Version 1.0, in force from 05.10.2026 · SHA-256 4fffe25bf87d179da2b30790ffb4acf70f1a4c4f926fc24eacbbebe5d1c36700 · text for checking the checksum

SRL "APB COPR" · postax.md

Privacy Policy

Effective date: 5 October 2026

We process only those personal data that are genuinely necessary for achieving the stated purposes. Your trust is our responsibility.

1. General Provisions

1.1. This Privacy Policy is the official document of SRL "APB COPR" (IDNO: 1020600014501, Republic of Moldova, mun. Chișinău, str. Ciocana 12, of. 16, MD-2052, email: support@postax.md) and establishes the procedure for processing and protecting personal data of postaX Platform Users at https://postax.md.

1.2. Processing is carried out in accordance with Law RM No. 195/2024, Regulation (EU) 2016/679 (GDPR) — taking into account Art. 27(2), Law No. 284-XV/2004.

1.3. This Policy forms an integral part of the Terms of Service.

2. Categories of Data Processed

Account data: email (login), name, password (bcrypt), phone for 2FA, billing address.

Payment data: date, amount, currency, status, paynet_order_id. Card data is not stored — payment via PayNet.md per PCI DSS standard.

Technical security logs: IP addresses, User-Agent, geolocation (country/city), timestamps. Retained 365 days.

Email metadata: sender/recipient addresses, Subject, Message-ID, message size, SMTP codes. Retained 365 days.

Message content: processed exclusively for delivery and storage. Personnel may not read users' correspondence.

Cookies: session JWT (24 h) and lang preference (365 days).

3. Purposes and Legal Bases for Processing

PurposeDataLegal Basis
Account creationRegistration dataPerformance of contract
Email service provisionAccount data, metadataPerformance of contract
Payment processing, fiscal documentsPayment and registration dataContract + legal obligation
Platform security, fraud preventionIP, security logsLegitimate interest of the Company
Optional marketing messagesEmail and contact dataData subject consent

4. Data Retention Periods

Account data: entire contract duration + 3 years after termination (limitation period under RM law).

Accounting and fiscal documents: 5 years (Tax Code RM).

Security logs (IP, authentication): 365 days.

Email metadata (transit logs): 365 days.

Message content and attachments: until account closure + 30 days after deletion.

5. Data Security and Protection

The Company applies a set of technical and organisational measures: TLS encryption in transit, bcrypt password hashing, administrative access restriction, backup, incident monitoring.

6. Transfer to Third Parties and Cross-Border Transfer

PayNet.md (SC Paynet Services SA): receives payment amount, name and email for PCI DSS processing.

IT infrastructure providers: certified data centres in RM and EEA.

State authorities of RM: disclosure only by court order.

Cross-border transfer to EEA — freely on the basis of adequacy decision. To third countries — only under SCC (EC Decision 2021/914).

Under Art. 27(2) GDPR, a permanent EU representative is not appointed (processing is of an occasional nature).

7. Rights of Data Subjects

Right of access — obtain information on processed data and a free copy.

Right to rectification — immediate correction of inaccurate data.

Right to erasure / "right to be forgotten" — where no grounds for continued processing exist.

Right to restriction of processing — during the period of disputing data accuracy.

Right to data portability — receive data in EML, ZIP, JSON formats.

Right to object — against processing for direct marketing.

Right to withdraw consent — at any time without affecting prior lawful processing.

Requests: dpo@postax.md. Response time: 1 month (extendable to 2 months with notification).

8. Processing of Minors' Data

RM citizens may give consent independently from age 14. Under-14s — only with parental consent. The Company does not intentionally collect data from persons under 14.

9. Company's Status as Processor (B2B)

For business clients, the Company acts as Processor. The business client is the independent Controller. The relationship is governed by the DPA: https://postax.md/api/documents/page/dpa/en.

10. Policy Amendments

The Company notifies of material changes 14 days in advance by email. Current version: https://postax.md/api/documents/page/privacy/en.

11. Contact Information and Supervisory Authority

DPO: dpo@postax.md

Support: support@postax.md

Address: Republic of Moldova, mun. Chișinău, str. Ciocana 12, of. 16, MD-2052

CNPDCP: Republic of Moldova, MD-2004, mun. Chișinău, str. Sergiu Lazo, 48

Phone: +373 (22) 820 801, +373 (22) 811 801

Email: centru@datepersonale.md

Website: www.datepersonale.md