Information

Privacy Policy

1. General provisions

This Privacy Policy (the “Policy”) describes how personal data of users of the sms.md platform is collected, stored, processed and protected by “ROCK SOFT” S.R.L (fiscal code 1021600014623, Chișinău, 8/1 Doctor Tudor Strișcă St., office 266; the “Operator”, “we”).

Personal data is processed in accordance with Law of the Republic of Moldova No. 133 of 08.07.2011 on personal data protection, the provisions of Law No. 195 of 25.07.2024 (transposing EU Regulation GDPR 2016/679, in force from 23 August 2026), and Law No. 72/2025 on electronic communications (in force from 01.01.2026, repealing Law No. 241-XVI/2007).

2. Personal data operator

  • Name: “ROCK SOFT” S.R.L
  • Director: Bodarev Valeri
  • Address: 8/1 Doctor Tudor Strișcă St., office 266, Chișinău, Republic of Moldova
  • Fiscal code (IDNO): 1021600014623
  • E-mail: [email protected]
  • Phone: +373 69 425 208

3. Roles of the Operator and the customer

The sms.md platform acts in two distinct roles:

  • Controller (data operator) — with respect to the personal data of the platform's own customers (individuals or representatives of legal entities registered on the platform): identification data, contact data, payment data.
  • Processor (authorised person) — with respect to SMS recipients' data (phone numbers and message content) provided by customer-controllers. The customer is responsible for the lawfulness of collecting and processing recipients' data, including obtaining consent for commercial campaigns.

Processing of SMS recipients' data in the role of processor is carried out solely on the documented instructions of the customer-controller under a data processing agreement (DPA), the current version of which is available to the customer in the dashboard, section “Documents”.

We do not use recipient databases received from customer-controllers for our own purposes — analytics, sales, database enrichment or third-party marketing — and we do not become a joint controller of that data.

4. Categories of personal data processed

Platform customers' data (as controller):

  • Identification data: first and last name, company name
  • Contact data: email address, phone number
  • Authentication data: email and password (hash)
  • Payment data: payment details and accounting documents
  • Technical data: IP address, browser type, activity logs

SMS recipients' data (as processor):

  • Phone numbers of message recipients
  • Content of the SMS messages submitted by the customer
  • Delivery reports (delivery status of each message)

5. Purposes and legal bases of processing

PurposeLegal basis
Provision of platform services (registration, authentication, SMS sending)Performance of a contract (Art. 6(1)(b) GDPR / Art. 5 of Law 133)
Invoicing and accountingLegal obligation (Art. 6(1)(c) GDPR)
Technical and operational communications (account notifications, reports)Legitimate interest (Art. 6(1)(f) GDPR)
Marketing communications (news, offers)Consent (Art. 6(1)(a) GDPR) — withdrawable at any time
Sending SMS on behalf of customersInstructions of the customer-controller (DPA)
Fraud prevention and platform securityLegitimate interest (Art. 6(1)(f) GDPR)

6. Data recipients

Personal data may be disclosed to:

  • Mobile operators (Moldcell S.A., Orange Moldova S.A., S.A. “Moldtelecom” under the Unite brand) — for the delivery of SMS messages
  • Payment service providers — for processing financial transactions
  • Cloud and infrastructure providers — for hosting the platform (under contracts with appropriate data protection safeguards)
  • Public authorities — where mandatory legal requirements apply

We do not sell or transfer your personal data to third parties for commercial purposes without your explicit consent.

The current named list of sub-processors (platform hosting, international SMS routing, email service) is available to customers in the dashboard, section “Documents”. Customers are notified of any change to the list at least 30 days in advance (email + banner in the dashboard), with the right to object.

7. Cross-border data transfers

Data may be processed on servers located in the Republic of Moldova and the European Union. Any transfer outside Moldova is carried out with the safeguards provided by Law No. 133/2011 (Art. 30–32) and, after August 2026, by Law No. 195/2024 — through standard contractual clauses or other appropriate mechanisms. Sub-processors' personnel may have technical access to data from countries outside the EU and the Republic of Moldova on the basis of standard contractual clauses (SCC) concluded by us with the respective sub-processor.

8. Data retention periods

  • Active account data: for the entire term of the contract
  • Inactive account data: 12 months from the last activity, then deleted or anonymised
  • SMS delivery logs: 6 months for operational and technical support purposes
  • Payment data: 5 years, as required by the tax legislation of the Republic of Moldova
  • SMS recipients' phone numbers: deleted upon completion of the campaign or at the customer-controller's request, but no later than 30 days after termination of the contract

9. Your rights

Under Law No. 195/2024 you have the following rights:

  • Right to information — to be informed about the data processed and the conditions of processing.
  • Right of access — to request a copy of the personal data we hold about you.
  • Right to rectification — to request correction of inaccurate or incomplete data.
  • Right to erasure — to request deletion of data where there is no lawful basis for continuing to store it.
  • Right to restriction of processing — to request temporary restriction of processing in the cases provided by law.
  • Right to data portability — to receive your data in a structured, machine-readable format.
  • Right to object — to object to the processing of your data, including to direct marketing — at any time and without giving reasons.
  • Right not to be subject to automated decisions — not to be subject to decisions based solely on automated processing.
  • Right to withdraw consent — at any time, without affecting the lawfulness of processing carried out before the withdrawal.
  • Right to lodge a complaint — with the National Centre for Personal Data Protection (CNPDCP) or with the courts.

To exercise your rights, contact us at [email protected]. We respond within 30 calendar days; where necessary, this period may be extended to 60 days, and we will inform you of the reasons for the extension. To protect your data from disclosure to third parties, we may request confirmation of the applicant's identity.

10. Data security

We apply appropriate technical and organisational measures to protect personal data: encryption of data in transit (TLS/HTTPS) and at rest, role-based access control, auditing of activity logs, periodic security testing. Access to personal data is limited to employees who need it to perform their duties.

11. Cookies

The sms.md website uses functional cookies necessary for the platform to work correctly (session, language settings) and analytics cookies to improve the service. By continuing to use the site after accepting the cookie notice, you agree to their use. You can disable cookies in your browser settings, which may affect the operation of certain site features.

12. Changes to the Policy

We reserve the right to amend this Policy. The current version is published on this page with the date of the update. We recommend checking this page periodically. Continued use of the platform after changes are published constitutes acceptance of them.

13. Contact details and supervisory authority

For any questions relating to the processing of personal data:

You have the right to lodge a complaint with the supervisory authority:

  • National Centre for Personal Data Protection (CNPDCP)
  • Address: 48 Serghei Lazo St., Chișinău, MD-2004
  • Phone: (022) 820 801 | E-mail: [email protected]
  • Website: datepersonale.md

Version of 19 August 2026.