Last updated: 24 August 2026
The personal data controller is the insurance and/or reinsurance broker „PROFASIG-PLUS” S.R.L., IDNO 1011600020131, with its registered office at MD-2009, mun. Chișinău, str. Vasile Alecsandri 11, ap. 7 and its operating office at mun. Chișinău, str. Vasile Alecsandri 13, of. 10. You may contact us at [email protected] or +373 68 878 771.
The internal contact point for personal data protection matters is Adrian Erhan. This statement does not constitute the formal appointment of a Data Protection Officer (DPO), unless such an appointment has been made separately.
This Policy applies to visitors to profasig.md; individuals who request a quotation, start a calculation, order or purchase an insurance policy, ask to be contacted, or communicate with us by telephone, email or other channels; and individuals whose personal data is provided in connection with an insurance contract.
identification data: first name, last name, IDNP or IDNO, and other information legally required for identification or policy issuance;
vehicle and related document data: vehicle registration certificate number, registration plate number, technical characteristics, and ownership or right-of-use information;
contact data: telephone number, email address, postal address and contact preferences;
insurance data: requested product, period, travel area, selected insurer, premium, driver information and other data required for assessment and issuance;
order and payment data: order identifier, amount, payment status and confirmation from the payment processor. Profasig does not request or store the full card number, CVV/CVC or banking authentication data;
correspondence and requests: message content, submitted documents and the history of the customer relationship;
online technical data: IP address, device and browser identifiers, security logs, pages visited, traffic source and usage events, within permitted limits and according to cookie choices;
data concerning employees, representatives or other individuals included in a request, only where necessary for the stated purpose.
We obtain personal data directly from the data subject or the person requesting insurance; from documents provided to us; from official systems and insurer platforms lawfully accessed; from the payment processor for transaction confirmation; and, for technical data, from the device used to access the website.
If you provide personal data about another individual, you must have the right to disclose it and must inform that individual of this Policy.
|
Purpose |
Examples |
Legal basis |
|---|---|---|
|
Quotation and issuance |
Calculation, checks, insurer selection, policy issuance and delivery |
Pre-contractual steps and performance of a contract |
|
Legal obligations |
Accounting, taxation, insurance requirements, fraud prevention and responses to authorities |
Compliance with a legal obligation |
|
Customer relationship |
Support, complaints, data correction and the establishment or defence of rights |
Contract, legal obligation and legitimate interests |
|
Security |
Logs, prevention of unauthorised access and incident investigation |
Legitimate interests and legal obligation |
|
Analytics and advertising |
Measuring traffic and conversions through non-essential cookies |
Consent, where required |
|
Direct marketing |
Offers and promotional messages |
Separate consent or another permitted and documented legal basis |
Data marked as mandatory is necessary for calculation, identification, issuance, payment or compliance with legal obligations. Refusal to provide it may make it impossible to provide a quotation or issue the requested product. Marketing data and non-essential cookies are optional.
authorised Profasig employees, within the scope of their duties;
partner insurance companies and official systems used for calculation and issuance;
the payment processor and bank, strictly for initiating and confirming payment;
IT service providers, including Five Stars Digital Agency, and hosting, email and backup providers, under documented contracts and instructions;
analytics or advertising providers, including Google, only as configured and, for non-essential technologies, after consent;
the National Bank of Moldova, the National Centre for Personal Data Protection, the State Tax Service, law enforcement bodies, courts or other authorities where required by law or a lawful request;
legal advisers, auditors or other professionals subject to confidentiality obligations.
The specific list of processors and partners is maintained internally and kept up to date. Upon request, we may provide additional information within the limits of the law and commercial confidentiality.
Some global technology services may involve access to or storage of personal data outside the Republic of Moldova. Profasig permits such transfers only where a lawful mechanism and appropriate safeguards are in place under Chapter V of Law No. 195/2024. Information about the applicable safeguards may be requested using our contact details.
We retain personal data only for as long as necessary for the relevant purpose and legal obligations. When the applicable period expires, personal data is deleted, anonymised or archived with restricted access.
|
Category |
Adopted period/criterion |
|---|---|
|
Contact requests not followed by a contract |
12 months after the request is closed |
|
Incomplete calculation/quotation |
no more than 90 days, unless there is a dispute, suspected fraud or a legal retention obligation |
|
Contracts, policies, orders and supporting documents |
for the duration of the relationship and thereafter in accordance with insurance, tax, accounting and archival retention rules; accounting supporting documents — at least 6 years |
|
Complaints and disputes |
until final resolution and expiry of the periods for establishing or defending rights |
|
Marketing |
until consent is withdrawn or an objection is made; evidence of the choice is retained as necessary to demonstrate compliance |
|
Security logs |
generally 12 months, unless an incident requires longer retention |
|
Cookies |
according to the periods displayed in the preference panel and Cookie Policy |
|
Backups |
according to the provider's documented technical cycle; restricted access until overwritten or deleted |
We apply technical and organisational measures proportionate to the risks, including access controls, individual passwords, staff confidentiality obligations, backups, updates, transmission security and periodic access-right reviews. No online transmission can be guaranteed to be entirely risk-free, but this does not limit Profasig's legal obligations.
to receive information and access your personal data;
to rectify inaccurate data and complete incomplete data;
to erase personal data where the legal conditions are met;
to restrict processing;
to data portability where provided by law;
to object to processing based on legitimate interests and, at any time, to direct marketing;
to withdraw consent without affecting the lawfulness of processing carried out before withdrawal;
rights relating to solely automated decisions, where such decisions are used;
to lodge a complaint with the National Centre for Personal Data Protection and bring proceedings before a court.
Requests should be sent to [email protected]. We may request information reasonably necessary to verify your identity. We respond without undue delay and generally within one month, subject to any extension permitted by law.
Profasig services are not directed specifically at children. Where processing concerns a minor, it is carried out only to the extent necessary, through the legal representative or on another basis permitted by law.
The calculator may perform automated calculations based on applicable rates and rules. Profasig does not intend to make decisions solely by algorithms that produce significant legal effects, except where necessary for performing a contract or authorised by law. The customer may request human intervention where the law grants that right.
We may update this Policy if our processes, providers or the law change. The current version and its update date are published on the website. Material changes will be highlighted through appropriate means.
For questions and to exercise your rights: [email protected], +373 68 878 771, for the attention of Adrian Erhan. The supervisory authority is the National Centre for Personal Data Protection: https://datepersonale.md/.
Leave a phone number and we will contact you within 5 minutes.