GDPR compliance
What we do to meet Moldova's Law No. 195/2024, the GDPR and UK GDPR, and the documents your legal team will ask for.
We are S.R.L. MARGOVIMER, established in the Republic of Moldova, and primarily subject to Law No. 195/2024 on the protection of personal data (in force from 23 August 2026), overseen by the National Centre for Personal Data Protection (Centrul Național pentru Protecția Datelor cu Caracter Personal, CNPDCP). Because we also offer the Service to people in the EU and UK, the sections below describe how we meet the GDPR and UK GDPR for those users under their extraterritorial scope.
For account data — your name, email and organisation — we are the controller. For the story text, votes and estimates you bring into a room, your organisation is the controller and we are the processor acting on its instructions under Article 28.
Contract for running the Service and billing. Legitimate interests for security and product improvement, with a balancing test available on request. Consent for optional emails and non-essential cookies. Legal obligation for tax records. No automated decision-making with legal effect, and no use of your session content to train models.
Where a processor sits outside the EEA or UK we rely on the Standard Contractual Clauses with the UK Addendum, backed by a transfer impact assessment. The same safeguards cover transfers between us, in Moldova, and our EEA/UK-based processors, since Law No. 195/2024 on the protection of personal data requires equivalent protection for data leaving Moldova. Copies are available on request.
Access, rectification, erasure, restriction, portability and objection. Export and account deletion are self-service in Settings; written requests are answered within one month. Requests about content your employer brought into a room go to them first, and we help them respond.
We keep an Article 30 record of processing, a sub-processor register with 30 days' notice of changes, and staff training on handling personal data. For UK users our UK GDPR representative is [name, address]. Our privacy contact is Andrei Barbier, reachable at privacy@planningpoker.cloud.
Application and database: hosted within the EU by default. Email delivery and monitoring: EU-based providers, or safeguarded by Standard Contractual Clauses where they are not. Canadian hosting is available on Enterprise.
The same rights machinery serves requests under Law No. 195/2024 on the protection of personal data (access, rectification, erasure, restriction, portability, objection — complaints go to the National Centre for Personal Data Protection (Centrul Național pentru Protecția Datelor cu Caracter Personal, CNPDCP)), CCPA/CPRA requests from California, the equivalent state laws elsewhere in the US, and PIPEDA and Quebec Law 25 in Canada. One request form, one 45-day worst case.