DRAFT FOR THE LAWYER, 20 September 2026
Personal data processing agreement
Version [1.0] of [DATE]
Annex No. 2 to Contract No. [...] of [...]
The Parties to Contract No. [...] of [...] (hereinafter the "Contract"), the Seller and the Company, as identified in the Contract, have agreed as follows.
Chapter 1. Subject matter and the roles of the Parties
Art. 1. Subject matter
1.1. This Agreement governs the processing of personal data that the Seller carries out for the Company in the performance of the Contract. The basis is Law No. 195 of 25.07.2024 on the protection of personal data, Monitorul Oficial No. 367-369 of 23 August 2024, art. 574, in force from 23 August 2026 (the "Law No. 195/2024").
1.2. This Agreement forms an integral part of the Contract.
1.3. Terms defined in the Contract have the same meaning in this Agreement. A reference to Annex No. N means an annex to the Contract, and a reference to Appendix No. N means an appendix to this Agreement.
Art. 2. The Company as controller
2.1. The Company is the controller of what it decides itself about its Company users. That is: who holds each Company card, the label the Company gives the person, the placing of money on a card and its taking back, the limits of the card, the switching on and off of Top-up by user, and the reports and statements per Company user that the Seller prepares for the Company.
2.2. The purposes and the means of this processing are determined by the Company. The stated purposes are the management of the Company's spending and the settlement with its Company users.
2.3. For the admission of a member of the Company staff to the Cabinet, and for the role given to that person, the controller is the Company.
2.4. The Company gives instructions, objects to a sub-processor, chooses, when the processing ends, whether the data is returned to it or erased, and audits the Seller, under Art. 7, Art. 10, Art. 14 and Art. 15.
Art. 3. The Seller as processor
3.1. For the data set out in Art. 2 the Seller is the Company's processor. It must process that data only for the Company and only within the limits of this Agreement.
3.2. The Seller must not process the data received from the Company for its own purposes, other than those set out in Art. 4, and must not disclose that data to another company.
3.3. Where the Seller itself determines the purposes and the means of a processing operation, it is the controller of that operation, whatever name the documents give it (art. 28 para. (9) of Law No. 195/2024).
3.4. The Seller declares that it provides sufficient guarantees to implement appropriate technical and organisational measures, within the meaning of art. 28 para. (1) of Law No. 195/2024. The measures are described in Appendix No. 1.
Art. 4. The Seller as independent controller
4.1. The User account, the ePay card and the Balance of the same person are processed by the Seller as controller. The Company does not see that data. Its processing follows the privacy policy (document 02).
4.2. The Seller is also the controller of its own sale: the operations made with any card, the Fiscal receipts, the accounting and tax records, the handling of complaints and the security of the system. The Company gives no instructions on that processing, and its basis is the contract, a legal duty and the Seller's legitimate interest.
4.3. The sign-in accounts of the Company staff, the cryptographic fingerprint of the password, their sessions and the log of actions in the Cabinet are processed by the Seller as controller, for the running and the security of its own service, under point 9.5 of Annex No. 3 "Terms of use of the Company Cabinet". Suspension of access for security, and the sending of the invitation to the first Owner, are the Seller's own acts, taken without an instruction of the Company.
4.4. Out of the processing set out in point 4.2 the Seller passes to the Company, as an independent controller, the data the Company needs to manage the Company cards. What that data covers is set out in Art. 22 and Art. 23.
4.5. The Parties do not jointly determine the purposes and the means of any processing and are not joint controllers within the meaning of art. 26 of Law No. 195/2024. Each Party is liable for the processing for which it is named as controller.
4.6. No clause of the Contract and of this Agreement restricts the rights that Law No. 195/2024 gives a Company user, either against the Seller or against the Company.
Chapter 2. Description of the processing
Art. 5. The elements of the processing
5.1. The processing that the Seller carries out for the Company has the following elements:
| Element | Content |
|---|---|
| Subject matter | making the Cabinet and the Company cards available to the Company, keeping the record of the cards, the labels, the limits and the distribution of money, and drawing up the reports and statements per Company user |
| Duration | as set out in Art. 6 |
| Nature | collection, recording, storage, organisation, consultation, transmission to the Company and erasure of the data, by automated means |
| Purpose | the Company's management of the spending made with the Company cards and the settlement with its Company users |
| Categories of data | the name, the surname and the telephone number that the Company enters under Art. 10 of the Contract; the label given by the Company; the kind of card, its status and its limits; the placings and takings back made by the Company; Top-ups by user; the operation data carried in the reports and statements drawn up for the Company, that is the date, the time, the Site, the service, the amount, the Company discount, the Hold and the Refund; the risk flag that concerns the Company's cards, without the evidence behind it; the name, the surname, the e-mail address and the role of the Company staff whom the Company admits to the Cabinet |
| Categories of data subjects | Company users; Company staff |
| Special categories of data | not processed |
5.2. The Seller must not ask the Company for data of the special categories set out in art. 9 of Law No. 195/2024, or for data on criminal convictions. The confirmation of a payment by face or by fingerprint is carried out by the device of the Company user; the Seller receives the result of the check alone, and no biometric data.
5.3. The Cabinet, the statements and the receipts display the telephone number masked. The Company knows the number it entered itself, and the processing of that number in the Company's own records is not the subject of this Agreement.
Art. 6. Duration of the processing
6.1. The processing for the Company lasts as long as the Contract, and runs on for the [90] (ninety) days during which the Cabinet stays open for consultation after the Contract ends, under Art. 42 of the Contract.
6.2. The Seller must not extend that period on its own initiative.
Chapter 3. Duties of the Seller as processor
Art. 7. Documented instructions
7.1. The Seller must process the data only on the documented instructions of the Company. Those instructions are the Contract and this Agreement, the settings the Company staff make in the Cabinet, and the calls the Company makes through the programming interface, where it has been switched on. An instruction given in another way is confirmed in writing.
7.2. Point 7.1 applies to the transfers of data outside the Republic of Moldova set out in Art. 16 as well.
7.3. The data is processed without an instruction of the Company only where a normative act of the Republic of Moldova requires the Seller to do so. In that case the Seller must inform the Company of the legal duty before the processing, unless the normative act forbids such information on important grounds of public interest.
7.4. Where, in the Seller's view, an instruction of the Company breaches the personal data protection law, the Seller must inform the Company at once. The performance of that instruction may be suspended until the Company answers.
Art. 8. Confidentiality of the authorised persons
8.1. Access to the Company's data must be granted by name, and only to the persons who need it for the performance of the Contract.
8.2. Those persons are bound by a duty of confidentiality under their individual employment contract, their job description or a separate undertaking. The duty stays after their relationship with the Seller ends.
Art. 9. Security measures
9.1. The Seller must apply the technical and organisational measures required by art. 32 of Law No. 195/2024. The measures in force at the date of signature, with the state of each, are described in Appendix No. 1.
9.2. A measure may be replaced with another one that is at least as strong. The agreed level of security must not be lowered.
9.3. At the written request of the Company, once a year, the Seller must provide an updated description of the measures set out in Appendix No. 1.
Art. 10. Sub-processors
10.1. The Company gives a general authorisation for the use of other processors (the "sub-processors"), under art. 28 para. (2) of Law No. 195/2024. The sub-processors existing at the date of signature are listed in Appendix No. 2. The recipients that receive data as independent controllers are named separately, at the end of that appendix.
10.2. The Seller must announce the addition or the replacement of a sub-processor in the Cabinet and at the Company's e-mail address given in Annex No. 1 to the Contract, at least [30] (thirty) days before that sub-processor starts processing. The announcement states the name, the service, the data transmitted and the country.
10.3. The Company may object, with reasons, within [15] (fifteen) days of the announcement. The Parties look for a solution in the next [15] (fifteen) days. If they find none, the Company may declare the termination of the Contract under Art. 39 of the Contract, without penalty and without the notice period set out in that article, and the final settlement is made under Art. 42 of the Contract.
10.4. On each sub-processor the Seller must impose, by contract, the same data protection duties that it takes on under this Agreement. For the acts of its sub-processors the Seller is liable to the Company as for its own.
Art. 11. Help with the rights of data subjects
11.1. The Seller must help the Company answer requests about the rights set out in chapter III of Law No. 195/2024, among them access, rectification, erasure, restriction of processing, portability, objection, the notification of recipients under art. 19 and the right under art. 22. The help is given through the functions of the Cabinet and, where those are not enough, on a written request, within [10] (ten) working days.
11.2. Where a request about the processing carried out for the Company reaches the Seller, the Seller must not answer on the merits. It must pass the request to the Company within [3] (three) working days and tell the person that the request has been passed on.
11.3. Where the request also concerns a processing operation for which the Seller is the controller, the Seller must answer that part itself, within the period the law sets, and must tell the person which part went to the Company, with the Company's contact details.
11.4. Requests that concern the User account, the ePay card and the Balance alone are settled by the Seller.
Art. 12. Help with security and with the impact assessment
12.1. The Seller must help the Company meet the duties set out in art. 32 to art. 36 of Law No. 195/2024, taking into account the nature of the processing and the information available to it. The help covers the security of processing, the notification of personal data breaches, the communication to data subjects, the data protection impact assessment and the prior consultation of the National Centre for Personal Data Protection (the "Centre").
12.2. For an impact assessment the Seller must provide the Company, on a written request, with the description of the processing, the measures set out in Appendix No. 1 and the list of sub-processors. The period is [15] (fifteen) working days from the request.
Art. 13. Notification of personal data breaches
13.1. The Seller must notify the Company without undue delay and at the latest within [48] (forty-eight) hours from the moment it becomes aware of a breach of security affecting the data processed for the Company.
13.2. Time runs from the moment an employee of the Seller becomes aware of the breach.
13.3. The notification describes the nature of the breach and the categories and approximate number of data subjects and records affected. It states the likely consequences of the breach, the measures taken or proposed to remedy it, and the name of the person from whom the Company can obtain further information. Information that cannot be given at once is completed as it is obtained, without undue delay.
13.4. The Company notifies the breach to the Centre within the period set out in art. 33 of Law No. 195/2024 and, where the law requires it, informs the data subjects under art. 34 of the same law. The Seller makes those notifications on behalf of the Company only at the Company's written request.
Art. 14. Information and audit
14.1. The Seller must make available to the Company the information needed to demonstrate compliance with the duties set out in art. 28 of Law No. 195/2024 and in this Agreement.
14.2. An audit starts on documents and through a questionnaire, which the Seller must answer within [30] (thirty) days of receipt.
14.3. If the answer is not sufficient, the Company may request an on-site audit, once a year, on [30] (thirty) days' written notice. After a security breach that affected the Company's data, an on-site audit may be requested at any time.
14.4. The auditor mandated by the Company must not carry on an activity that competes with the Seller's, and must sign a confidentiality undertaking. The audit is carried out during working hours, without endangering the security of the system and without access to the data of other companies or of Users.
14.5. Audit costs are borne by the Company. If the audit finds a breach of this Agreement by the Seller, those costs are borne by the Seller.
14.6. The Seller must contribute to the audit and to the inspection: it gives explanations and produces the settings of the system and the documents requested.
14.7. The Seller must keep a record of the categories of processing activities carried out for the Company, under art. 30 of Law No. 195/2024, and must produce it to the Company on request.
Art. 15. Return or erasure of the data
15.1. At the end of the period set out in Art. 6 the Seller must return to the Company the data processed for it, in a machine-readable format, or must erase that data. The choice belongs to the Company and is communicated in writing. If the Company does not choose within [30] (thirty) days, the data is erased.
15.2. The existing copies are erased as well. Backup copies are erased on their ordinary rotation, at the latest within [90] (ninety) days.
15.3. Primary documents, tax documents and statements are kept for as long as the accounting and tax law requires, under the Law on accounting and financial reporting No. 287 of 15.12.2017. For those documents the Seller is the controller.
15.4. The audit log and the money ledger are kept on the basis of the Seller's legitimate interest in proving who carried out each operation and in making any later change detectable. Both registers are built so that an entry cannot be erased; the entries are therefore kept for [72] (seventy-two) months and, after that period, for as long as they stay necessary for that purpose.
15.5. For the data that does not fall under point 15.3 and point 15.4 the Seller may choose anonymisation instead of erasure, where the result no longer allows the person to be identified.
Art. 16. Transfers outside the Republic of Moldova
16.1. The data processed for the Company is stored on servers located in the municipality of Chisinau, Republic of Moldova.
16.2. A transfer to another state or to an international organisation is made only in one of the following cases:
a) the state is a member of the European Economic Area, in which case no special authorisation is needed (art. 44 para. (2) of Law No. 195/2024);
b) there is a decision on an adequate level of protection, within the meaning of art. 45 para. (3) of the same law;
c) the transfer is based on standard data protection clauses approved by the Centre or adopted by the European Commission (art. 46 para. (2) letter c) of the same law);
d) the transfer is based on other adequate safeguards set out in art. 46 of the same law, with the authorisation of the Centre where the law requires it.
16.3. The transfers outside the Republic of Moldova existing at the date of signature are those listed in Appendix No. 2, with the country and the safeguard on which each is based. The Seller must not include the telephone number or the whole card number in the text of the notices sent to the device of a Company user.
16.4. At the Company's request the Seller must tell it which safeguard a transfer is based on and must give it a copy of that safeguard.
Chapter 4. Duties of the Company as controller
Art. 17. Legal basis
17.1. The Company must have and keep a legal basis for entering in the Cabinet the data set out in Art. 10 of the Contract. At the Seller's request that basis is stated in writing.
17.2. The Company must not build that processing on the consent of a Company user who is its employee. Consent is not freely given where the performance of a contract is conditioned on accepting a processing operation that is not necessary for that contract (art. 7 para. (4) of Law No. 195/2024).
Art. 18. Informing the Company users
18.1. Before it adds a person to the Cabinet, the Company must inform that person of:
a) the Company's capacity as controller and its contact details;
b) the purposes of the processing and the legal basis;
c) the categories of data;
d) the fact that the operations made with the Company card, including a risk flag that concerns those cards, are visible to the Company;
e) the fact that the Seller processes that data as processor;
f) the storage period;
g) that person's rights and the right to lodge a complaint with the Centre.
18.2. The Seller gives the Company a model information notice, set out in document 09, Consent texts and in-app notices. The Company may use the model or its own text.
18.3. At its first communication with a Company user, the Seller sends that Company user the information it owes on its own account for the data received from the Company, including the source of that data (art. 14 of Law No. 195/2024). That information does not replace the information owed by the Company.
Art. 19. Lawful instructions
19.1. The Company must give only instructions that comply with the personal data protection law, and is liable for them.
19.2. Only data that is accurate and needed for the management of the Company cards may be entered in the Cabinet. The data of persons who do not use those cards must not be entered.
19.3. The Company must keep the data it has entered up to date. A person who no longer uses the Company cards is removed from the Cabinet without undue delay and at the latest within [1] (one) working day.
Art. 20. Requests of data subjects
20.1. Requests of Company users about the processing for which the Company is the controller are settled by the Company, within the periods set out in Law No. 195/2024.
20.2. Where the request concerns the User account, the ePay card, the Balance or the sign-in account for the Cabinet, the Company directs the person to the Seller.
Art. 21. Access of the Company staff
21.1. The Company must give each member of the Company staff only the role that person needs, and must withdraw the access without undue delay and at the latest within [1] (one) working day from the day the person loses it.
21.2. At least one member of the Company staff keeps the owner role. The Company is liable for the actions taken in the Cabinet with the credentials of its Company staff, save where those credentials became known to another person through a breach of the Seller's duties.
21.3. The Company must tell the Seller without delay if the credentials of a member of its Company staff have become known to another person.
Chapter 5. Top-up by user
Art. 22. What the Company sees
22.1. Where Top-up by user is switched on, the Company sees in the Cabinet the amount a Company user has put on the Company card, the date and time of that top-up, and the User part left on the card.
22.2. The Company is the controller of that information in its own records and uses it to settle with the Company user. The settlement is made outside the App, and the Seller is not a party to it.
22.3. The Seller must not disclose to the Company the source of the money that a Company user put on the card.
Art. 23. What the Company does not see
23.1. The Company does not see:
a) the User account, the ePay card, the Balance and the person's own payments;
b) the whole telephone number;
c) the person's complaints and correspondence with the Seller's support;
d) the Seller's internal notes;
e) the person's membership of another company and the data of another company;
f) the evidence behind a risk flag, even where the flag itself is shown to the Company under Art. 5.
23.2. The Seller separates the data of each company through controls at the level of the database and of the application, so that a member of the Company staff cannot read the data of another company.
Chapter 6. Liability
Art. 24. Liability of the Parties
24.1. Each Party is liable for its own breach of Law No. 195/2024 and of this Agreement.
24.2. A fine imposed on a Party is borne by that Party. The Party fined may claim from the other Party the sum that matches that other Party's contribution to the act penalised.
24.3. A Party that has compensated a data subject for damage caused in part by the other Party may claim from that other Party the share falling on it.
24.4. The limits of liability set out in the Contract apply to this Agreement as well. They do not cover damage caused by intent or gross fault, the cases in which the law does not allow liability to be limited, or the sums that one Party pays to a data subject or to the Centre as a result of the other Party's breach of this Agreement, whatever the kind of damage.
Chapter 7. Term, termination and final clauses
Art. 25. Term
25.1. This Agreement enters into force on the day the Contract enters into force and has effect for as long as the Seller processes data for the Company.
25.2. The duty of confidentiality of the authorised persons, set out in Art. 8, stays in force without a time limit. Commercial confidentiality follows Art. 36 of the Contract.
Art. 26. Termination and amendment
26.1. This Agreement cannot be terminated separately from the Contract. It has effect until the duties set out in Art. 15 are met.
26.2. If Law No. 195/2024 or an act of the Centre requires other clauses, the Parties sign an addendum within [30] (thirty) days of the request of either of them. Until it is signed, the provisions of the law apply.
26.3. The standard contractual clauses approved by the Centre for the relations between a controller and a processor, once approved, replace the clauses of this Agreement that conflict with them (art. 28 para. (7) of Law No. 195/2024).
Art. 27. Final clauses
27.1. This Agreement is concluded in writing, including in electronic form (art. 28 para. (8) of Law No. 195/2024).
27.2. Appendix No. 1 and Appendix No. 2 form an integral part of this Agreement. Appendix No. 2 is updated under Art. 10, without an addendum. Any other amendment of this Agreement is made by a signed addendum, under Art. 45 of the Contract.
27.3. In case of a conflict between this Agreement and the Contract on the processing of personal data, this Agreement applies.
27.4. This Agreement is governed by the law of the Republic of Moldova. Disputes are settled as the Contract provides.
27.5. This Agreement is signed in two copies of equal legal force, one for each Party.
27.6. The Seller's contact point for this Agreement is dev@e-gaz.md, and the Company's contact point is the person named in Annex No. 1 to the Contract. From the moment it appoints a data protection officer, the Seller gives the Company that officer's contact details and publishes them (art. 37 of Law No. 195/2024).
Appendix No. 1. Technical and organisational measures
The "State" column shows what is running at the date of signature. A measure shown as planned applies from the day the production server is put into operation.
| Measure | Content | State |
|---|---|---|
| Encryption in transit | all traffic between the App, the Cabinet and the Seller's servers is encrypted, with certificates renewed automatically | planned; the configuration is prepared and tested |
| Encryption of secrets and backups | the secret behind the Rotating QR is encrypted with AES-256-GCM, with a versioned key for rotation; the database backups are encrypted. The database itself is not encrypted at disk level | running for the secret; the backups are planned |
| Passwords and codes | the passwords of the Company staff are kept as values transformed with argon2; one-time codes and session renewal tokens are transformed with bcrypt. Their text is not kept | running |
| Access by role | each role in the Cabinet and in the administration panel opens only the sections it needs; access is granted by name and withdrawn when the need ends | running |
| Separation of companies | the data of each company is separated through controls at the level of the database and of the application; a request coming from one company cannot read the data of another | running; row level separation in the database is being extended to every table that carries the company identifier |
| Audit log | every administrative change is written into a log that can only be appended to; entries are neither erased nor altered | running. Entries made from [DATE] onwards display telephone numbers masked; earlier entries cannot be altered, because the log does not allow erasure |
| Money ledger | every entry carries the fingerprint of the entry before it, so that a later change can be detected | running |
| Backups | a full copy of the database every night, encrypted; a restore check every month; a copy before every release into production | planned; the procedure is written and tested |
| Hosting | servers located in the municipality of Chisinau, Republic of Moldova | planned; the supplier is chosen, the server is not yet rented |
| Network perimeter | only the ports needed for the service are open; administrative access to the servers is by key only | planned; the configuration is prepared |
| Technical logs | telephone numbers appear masked in the server logs, and the logs rotate within [90] (ninety) days at the latest | running |
| Review of the measures | the Seller reviews the measures at least once a year and after every important change of the system | running |
Appendix No. 2. List of sub-processors
| Sub-processor | Service | Data received | Country | Transfer safeguard | State |
|---|---|---|---|---|---|
| StarNet | hosting of the servers and of the database | all data processed for the Company, as infrastructure | Republic of Moldova | no transfer | the supplier is chosen; the server is not yet rented |
| [SMS SUPPLIER] | sending SMS messages: the invitation of a person and one-time codes | the telephone number and the text of the message | [COUNTRY] | [SAFEGUARD] | the supplier is not yet chosen |
| [E-MAIL SUPPLIER] | sending e-mail to the Company staff: invitations, password recovery, statements | the e-mail address and the text of the message | [COUNTRY] | [SAFEGUARD] | the supplier is not yet chosen |
| Expo Project, Inc. | delivery of notices to the App | the delivery identifier and the text of the notice | United States of America | [SAFEGUARD, Art. 16.2] | switched on at launch |
| Apple Inc. | delivery of notices to iOS devices | the delivery identifier and the text of the notice | United States of America | [SAFEGUARD, Art. 16.2] | switched on at launch |
| Google LLC | delivery of notices to Android devices | the delivery identifier and the text of the notice | United States of America | [SAFEGUARD, Art. 16.2] | switched on at launch |
| Fuel equipment supplier | dispensing fuel at a Site | the public card number, the kind of card, the Company discount, the Hold amount and the session identifier | Republic of Moldova | no transfer | LSCard; a local simulator runs today |
| Wash equipment supplier | starting the wash post | the amount to credit at the wash post | Republic of Moldova | no transfer | ICW; a local simulator runs today |
| Till supplier | data exchange with the till of a Site | nothing today: the cashier enters the till receipt number by hand | [COUNTRY] | [SAFEGUARD] | the supplier is not yet chosen; the data exchange is not switched on |
| The Seller's advisers: the lawyer, the auditor, the accountant | help on a particular case | the data strictly needed for the case, under a duty of secrecy | Republic of Moldova | no transfer | as needed |
The bank through which the Company account is funded, and the public authorities, receive data under their own legal duties, as independent controllers, and are not sub-processors. Apple Inc. and Google LLC are independent controllers for their own platforms.
The App sends no error reports today. If the Seller switches that function on, the reports will be received and kept on its own servers in the municipality of Chisinau, without the name, the telephone number and the e-mail address, and Appendix No. 2 will be updated under Art. 10.