Privacy Policy
Draft. This document is a working basis. It must be
reviewed by a lawyer and completed with company details before publication.
Placeholders are marked [like this].
This policy describes how [COMPANY NAME SRL]
(“Convia”, “we”), registered at [address]
(IDNO [number]), processes personal data in the
end-to-end analytics service convia.md. We comply with Law No. 133/2011 of the
Republic of Moldova on the protection of personal data, and with the GDPR for
visitors from the EEA.
1. Two roles
- Controller — for the data of our customers (account holders):
name, email, sign-in credentials, billing details.
- Processor (on the customer's instructions) — for the data of
visitors to our customers' websites, collected by the Convia tag. The
controller of that data is the customer who owns the website; processing
terms are set out in a data processing agreement (DPA).
2. What the tag collects
- visit events: pages, time, referral source, advertising parameters
(UTM, gclid, fbclid), device type, country derived from IP (the IP address
itself is not stored);
- anonymous visitor and session identifiers (random, in browser localStorage);
- on form submission — the contact details the visitor entered themselves
(phone, email). Only their cryptographic hashes are kept in the analytics
store; the original contact details are available solely to the customer
who owns the website.
The tag does not collect the contents of other form fields, passwords or payment data.
3. Purposes and legal bases
- analysing advertising performance for the customer — performance of a contract;
- sending lead and sale data to advertising platforms (Google, Meta) — on the
customer's instruction and settings, in hashed form;
- account operation, support and invoicing — performance of a contract;
- security and abuse prevention — legitimate interest.
4. Storage and retention
Data is stored on servers in [hosting jurisdiction].
Visit events — [24 months] or less depending on the
customer's plan; account data — for the term of the contract and
[3 years] thereafter for accounting purposes. Once the
retention period ends, data is deleted or anonymised.
5. Who data is shared with
- infrastructure sub-processors: [hosting provider];
- advertising platforms (Google, Meta) — only where the customer has enabled
it, and only hashed contact details;
- public authorities — upon lawful request.
- Telegram — if the customer has enabled lead notifications to their own
chat. The message carries only the channel, campaign and a link to the
lead; no phone, no email and no name are sent. The chat and account
belong to the customer. The
message stays in Telegram: only the chat owner can delete it.
We do not sell personal data.
6. Data obtained through Google APIs
This section separately describes the data we receive through Google APIs
when a customer connects their Google Ads account (“Google user data”).
- What we receive: the OAuth refresh token, the list of advertising
accounts the customer granted access to, and daily campaign statistics —
cost, clicks, impressions. We do not receive or ask for passwords.
- How we use it: solely to build the customer's reports — cost per
lead and return on ad spend. Access is read-only: we do not create, modify
or pause campaigns.
- Whom we share it with: no one. This data is visible only to users
of the project that granted access. We do not sell it, do not transfer it
to data brokers, do not use it for targeted advertising, creditworthiness
assessment or training artificial intelligence models, and do not transfer
or disclose it to third parties for purposes other than those described
here.
- How we protect it: transmission over HTTPS only; the token is
stored encrypted (AES-256-GCM, with the key held outside the database and
separate from the key used for contact details); access inside the
application is limited by roles; servers are located in the European Union
(Germany). Backups preserve the same field-level encryption.
- How it is deleted: the customer can revoke access at any time —
in their Google account settings or on the “Connections” screen of the
Service. On revocation we delete the token; spend statistics already
loaded are deleted together with the project or on request.
7. Data subject rights
You have the right to request access, rectification, erasure, restriction of
processing and portability of your data, and to withdraw consent. If your data
was collected by the tag on a customer's website, contact the owner of that
website (the controller); we will assist them in fulfilling the request.
Contact: [privacy@convia.md]. The supervisory authority
is the National Center for Personal Data Protection of the Republic of Moldova
(CNPDCP).
8. Cookies and localStorage
The tag uses localStorage for anonymous identifiers and the event queue; the
convia.md service uses localStorage for the sign-in session. The obligation to
inform visitors about data collection rests with the website owner; we provide
ready-made notice texts.
9. Changes
Updates to this policy are published on this page together with their
effective date. Current version: [date].