Agreement on personal data processing
Agreement on the Processing of Personal Data
Last updated: 2 October 2026
1. General Provisions
1.1. Personal Data Controller
This Agreement on the Processing of Personal Data establishes the procedure, purposes, and conditions for the processing of personal data by EMG CONSULTING GROUP S.R.L., operating through the website e-visa.md, hereinafter referred to as the “Controller”.
Controller contact details:
-
website: https://e-visa.md/;
-
e-mail: support@e-visa.md;
-
address: Republic of Moldova, Chișinău Municipality, 14 Grigore Ureche Street, Office 1;
-
telephone: +373 79 170 493.
1.2. Purpose of this Agreement
The Controller respects every individual’s right to privacy and applies appropriate organisational, legal, and technical measures to protect personal data.
This Agreement applies to personal data received by the Controller:
-
through application forms on e-visa.md;
-
through consultation request forms;
-
through contact forms;
-
by e-mail;
-
by telephone;
-
through messaging applications and other communication channels;
-
during consultations;
-
in connection with the conclusion and performance of contracts;
-
when receiving documents from a client or their representative;
-
while providing services related to the preparation of documents for obtaining a visa or other migration and consulting services;
-
during interaction with public authorities, diplomatic missions, consular offices, translators, notaries, banks, and other organisations to the extent necessary for the provision of the service requested by the client.
1.3. Applicable Legislation
Personal data is processed in accordance with Law of the Republic of Moldova No. 195 of 25 July 2024 on the Protection of Personal Data, which entered into force on 23 August 2026.
Where applicable to a particular processing activity, the Controller may also take into account the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, commonly known as the General Data Protection Regulation (GDPR), as well as other applicable legislation.
2. Key Definitions
2.1. Personal Data
Personal data means any information relating to an identified or identifiable natural person, directly or indirectly.
2.2. Data Subject
A data subject is the natural person to whom the processed personal data relates, including a website visitor, applicant, client, prospective client, payer, client representative, or another person whose information is provided to the Controller.
2.3. Processing of Personal Data
Processing of personal data means any operation or set of operations performed on personal data, including collection, recording, organisation, storage, modification, consultation, use, disclosure, transmission, granting access, restriction, anonymisation, deletion, and destruction.
2.4. Controller
The Controller is the legal entity which, alone or jointly with others, determines the purposes and means of processing personal data.
2.5. Recipient
A recipient means a natural or legal person, public authority, diplomatic mission, consular office, or other organisation to which personal data may be disclosed on a lawful basis.
2.6. Processor
A processor is a natural or legal person who processes personal data on behalf of the Controller in accordance with the Controller’s instructions and applicable legislation.
3. Personal Data That May Be Processed
The scope of personal data processed depends on the nature of the user’s request, the selected service, and the requirements applicable to the relevant visa category or migration procedure.
3.1. Identification and Contact Data
The Controller may process:
-
first name;
-
last name;
-
patronymic or middle name, where applicable;
-
previous names or surnames, where required for document preparation;
-
date of birth;
-
place of birth;
-
sex;
-
nationality;
-
nationality at birth;
-
marital status;
-
residential address;
-
registered address;
-
telephone number;
-
e-mail address;
-
contact details used in messaging applications.
3.2. Passport and Identity Document Data
Depending on the requested service, the Controller may receive and process:
-
passport number;
-
passport series, where applicable;
-
passport issue date;
-
passport expiry date;
-
issuing authority;
-
country of issue;
-
copies or photographs of passport pages;
-
national identification numbers;
-
information contained in identity documents;
-
residence permit details;
-
information about previously issued visas;
-
information contained in other documents confirming identity or immigration status.
3.3. Travel Information
In connection with visa-related services, the following information may be processed:
-
intended date of entry into the Republic of Moldova;
-
intended date of departure;
-
purpose of travel;
-
intended duration of stay;
-
travel itinerary;
-
country of departure;
-
country of destination;
-
transit information;
-
information about previous travel;
-
airline ticket details and other transport documents;
-
accommodation booking details;
-
address of stay in the Republic of Moldova;
-
information about the host person or organisation;
-
information about the intended place of stay.
3.4. Documents Required for a Visa Application
Depending on the visa category, the applicant’s nationality, and the requirements of competent authorities, the Controller may receive and process:
-
applicant photographs;
-
invitations;
-
booking confirmations;
-
tickets or itinerary confirmations;
-
employment information;
-
employment certificates;
-
employer information;
-
educational documents;
-
bank statements;
-
proof of income;
-
documents confirming sufficient financial means;
-
insurance policies;
-
documents confirming the purpose of travel;
-
documents confirming family relationships;
-
birth certificates;
-
marriage certificates;
-
information about children, spouse, and other family members;
-
documents relating to the host person or organisation;
-
work permits or other authorisation documents;
-
documents confirming the right of residence in a third country;
-
other documents required for the specific service.
The Controller requests only the data and documents necessary to assess the request or provide the contracted service.
3.5. Data Relating to Other Persons
Documents submitted by the applicant may contain personal data relating to:
-
spouse;
-
parents;
-
children;
-
host person;
-
employer;
-
inviting person;
-
other natural persons.
By providing personal data relating to another person, the client confirms that they have a lawful basis for doing so and, where required by law, that the relevant person has been duly informed.
3.6. Financial and Contractual Data
The Controller may process:
-
information concerning payments for services;
-
payer information;
-
banking details;
-
invoice number and date;
-
contract details;
-
payment document details;
-
information concerning refunds;
-
history of requested and provided services.
Where payment is made through a bank or an external payment service provider, the Controller does not store the full payment card number, CVV/CVC code, or other card data processed directly by the payment provider.
3.7. Requests and Correspondence
The Controller may retain:
-
requests submitted through website forms;
-
e-mail correspondence;
-
messages exchanged through messaging applications;
-
documents and photographs sent by the client;
-
client comments;
-
information provided during consultations;
-
history of interactions with the Controller’s employees;
-
information concerning the progress of the service;
-
telephone call recordings, where such calls are recorded and the client has been informed in advance.
3.8. Technical Data
When the website is accessed, the following data may be processed automatically:
-
IP address;
-
device type;
-
browser type and version;
-
operating system;
-
date and time of visit;
-
pages viewed;
-
referring page;
-
user actions on the website;
-
technical identifiers;
-
cookies and similar technologies;
-
UTM parameters and other information concerning the source of traffic.
Non-essential analytical and marketing technologies are used taking into account the user’s preferences expressed through the website’s cookie management mechanism.
4. Purposes of Personal Data Processing
The Controller processes personal data only for specified and legitimate purposes.
4.1. Processing User Requests
Personal data may be used for:
-
receiving and reviewing requests;
-
contacting the user;
-
providing information about services;
-
determining the appropriate service;
-
conducting a preliminary assessment of the situation;
-
arranging a consultation.
4.2. Preliminary Assessment of Visa Eligibility
The Controller may use the provided information for:
-
determining the applicable visa category;
-
analysing the applicant’s nationality and immigration status;
-
identifying the general requirements applicable to the applicant;
-
checking whether the provided information is complete;
-
preparing a list of required documents;
-
identifying potential deficiencies or risks in the submitted documentation.
Such an assessment does not constitute and does not guarantee a favourable decision by a competent public authority.
4.3. Preparation of Visa Documents
Personal data may be processed for:
-
preparing applications;
-
completing forms;
-
reviewing documents;
-
preparing supporting documents;
-
preparing documentation for submission to competent authorities;
-
arranging translation and formalisation of documents;
-
organising the obtaining of required documents.
4.4. Provision of Contracted Services
Personal data may be used for:
-
concluding and performing contracts;
-
identifying the client;
-
providing consulting services;
-
preparing documents;
-
assisting with visa procedures;
-
informing the client about the progress of the service;
-
delivering completed documents to the client;
-
processing payments;
-
issuing invoices and payment documents.
4.5. Interaction with Public Authorities and Other Organisations
To the extent necessary for the contracted service, personal data may be used for interaction with:
-
public authorities of the Republic of Moldova;
-
the General Inspectorate for Migration;
-
the Ministry of Foreign Affairs;
-
diplomatic missions and consular offices;
-
foreign public authorities;
-
notaries;
-
translators;
-
banks and payment institutions;
-
insurance companies;
-
courier services;
-
other organisations whose involvement is necessary for the provision of the service.
4.6. Compliance with Legal Obligations
Personal data may be processed for:
-
compliance with accounting and tax requirements;
-
maintaining financial records;
-
responding to lawful requests from public authorities;
-
fraud prevention;
-
ensuring security;
-
protecting the Controller’s legal rights and legitimate interests;
-
handling complaints;
-
resolving disputes;
-
establishing, exercising, or defending legal claims.
4.7. Website Operation and Security
Technical data may be processed for:
-
ensuring the proper operation of the website;
-
protecting information systems;
-
preventing unauthorised access;
-
identifying technical errors;
-
preventing abuse;
-
maintaining technical logs;
-
creating backups;
-
restoring data.
4.8. Analytics and Service Improvement
Where an appropriate legal basis exists, analytical tools may be used for:
-
analysing website traffic;
-
evaluating the use of individual website pages;
-
identifying traffic sources;
-
improving the website structure;
-
improving usability;
-
evaluating the effectiveness of advertising campaigns;
-
improving service quality.
4.9. Marketing and Informational Communications
The Controller may send information about its services and offers only where an appropriate legal basis exists.
Where the law requires consent for marketing communications, such consent will be requested separately and will not be a condition for receiving the main service.
Users may unsubscribe from marketing communications at any time.
5. Legal Bases for Processing
Depending on the specific purpose, personal data may be processed on the basis of:
-
the data subject’s consent;
-
the necessity to take steps at the data subject’s request before entering into a contract;
-
the conclusion and performance of a contract;
-
compliance with the Controller’s legal obligations;
-
the legitimate interests of the Controller or a third party, provided that the rights and freedoms of the data subject are respected;
-
the necessity to establish, exercise, or defend legal claims;
-
other legal grounds provided for by applicable legislation.
Where processing is based on consent, the user has the right to withdraw that consent at any time.
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Withdrawal of consent does not automatically require the deletion of all data where the Controller is required or entitled to continue storing such data on another legal basis.
6. Provision of Personal Data
Users provide their personal data voluntarily.
However, certain information may be necessary for:
-
reviewing a request;
-
determining whether the requested service can be provided;
-
preparing a visa application;
-
concluding a contract;
-
performing a contract;
-
complying with legal requirements.
If the user does not provide the necessary information or documents, the Controller may be unable to assess the request or provide the relevant service.
Users are required to provide accurate and up-to-date information.
The Controller is not responsible for consequences caused by the provision of inaccurate, incomplete, or outdated information.
7. Recipients of Personal Data
Depending on the nature of the service, personal data may be accessible to or transferred to:
-
employees and authorised representatives of the Controller;
-
legal advisers;
-
translators;
-
notaries;
-
public authorities of the Republic of Moldova;
-
migration authorities;
-
diplomatic missions;
-
consular offices;
-
foreign competent authorities where required by the procedure;
-
banks and payment institutions;
-
insurance companies;
-
postal and courier services;
-
hosting service providers;
-
e-mail service providers;
-
CRM system providers;
-
cloud service providers;
-
communication service providers;
-
technical support providers;
-
analytics providers;
-
other organisations whose involvement is necessary for the provision of the service.
Each recipient receives only the amount of personal data necessary for the relevant purpose.
The Controller may also disclose personal data where required by applicable law or by a lawful request from a competent authority.
8. Disclosure of Data to Public Authorities
The user understands that the provision of visa-related services may require the transfer of personal data to public authorities responsible for entry, stay, immigration matters, or visa issuance.
Such authorities independently determine how the personal data provided to them is processed in accordance with the legislation applicable to their activities.
EMG CONSULTING GROUP S.R.L. and e-visa.md are not public authorities and do not independently make decisions regarding the approval or refusal of visas.
The decision on a visa application is made exclusively by the competent authority.
9. International Transfers of Personal Data
Due to the international nature of visa services and the use of electronic communication tools, personal data may be transferred to or accessed from outside the Republic of Moldova.
This may occur:
-
when interacting with foreign diplomatic missions and consular offices;
-
when interacting with foreign public authorities;
-
when using e-mail and messaging applications;
-
when using cloud services;
-
when using analytical and technical platforms;
-
when engaging foreign service providers or partners;
-
where required by the nature of the service requested by the client.
Where international transfers take place, the Controller applies safeguards required by applicable legislation.
10. Retention Period
Personal data is retained only for as long as necessary to achieve the purposes for which it was processed.
The retention period is determined taking into account:
-
the nature of the request;
-
the selected service;
-
the duration of contract performance;
-
the period required for processing a visa or other application;
-
accounting and tax requirements;
-
statutory limitation periods;
-
the need to handle complaints;
-
the need to confirm the provision of services;
-
lawful requests from public authorities;
-
backup retention periods.
Where a user requests a consultation or submits an enquiry but no contract is concluded, the relevant data may be retained for a reasonable period necessary for follow-up communication, documenting the history of the enquiry, handling possible complaints, or protecting the Controller’s legitimate interests.
Data relating to clients who received services may be retained after completion of the service for the period required by law or for as long as objectively necessary to confirm the services provided and protect the rights of the parties.
After the applicable retention period expires, personal data is deleted, destroyed, or anonymised unless continued retention is required by law.
11. Protection of Personal Data
The Controller applies appropriate organisational and technical measures to protect personal data against:
-
unlawful access;
-
accidental loss;
-
destruction;
-
alteration;
-
unauthorised copying;
-
unauthorised disclosure;
-
unlawful use;
-
other unlawful forms of processing.
Depending on the information systems used and the nature of the data processed, such measures may include:
-
access rights management;
-
passwords;
-
multi-factor authentication;
-
secure data transmission channels;
-
antivirus protection;
-
backups;
-
software updates;
-
access control for information systems;
-
confidentiality obligations for employees and contractors;
-
physical protection of equipment and documents.
Access to personal data is granted only to persons who require such access for the performance of their professional or contractual duties.
12. Rights of the Data Subject
Within the limits and under the conditions provided by applicable law, the data subject has the right:
-
to know whether their personal data is being processed;
-
to obtain information about the purposes of processing;
-
to access their personal data;
-
to obtain a copy of their personal data;
-
to request rectification of inaccurate data;
-
to complete incomplete data;
-
to request deletion of personal data;
-
to request restriction of processing;
-
to object to processing;
-
to object at any time to the use of personal data for direct marketing purposes;
-
to withdraw previously given consent;
-
to exercise the right to data portability where applicable;
-
to receive information about recipients of personal data;
-
not to be subject to decisions based solely on automated processing where such decisions produce legal or similarly significant effects and no lawful basis applies;
-
to lodge a complaint with the National Center for Personal Data Protection of the Republic of Moldova;
-
to apply to a court for the protection of their rights.
Certain rights may be restricted in cases provided by law, including where continued processing is necessary for contract performance, compliance with a legal obligation, or the establishment, exercise, or defence of legal claims.
13. Exercising Data Protection Rights
To exercise their rights in relation to personal data, users may contact the Controller:
-
by e-mail: support@e-visa.md;
-
at: Republic of Moldova, Chișinău Municipality, 14 Grigore Ureche Street, Office 1;
-
by telephone: +373 79 170 493.
The request should preferably include:
-
first and last name;
-
contact details;
-
the nature of the request;
-
information enabling the relevant application, contract, or service to be identified;
-
the preferred method of receiving a response.
To prevent unauthorised access to another person’s personal data, the Controller may request additional information necessary to verify the identity of the applicant.
Requests will be handled without undue delay and within the time limits established by applicable legislation.
14. Personal Data of Minors
Where documents are prepared for a minor, the Controller may process the child’s personal data to the extent necessary for the provision of the requested service.
Such data must be provided by a parent, legal representative, or another person who has a lawful basis to act on behalf of the minor.
The Controller may request documents confirming the authority of that person.
15. Automated Processing
The Controller may use automated information systems for managing requests, client relationships, website operation, and internal business processes.
The use of automated systems does not mean that decisions regarding visa eligibility are made automatically.
Final decisions on visa approval or refusal are made exclusively by the competent public authorities in accordance with applicable legislation.
16. Cookies
The e-visa.md website may use strictly necessary cookies without which certain website functions may not operate correctly.
Analytical, functional, and advertising cookies are used taking into account the choices made by the user through the website’s cookie management mechanism.
Users have the right to change their preferences or withdraw consent to the use of non-essential cookies.
Detailed information about the technologies used may be provided in a separate Cookie Policy.
17. Third-Party Services and Websites
The website may contain:
-
links to public authority websites;
-
links to banking and payment service websites;
-
links to insurance providers;
-
third-party service elements;
-
analytical tools;
-
communication tools;
-
integrations with external platforms.
Once a user accesses an independent third-party website, personal data processing is carried out by the relevant provider in accordance with its own privacy policy.
The Controller is not responsible for the data processing practices of independent third-party websites, except where the relevant organisation processes personal data directly on behalf of the Controller.
18. User Responsibility for Submitted Documents
The user is responsible for the accuracy of the information and documents submitted to the Controller.
The user undertakes not to submit:
-
forged documents;
-
information known to be false;
-
documents obtained unlawfully;
-
personal data of third parties where there is no lawful basis for providing such data.
The Controller reserves the right to refuse to process documents or provide services where there are reasonable doubts regarding the lawful origin, authenticity, or compliance of the submitted information with applicable legal requirements.
19. No Guarantee of Visa Issuance
Providing personal data, submitting documents, paying for services, or entering into a contract with the Controller does not guarantee the issuance of a visa.
The Controller provides informational, consulting, and document preparation services within the scope of the relevant order.
The decision regarding visa issuance, validity period, number of permitted entries, or visa refusal is made exclusively by the competent public authority.
20. Amendments to this Agreement
The Controller may amend this Agreement periodically, including in connection with changes to:
-
legislation;
-
requirements of public authorities;
-
service provision procedures;
-
the website’s technical infrastructure;
-
information systems used;
-
categories of personal data processed;
-
purposes and methods of processing.
The current version of the Agreement is published on e-visa.md.
The date of the latest revision is indicated at the beginning of the document.
Where amendments materially affect user rights or personal data processing conditions, the Controller may additionally notify users through available communication channels and, where required by law, request renewed consent.
21. Final Provisions
This Agreement is a publicly available document and applies to the processing of personal data through e-visa.md and other communication channels used by the Controller.
Simply visiting or continuing to use the website does not constitute consent to all possible forms of personal data processing.
Where applicable law requires the data subject’s consent, such consent must be obtained through a separate affirmative action by the user.
For any questions regarding the processing, use, or protection of personal data, please contact:
EMG CONSULTING GROUP S.R.L. — e-visa.md
E-mail: support@e-visa.md
Address: Republic of Moldova, Chișinău Municipality, 14 Grigore Ureche Street, Office 1
Telephone: +373 79 170 493