Privacy Policy
This Privacy Notice explains how we process your personal data when you use miapos.md and miapos.eu, the miaPOS merchant onboarding flow, or the miaPOS instant-payment acceptance platform. It applies together with our Cookie Policy and Company Details.
Last updated: 19 July 2026.
1. Data controller
- For miapos.md (users in the Republic of Moldova): Finergy Tech S.R.L., IDNO 1023600029900, registered office: MD-2060, bd. Dacia 38/3, ap. 151, Chișinău municipality, Republic of Moldova.
- For miapos.eu (users in the European Union): Instapay Tech S.R.L., registration number 51070272, registered office: Iași county, Iași municipality, Str. Răchiți no. 4, ground floor, Bl. C8, Ap. 3B, Romania.
Distinct controllers per domain. We have not appointed a Data Protection Officer (DPO); for any question regarding personal data please contact us at [email protected], tel. +373 690 02 773.
2. Data we collect
- Merchant identification data: company name, IDNO / registration number.
- Representative / administrator data: first name, last name, IDNP (personal numeric code), phone, email.
- Technical data: IP address, device / browser type, access logs (for platform security).
- Transaction data processed via the platform (no card data — miaPOS operates exclusively on instant / IPS rails and does not process cards).
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Merchant onboarding | Performance of a contract / pre-contractual measures (art. 6(1)(b) GDPR / art. 5(1)(b) Law 195/2024) |
| Processing payments and keeping transaction records | Legal obligation (AML/KYC, accounting) — art. 6(1)(c) |
| Platform security and fraud prevention (reCAPTCHA) | Legitimate interest / consent — art. 6(1)(a) / (f) (see Cookie Policy) |
| Marketing communications and analytics | Consent — art. 6(1)(a) |
4. Data recipients
- Partner banks — for payment settlement and merchant account activation.
- Cloudflare, Inc. — hosting, security and temporary storage of the verification (OTP) session in Workers KV.
- sms.md — SMS provider for phone-number verification (OTP).
- Twilio SendGrid, Inc. (USA) — email service through which the onboarding request is delivered to the miaPOS team.
- Google Ireland Ltd / Google LLC — reCAPTCHA v3, loaded only after your consent, to protect the onboarding form against bots (briefly shares your IP address with Google).
Fonts are hosted locally on our servers — no third-party transfer occurs on page load. We have or will conclude a Data Processing Agreement (DPA) with each processor; we can provide details on request.
5. International transfers
Personal data may be transferred between the Republic of Moldova and the European Union and, via our providers (e.g. Cloudflare, Google, Twilio SendGrid — processing outside the EU, including in the United States), processed outside the European Economic Area. Such transfers are covered by the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework, together with a DPA with each provider. You can request a copy of the safeguards used for a specific transfer by writing to [email protected].
6. Retention
- Onboarding data, representative data (including IDNP) and transaction data: 5 years from the end of the contractual relationship (AML/KYC and accounting requirements); afterwards the data is deleted or anonymised.
- Unregistered or abandoned onboarding requests: 6 months from the last activity, then deletion.
- OTP verification sessions: a few minutes (short TTL in Workers KV, auto-deleted).
- Site access logs: up to 30 days for security purposes.
7. Your rights
Under Regulation (EU) 2016/679 (GDPR) and Law no. 195/2024 on personal data protection (Republic of Moldova, in force from 23 August 2026), you have the right to:
- Access your personal data (art. 15 GDPR).
- Rectification of inaccurate or incomplete data (art. 16).
- Erasure — the "right to be forgotten" — subject to legal retention obligations (art. 17).
- Restriction of processing (art. 18).
- Object to processing based on legitimate interest (art. 21).
- Data portability in a structured, machine-readable format (art. 20).
- Withdraw consent at any time, without affecting past processing (art. 7(3)).
To exercise your rights: [email protected]. We will respond within one month, extendable by two further months for complex requests (art. 12(3) GDPR).
Right to lodge a complaint with the supervisory authority:
- Republic of Moldova: National Centre for Personal Data Protection (CNPDCP) — datepersonale.md.
- European Union: National Supervisory Authority for Personal Data Processing (ANSPDCP), Romania — dataprotection.ro. You may also lodge a complaint with the authority in your EU country of residence.
8. Automated decisions and profiling
We do not make automated decisions producing legal effects or similarly significant effects within the meaning of art. 22 GDPR. The final decision to activate a merchant account is taken by the partner bank.
9. Cookies
Details about the cookies we use, their categories and how to manage them — see the Cookie Policy.
10. Changes
Any update to this policy will be published on this page with a revised date. Continued use of the site or the platform after a change confirms that you have read the updated version. Previous versions are available on request.