Privacy Policy

Last updated: 2 September 2026

1. Who we are (the data controller)

Connect Media Solutions SRL (“the Company”, “we”) is the controller of the personal data collected through this website. Bsmart is the brand we provide our services under and the name this site is known by (bsmart.md); the company legally answerable for your data is the one named above. You can contact us at: info@bsmart.md, +373 790 239 00, Chișinău, Republic of Moldova.

2. What data we collect

  • Data from the contact forms, provided voluntarily: your name, your phone number and, on the blog page, your email address. On the free audit page, your answers to the questionnaire are sent together with the request, so that we can prepare the recommendations.
  • The page you submitted the form from and the traffic source (the utm parameters in the address and the referring page, if any) — so that we know where requests come from. These are read from the page address at the moment of submission; we do not store any identifier for this purpose.
  • IP address — for security and abuse prevention: when a form is submitted it is recorded in full and is then anonymised automatically after 30 days (the last IPv4 segment, or the last IPv6 groups, are removed) — beyond that window there is no reason to keep it whole; for rate limiting it is stored only as a keyed hash, which changes daily; for traffic statistics it is anonymised from the start.
  • Usage data — collected only with your consent: the path of the page visited (without the parameters in the address), the referring site reduced to domain and path (without parameters), the browser language, the device type and browser family (derived from the user agent; the full string is not sent), the screen resolution, a session identifier (valid while the tab is open) and a visitor identifier that is regenerated every 24 hours, so that no profile can be built from one day to the next. Details in section 3.
  • The record of your cookie choice: a random identifier generated in your browser, what you chose for each category, the version of the policy that was on screen and when you decided. It is saved on our server whether you accept or refuse — precisely so that we can show you were asked and what you answered (Art. 7(1) GDPR). It contains no IP address, no visitor identifier and not the page you decided on.

2a. Data received through our CRM platform

Besides the data collected through this website, we process data that reaches us through the CRM platform we build and host for our clients.

When you fill in a form from an advert published on Facebook or Instagram by one of our clients, Meta passes us your answers — usually your name, phone number and email address, together with the questions that client asked in the form. We deliver them into that company’s CRM, and they will contact you.

In this situation the controller of your data is the company that published the advert, not Bsmart. We act as a processor: we handle the data solely on their instructions, under a contract, and never for our own purposes.

For requests about this data you may write to that company directly, or to us at info@bsmart.md — we pass the request on.

3. Cookies and similar technologies

We use the following categories. The two analytics categories can be accepted separately: accepting our own statistics does not start Microsoft Clarity, and the other way round. Refusing costs exactly one click, the same as accepting.

  • Strictly necessary (no consent required): the record of your cookie choice and your language preference (stored in localStorage, on your device) and the session cookie for the admin area, which is set only when an administrator logs in.
  • Our own statistics (optional): hosted on our server — the data listed in section 2, item “Usage data”, with the visitor identifier regenerated every 24 hours. They are aggregated (number of visits, pages, sources, devices), are not combined with the data from forms, and go to no one else.
  • Microsoft Clarity (optional, a separate choice): interaction heatmaps and session recordings. The form and chat fields are marked for masking, so what you type into them does not reach the recording. It sets cookies such as _clck, _clsk, CLID, MUID, and the data is processed by Microsoft, including outside the EU (section 7).

You can change your choice at any time, per category: . If you decline or withdraw consent, that tool is no longer loaded; withdrawing statistics deletes our visitor and session identifiers from your device, and withdrawing Clarity asks its cookies on bsmart.md to expire, while a recording that has already started stops completely on the next page load.

3a. The chat on this site

The chat in the corner of the page runs entirely in your browser: the answers are picked from a fixed list we wrote ourselves. What you type into it is not sent to our server, not stored, and does not reach any external service, and the field is marked for masking, so it does not appear in Microsoft Clarity recordings either. The conversation is gone when you close the page. To actually reach us, use the form or the contact details — the sections above apply there.

4. Purposes of processing

  • To contact you about the services you requested and to prepare personalised offers.
  • To understand how the website is used and to improve it (analytics), only with your consent.
  • To keep the website secure and prevent abuse (forms, automated attacks).

5. Legal basis

Processing is based on your consent for being contacted (ticking the box in the form) and for each analytics tool separately (your choice in the cookie banner), and on our legitimate interest in the security of the website and the prevention of abuse — Article 6(1)(a) and (f).

The applicable law is Law no. 195/2024 on the protection of personal data, in force since 23 August 2026, which replaced Law no. 133/2011 and transposes Regulation (EU) 2016/679 (GDPR). For visitors from the European Union, the GDPR also applies directly. The two instruments share the same article numbering, so the references in this policy hold for both.

The records of your cookie choice (section 2) are the exception: they are saved on the basis of the obligation to be able to demonstrate consent and of our legitimate interest — Article 6(1)(c) and (f) — which is why one is saved when you refuse as well. Asking for consent in order to be able to prove a refusal would make no sense.

6. Where the data goes and who we share it with

Our CRM system (crm.bsmart.md) is our own application, hosted on our own infrastructure. Requests submitted through the forms go there to be handled; with your consent for analytics, the pages you visited also go there together with the visitor identifier (regenerated every 24 hours), so that we can link a request to the pages that preceded it. This is not a transfer to a third party — the data stays with the same controller.

Third parties that may process data on our behalf:

  • Microsoft Clarity (Microsoft) — for analytics, only with your consent.
  • The hosting provider (VPS) — on whose infrastructure our servers run.

For the CRM platform described in 2a, the data is processed by the following providers, on our behalf and the client’s:

  • Hetzner — hosting the platform — Germany.
  • Telegram — notifications to the company’s users — international.
  • Google Cloud — reading scanned documents — United States.
  • Google Cloud — transcribing voice notes — European Union.
  • Anthropic — automated summaries and reports — United States.

Before any text reaches the AI provider, phone numbers, email addresses and identification numbers are substituted automatically. The exception is reading a transaction document, where the details on the document are the very thing being extracted; a person checks the result before it is used.

We keep this data for as long as the contract with the client company lasts, and delete it on their instruction or when the contract ends.

7. International transfers

If you choose to accept the analytics tools, Microsoft Clarity may process data outside the Republic of Moldova and the European Union, including in the United States, on the basis of the adequate-safeguard mechanisms provided by Microsoft (standard contractual clauses, or frameworks such as the Data Privacy Framework). If you decline, this transfer does not take place.

Our own statistics, the forms and the CRM run on our servers. The website fonts are hosted locally, precisely to avoid sending your IP address to external services.

8. How long we keep the data

  • Form data: at most 24 months from submission; the IP address attached to it is anonymised after 30 days, even though the rest of the request is kept longer; requests whose delivery to the CRM failed are kept separately for at most 90 days, so that they can be resubmitted manually.
  • Traffic statistics (with anonymised IP): at most 14 months.
  • The record of your cookie choice: 36 months. Proof of a consent has to outlive the consent itself — otherwise it could no longer answer the question “was this person ever asked?”.
  • Free audit reports: at most 12 months.
  • Security data (rate limiting, login attempts): hours, at most one day.
  • Deletion runs automatically, every day; a backup is made before deletion, and backups are kept for at most 30 days. You can request the deletion of your data at any time.

9. Your rights

You have the right of access, rectification, erasure, restriction, objection, portability and withdrawal of consent at any time (without affecting the lawfulness of the processing carried out before) — Articles 13–22 of Law no. 195/2024. To exercise these rights, write to us at info@bsmart.md; we reply within one month of receiving the request at the latest.

You also have the right to lodge a complaint with the National Center for Personal Data Protection of the Republic of Moldova: str. Serghei Lazo nr. 48, MD-2004, Chișinău; tel. +373 22 820 801; centru@datepersonale.md; datepersonale.md. If you are in the European Union, you may also turn to the supervisory authority in your country.

10. Security

We apply appropriate technical and organisational measures: encrypted connection (HTTPS/TLS), restricted and authenticated access to data, storage of the data files outside the public directory of the server, IP anonymisation in the statistics and a keyed hash for the rate-limiting data.

11. Changes

We may update this policy. Any change will be published on this page, together with the date of the update; your cookie choice is recorded together with the version of the policy you accepted.

12. Contact

For any question about personal data:
Email: info@bsmart.md
Phone: +373 790 239 00
Address: Chișinău, Republic of Moldova

B
Bsmart Assistant
Online