Call center +373 791 70 493
Number for consultation +373 791 70 493

Agreement on personal data processing

Agreement on the Processing of Personal Data

Last updated: 2 October 2026

1. General Provisions

1.1. Personal Data Controller

This Agreement on the Processing of Personal Data establishes the procedure, purposes, and conditions for the processing of personal data by EMG CONSULTING GROUP S.R.L., operating through the website e-visa.md, hereinafter referred to as the “Controller”.

Controller contact details:

1.2. Purpose of this Agreement

The Controller respects every individual’s right to privacy and applies appropriate organisational, legal, and technical measures to protect personal data.

This Agreement applies to personal data received by the Controller:

1.3. Applicable Legislation

Personal data is processed in accordance with Law of the Republic of Moldova No. 195 of 25 July 2024 on the Protection of Personal Data, which entered into force on 23 August 2026.

Where applicable to a particular processing activity, the Controller may also take into account the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, commonly known as the General Data Protection Regulation (GDPR), as well as other applicable legislation.

2. Key Definitions

2.1. Personal Data

Personal data means any information relating to an identified or identifiable natural person, directly or indirectly.

2.2. Data Subject

A data subject is the natural person to whom the processed personal data relates, including a website visitor, applicant, client, prospective client, payer, client representative, or another person whose information is provided to the Controller.

2.3. Processing of Personal Data

Processing of personal data means any operation or set of operations performed on personal data, including collection, recording, organisation, storage, modification, consultation, use, disclosure, transmission, granting access, restriction, anonymisation, deletion, and destruction.

2.4. Controller

The Controller is the legal entity which, alone or jointly with others, determines the purposes and means of processing personal data.

2.5. Recipient

A recipient means a natural or legal person, public authority, diplomatic mission, consular office, or other organisation to which personal data may be disclosed on a lawful basis.

2.6. Processor

A processor is a natural or legal person who processes personal data on behalf of the Controller in accordance with the Controller’s instructions and applicable legislation.

3. Personal Data That May Be Processed

The scope of personal data processed depends on the nature of the user’s request, the selected service, and the requirements applicable to the relevant visa category or migration procedure.

3.1. Identification and Contact Data

The Controller may process:

3.2. Passport and Identity Document Data

Depending on the requested service, the Controller may receive and process:

3.3. Travel Information

In connection with visa-related services, the following information may be processed:

3.4. Documents Required for a Visa Application

Depending on the visa category, the applicant’s nationality, and the requirements of competent authorities, the Controller may receive and process:

The Controller requests only the data and documents necessary to assess the request or provide the contracted service.

3.5. Data Relating to Other Persons

Documents submitted by the applicant may contain personal data relating to:

By providing personal data relating to another person, the client confirms that they have a lawful basis for doing so and, where required by law, that the relevant person has been duly informed.

3.6. Financial and Contractual Data

The Controller may process:

Where payment is made through a bank or an external payment service provider, the Controller does not store the full payment card number, CVV/CVC code, or other card data processed directly by the payment provider.

3.7. Requests and Correspondence

The Controller may retain:

3.8. Technical Data

When the website is accessed, the following data may be processed automatically:

Non-essential analytical and marketing technologies are used taking into account the user’s preferences expressed through the website’s cookie management mechanism.

4. Purposes of Personal Data Processing

The Controller processes personal data only for specified and legitimate purposes.

4.1. Processing User Requests

Personal data may be used for:

4.2. Preliminary Assessment of Visa Eligibility

The Controller may use the provided information for:

Such an assessment does not constitute and does not guarantee a favourable decision by a competent public authority.

4.3. Preparation of Visa Documents

Personal data may be processed for:

4.4. Provision of Contracted Services

Personal data may be used for:

4.5. Interaction with Public Authorities and Other Organisations

To the extent necessary for the contracted service, personal data may be used for interaction with:

4.6. Compliance with Legal Obligations

Personal data may be processed for:

4.7. Website Operation and Security

Technical data may be processed for:

4.8. Analytics and Service Improvement

Where an appropriate legal basis exists, analytical tools may be used for:

4.9. Marketing and Informational Communications

The Controller may send information about its services and offers only where an appropriate legal basis exists.

Where the law requires consent for marketing communications, such consent will be requested separately and will not be a condition for receiving the main service.

Users may unsubscribe from marketing communications at any time.

5. Legal Bases for Processing

Depending on the specific purpose, personal data may be processed on the basis of:

Where processing is based on consent, the user has the right to withdraw that consent at any time.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Withdrawal of consent does not automatically require the deletion of all data where the Controller is required or entitled to continue storing such data on another legal basis.

6. Provision of Personal Data

Users provide their personal data voluntarily.

However, certain information may be necessary for:

If the user does not provide the necessary information or documents, the Controller may be unable to assess the request or provide the relevant service.

Users are required to provide accurate and up-to-date information.

The Controller is not responsible for consequences caused by the provision of inaccurate, incomplete, or outdated information.

7. Recipients of Personal Data

Depending on the nature of the service, personal data may be accessible to or transferred to:

Each recipient receives only the amount of personal data necessary for the relevant purpose.

The Controller may also disclose personal data where required by applicable law or by a lawful request from a competent authority.

8. Disclosure of Data to Public Authorities

The user understands that the provision of visa-related services may require the transfer of personal data to public authorities responsible for entry, stay, immigration matters, or visa issuance.

Such authorities independently determine how the personal data provided to them is processed in accordance with the legislation applicable to their activities.

EMG CONSULTING GROUP S.R.L. and e-visa.md are not public authorities and do not independently make decisions regarding the approval or refusal of visas.

The decision on a visa application is made exclusively by the competent authority.

9. International Transfers of Personal Data

Due to the international nature of visa services and the use of electronic communication tools, personal data may be transferred to or accessed from outside the Republic of Moldova.

This may occur:

Where international transfers take place, the Controller applies safeguards required by applicable legislation.

10. Retention Period

Personal data is retained only for as long as necessary to achieve the purposes for which it was processed.

The retention period is determined taking into account:

Where a user requests a consultation or submits an enquiry but no contract is concluded, the relevant data may be retained for a reasonable period necessary for follow-up communication, documenting the history of the enquiry, handling possible complaints, or protecting the Controller’s legitimate interests.

Data relating to clients who received services may be retained after completion of the service for the period required by law or for as long as objectively necessary to confirm the services provided and protect the rights of the parties.

After the applicable retention period expires, personal data is deleted, destroyed, or anonymised unless continued retention is required by law.

11. Protection of Personal Data

The Controller applies appropriate organisational and technical measures to protect personal data against:

Depending on the information systems used and the nature of the data processed, such measures may include:

Access to personal data is granted only to persons who require such access for the performance of their professional or contractual duties.

12. Rights of the Data Subject

Within the limits and under the conditions provided by applicable law, the data subject has the right:

Certain rights may be restricted in cases provided by law, including where continued processing is necessary for contract performance, compliance with a legal obligation, or the establishment, exercise, or defence of legal claims.

13. Exercising Data Protection Rights

To exercise their rights in relation to personal data, users may contact the Controller:

The request should preferably include:

To prevent unauthorised access to another person’s personal data, the Controller may request additional information necessary to verify the identity of the applicant.

Requests will be handled without undue delay and within the time limits established by applicable legislation.

14. Personal Data of Minors

Where documents are prepared for a minor, the Controller may process the child’s personal data to the extent necessary for the provision of the requested service.

Such data must be provided by a parent, legal representative, or another person who has a lawful basis to act on behalf of the minor.

The Controller may request documents confirming the authority of that person.

15. Automated Processing

The Controller may use automated information systems for managing requests, client relationships, website operation, and internal business processes.

The use of automated systems does not mean that decisions regarding visa eligibility are made automatically.

Final decisions on visa approval or refusal are made exclusively by the competent public authorities in accordance with applicable legislation.

16. Cookies

The e-visa.md website may use strictly necessary cookies without which certain website functions may not operate correctly.

Analytical, functional, and advertising cookies are used taking into account the choices made by the user through the website’s cookie management mechanism.

Users have the right to change their preferences or withdraw consent to the use of non-essential cookies.

Detailed information about the technologies used may be provided in a separate Cookie Policy.

17. Third-Party Services and Websites

The website may contain:

Once a user accesses an independent third-party website, personal data processing is carried out by the relevant provider in accordance with its own privacy policy.

The Controller is not responsible for the data processing practices of independent third-party websites, except where the relevant organisation processes personal data directly on behalf of the Controller.

18. User Responsibility for Submitted Documents

The user is responsible for the accuracy of the information and documents submitted to the Controller.

The user undertakes not to submit:

The Controller reserves the right to refuse to process documents or provide services where there are reasonable doubts regarding the lawful origin, authenticity, or compliance of the submitted information with applicable legal requirements.

19. No Guarantee of Visa Issuance

Providing personal data, submitting documents, paying for services, or entering into a contract with the Controller does not guarantee the issuance of a visa.

The Controller provides informational, consulting, and document preparation services within the scope of the relevant order.

The decision regarding visa issuance, validity period, number of permitted entries, or visa refusal is made exclusively by the competent public authority.

20. Amendments to this Agreement

The Controller may amend this Agreement periodically, including in connection with changes to:

The current version of the Agreement is published on e-visa.md.

The date of the latest revision is indicated at the beginning of the document.

Where amendments materially affect user rights or personal data processing conditions, the Controller may additionally notify users through available communication channels and, where required by law, request renewed consent.

21. Final Provisions

This Agreement is a publicly available document and applies to the processing of personal data through e-visa.md and other communication channels used by the Controller.

Simply visiting or continuing to use the website does not constitute consent to all possible forms of personal data processing.

Where applicable law requires the data subject’s consent, such consent must be obtained through a separate affirmative action by the user.

For any questions regarding the processing, use, or protection of personal data, please contact:

EMG CONSULTING GROUP S.R.L. — e-visa.md

E-mail: support@e-visa.md

Address: Republic of Moldova, Chișinău Municipality, 14 Grigore Ureche Street, Office 1

Telephone: +373 79 170 493