Bonusuri.md

Privacy Policy

2026-10-02

Controller and contact

Bonusuri.md is the platform brand. Existing details: independent entrepreneur, IDNO 1026023042507, Republic of Moldova. The controller must provide the full legal name and official address; a brand is not a substitute for legal identification. Data requests: adsmoldova77@gmail.com, +373 60 178 298.

Applicable framework

Updated 2 October 2026. This policy considers Moldova Law 195/2024, effective 23 August 2026, and Electronic Communications Law 72/2025. GDPR may additionally apply when services target people in the EU/EEA or their behaviour is monitored; translation alone does not determine its applicability.

Accounts

Email and password are sent directly to Supabase Auth for registration and sign-in. Supabase manages email verification, passwords and sessions. The application does not store plaintext passwords. The authentication session is stored in your browser; sign out on shared devices.

Tasks, profiles and payments

Forms may request your name, phone, email, payment method and necessary payment details, task results, confirmations and acceptance/review timestamps. IDNP is optional and should only be provided when the controller explains its necessity for documented payments. Do not send card numbers, CVV, passwords, banking codes or identity-document copies. Cloud saving depends on service availability; a local simulation does not confirm payment.

Companies and communication

Company requests include business name, contact person, phone/email, task type, budget, participant estimate and description, used to answer the request and prepare cooperation. Opening WhatsApp sends information to WhatsApp when you use that service; review the message before sending.

Purposes and legal bases

Authentication, requested assistance, tasks and reward records support the requested service and precontractual/contractual steps. Tax and recordkeeping obligations apply where relevant. Abuse prevention serves a legitimate security interest requiring a proportionality assessment. Analytics, marketing and optional preferences use separate cookie consent; acknowledging this policy is not advertising consent.

Providers and recipients

Vercel hosts the website and handles technical requests; Supabase provides authentication and the database when enabled; Resend delivers transactional authentication emails through SMTP. Vercel Blob support is prepared for private evidence files and may be unavailable. The operator and authorised personnel handle requests and payments. Payment providers receive necessary information for manual transfers; no integrated card checkout exists.

AI assistant

Only when you submit a question, up to the latest 10 messages, limited to 1,400 characters each, are sent by the server to OpenAI. The conversation remains in page memory. Requests set store:false, which does not automatically eliminate provider security logs. Do not enter personal, banking or document data. AI answers may be inaccurate and do not approve tasks or payments.

Analytics and marketing

GA4 and Vercel Web Analytics load only with analytics consent. Configured Meta/TikTok pixels require marketing consent. A mixed GTM container requires both permissions. Trackers are not initialised on private pages or URLs containing query parameters or fragments. No newsletter or promotional subscription is implemented in the audited code.

International transfers

Providers may process information outside Moldova, including the EU and US. The controller must confirm actual locations, processor agreements, subprocessors and applicable transfer safeguards. No unverified clauses or safeguards are claimed. Contact us for information about a specific transfer.

Retention

Cookie consent technically expires after 180 days. Preferences without contact/payment details may remain until withdrawal or local deletion. Simulation input stays in page memory until closing/reloading. Accounts, requests and payment records require an approved retention schedule based on the relationship, request handling and applicable legal obligations. Automatic deletion has not been verified for every category; the controller must communicate the applicable periods.

Your rights

You may request access, correction, erasure, restriction, objection and portability where legal conditions apply. Withdraw optional consent in Cookie settings without affecting earlier lawful processing. For export, correction or account closure, contact the address above, preferably from your account email; never send your password. Proportionate identity checks may be necessary. Any legal retention exception to deletion must be explained individually.

Complaints and minors

You can complain to Moldova's National Centre for Personal Data Protection using the contact and complaints procedures at datepersonale.md (centru@datepersonale.md; +373 22 820 801; 48 Serghei Lazo Street, Chișinău MD-2004). Where GDPR applies, you may also contact the competent EU/EEA supervisory authority. Paid tasks are intended for adults aged 18 or over; the checkbox is a declaration, not documentary age verification.

Security and changes

Cloud data access requires authentication and ownership checks. Transport uses HTTPS; sensitive profile values are encrypted when encryption is configured and otherwise are not retained in full. No measure guarantees absolute security. This technical policy requires the controller to complete and obtain legal review of identification, retention and transfers.

CNPDCP