DRAFT FOR THE LAWYER, 20 September 2026
ePay privacy policy
Version [1.0] of [DATE]
1. In brief
1.1. The Seller processes the data needed for the User account, for the Balance and for payment in the Network: the telephone number, the name and surname, the operations and their documents.
1.2. A Balance top-up through MIA is executed by the bank, which tells the Seller the amount and the reference of the payment. The User's bank account details and bank card details do not reach the Seller.
1.3. The Site of an operation is recorded, because it forms part of the document of that operation. The coordinates of the telephone stay on the device.
1.4. Payment is confirmed by face or fingerprint on the telephone itself. The App receives from the device only the answer "confirmed" or "not confirmed".
1.5. The Seller passes data only to the recipients in chapter 6, and runs no behavioural analysis tool in the App.
1.6. A Company that has issued a Company card sees the operations made with that card. The User's ePay card and personal payments are not shown to it.
1.7. From the App the User may request an export of his data and the deletion of the User account. If there is money on the Balance, the account is closed under chapter 11.
1.8. The accounting and tax documents of the operations are kept under point 8.1. In them the User appears under an internal identifier, and the telephone number is shown masked on receipts and in the Company's statements.
2. The controller and its contact details
2.1. The controller of the data is SRL "DII-TEH-GROUP", IDNO 1017600052819, with its seat at mun. Chișinău, str. Socoleni 2/6, Republic of Moldova, hereinafter the Seller. The Seller owns the Network and the ePay App.
2.2. Processing follows Law No. 195 of 25.07.2024 on personal data protection, in force from 23 August 2026.
2.3. Requests about personal data and about the rights in chapter 10 go to dev@e-gaz.md or in writing to the Seller's seat, marked "Data protection".
2.4. If a data protection officer must be appointed under art. 37 of Law No. 195/2024 (Monitorul Oficial No. 367-369 of 23 August 2024, art. 574, in force from 23 August 2026), the Seller publishes his contact details in this Policy. It also gives them to the National Centre for Personal Data Protection, hereinafter the Centre, under art. 37 para. (7) of the same law. Until those details are published, requests go to the address in point 2.3.
3. The persons concerned
3.1. This Policy covers: a) Users of the App, including Company users; b) Company staff working in the Cabinet; c) the Seller's staff working in the internal panel; d) persons who send the company application form from the website; e) visitors to the website https://epay.e-gaz.md; f) persons who write to support; g) the heir of the User and the legal representative, when they receive the Balance in his place.
3.2. The App uses no cookies. What the App keeps on the User's telephone, and the cookies and browser storage of the Cabinet, of the internal panel and of the website, are described in the notice on cookies and browser storage, document 08.
3.3. Terms written with a capital letter have the meaning given by the Terms of use of the ePay application, hereinafter the Terms, document 01.
4. Categories of data and their sources
4.1. The Seller processes the following categories of data.
| Category | The data | Source |
|---|---|---|
| User account | telephone number; name and surname; confirmation of being 18 (eighteen) years old; e-mail address, if the User adds one, and the date it was confirmed; chosen language; state of the account | the User, at registration |
| Sign-in and sessions | the codes sent by SMS, kept as a cryptographic fingerprint, the number of attempts and the IP address of the request; open sessions: identifier and label of the device, platform, App version, date of last activity | the User and the system |
| Passkeys and recovery through support | the passkey's public key (the private key never leaves the phone), the known devices; on a recovery through support: the reason noted by the staff member, the numbers of the facts confirmed, the moments of the procedure and the staff member who handled it | |
| Notifications | the device's push notification identifier, the platform; the notifications sent and the date they were read | the User's telephone, through the Apple and Google services |
| Cards | the User's ePay card and Company cards; how the card is held, in the App, in the card application of the telephone or on plastic; the secret behind the Rotating QR, kept encrypted | the system, when the card is issued |
| Balance | the Balance in lei and every movement on it: date, time, amount, kind of movement and its document | the system |
| Balance top-up through MIA | the amount, the bank reference of the payment, the state of the payment, the moment of crediting | the bank |
| Cash Balance top-up | the Site, the cashier who took the money, the amount, the number of the till receipt, the state, a cancellation of the credit and its reason | the Site |
| Payments | the Hold and its amount, the amount paid, the service and the equipment of the Site, the card used, the ePay discount or the discount in the Company's contract, Refunds, Corrections and the public reason of each Correction | the User, the equipment of the Site |
| Documents of operations | the Advance confirmation for each top-up through MIA; the Fiscal receipt issued at the Site | the system, the fiscal equipment of the Site |
| Stamps and Coupons | the number of Stamps; the Coupons, with the code, the state, the date and the Site of redemption | the system, from the payments |
| Company cards | the status of Company user; the cards, the Company part and the User part; the operations with them; the label the Company gave the User | the Company |
| Complaints | the text of the complaint, the operation concerned, the category and the resolution | the User |
| Account closure and balance payout | the request and its state, the amount paid out; in the request: the kind of identity document, its series and the last 4 (four) characters of its number; in the cash disbursement order: the name, the number, the issuer and the date of issue of the document; the member of staff who checked the document and the one who paid | the User, at the Seller's seat |
| Payment to an heir or to a legal representative | the name and surname, the identity document under point 11.3, the number, the date and the issuer of the certificate of inheritance | the person who receives the payment |
| Acceptance of the Terms | the document and the version accepted, the date, the time, the session, the platform, the App version and the language | the App, at acceptance |
| Security and prevention of abuse | the IP address and the time of requests; abuse signals, risk marks and the evidence behind them; the technical logs of the servers, in which the telephone number is masked | the User's network and device |
| Support and audit | the internal notes of staff on a case, the reason for consulting a User's data, the entries of the audit log | the Seller's staff |
| Error reports | the model of the device, the version of the operating system and of the App, the trace of the error; without the name, the telephone number and the e-mail address | the App, if the function is switched on |
4.2. The Seller does not ask for and does not keep a copy of the identity document, the User's bank card details, the contact list or the photographs on the telephone. No behavioural analysis tool runs in the App.
4.3. The position of the telephone is used on the device alone, to order the list of Sites by distance. The coordinates are not sent to the Seller's servers and are not stored. A refusal of the permission affects no other function of the App.
4.4. The camera is used only to read codes. The images are not stored and are not sent.
4.5. The face and the fingerprint are checked by the operating system of the telephone. The App receives from the device only the answer "confirmed" or "not confirmed". The Seller does not process biometric data.
4.6. The telephone number, the name, the surname and the confirmation of being 18 (eighteen) years old are needed to conclude the contract. Without them the User account cannot be created. The e-mail address is optional; without it the User receives no documents by e-mail and cannot switch on the second step of verification by e-mail. At Account closure and balance payout the Rules for cash operations, approved by Government Decision No. 764 of 25.11.1992, require the identity document to be shown; without it the Seller does not pay out the cash.
4.7. The App sends no error reports today. If the function is switched on, the reports reach the Seller's servers in Chisinau and are passed to nobody else.
5. Purposes and legal bases
5.1. Each purpose has one legal basis, among those set out in art. 6 of Law No. 195/2024.
| Purpose | The data | Basis |
|---|---|---|
| Creating the User account, signing in by SMS code, keeping sessions | User account, sign-in and sessions | performance of the contract with the User |
| Keeping the Balance, top-ups, payments, Holds, Refunds and Corrections | Balance, top-ups, payments, cards | performance of the contract with the User |
| Issuing the Advance confirmation, receiving the Fiscal receipt, accounting and tax records, reconciliation with the bank and with the Sites | documents of operations, Balance, payments | legal duty of the Seller |
| Stamps, Coupons and Campaigns | Stamps, Coupons, payments | performance of the contract with the User |
| Issuing and servicing Company cards, drawing the reports and statements for the Company | Company cards, the operations with them, the label | performance of the contract with the Company |
| Service notifications: payments, Refunds, Coupons, card events, security | notifications, User account | performance of the contract with the User |
| Receiving and registering a complaint, answering within the statutory period | complaints | legal duty of the Seller |
| Resolving the complaint and returning the amount | complaints, operations | performance of the contract with the User |
| Checking the identity of the person paid and drawing the cash disbursement order | the account closure file | legal duty of the Seller |
| Closing the User account and paying out the Balance | Balance, User account | performance of the contract with the User |
| Security of the App and of the Network, prevention of abuse | security and prevention of abuse, operations | legitimate interest of the Seller, art. 6 para. (1) letter f) |
| The audit log of staff actions and the internal notes of support | support and audit | legitimate interest of the Seller, art. 6 para. (1) letter f) |
| Keeping the App in working order from the error reports | error reports | legitimate interest of the Seller, art. 6 para. (1) letter f) |
| Proof of acceptance of each version of the Terms | acceptance of the Terms | legitimate interest of the Seller, art. 6 para. (1) letter f) |
| Promotional messages about Campaigns and Coupons | User account, notifications | consent of the User, art. 6 para. (1) letter a) |
| Answering a request of an authority | the data the authority requires | legal duty of the Seller |
| Defending the Seller's rights before an authority or a court | the data needed for the case | legitimate interest of the Seller, art. 6 para. (1) letter f) |
5.2. The Seller weighed each legitimate interest against the rights of the person concerned. Security and prevention of abuse protect the Users' Balance, and for that purpose only technical data and data of the operation are processed. The audit log and the support notes show who touched a User's data and money, without which a complaint cannot be checked. Error reports are cleaned of the name, the telephone number and the e-mail address before they leave the telephone. Proof of acceptance holds the version, the date and the time, because otherwise the Seller cannot show which text was accepted. Defence before an authority or a court uses only the data of the case.
5.3. A person concerned may object at any time to processing based on legitimate interest, on grounds relating to his situation, under point 10.1 letter f). The Seller stops the processing, unless it shows legitimate grounds that override the interests and rights of the person.
5.4. Promotional messages are sent only with the consent of the User. Consent is withdrawn as easily as it was given, from the App, under Profile, Notifications, or by a request to the address in point 2.3, under art. 7 of Law No. 195/2024. Withdrawal does not touch the processing carried out before it.
5.5. Service notifications are not promotional messages. The User may switch them off in the settings of the telephone, and the messages stay in the App.
5.6. If the Seller comes to process the data for a purpose other than the one for which it collected them, it informs the person concerned of that purpose before starting such processing.
6. Recipients of the data
6.1. The Seller passes the data only to the recipients below.
| Recipient | What it receives | Status | State at the date of this version |
|---|---|---|---|
| StarNet, Chisinau, the hosting supplier | all data, as infrastructure | processor | supplier chosen; the server is not yet rented |
| [SMS SUPPLIER] | the telephone number and the text of the message: sign-in code, invitation, service notification and promotional message, if the User asked for it | processor | the supplier is not yet chosen |
| [E-MAIL SUPPLIER] | the e-mail address and the text of the message: invitation, password reset, the Company's statements and promotional message, if the User asked for it | processor | the supplier is not yet chosen |
| [BANK] | the amount, the reference of the operation and the result of the payment; it receives no telephone number from the Seller | independent controller | candidate: maib; the circuit is not yet switched on |
| Expo Project, Inc. | the delivery identifier and the text of the notification | processor | switched on at launch |
| Apple Inc., Google LLC | the delivery identifier and the text of the notification | processors for the delivery, and independent controllers for their own platforms | switched on at launch |
| [ANTI-BOT CHECK SUPPLIER] | the IP address of the visitor and data about his browser and device, on the page of the company application form alone | processor, and independent controller in defending its own service | the supplier is not yet chosen |
| The supplier of the fuel equipment | the public number of the card, the kind of card, the discount, the amount of the Hold and the identifier of the session | processor | LSCard; today a local simulator runs in its place |
| The supplier of the wash equipment | the amount to credit at the wash post | processor | ICW; today a local simulator runs in its place |
| The supplier of the tills | nothing today: the cashier types the number of the till receipt by hand | processor, once the exchange of data is switched on | the supplier is not yet chosen |
| The Company that issued the Company card | the data listed in point 12.5 | controller for its own cards | in operation |
| Public authorities: the tax body, the consumer protection authority, the Centre, the criminal investigation bodies, the courts | the data required under the law | independent controllers | on request |
| The Seller's lawyer and auditor | the data strictly needed for the case, under a duty of secrecy | independent controllers, under their own professional duties | when needed |
| The accountant, if the service is outsourced | the data needed for the accounting records | processor | when needed |
6.2. With every processor the Seller concludes a written contract. That contract obliges the processor to handle the data only on the Seller's instructions, to protect them and to delete them when the service ends. For the delivery of notifications on the Apple and Google platforms the terms published by those platforms also apply, which the Seller accepts when it registers the App.
6.3. The Seller's staff see the data only according to their role. A member of staff who consults a User's data for a support case first writes the reason, and the reason and the consultation enter the audit log. Every change a member of staff makes to a User's data also enters the audit log.
7. Transfers outside the Republic of Moldova
7.1. The Seller's servers are hosted in Chisinau, Republic of Moldova. The Users' data stay there.
7.2. Push notifications leave the Republic of Moldova. The delivery identifier and the text of the notification reach Expo Project, Inc., Apple Inc. and Google LLC, in the United States of America. The transfer is needed to deliver to the telephone the notifications the User asked for. The Seller puts neither the telephone number nor the full card number into the text of a notification.
7.3. For the United States of America there is no decision of the Centre on the adequacy of the level of protection, within the meaning of art. 45 para. (3) of Law No. 195/2024. The transfer under point 7.2 is based on [GROUND OF THE TRANSFER]. A copy of the safeguard is requested at the address in point 2.3.
7.4. If the Seller chooses a supplier of electronic mail or a supplier of the anti-bot check outside the Republic of Moldova, that supplier receives the e-mail address and the text of the message, or the IP address of the visitor and data about his browser and device. The name of the supplier, the state and the ground of the transfer are written into the next version of this Policy.
7.5. A transfer is made only in one of the cases set out in art. 44 para. (2), art. 45 para. (3) and art. 46 of Law No. 195/2024. For the states of the European Economic Area no special authorisation is needed.
7.6. No other transfer outside the Republic of Moldova is made.
8. Retention periods
8.1. The retention periods are those in the table. When a period runs out, the data are deleted or anonymised.
| The data | Period | Setting in the system |
|---|---|---|
| Telephone number, name, surname and the other data of the User account | for the life of the User account; on deletion the telephone number is replaced by an internal identifier | no setting |
| Codes sent by SMS | 24 (twenty-four) hours | retention.otp_challenge_hours |
| Closed or expired sessions | 30 (thirty) days | retention.session_days |
| An unused session | ends after 12 (twelve) months in which the App was not opened; its row is deleted 30 (thirty) days after it ends. The period does not concern the User account or the Balance | |
| The record of a recovery through support | as long as the Seller's audit log | |
| An unused push notification identifier | 30 (thirty) days | retention.push_token_stale_days |
| Notifications sent | 365 (three hundred and sixty-five) days | retention.notification_days |
| The data export link | 24 (twenty-four) hours | privacy.export_link_ttl_hours |
| Accounting and tax documents of the operations: payments, Refunds, Corrections, receipts, the cash disbursement order | [STATUTORY PERIOD] years from the end of the financial year in which the document was drawn, under the Law on accounting and financial reporting No. 287 of 15.12.2017 and the Tax Code No. 1163 of 24.04.1997 | retention.accounting_months |
| The audit log of staff actions | [72] (seventy-two) months and, after that period, for as long as the entries stay necessary for that purpose; the ledger of money movements follows the same rule | no setting |
| Internal support notes and the reason for consulting data | for the life of the User account; deleted with it | no setting |
| The text of a complaint | 1095 (one thousand and ninety-five) days from its closure; the record of the complaint and the resolution stay | retention.complaint_text_days |
| Proof of acceptance of the Terms and the deletion request | 1095 (one thousand and ninety-five) days from the execution of the deletion | retention.consent_after_deletion_days |
| Closed risk marks, with their evidence | 90 (ninety) days | retention.risk_technical_days |
| Abuse signals | 7 (seven) days | risk.signal_retention_days |
| Technical logs of the servers | no more than 90 (ninety) days | no setting |
| Cabinet password reset requests | 24 (twenty-four) hours | retention.password_reset_hours |
| Access accounts of Company staff | for the time of work in the Cabinet, plus the [90] (ninety) days for which the Cabinet stays open for consultation after the contract with the Company ends | the setting does not yet exist |
| The Cabinet log | for the term of the contract with the Company and a further [3] (three) years, under Annex No. 3 | the setting does not yet exist |
| The log of Requests to the programming interface | [400] (four hundred) days for the Production environment and [14] (fourteen) days for the Test environment | the setting does not yet exist |
| Access accounts of the Seller's staff | for the time of the employment relation | the setting does not yet exist |
| The application sent through the company form and the documents uploaded with it | until the contract is concluded or refused, then [PERIOD TO BE SET] | the setting does not yet exist |
| The file of an Account closure and balance payout | for as long as the cash disbursement order of that payment is kept | the setting does not yet exist |
| Cash top-ups and the daily reconciliation of the till | the period of the accounting documents | the setting does not yet exist |
| Settlement of the User part from a Company card | until settlement, then the period of the accounting documents | the setting does not yet exist |
| The secret behind the Rotating QR | deleted with the session or when the card is blocked | the setting does not yet exist |
| The contact between a card and a Site | 120 (one hundred and twenty) seconds; the data of the operation that follows are kept with that operation | the setting does not yet exist |
8.2. The periods written in square brackets are settled before publication. They are then written into the system as settings, so that deletion runs by itself.
8.3. The ledger of money movements and the audit log are tied into a chain of cryptographic fingerprints and cannot be changed unnoticed. Accounting and tax documents are not deleted before their period runs out.
8.4. The label given by the Company and the Company's statements are the Company's own records. The Company, not the Seller, sets their period.
9. Automated decisions
9.1. The Seller takes no decision based solely on automated processing that produces legal effects for the User or similarly affects him to a significant degree, within the meaning of art. 22 of Law No. 195/2024.
9.2. Abuse signals open a risk mark and alert a member of the Seller's staff. Blocking a card or a User account is decided by a member of staff, is given a written reason and enters the audit log. The Seller has put no rule into operation that blocks a card or an account by itself. If it puts one into operation, it first amends this Policy, states the logic of the rule and secures the rights in point 9.5.
9.3. The anti-bot check on the page of the company application form decides by itself whether the form may be sent. A negative result stops the sending and asks for another attempt. It produces no other effect on the person, it leaves open the route set out in document 08, and the Seller takes no decision on concluding the contract on the strength of it.
9.4. The fixed limits of the App are rules announced in advance and the same for everyone. They include the number of SMS codes requested in one hour, the expiry of a code and the life of the Rotating QR. They are not decisions about a person.
9.5. A User whose card or account has been blocked may ask for a member of staff to step in. He may state his point of view and contest the decision, at the address in point 2.3.
9.6. The Seller builds no consumption profiles for advertising.
10. The rights of the persons concerned
10.1. The rights below belong to every person whose data the Seller processes, not to the User alone: a) the right to learn whether the Seller processes his data and to receive a copy of them (art. 15); b) the right to ask for the rectification of inaccurate data (art. 16); c) the right to ask for the erasure of the data (art. 17), within the limits of chapter 11; d) the right to ask for the restriction of processing (art. 18); e) the right to receive the data he provided, in a structured, commonly used and machine-readable format (art. 20); f) the right to object to processing based on legitimate interest, on grounds relating to his situation, and at any time to promotional messages (art. 21); g) the right to withdraw his consent (art. 7); h) the right to lodge a complaint with the Centre and to apply to a court.
10.2. The User exercises his rights from the App, under Profile, where he finds the export of the data, the deletion of the User account and the consents. The objection to promotional messages sits under Profile, Notifications. A member of Company staff, a member of the Seller's staff, a visitor to the website, a person who sent the company application form and an heir send their request to the address in point 2.3. A Company user addresses the Company for the data in point 12.1 and the Seller for the rest.
10.3. To be sure that the request comes from the person concerned, the Seller may send a code to the telephone number of the account. It may also ask for the data that identify that person in its records. It does not ask for new data merely to delay the answer.
10.4. The export is given as a signed link, valid for 24 (twenty-four) hours from the request. The file holds the data of the User account, the Balance and its movements, the payments, the Coupons, the Stamps, the complaints and copies of the receipts.
10.5. The export leaves out passwords, cryptographic fingerprints, the internal notes of staff and the identification details of a Company. Risk marks and the evidence behind them are not given, because they concern other persons as well and would reveal how abuse is countered. The User may ask separately, at the address in point 2.3, for confirmation of whether a risk mark concerning him exists.
10.6. The Seller answers without undue delay and at the latest within one month of receiving the request. The period may be extended by two months where the request is complex. The person concerned is then told of the extension and of the reasons for it within the first month, under art. 12 para. (3) of Law No. 195/2024. If the Seller does not act on the request, it states the reasons within that same month. It also points to the complaint to the Centre and to court action, under art. 12 para. (4).
10.7. The exercise of the rights is free of charge. For requests that are manifestly unfounded or excessive, in particular because they repeat, the Seller may charge a reasonable fee or may refuse the request. The burden of proving that a request is manifestly unfounded or excessive falls on the Seller, under art. 12 para. (5).
10.8. The Seller communicates to every recipient to whom it passed the data each rectification, erasure or restriction of processing. This duty ceases where the communication is impossible or calls for a disproportionate effort, under art. 19 of Law No. 195/2024. At the request of the person concerned, the Seller names those recipients.
10.9. The contact details of the Centre, Centrul Național pentru Protecția Datelor cu Caracter Personal: [CENTRE ADDRESS], [CENTRE E-MAIL], [CENTRE WEBSITE].
11. Deletion of the User account, Account closure and balance payout
11.1. The User asks for deletion of the User account from the App, under Profile, or by a request to the address in point 2.3. The request is executed after a reflection period of 14 (fourteen) days, during which the User may cancel it from the App.
11.2. Deletion is held back while at least one of the following exists: a) the status of Company user; b) a Company card with a User part greater than zero; c) an unfinished wash or fuelling order; d) a payment in progress; e) an open Refund; f) a hold for security reasons; g) money on the Balance of the ePay card. The App shows the User which of them holds the deletion back.
11.3. Where there is money on the Balance, the account is closed through Account closure and balance payout, under the Terms. The User comes to the Seller's seat with an identity document. The request records the kind of document, its series and the last 4 (four) characters of its number. The cash disbursement order records the name, the number, the issuer and the date of issue of the document, because the rules for cash operations require those details when cash is paid out. The order is kept in the Seller's accounting documents, for their period, and is used for no other purpose. The Seller makes no copy of the identity document and keeps none.
11.4. After the payout the account is deleted under points 11.5 and 11.6.
11.5. When the deletion is executed, the telephone number is replaced by an internal identifier. The sessions, the push notification identifiers, the notifications, the SMS codes, the internal support notes and the number of Stamps are deleted, and Coupons not yet redeemed are cancelled.
11.6. After deletion the following stay, for the periods in chapter 8: a) the accounting and tax documents of the operations, because the accounting law and the tax law require them to be kept; b) the record of a complaint and its resolution, the text of which is deleted at its own term; c) the proof of acceptance of the Terms and the deletion request, as proof that the procedure was followed; d) the label given by the Company and the Company's statements, which are the Company's own records.
11.7. In the records under point 11.6 letters a), b) and c) the User appears under an internal identifier, and the telephone number is shown masked on receipts and in the Company's statements. The label under letter d) stays as the Company wrote it, and it is usually the name of the person or a vehicle plate. The Seller does not claim that the person can no longer be identified from those records.
11.8. A complaint open at the moment of deletion is dealt with further by e-mail, at the address the User gives.
12. Company users
12.1. The Company is the controller for what it decides itself about Company users: who holds each Company card, the label the Company gives the person, the placing of money on the card and its taking back, the limits of the card, the switching on and off of Top-up by user, and the reports and statements per Company user that the Seller draws for the Company. For that processing the Seller is the Company's processor and acts on its instructions, under the data processing agreement, Annex No. 2 to the contract with the Company.
12.2. The Seller is an independent controller for the User account of the same person, for the ePay card and the Balance, for its own sales on any card, for the access accounts of Company staff and for the audit log of the Cabinet.
12.3. The Company enters into the Cabinet the name, the surname and the telephone number of the Company user, under Art. 10 of the contract with the Company, and the Seller receives them from it. The Company also gives the label.
12.4. The information the Seller owes in its own right for the data received from the Company, including their source, is shown on the first screen the person sees after opening the link in the invitation SMS. It follows art. 14 of Law No. 195/2024 and document 09. That information does not replace the information the Company owes.
12.5. The Company sees: the cards it has issued and their balances, the Company part and the User part; every operation made with its cards, with the date, the time, the Site, the amount and the service; the label it gave the User; whether the status of Company user is in force; the Top-ups by user made onto its card; a risk mark that concerns its cards. The telephone number is shown to it masked.
12.6. The Company does not see: a) the User account, the ePay card, the Balance and the personal payments of the person; b) the full telephone number; c) the complaints of the person and his correspondence with support; d) the internal notes of the Seller's staff; e) the person's membership of another company and the data of another company; f) the evidence behind a risk mark.
12.7. Requests about the data in point 12.1 go to the Company. If such a request reaches the Seller, it passes the request to the Company within [3] (three) working days and tells the person that it has done so. Requests that concern only the User account, the ePay card and the Balance are dealt with by the Seller.
12.8. The Company keeps the label and its statements after the User account is deleted, as its own record of its fleet.
13. Company staff, the Seller's staff, visitors to the website and applicants
13.1. For Company staff, the Seller processes the e-mail address, the password as a cryptographic fingerprint, the role in the Cabinet, the language and the log of actions taken in the Cabinet. The Seller is the controller of those data, because they serve it in running and defending its own service. The basis is the Seller's legitimate interest in the security of the Cabinet and in being able to show who worked in it. The data come from the Company, and the periods are those in point 8.1.
13.2. For its own staff the Seller processes the e-mail address, the password as a cryptographic fingerprint, the role, the Site at which the person works and the log of actions in the internal panel. The basis is the employment relation and the Seller's legitimate interest in security.
13.3. Through the company application form on the website, the Seller processes the name of the contact person, the telephone number, the e-mail address, the message, the documents uploaded and a fingerprint of the IP address. The basis is pre-contractual measures taken at the request of the person. Uploaded documents are scanned for viruses.
13.4. For visitors to the website, the Seller processes the server logs: the IP address, the page requested and the time of the request. The basis is the Seller's legitimate interest in security, and the period is no more than 90 (ninety) days. The cookies are described in document 08.
13.5. The anti-bot check loads only on the page of the company application form, and only after the visitor accepts it there. The basis is his consent, under document 08. A visitor who does not accept the check sends the application by the routes set out in that document.
13.6. For a Company that works through the programming interface, the Seller keeps a log of Requests. It uses the log only for the security of the interface, for proof of the operations, for the accounting records and for meeting its legal duties. The basis is the Seller's legitimate interest in the security of the interface and in proving the operations, and, for the accounting records, the Seller's legal duty. The log is passed to no one other than the processors listed in the data processing agreement.
14. Security of the data
14.1. The Seller takes the measures required by art. 32 of Law No. 195/2024: a) connections to the servers are encrypted, with certificates renewed automatically; b) backups are taken every night, are encrypted, and their restoration is tested every month; c) the secret behind the Rotating QR is kept encrypted, under a key that can be changed; d) SMS codes and session keys are kept only as a cryptographic fingerprint, and the passwords of staff and of Company staff are derived with the argon2 algorithm; e) access is granted by role, and the data of each Company are separated at the level of the database; f) the audit log records the actor, the action and the values changed, cannot be deleted and shows the telephone number masked; g) the ledger of money movements is tied into a chain of cryptographic fingerprints; h) only the necessary ports are open on the servers, administrative access goes by keys, and the secrets are kept encrypted.
14.2. Every Refund, every Correction, every movement of money between the cards of the same User and every payout of the Balance is decided by the Seller's accountant. The decision states a reason, enters the audit log and is sent by e-mail to the Seller's Administrator. Members of the Seller's staff who hold a right over money or the right to change settings — the Administrator, the accountant and any role with such a right — sign in to the Seller's internal panel only with a code from an authenticator app, as a second factor; other staff do not need one.
14.3. If a breach of the security of the data occurs that may give rise to a risk for the rights of persons, the Seller notifies the Centre without undue delay. The notification is made, where possible, within 72 (seventy-two) hours of the day on which the Seller learned of the breach, under art. 33 of Law No. 195/2024. Where the risk is high, the Seller informs the person concerned as well, under art. 34.
15. Persons under 18 years of age
15.1. The App is intended for persons who have reached 18 (eighteen) years of age. The Seller does not knowingly process the data of a person below that age.
15.2. If the Seller learns that a User account belongs to a person under 18 (eighteen) years of age, it closes the account and deletes the data. The money on the Balance is paid to the legal representative under chapter 11.
16. Changes to the Policy
16.1. The Seller amends this Policy when the service, a supplier or the law changes.
16.2. Every version has a number and a date. The version in force is shown in the App, under Profile, and on the website.
16.3. A material change is announced in the App at least 15 (fifteen) days before it takes effect, stating the date from which the new version applies.
16.4. This Policy is brought to the notice of the persons concerned. It is not accepted, and no function of the App is stopped for want of an acceptance of it.