Privacy policy

PRIVACY POLICY OF THE OPTICA FAMILIEI PLATFORM

Date of last update: 10.07.2026

Article 1. Purpose and legal basis of the Policy

(1)     This Privacy Policy (“Policy”) aims to clearly and comprehensively inform users of the Farmacia Familiei platform (“Platform”) about the manner in which Farmacia Familiei S.R.L. (“the Controller”) processes personal data, in accordance with Law No. 195 of 25.07.2024 on the protection of personal data.

(2)     This Policy governs all personal data processing operations carried out through the Platform, including those associated with its use in guest mode for placing orders, creating and managing user accounts, participating in loyalty programmes, commercial communications, and promotional and gamification mechanisms.

(3)     The processing of personal data is based on the principles of lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, as well as the principle of the controller’s accountability, as regulated under art. 5 of Law No. 195/2024.

Article 2. Identity and contact details of the Controller and DPO

(1)     The controller of personal data is:

           Name: Farmacia Familiei S.R.L.

           IDNO: 1005600017723

           Address: Chișinău municipality, 23 Burebista Street, Republic of Moldova

           E-mail: office@farmaciafamiliei.md

           Phone: 060122611

(2)     The Data Protection Officer (DPO) may be contacted at: dpo@farmaciafamiliei.md

Article 3. Categories of data subjects

The Controller may process data of the following categories of data subjects:

a)        users of the Platform in guest mode;

b)       users who create an account on the Platform;

c)        customers who place orders/reservations or use delivery services;

d)       participants in loyalty programmes;

e)        participants in promotions, prize draws or gamification mechanisms;

f)         persons who receive commercial marketing communications;

g)        persons who contact the Controller for support or complaints.

Article 4. Categories of data processed

Depending on the interaction with the Platform, we may process the following categories of data:

a)        Identification data: name, surname, IDNP, date of birth, loyalty card number (where applicable).

b)       Contact data: phone number, e-mail address, delivery address, billing address.

c)        Account data: username, password (stored in a secure format), account settings and preferences.

d)       Order and transaction data: products ordered, value, payment method, delivery status, order history and returns.

e)        Loyalty programme and gamification data: points accumulated, levels, rewards, participation in missions/games, benefits history.

f)         Technical and usage data: online identifiers (device ID, push token), IP address, operating system, application version, technical logs, events in the application (e.g. click/button, screen visited), collected for security and improvement purposes.

g)        Data used for marketing: communication preferences, message open history, campaign interactions (to the extent permitted by consent or the applicable legal regime).

The Controller does not intentionally collect special categories of data (e.g. health data, diagnosis, medical data) through the Platform, except where such a processing flow is expressly introduced and separately regulated, in accordance with art. 9 of Law No. 195/2024.

Article 5. Sources of data

Data may come from the following sources:

a)        directly from the data subject, by completing fields in the Platform (account creation, order placement, loyalty enrolment, marketing consent, etc.);

b)       from the history of the commercial relationship (orders, returns, interactions with the support service);

c)        from service providers (e.g. payment processor, courier, IT suppliers) to the extent necessary for payment confirmation, delivery and technical support;

d)       from automated sources, through technical modules of the Platform (e.g. device identifiers, logs).

Article 6. Purposes and legal bases

(1)     We process personal data for the following purposes, based on the legal grounds provided under art. 6 of Law No. 195/2024:

           Use of the Platform in guest mode:

           Purpose: enabling the placement of an order without creating an account.

           Legal basis: performance of a contract or pre-contractual measures (art. 6 para. (1) lit. b) for order placement; legitimate interest (Platform operation and security).

           Creation and management of a user account:

           Purpose: user registration and authentication, profile management, access to order history, personal settings.

           Legal basis: performance of a contract or pre-contractual measures (art. 6 para. (1) lit. b).

           Order processing, delivery, returns:

           Purpose: receiving and processing orders, delivering products, managing returns and payments, issuing fiscal documents.

           Legal basis: performance of a contract (art. 6 para. (1) lit. b) and compliance with legal obligations (e.g. tax, accounting).

           Loyalty programme and commercial benefits:

           Purpose: awarding points, discounts, benefits and tracking participation in the loyalty programme.

           Legal basis: performance of a contract (acceptance of loyalty programme terms) and, where applicable, legitimate interest (efficient management of the customer relationship).

           Operational communication and support:

           Purpose: communicating with the user regarding order confirmation and status, account notifications, technical or security notifications, handling requests and complaints.

           Legal basis: performance of a contract and legitimate interest (ensuring effective communication and service security).

           Direct marketing (SMS, email, Viber/WhatsApp/Telegram/messaging, push notifications, Web Push):

           Purpose: sending offers, promotions, information about similar products and services, loyalty programmes, satisfaction surveys.

           Legal basis:

           primarily, the consent of the data subject (art. 6 para. (1) lit. a), expressed through a separate checkbox, not conditional on account creation; and

           exercise of the right to object for situations where marketing is based on legitimate interest within the limits permitted by law.

           Promotions, prize draws, gamification:

           Purpose: organising and administering promotional campaigns, prize draw or random extraction mechanisms, as well as gamification mechanisms without random extraction.

           Legal basis: performance of a contract (acceptance of the specific campaign regulation) and legitimate interest (promotion of services), respecting the conditions regarding consent and separate notification where additional data is processed.

           Fraud prevention and system security:

           Purpose: detecting and preventing fraud attempts, abuse and unauthorised access, as well as ensuring the integrity and availability of systems.

           Legal basis: legitimate interest (protecting the Controller’s activities and users), within the limits of art. 6 para. (1) lit. f.

           Compliance with legal obligations and defence of rights:

           Purpose: compliance with legal obligations (e.g. archiving, accounting, reporting), dispute resolution, defence of rights before courts or authorities.

           Legal basis: art. 6 para. (1) lit. c and f of Law No. 195/2024.

(2)     If the Controller intends to process data for a purpose other than that for which they were initially collected, it shall inform the data subject in advance, in accordance with art. 13 para. (3) of Law No. 195/2024.

Article 7. Consent

(1)     Where processing is based on consent, the Controller ensures that it constitutes a freely given, specific, informed and unambiguous indication of the data subject’s wishes, expressed by a statement or a clear affirmative action, such as ticking a dedicated checkbox.

(2)     The consent request is presented in a form that clearly distinguishes it from other aspects (e.g. acceptance of the Terms and Conditions or enrolment in the loyalty programme, acceptance of the marketing programme), using clear and plain language.

(3)     The data subject has the right to withdraw consent at any time, as easily as it was given, without affecting the lawfulness of processing carried out prior to withdrawal.

(4)     In assessing whether consent is freely given, the Controller takes into account whether the performance of a contract or access to the Platform is conditional on consent to the processing of data that are not necessary for the performance of that contract, within the meaning of art. 7 para. (4).

Article 8. Recipients and processors

(1)     Personal data may be disclosed to the following categories of recipients:

a)        IT service providers, hosting, maintenance and Platform development;

b)       online payment processors (e.g. bank, payment service providers);

c)        courier companies and delivery services;

d)       providers of SMS, email and push notification sending services;

e)        marketing and analysis service providers, within the limits of consent and legitimate interest;

f)         external consultants (lawyers, accountants, auditors) and public authorities, within the limits of legal obligations.

(2)     Where a recipient processes data on behalf of the Controller, it has the status of processor and acts on the basis of a contract that meets the conditions of art. 28 of Law No. 195/2024.

Article 9. International data transfers

If personal data are transferred to recipients outside the Republic of Moldova, the Controller shall carry out the transfer only under the conditions provided by Law No. 195/2024 and shall inform the data subject about the adequate or appropriate safeguards, as the case may be.

Article 10. Storage period

(1)     Personal data are kept only for the period necessary to fulfil the purposes for which they were collected, or for the period provided by applicable normative acts (e.g. accounting and tax archiving deadlines).

(2)     Upon expiry of the relevant periods, data will be deleted, anonymised or retained only to the extent necessary for establishing, exercising or defending a right before a court.

Article 11. Profiling and gamification

(1)     The Controller may use data on Platform interactions and order history for the purpose of personalising the experience, awarding benefits within the loyalty programme and presenting adapted offers, without producing significant legal effects on the data subject within the meaning of art. 22 of Law No. 195/2024.

(2)     Simple gamification mechanisms (e.g. points accumulation, levels, commercial rewards) are used for the purposes of loyalty and customer experience, the legal basis being performance of contract and legitimate interest, with the data subject being informed in this Policy and/or in the specific terms applicable to these mechanisms.

(3)     For prize draws and mechanisms with random extraction, the Controller shall adopt a dedicated regulation for each campaign, which shall clearly describe the purpose, conditions of participation, categories of data, method of designating winners and data retention periods.

Article 12. Rights of the data subject

The data subject has, under the conditions of Law No. 195/2024, the following rights:

a)        the right to be informed (art. 12–14);

b)       the right of access to data (art. 15);

c)        the right to rectification (art. 16);

d)       the right to erasure (“right to be forgotten”) (art. 17);

e)        the right to restriction of processing (art. 18);

f)         the right to data portability (art. 20);

g)        the right to object, including to direct marketing (art. 21);

h)       the right not to be subject to an individual automated decision, including profiling, under the conditions of art. 22;

i)         the right to lodge a complaint with the National Centre for Personal Data Protection.

Article 13. Exercise of rights

(1)     The data subject may exercise the rights referred to in the preceding article by submitting a written request to the Controller at the contact details provided in art. 2.

(2)     The Controller shall respond without undue delay, within at most one month of receiving the request, with the possibility of extension by a further 60 days in justified cases, in accordance with art. 12 para. (3) of Law No. 195/2024.

(3)     As a rule, information and measures taken are provided free of charge; the Controller may charge a reasonable fee or refuse the request if it is manifestly unfounded or excessive, in particular due to its repetitive nature.

Article 14. Data security and security incidents

(1)     The Controller implements appropriate technical and organisational measures to ensure a level of security appropriate to the risks, including, where applicable, pseudonymisation, encryption, access controls, internal confidentiality policies and staff training.

(2)     In the event of a personal data breach that may generate a risk to the rights and freedoms of data subjects, the Controller shall notify the National Centre for Personal Data Protection and, where applicable, the data subject, in accordance with art. 33–34 of Law No. 195/2024.

Article 15. Policy updates

(1)     The Controller may modify this Policy whenever necessary, including as a result of legislative changes or operational changes in the Platform.

(2)     The updated version will be published on the Platform, and, to the extent that the changes are substantial or concern processing for which the legal basis is consent, the Controller will inform users and, if necessary, will request new consent.