PRIVACY POLICY
regarding the processing of personal data through the website and in the provision of Rapid Link SRL services
This Privacy Policy informs individuals on how Rapid Link SRL collects, uses, stores, transmits, and protects personal data within its activities, particularly through the rapidlink.md website.
Rapid Link SRL places high importance on personal data protection and respecting the right to privacy.
Personal data processing is carried out in compliance with the applicable legislation of the Republic of Moldova, including:
- Law No. 195/2024 on personal data protection;
- other normative acts applicable depending on the nature of the service and processing;
- requirements applicable to electronic communications services, information security, accounting, taxation, and archiving, as appropriate.
Law No. 195/2024 transposes into national legislation the principles and requirements of Regulation (EU) 2016/679 (GDPR). It applies in the Republic of Moldova starting August 23, 2026.
This Policy applies to personal data processed through the rapidlink.md website, as well as data processed in connection with requesting, contracting, providing, administering, and supporting Rapid Link services, to the extent that they concern individuals.
The personal data controller is:
Rapid Link SRL
Headquarters: Republic of Moldova, mun. Chișinău, 71/7 Gheorghe Asachi St.
General E-mail: office@rapidlink.md
Sales E-mail: sales@rapidlink.md
Technical Support E-mail: support@rapidlink.md
Phone: +373 22 820 820
Website: rapidlink.md
Rapid Link SRL determines the purposes and means of personal data processing within its activities, in accordance with applicable legislation.
Data Protection Officer / Contact point for data protection:
[First and Last Name –]
[Dedicated Data Protection E-mail –]
Rapid Link SRL processes personal data in compliance with the following principles:
- lawfulness, fairness, and transparency;
- purpose limitation;
- data minimization;
- accuracy of data;
- storage limitation;
- integrity and confidentiality;
- controller accountability.
Rapid Link SRL collects and uses only adequate, relevant, and necessary data for the specified and legitimate purposes of processing.
Depending on the service used or interaction with Rapid Link, the following categories of data may be processed:
4.1. Identification Data
- first and last name;
- identification data required for concluding and executing the contract;
- signature;
4.2. Contact Data
- phone number;
- e-mail address;
- installation or service provision address;
- other contact data provided by the data subject.
4.3. Contractual and Commercial Data
- information regarding requested services;
- information regarding contracts;
- quote/offer requests;
- billing and payment data;
- history of communications and requests.
4.4. Technical Data
Depending on the service used, certain technical data may be processed, including:
- IP addresses;
- equipment identifiers;
- MAC addresses, when necessary for service delivery;
- connection data;
- data regarding connected devices and equipment;
- technical data required for diagnosing and troubleshooting incidents;
4.5. Data from Communications with Rapid Link
Information provided through the following may be processed:
- contact forms;
- quote/offer requests;
- connection requests;
- technical support requests;
- feedback and complaints;
- e-mail communications;
- telephone communications, to the extent legally and reasonably recorded.
4.6. Website Usage Data
The website may process certain technical information regarding access to and usage of online resources, including cookies and similar technologies, in accordance with the Cookie Policy.
Rapid Link SRL may process personal data for the following purposes:
5.1. Provision of Services
For:
- installation and activation of services;
- administration of services;
- ensuring their operation;
- technical monitoring;
- maintenance;
- identifying and troubleshooting malfunctions;
- technical support;
- managing customer requests.
5.2. Conclusion and Execution of Contracts
Data may be processed for:
- preparing offers and quotes;
- concluding contracts;
- executing contractual obligations;
- communication with the customer;
- managing the contractual relationship.
5.3. Invoicing and Accounting
For:
- issuing invoices;
- recording payments;
- accounting;
- fulfilling tax and accounting obligations;
- managing receivables.
5.4. Technical Support and Incident Management
Data may be used for:
- logging tickets;
- identifying the customer;
- diagnosing issues;
- resolving incidents;
- monitoring service quality;
- preventing and investigating security incidents.
5.5. Security
Technical data and logs may be processed for:
- network and system security;
- preventing unauthorized access;
- detecting suspicious activities;
- investigating incidents;
- ensuring service continuity;
- protecting Rapid Link infrastructure and customers.
5.6. Commercial Communications
Where an appropriate legal ground exists, Rapid Link may send information regarding:
- new services;
- offers;
- promotions;
- products and solutions;
- events and commercial communications.
Commercial communications requiring consent will be carried out only after obtaining such consent.
Depending on the purpose, Rapid Link SRL may process data on the basis of one or more of the following legal grounds provided by Law No. 195/2024:
- consent of the data subject;
- necessity for the performance of a contract or taking steps at the request of the individual prior to entering into a contract;
- compliance with a legal obligation;
- protection of vital interests of the individual;
- performance of a task carried out in the public interest, where applicable;
- legitimate interest of Rapid Link or a third party, respecting the rights and freedoms of the data subject.
Consent will not be requested when another appropriate legal ground exists for processing the data.
When processing is based on consent, it must be freely given, specific, informed, and unambiguous. Silence, pre-ticked boxes, or inactivity do not constitute valid consent.
Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.
Personal data may be accessed or transmitted, to the extent necessary to achieve stated purposes and on a legal basis, to:
- authorized Rapid Link employees;
- departments responsible for sales, support, technical, accounting, and administration;
- IT service providers;
- hosting, cloud, backup, or other IT service providers;
- maintenance and technical support service providers;
- processors authorized by Rapid Link;
- financial institutions, to the extent necessary for payment processing;
- public authorities and institutions, when disclosure of data is required or permitted by law;
- other entities in cases provided by applicable legislation.
Rapid Link will not disclose personal data to unauthorized recipients.
When an entity processes data on behalf of Rapid Link, the company will apply the necessary measures to ensure processing is carried out in accordance with applicable legislation and within established instructions.
Rapid Link SRL retains personal data only for the period necessary to achieve the purpose for which it was collected or for the period required by applicable legislation.
The retention period may vary depending on:
- the type of data;
- the nature of the service;
- duration of the contractual relationship;
- legal obligations;
- security necessities;
- settlement of disputes or complaints;
- archiving requirements.
Upon expiration of the applicable period, data is deleted, anonymized, or archived, as appropriate, in accordance with legislation and internal Rapid Link policies.
Exact retention periods are established in internal company retention policies and registers.
Rapid Link SRL applies appropriate technical and organizational measures to protect personal data against:
- unauthorized access;
- loss;
- destruction;
- unauthorized alteration;
- disclosure;
- misuse;
- other forms of unlawful processing.
Depending on the nature and risks of processing, measures may include:
- access control;
- user authentication;
- role-based permission management;
- passwords and authentication mechanisms;
- system monitoring;
- access and event logging;
- backup and data recovery;
- network infrastructure protection;
- physical security measures;
- incident management procedures;
- staff training;
- business continuity measures.
Rapid Link maintains an information security management system certified according to ISO/IEC 27001 for telecommunications and data center services.
The application of security measures is carried out according to the specific risks associated with the processing.
Under the conditions and limits provided by Law No. 195/2024, data subjects may benefit from the following rights:
- right to information;
- right of access to data;
- right to rectification of inaccurate data;
- right to erasure of data ("right to be forgotten"), in cases provided by law;
- right to restriction of processing;
- right to object;
- right to withdraw consent, when processing is based on consent;
- right not to be subject to a decision based solely on automated processing, in cases provided by law;
- other rights provided by applicable legislation.
The exercise of a right is not absolute and may be subject to legal limitations depending on the legal basis and purpose of processing.
The rapidlink.md website may use cookies and similar technologies for:
- website operation;
- security;
- storing certain preferences;
- analyzing website usage;
- improving services;
- other purposes set forth in the Cookie Policy.
Cookies requiring consent will be activated under conditions set by applicable law and based on individual user choices.
Additional information regarding cookies will be presented in a separate Cookie Policy.
Within certain services, Rapid Link may process data stored or transmitted by customers.
Depending on the nature of the service and contractual relationship, Rapid Link may act as:
- data controller; or
- data processor on behalf of the controller.
Where Rapid Link acts as a processor, processing is carried out according to client/controller instructions and applicable contractual terms.
The parties' responsibilities regarding data protection may be further established through contract or a data processing agreement (DPA).
Rapid Link does not use, within the services covered by this Policy, decisions based solely on automated processing that produce legal effects or similarly significantly affect the data subject, except where such processing is permitted by applicable law and necessary safeguards are implemented.
If relevant profiling or automated decision processes are introduced, corresponding information will be provided to data subjects in accordance with law.
Rapid Link applies the principle of accountability and aims to demonstrate compliance of its processing activities with applicable legislation.
Depending on the nature, scope, context, and purposes of processing, as well as risks to data subjects, Rapid Link may carry out data protection impact assessments (DPIA) and implement additional risk reduction measures.
Law No. 195/2024 emphasizes a risk-based approach and demonstrable controller accountability.
If the data subject believes that the processing of their personal data violates applicable legislation, they may first contact Rapid Link SRL to clarify the situation.
The data subject also has the right to contact the competent supervisory authority for personal data protection, namely:
National Center for Personal Data Protection of the Republic of Moldova (CNPDCP)
Current contact details of the authority are available on its official website.
Rapid Link SRL may update this Policy in case of:
- legislative changes;
- changes to services offered;
- introduction of new technologies;
- changes to data processing procedures;
- changes to suppliers or data flows;
- modifications of security measures;
- other relevant changes.
For questions regarding personal data protection or to exercise rights:
Rapid Link SRL
Republic of Moldova, mun. Chișinău, 71/7 Gheorghe Asachi St.
E-mail: office@rapidlink.md
Phone: +373 22 820 820
Website: rapidlink.md
Data Protection Officer / DPO:
[First and Last Name –]
Data Protection E-mail:
[Dedicated Data Protection E-mail –]
