Politica de prelucrare a datelor cu caracter personal
Ultima actualizare: 28.08.2026
PERSONAL DATA PROTECTION REGULATIONS
I. General Provisions
These Regulations establish the conditions, procedures and purposes for processing the personal data of individuals who use the website nestcoffee.md (hereinafter referred to as the “Site”), operated by GOCUPS S.R.L., acting as the personal data controller.
The purpose of these Regulations is to inform data subjects about how their personal data are collected, used, stored, protected and, where applicable, transferred. Personal data processing is carried out in compliance with the provisions of Law No. 195/2024 on the Protection of Personal Data, as well as the principles of lawfulness, fairness, transparency, purpose limitation, data minimization and data security.
II. Personal Data Controller
GOCUPS S.R.L.
Registered office: Str. Burebista 114/2
IDNO: 1024600087688
Phone: 069018827
E-mail: infogocupcoffee@gmail.com
As the personal data controller, GOCUPS S.R.L. determines the purposes and means of processing personal data and takes the necessary measures to protect such data.
III. Categories of Data Subjects
* visitors to the Site;
* persons who create an account;
* customers who reserve products for in-store pickup;
* members of the loyalty program;
* persons who contact us with questions or complaints.
IV. Categories of Personal Data Processed
* e-mail address;
* first and last name (optional);
* telephone number (optional);
* information regarding orders placed: products, quantities, amount, pickup location and time;
* loyalty program information: plan, validity period and history of benefits granted;
* technical security data: device and browser type, IP address and login time.
We do not process bank or card details: the Site does not process online payments; payment is made in the store when the order is picked up. We do not request an IDNP and do not use passwords.
V. Methods of Data Collection
Data are collected directly from the data subject when they log in, complete their profile, place a reservation or activate a subscription. Certain technical data are collected automatically through strictly necessary cookies when visiting the Site.
VI. Purposes of Personal Data Processing
* creating and managing the user account;
* processing and preparing reservations for in-store pickup;
* administering the loyalty program and granting benefits;
* communicating with the data subject regarding their order;
* ensuring account security and preventing unauthorized access;
* fulfilling legal obligations, including accounting and tax obligations;
* sending marketing communications exclusively on the basis of consent.
VII. Legal Basis for Processing
* performance of a contract or pre-contractual steps — for accounts, reservations and subscriptions;
* legal obligation — for accounting and tax records;
* legitimate interest — for Site security and prevention of abuse;
* consent — for marketing communications and for cookies that are not strictly necessary.
VIII. Disclosure of Data to Other Persons
We do not sell or rent personal data.
For the operation of the Site, we use service providers acting as data processors, including website and database hosting services and an e-mail service for sending transactional messages. These providers process data exclusively on our instructions, on the basis of data processing agreements, and the infrastructure used is located within the European Union. We do not transfer personal data to countries outside the European Economic Area.
Personal data may be disclosed to public authorities where required by law.
IX. Retention of Personal Data
* account data — until deletion is requested;
* order data — for the period required by applicable accounting and tax legislation;
* authentication codes — 10 minutes, after which they become unusable;
* records of connected devices — no longer than 30 days from the last activity;
* data processed on the basis of consent — until consent is withdrawn.
X. Data Protection and Security Measures
The Site is served exclusively through a secure HTTPS connection. We implement protection against Cross-Site Request Forgery (CSRF), limits on the number of authentication attempts, session cookies marked as HttpOnly and SameSite, as well as parameterized database queries.
Authentication is performed without a password, using a one-time code sent by e-mail; only the cryptographic hash of the code is stored in the database. Internal access is restricted according to user roles, and administrative actions are recorded in an audit log.
XI. Rights of Data Subjects
* the right to access the personal data being processed;
* the right to rectification of inaccurate data;
* the right to erasure of personal data;
* the right to restriction of processing;
* the right to data portability;
* the right to object, including to direct marketing;
* the right to withdraw consent at any time;
* the right to lodge a complaint with the National Center for Personal Data Protection.
XII. How to Exercise Your Rights
Requests may be submitted by e-mail to infogocupcoffee@gmail.com or by telephone at 069018827. We respond within the time limits established by law. To prevent the disclosure of personal data to unauthorized persons, we may request confirmation of the data subject’s identity.
XIII. Final Provisions
These Regulations may be updated from time to time. The current version is permanently published on this page, together with the date of the latest update.
str. Tighina, 20, Chișinău, MD2001
infogocupcoffee@gmail.com · +373 (690) 18827