Version of 4 October 2026
1. Who processes your data
The personal data controller of the ADL.MARKET online store (the “Controller”, “we”):
ADL TRADE S.R.L., IDNO 1025600024518
Registered address: mun. Chișinău, sec. Râșcani, str. Gheorghe Madan nr. 87/7
Office: str. Serghei Lazo nr. 40, etaj 7, Chișinău, MD-2005
Warehouse (pickup and returns): 10 Nicolae Dimo Lane, Durlești, Chișinău
Phone: +373 79 909 980 · E-mail: info@adl.market · Mon–Fri, 09:00–18:00
This policy explains what data about customers and visitors of adl.market we process, why, on what legal basis, with whom we share it, how long we keep it and how you can exercise your rights. For any question about personal data, write to info@adl.market with the subject “Personal data”.
2. Legal framework
We process personal data in accordance with Law of the Republic of Moldova No. 133/2011 on personal data protection and any acts amending or replacing it, and with Law No. 284/2004 on electronic commerce (as regards commercial communications). We also follow the principles and standards of the EU General Data Protection Regulation — Regulation (EU) 2016/679 (GDPR) — and, where it applies to the processing (Art. 3 GDPR), its provisions. References to GDPR articles below are given for clarity.
We adhere to the principles of lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality (Art. 5 GDPR).
3. What data we process
- Contact details: first and last name, phone number, e-mail address; for legal entities — name, IDNO, registered address and contact person details;
- Order data: delivery address and locality, delivery and payment method, order contents and amount, comments, order history, enquiries and returns;
- Payment data: payment method, amount, status and date; for bank transfers — the payer's details from the payment document. Bank card data is covered in section 5;
- Account data: e-mail, password (stored only as a cryptographic hash), saved addresses, language, e-mail verification status, registration and last sign-in dates;
- Correspondence with us by phone, e-mail and messaging apps;
- Technical data: IP address, browser and device type, date and time of requests — in server logs and for abuse prevention;
- Consent records: identifier and date of the decision, document version, chosen cookie categories, language and browser type; newsletter subscription, its confirmation and unsubscription;
- Site usage and location data — only if the relevant services are enabled and you have consented (section 7).
We do not collect special categories of data (health, religious beliefs, etc.). Mention allergies or dietary needs in an order comment only if necessary.
4. Purposes and legal bases
- placing, paying for and delivering orders, returns and complaints — entering into and performing the contract (Art. 6(1)(b) GDPR);
- managing your account and order history — performance of the contract (Art. 6(1)(b));
- service messages about orders, payment and delivery — performance of the contract (Art. 6(1)(b));
- answering enquiries — performance of the contract or our legitimate interest in good customer service (Art. 6(1)(b), (f));
- newsletters and promotions — your separate consent (Art. 6(1)(a) GDPR, Law No. 284/2004);
- web analytics, personalisation, location data and advertising — your consent (Art. 6(1)(a));
- site security and prevention of fraud and promotion abuse — our legitimate interest (Art. 6(1)(f));
- accounting and tax records, responding to lawful requests from authorities — compliance with legal obligations (Art. 6(1)(c));
- proving consents obtained and defending our rights in disputes — legal obligation and our legitimate interest (Art. 6(1)(c), (f)).
Fields marked as required in the order form are needed to conclude the contract: without them we cannot accept and deliver the order. Consent to newsletters, analytics, personalisation and advertising is not a condition of purchase. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).
5. Payments
Orders are currently paid by bank transfer. In that case we only process the data in the payment document: payer, amount, date and payment reference.
When we enable card payments, they will be processed by the acquiring bank in its secure PCI DSS-compliant payment page with 3-D Secure authentication. The card number, expiry date and CVV are entered only on the bank's page — we neither receive nor store them. From the bank we will receive only the transaction result: amount, status, date, payment identifier and the masked card number. Saving a card for future purchases, if offered, will happen only with your consent, and you will be able to remove the card at any time. The bank also processes data as an independent controller under Law No. 114/2012 on payment services and electronic money and other financial regulations.
6. Newsletters
We send marketing and informational messages only to people who have given separate consent and confirmed the subscription via the link in our e-mail. You can unsubscribe at any time — via the link in every message, in your account or by writing to us; messages then stop. Service messages about your orders are not marketing and are sent regardless of your subscription. We keep records of subscription and unsubscription to prove consent and to avoid contacting you after you opt out.
7. Cookies, analytics and location
As of this version, the site uses only strictly necessary cookies; web analytics and advertising services are not enabled. If we enable them, they will load only after you consent to the relevant category, and they will be listed in the Cookie policy. Precise location may be requested only after you consent to the “Personalisation and location data” category and separately allow it in your browser. You can change or withdraw your consent at any time in “Cookie settings” at the bottom of the site.
8. Recipients
We share data only to the extent necessary for a specific purpose:
- couriers and delivery services — name, phone, address and order details for delivery;
- banks — to receive payments and make refunds: BC „MAIB” S.A. and, once card payments are enabled, the acquiring bank and card schemes;
- IT service providers — hosting and databases, e-mail delivery, file storage and backups. They act as processors on our instructions under contracts requiring confidentiality and data security (Art. 28 GDPR);
- analytics and advertising services — only if enabled and you have consented;
- accountants, auditors and lawyers — where necessary and subject to confidentiality;
- public authorities — in the cases and manner provided by law.
We do not sell or rent personal data. We will provide the current list of our processors on request.
9. International transfers
Some IT service providers may process data outside the Republic of Moldova, including in EU countries and the USA. We transfer data only to countries ensuring an adequate level of protection or subject to appropriate safeguards — such as standard data protection clauses — in accordance with Law No. 133/2011 and Chapter V GDPR. On request, we will tell you which safeguards apply.
10. Retention periods
- account data — until the account is deleted;
- orders, invoices and payment documents — for the periods set by Law No. 287/2017 on accounting and financial reporting and the Tax Code;
- correspondence and complaints — until the matter is resolved and limitation periods expire;
- newsletter data — until consent is withdrawn; unsubscription records — as long as needed to honour it;
- cookie consent records — for the validity of the consent (12 months) and up to 3 years afterwards, to prove that consent was obtained;
- technical logs — no more than 12 months;
- analytics data, if such a service is enabled — no more than 14 months.
When these periods expire, data is deleted or anonymised.
11. Data security
We apply technical and organisational measures: encrypted connections (HTTPS), passwords stored only as hashes, role-based and monitored staff access, staff confidentiality obligations, backups and logging of order changes. In the event of a personal data breach we will notify the National Center for Personal Data Protection and, where required by law, you.
12. Your rights
Under Law No. 133/2011 and Articles 15–22 GDPR you have the right to:
- be informed about the processing of your data and access it, including obtaining a copy;
- have inaccurate data corrected or incomplete data completed;
- have your data erased, including your account — except data we are legally required to keep;
- have processing restricted (blocked);
- receive the data you provided in a structured, machine-readable format and transmit it to another controller;
- object to processing based on our legitimate interest, and to direct marketing at any time without giving reasons;
- withdraw consent at any time — this does not affect the lawfulness of processing before withdrawal;
- not be subject to decisions based solely on automated processing.
To exercise your rights, write to info@adl.market from the address used in your account or order, or contact our office. We may ask you to verify your identity so that we do not disclose data to someone else. We respond without undue delay and within the time limits set by law; handling requests is free of charge.
If you believe we are infringing your rights, you may lodge a complaint with the National Center for Personal Data Protection of the Republic of Moldova (datepersonale.md) or go to court. We would appreciate it if you contacted us first — we will try to resolve the issue.
13. Minors
Orders may be placed by persons over 18. The site is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has given us their data, contact us and we will delete it.
14. Changes
We may update this policy, for example when enabling new services. The current version, with its date, is always published on this page. We will announce material changes on the site and ask for consent again if we expand the list of optional cookies.
15. Legislation
- Law of the Republic of Moldova No. 133/2011 on personal data protection;
- Law No. 284/2004 on electronic commerce;
- Law No. 114/2012 on payment services and electronic money;
- Law No. 287/2017 on accounting and financial reporting;
- Regulation (EU) 2016/679 (GDPR);
- Directive 2002/58/EC on privacy and electronic communications (ePrivacy).
This document is published in Romanian, Russian and English; in case of discrepancy, the Romanian version prevails.








