Data protection
Privacy Policy
What data we collect through this site, why we collect it, who we share it with, how long we keep it, and how you stay in control of it.
Last updated: 27 August 2026
We process your personal data in accordance with Regulation (EU) 2016/679 (GDPR), where it applies, and with the data protection law of the Republic of Moldova — Law no. 133/2011 and Law no. 195/2024, which adopts the GDPR standards. This page describes exactly what happens to your data on this site: every statement below corresponds to a real processing activity, not to a generic template.
1. Who we are
The controller who decides why and how the data collected through this site is processed is:
- Legal name: AGO Metal SRL
- Registration number (IDNO): «IDNO»
- Registered office: «adresa juridică», mun. Chișinău, Republica Moldova
- Email: houseprint32@gmail.com
- Phone: +373 60 103 888
- Websites: houseprint.md, houseprint.ro
That same email address is the channel through which you exercise the rights described in section 8. We reply within 30 days of receiving a request.
Both stores — houseprint.md and houseprint.ro — are operated by the same company on the same infrastructure. The languages, currencies and delivery methods differ; the data controller does not.
2. What data we collect
We collect strictly what we need in order to deliver your order, answer your questions and keep the site running. We never ask you to create an account, and we never ask for your card details on this site.
- Order data — your name, phone number, email address (optional), delivery address (country, plus district and locality in Moldova, or city and postal code elsewhere), the contents of the order and any notes you write.
- Contact form data — your name, phone number, email address (optional), the service you are interested in and your message.
- Technical data collected automatically — IP address, browser type and version, operating system, device type, language, date and time of access, and the page requested. These reach the server logs with every request, as on any website.
- Data about how you use the site — pages opened and actions such as adding a product to the cart or submitting a form, tied to a temporary session identifier (
hp_session_id) that is randomly generated and disappears when you close the tab. It is not linked to your name and does not follow you between visits. - Card details — these never reach us. For card payments, card details are entered directly on the secure Stripe page and never pass through our servers. All we receive from Stripe is confirmation that the payment succeeded or failed, the amount, and a transaction identifier.
- Data stored in your browser — your shopping cart (
houseprint-cart), your cookie choice (hp_consent), the delivery country you selected (hp_country) and the session identifier above. Full details are in section 4.
We do not knowingly collect special categories of data — concerning health, ethnic origin, political, religious or trade union beliefs, sex life or biometric data — and we ask that you do not send us such information through the form or in your order notes.
3. Purposes and legal bases
Every processing activity has a stated purpose and a legal basis. Here they all are:
| Purpose | Data used | Legal basis |
|---|---|---|
| Taking, producing and delivering your order, and contacting you about it | Name, phone, email, delivery address, order contents | Performance of a contract — art. 6(1)(b) GDPR |
| Answering the message you sent through the contact form and preparing a quote | Name, phone, email, selected service, your message | Pre-contractual steps at your request — art. 6(1)(b) GDPR |
| Collecting payment and preventing fraudulent transactions | Order data, the payment confirmation received from Stripe | Performance of a contract — art. 6(1)(b); legitimate interest — art. 6(1)(f) |
| Issuing sales documents and keeping accounting and tax records | Order and invoicing data | Legal obligation — art. 6(1)(c) GDPR |
| Keeping the site running, protecting it from abuse and investigating errors | Technical data, server logs | Legitimate interest — art. 6(1)(f) GDPR |
| Understanding which pages and products interest visitors, so we can improve the site | Usage events, the temporary session identifier | Legitimate interest — art. 6(1)(f) GDPR |
| Measuring whether one of our own ads led to an order | Click identifiers and Google advertising cookies | Your consent — art. 6(1)(a) GDPR |
| Defending ourselves in a complaint, dispute or inspection | The data relevant to that case | Legitimate interest — art. 6(1)(f) GDPR |
Where we rely on legitimate interest, we have weighed that interest against your rights and chosen the least intrusive option that still does the job — usage statistics, for instance, use an identifier that dies when you close the tab rather than a persistent profile. You can object to these activities at any time; see section 8.
We do not take automated decisions with legal effect on you, and we do not build behavioural profiles beyond measuring our own advertising campaigns.
5. Who we share data with
We do not sell your data and we do not hand it to anyone for somebody else’s marketing. We share it only with those we need in order to operate, and only as much as they need:
| Recipient | What they receive | Why |
|---|---|---|
| The courier or delivery company | Your name, phone number and delivery address | To bring you your order |
| Stripe Payments Europe, Ltd. (Ireland) | Card details, entered directly with them, the amount, and your email address if you provided one | Processing card payments, on orders from outside Moldova |
| Telegram FZ-LLC | The internal notification the team receives, containing your order or message details | Alerting us the moment an order or message arrives, so we can respond quickly |
| Google Ireland Limited | Advertising cookie identifiers and the conversion event — only if you accepted | Measuring our own Google Ads campaigns |
| Cloudflare, Inc. (R2 service) | Catalogue and gallery images, not customer data | Storing the site’s images |
| The provider of the server the site runs on | Technically everything that passes through the site, in their capacity as infrastructure provider | Hosting the site and the database |
| Our accountants and, on request, the competent authorities | Sales documents | Accounting, tax and legal obligations |
Each of these providers processes the data only on our instructions and under a contract imposing confidentiality and security measures. Authorities are the exception: they act under their own legal powers.
6. Transfers outside the European Economic Area
Our company is established in the Republic of Moldova, and the servers and database are located outside the European Economic Area. So if you write to us or order from the EU or EEA, your data reaches a third country within the meaning of Chapter V of the GDPR.
These transfers rely on the safeguards set out in Chapter V of the GDPR — principally the standard contractual clauses adopted by the European Commission — against the background of Moldovan data protection law, which adopts the GDPR standards through Law no. 195/2024. Some of the providers in section 5, such as Google or Cloudflare, may also process data outside the EEA, likewise under standard contractual clauses.
You can request a copy of the applicable safeguards at the email address in section 1.
7. How long we keep data
We keep each category of data for as long as we need it for the stated purpose, then delete or anonymise it.
| What | How long |
|---|---|
| Orders and the related accounting documents | As long as the applicable accounting and tax law requires, at least 5 years from the end of the financial year |
| Messages received through the contact form | 2 years from the last exchange |
| Server logs | 12 months |
| Site usage events | 24 months |
| Your cookie choice | 1 year, after which we ask again |
| Google Ads cookies | Per Google’s policies, up to 90 days |
If a complaint, dispute or inspection arises, we keep the relevant data until it is finally resolved, even if the period in the table has passed.
8. Your rights
In respect of your data you have the following rights, which you can exercise at any time:
- Access — to find out what data we hold about you and to receive a copy of it.
- Rectification — to have incorrect or incomplete data corrected, for example a mistyped delivery address.
- Erasure — to have data deleted once we no longer have a legitimate reason to keep it. We cannot delete documents that accounting law obliges us to archive.
- Restriction — to have processing paused, for example while we look into an objection of yours.
- Portability — to receive the data you gave us in a structured, machine-readable format.
- Objection — to object to processing based on our legitimate interest, including usage statistics.
- Withdrawal of consent — to withdraw your acceptance of advertising cookies, at any time and without giving a reason. Withdrawal does not affect processing lawfully carried out beforehand.
- Not to be subject to automated decisions — no such decisions are made on this site.
Send your request to houseprint32@gmail.com. It is free, and you will have an answer within 30 days. If we cannot identify you from the request itself, we may ask for additional information — an order number, for instance — strictly so that we do not hand your data to somebody else.
If you are unhappy with how we handled your request, you have the right to lodge a complaint with a supervisory authority: in the Republic of Moldova with the National Center for Personal Data Protection (datepersonale.md), in Romania with the National Supervisory Authority for Personal Data Processing (dataprotection.ro), and elsewhere in the EU or EEA with the authority of the country where you live or work. You also have the right to go to court.
9. Data security
The measures we actually take, not a list of intentions:
- All traffic to the site is encrypted with HTTPS.
- Card details never touch our servers — they are entered directly with Stripe, which is PCI DSS certified.
- The admin panel is reachable only with an individual account and password, and passwords are stored hashed, never in the clear.
- Access to orders and messages is limited to the team members who need it to do their work.
- The database is backed up regularly, and the backups are protected to the same standard as the original data.
No measure offers an absolute guarantee, however. Should a security breach occur that may affect your rights, we notify the supervisory authority within 72 hours and inform you directly where the risk is high.
10. Children’s data
The site is not aimed at children and we do not knowingly collect data from anyone under 16. An order means a contract, so an adult places it. If you are a parent or guardian and believe we have received your child’s data, write to us and we will delete it.
11. Changes to this policy
We update this policy whenever what we do with data changes — a new provider, a new purpose, a new legal obligation. The date of the last update is shown at the top of the page, and if a change is significant we announce it on the site as well, not only here.
For any question about this policy or about your data, write to houseprint32@gmail.com or call +373 60 103 888.
You can withdraw your consent
Advertising and measurement cookies are only set if you accept them, and you can change your mind at any time, as easily as you gave it. The button below erases your saved answer and brings the consent banner back so you can choose again.
