of the processing, in compliance with legal obligations.

23.2. The duration depends on: the nature of the data; the purpose of the processing; the existence of a contractual relationship; tax and accounting obligations; other legal obligations; the need to prove certain operations; the existence of disputes; fraud prevention; the exercise or defence of rights.

23.3. Indicative periods:

Situation Period
Requests and quotes that did not lead to a contract [12 months] from the last communication
Contracts, invoices, financial and accounting documents the period required by tax and accounting legislation [to be confirmed with the accountant]
Marketing data until withdrawal of consent or objection
Technical data and cookies according to the duration set out in the Cookie Policy
Data necessary in a dispute until final resolution and the exhaustion of legal time limits

23.4. Upon expiry of the applicable period, data is erased, anonymised or archived, as applicable, in accordance with the law.

24. Data After the End of the Relationship

24.1. The end of the relationship with a client or the deletion of an account does not mean that all data can be erased immediately.

24.2. Some data must be kept for: legal obligations; accounting and taxation; records of contracts; defence of rights; resolution of disputes; fraud prevention; other legal obligations.

24.3. After the relevant period has expired, data is erased, anonymised or archived in accordance with the law.

25. Data Security

We apply technical and organisational measures appropriate to the risks associated with processing. Depending on the situation, these include:

  • access control and restriction;
  • authentication, strong passwords and security mechanisms;
  • protection of accounts and devices;
  • system updates;
  • backup copies;
  • access monitoring;
  • measures against unauthorised access, loss or destruction of data;
  • internal incident procedures.

26. Access to Data

26.1. Access to data is limited to persons who need it to perform their duties.

26.2. Where a person or an external provider does not need certain data, access to it is restricted. Persons with access are bound by confidentiality.

27. Personal Data Breaches

27.1. In the event of an incident that may constitute a personal data breach, we assess it and apply the measures provided by law. These may include: identifying the incident; limiting the effects; securing the systems; assessing the data affected; identifying the persons affected; documenting the incident; preventing recurrence.

27.2. Where the law so requires, we notify the National Center for Personal Data Protection (CNPDCP) without undue delay and, where feasible, no later than 72 hours after becoming aware of it. If the incident is likely to result in a high risk to the rights and freedoms of persons, we also inform them.

27.3. Relevant incidents are appropriately documented.

28. Authentication Data and Passwords

28.1. We do not ask you to submit passwords through ordinary contact forms.

28.2. In technical projects, where access to certain systems is necessary, we use methods that reduce the risk of exposing credentials (for example, delegated access via a collaborator invitation, instead of transmitting the password).

28.3. Passwords should not be transmitted through unsecured channels if an appropriate technical alternative exists.


Part VI. Rights of Data Subjects

29. Rights of Data Subjects

Under the conditions and within the limits of the law, you have the following rights:

29.1. Right to be informed – to receive clear information about how your data is processed.
29.2. Right of access – to find out whether we process your data and, where applicable, to receive a copy and the relevant information about the processing.
29.3. Right to rectification – to request the correction of inaccurate data or the completion of incomplete data.
29.4. Right to erasure – to request the erasure of data, under the conditions of the law. The right is not absolute: some data may be kept for legal reasons or for the defence of rights.
29.5. Right to restriction of processing – to request the limitation of the use of data, in the cases provided by law.
29.6. Right to object – to object to certain processing, under the conditions of the law. In the case of direct marketing, you may object at any time.
29.7. Right to data portability – to receive the data in a structured, commonly used and machine-readable format, or to have it transmitted to another controller, where the legal conditions are met.
29.8. Right to withdraw consent – at any time, where processing is based on consent.
29.9. Rights relating to automated decisions – not to be subject to a decision based solely on automated processing, including profiling, with legal effects or similarly significant effects, under the conditions of the law.

30. How You Can Exercise a Right

30.1. Send your request to:

E-mail: Radluxco@gmail.com
Telephone: +373 67 545 918

30.2. We recommend e-mail for written requests, so that the request can be identified exactly and its resolution documented.

30.3. The request must contain enough information to identify you and to understand the right being exercised.

31. Identity Verification

In order to protect data and prevent unauthorised access, we may request additional information to verify your identity where we have reasonable doubts. The request for additional information is proportionate to the risk and does not lead to unnecessary collection of data.

32. Handling of Requests

32.1. We examine requests without undue delay and, as a rule, within 30 days of receipt. Depending on the nature and complexity of the request, the period may be extended under the conditions permitted by law, with notice to you.

32.2. Requests are handled free of charge, except in the cases provided for in section 33.

32.3. If we cannot grant the request, we will communicate to you, as applicable, the reasons for the refusal and the possibility of challenging the decision or of lodging a complaint with the supervisory authority.

33. Manifestly Unfounded or Excessive Requests

In the case of manifestly unfounded or excessive requests, in particular because of their repetitive nature, we may apply the measures permitted by law (for example, a reasonable fee or a reasoned refusal). Any such measure is justified and proportionate.

34. Complaint to the Supervisory Authority

34.1. If you consider that the processing of your data infringes the law, you have the right to lodge a complaint with the competent authority:

National Center for Personal Data Protection (CNPDCP) of the Republic of Moldova – www.datepersonale.md

34.2. The right to lodge a complaint with the authority does not exclude the possibility of contacting us first to clarify the situation; however, contacting us is not a prerequisite.

34.3. Law 195/2024 establishes the mechanisms for supervision and for the resolution of complaints.

35. User Responsibility

You are responsible for the accuracy of the data you submit to us. Please:

  • do not submit data about other persons without the right to do so;
  • do not submit passwords through public forms;
  • do not submit sensitive data if it is not necessary;
  • use the official communication channels;
  • inform us when the data provided needs to be corrected.

Part VII. Data in Client Projects

36. Confidentiality of Project Information

36.1. Information provided by clients and potential clients within projects is treated as confidential, to the extent that its nature and the relationship between the parties so require.

36.2. We do not arbitrarily disclose information about clients' projects.

36.3. The use of a project as a portfolio example, case study or advertising material is done only in compliance with the conditions established with the client and the applicable rights.

37. Our Clients' Data and Our Legal Role

37.1. We distinguish between:

  • A. data of persons who use the Radlux&Co. website – in this case we act as controller;
  • B. data that a client transmits to us or makes available to us within a project, including the data of the beneficiary's end customers.

37.2. In situation B, depending on the nature of the project and the client's instructions, we may act as controller, as processor or, in particular situations, in another legal capacity determined by the circumstances.

37.3. Roles are not established solely by the designation in the contract, but by who determines the purposes and means of the processing.

37.4. When we act as processor, we process data in accordance with the controller's documented instructions, within the limits of the contract and the law. In this case, data subjects' requests regarding the data in the store must be addressed to the store owner (the controller).

38. Data Processing in Shopify Projects

38.1. In the development or administration of a Shopify store, several categories of data may exist: data about administrators; data about the store's customers; data about orders; contact data; delivery data; data about products; data about communications; other data entered into the platform.

38.2. Our legal role with regard to this data depends on the actual activity and on the contractual relationship with the store owner.

38.3. When we process data on behalf of the client, the applicable contracts and instructions reflect this relationship (including, where applicable, a data processing agreement).

39. Data Protection by Design and by Default

In developing online stores and e-commerce solutions, we seek, to the extent applicable, to integrate data protection requirements from the design phase, through:

  • minimal data collection;
  • limitation of access;
  • appropriate configuration of permissions;
  • avoidance of unnecessary collection;
  • protection of forms;
  • correct configuration of analytics tools;
  • control of installed applications;
  • securing of accounts;
  • respect for preferences regarding commercial communications.

40. Risk Assessment and Impact Assessment

40.1. For processing that may present high risks to the rights and freedoms of persons, we may carry out a risk assessment and may implement additional protection measures.

40.2. Where the law requires a data protection impact assessment, we carry it out under the conditions provided by law.

41. Records of Processing

41.1. We keep, as applicable and to the extent required by law, the documentation necessary to demonstrate compliance: records of processing activities; purposes; legal bases; categories of data and of data subjects; recipients; retention periods; security measures; providers and processors; international transfers; incidents; requests from data subjects.

41.2. These records are internal and are not published in full in the Policy. We make them available to the supervisory authority upon request.


Part VIII. Final Provisions

42. Relationship with the Cookie Policy and the Terms and Conditions

42.1. This Policy describes the general framework of data protection. The details about cookies (types, purpose, duration, provider, category, necessity, management of preferences) can be found in the Cookie Policy.

42.2. The use of the website is also governed by the Terms and Conditions of the website (rules regarding the use of the website, content, services, communication and other legal aspects). This Policy specifically regulates the protection and processing of personal data.

43. Amendment of the Policy

43.1. We may amend the Policy when there are changes in legislation, activity, the website, services, technological tools, providers, methods of collection, storage or processing, purposes, forms, marketing or analytics methods, international transfers or the relevant legal bases, or when clarifications are needed.

43.2. The version in force is published on the website, with the date of the last update.

43.3. For significant changes that substantially affect the manner of processing, we will additionally inform you where necessary.

44. Final Provisions

44.1. This Policy is the public document by which we inform data subjects about the main aspects of the processing of personal data, and it applies together with the legislation in force.

44.2. If legislation changes, mandatory legal rules prevail over any wording in the Policy that would become incompatible with them.

44.3. The Policy does not limit the rights of data subjects provided by law.

45. Contact Details

Radlux&Co.
Data Protection Officer (DPO): Radu Ucraineț
Telephone: +373 67 545 918
E-mail: Radluxco@gmail.com
Address: Hristo Botev 25, Chișinău, MD-2043, Republic of Moldova