Skip to content

Privacy statement

Last updated: 2026-09-08

Storm Energy SRL (the TSYNC brand) respects the privacy of your data. This statement explains what personal data we process, for what purpose, on what legal basis, who we share it with, how long we keep it and what rights you have.

1. Data controller

The controller of your personal data is Storm Energy SRL (IDNO 1021600044877), based in Chișinău, Republic of Moldova, which operates the tsync.pro website and the TSYNC brand.

For any data protection matter, including exercising your rights, write to us at privacy@tsync.pro (or at our general address, contact@tsync.pro).

You can also call us on +373 786 77 888. The phone is our general contact line; please still send requests about your rights in writing, to privacy@tsync.pro, so that we can acknowledge receipt and track the statutory one-month deadline.

The person accountable for data protection within the company is Mihail Tornea, CEO and co-founder. Requests sent to privacy@tsync.pro reach him and are tracked through to an answer.

For clarity: this is not a data protection officer within the meaning of art. 37 of Law no. 195/2024 or art. 37 GDPR. Our processing does not fall within any of the three cases where designation is mandatory — we are not a public authority, we do not carry out large-scale systematic monitoring and we do not process special categories of data on a large scale. We have nevertheless designated an accountable person so that your requests always have a named recipient, and the decision is documented internally.

2. Applicable legal framework

We process data in accordance with Law no. 195/2024 on personal data protection (applicable from 23 August 2026), which replaces Law no. 133/2011 and transposes European standards into the law of the Republic of Moldova.

Where you are located in the European Union or the European Economic Area, processing also complies with Regulation (EU) 2016/679 (GDPR), since we directly address clients in Romania, Ukraine and other European countries.

Storm Energy SRL has no establishment, branch, subsidiary or representative office in the European Union. The projects we deliver in Romania, Bucharest included, are run from our office in Chișinău, through travel to the client and through our local partner — not through stable arrangements of our own on Union territory. The GDPR therefore applies to us under art. 3(2) GDPR, because we offer services to people located in the Union, and not under art. 3(1).

We have not designated a representative in the Union within the meaning of art. 27 GDPR, because we fall within the exception in art. 27(2)(a): the processing carried out through this site is occasional and low in volume, limited to professional contact details, does not amount to monitoring, includes no special categories of data or data relating to criminal convictions, and is unlikely to result in a risk to the rights and freedoms of individuals. We review this position periodically and will designate a representative, publishing their details here, if the volume or nature of our processing changes so that the exception no longer applies.

3. What data we collect

We collect only the data needed for the purpose pursued (data minimisation). Through the contact form or by email we collect:

  • your first name and, if you fill it in, your last name;
  • your email address;
  • your phone number (optional);
  • the subject of your request (optional; it may be pre-filled with the package you came from on the pricing page);
  • the content of your message and any data you choose to include in it;
  • technical data generated automatically on submission: IP address, date and time of submission, and the result of the anti-spam check.

We do not always receive your data directly from you. We may also obtain it indirectly: from a referral made by one of our clients or partners, from a business card or a QR/vCard exchanged at a meeting, from a trade fair, conference or other professional event we attend, or from public professional sources — your company website, public registers, your professional profile.

In those situations we obtain the same categories of professional contact details: name and surname, job title, company, email address and sometimes a phone number. We do not build profiles and we do not buy contact lists.

Where we obtain your data indirectly, we inform you about the processing at the first contact we have with you, telling you the source and pointing you to this statement, in line with art. 14 of Law no. 195/2024 and art. 14 GDPR.

If you write to us through a messaging channel — Facebook Messenger, Instagram Direct or WhatsApp — the data we receive from the platform is different and is described separately in section 4.

4. Messages you send us through messaging channels

If you write to us on Facebook Messenger, Instagram Direct or WhatsApp, your message is delivered into our internal conversation system, where a colleague reads it and replies — not a bot.

  • What we receive from the platform: the content of your message and any files attached to it, the public name or username of the account you write from, your public profile picture, a technical conversation identifier (scoped to our page — it is not your account) and the time of the message;
  • Why: so that we can answer you, and so that we can recognise that you are the person we have spoken to before or already have an order or a quotation for. Without it, every message would look like it came from a stranger and we would ask you for the same details again and again. The basis is the conversation you started with us and our legitimate interest in keeping a record of the commercial relationship (art. 6(1)(b) and (f));
  • What we do not do: we do not use this data for advertising, we do not sell it, we do not pass it to other companies and we do not build profiles from it. It stays in our own system, accessible only to our team;
  • How long we keep it: for as long as the conversation is relevant, and we delete it 24 months after the last interaction, like the rest of our messages;
  • Deletion: write to privacy@tsync.pro and we will delete the conversation and the associated profile data.

Please note that the platform you wrote to us through (Meta) keeps its own separate copy of the conversation under its own rules. We can delete only our copy; that copy has to be requested from them.

5. What the form tick-box means

The tick-box "I have read and acknowledge the Privacy statement" confirms that you have been informed — it is not consent to processing. Processing your message is not based on consent but on the bases described in section 6. You therefore do not need to "withdraw" the tick to object: you may object or request erasure at any time, as set out in section 11.

6. Purposes and legal bases

We process your data only for the purposes below, each with its own legal basis (art. 6 of Law no. 195/2024 and art. 6 GDPR):

  • To answer your enquiry and prepare a quote or consultation — basis: steps taken at your request prior to entering into a contract (art. 6(1)(b));
  • To manage the business relationship and our correspondence, where you write on behalf of an organisation — basis: our legitimate interest in responding to business enquiries and running our business (art. 6(1)(f));
  • To protect the form against spam and automated abuse (Turnstile check, IP address, anti-flood filter) — basis: our legitimate interest in site security (art. 6(1)(f));
  • To comply with legal, accounting and tax obligations, if your enquiry becomes a contractual relationship — basis: legal obligation (art. 6(1)(c));
  • To come back to you with a follow-up you have expressly asked for — for example to let you know when a feature, a service or an availability becomes real — basis: steps taken at your request prior to a contract (art. 6(1)(b)) or, as the case may be, our legitimate interest in acting on a request we received (art. 6(1)(f)). Such a request covers strictly the subject you indicated and does not amount to consent to commercial or marketing communications;
  • To receive and answer the messages you send through Facebook Messenger, Instagram Direct or WhatsApp, and to link the conversation to your customer record — basis: steps taken at your request (art. 6(1)(b)) and our legitimate interest in keeping a record of the commercial relationship (art. 6(1)(f)); the detail is in section 4;
  • To establish, exercise or defend legal claims where necessary — basis: legitimate interest (art. 6(1)(f)).

7. What we do not do with your data

  • we do not sell or rent your data;
  • we do not use it for behavioural advertising or profiling;
  • we do not send you newsletters or marketing messages without separate consent, which you can withdraw at any time;
  • we do not make automated decisions producing legal effects concerning you, and we do not subject you to automated profiling;
  • we do not request or want special categories of data (health, beliefs, biometric data etc.) — please do not include them in your message.

8. Who else has access to the data (processors)

We do not disclose your data publicly. The following categories of providers may process it strictly to let us operate and only on our instructions, bound by contractual confidentiality and security obligations (art. 28 of Law no. 195/2024 and art. 28 GDPR):

  • our web and email hosting provider, which stores the site and the mailboxes (infrastructure located in the United Kingdom);
  • Cloudflare, Inc. — for the Turnstile anti-spam verification of the form;
  • Google — the provider of the secondary business mailbox into which certain work messages are imported or duplicated;
  • professional service providers (accounting, legal advice), only if your enquiry becomes a contractual relationship;
  • public authorities, exclusively where we are under a legal obligation to disclose information to them.

9. International data transfers

As a company in the Republic of Moldova serving European clients, data may cross borders. We transmit data to the providers in section 8 located in the United Kingdom and, in Cloudflare's case, in other jurisdictions.

If you are located in the European Union and you send us the data yourself — through the contact form, by email or at a meeting — the data reaches the Republic of Moldova because you chose to approach a company based here. In that situation there is no data exporter separate from you, and the direct collection does not in itself constitute a transfer within the meaning of Chapter V of the GDPR; it remains subject to all the other obligations of the Regulation, which we undertake through this document.

The situation is different where, in the course of a collaboration, we receive data from a client in the Union — for example the data of their employees or customers, needed for the service under contract. There an exporter does exist, and the transfer to us is made on the basis of the standard contractual clauses adopted by the European Commission, together with the supplementary measures required by the transfer assessment. The Republic of Moldova is not, to date, the subject of an adequacy decision.

From 23 August 2026 the Republic of Moldova applies a framework aligned with the GDPR, and transfers out of Moldova are made only to jurisdictions ensuring an adequate level of protection or on the basis of appropriate safeguards.

10. How long we keep the data

  • messages received through the form and related correspondence: we keep them for as long as the discussion is live and review them at least once a year. Deletion follows the first trigger event — you tell us you are no longer interested or ask for erasure, we decide internally that no collaboration will follow, or 24 months pass from the last interaction without the discussion resuming;
  • messages received through messaging channels (Messenger, Instagram Direct, WhatsApp) and the associated profile data: the same periods as for correspondence through the form — erasure 24 months after the last interaction, or earlier if you ask us;
  • data relating to a contractual relationship: for the duration of the contract and thereafter per statutory archiving and limitation periods;
  • accounting and tax documents: for the periods required by the law of the Republic of Moldova;
  • technical anti-spam data (the IP address recorded in the notification email): kept together with that message and deleted along with it.

Data kept for a follow-up you asked for (section 6) stays with us until the request loses its object — you tell us you no longer want to be contacted, we have actually told you the feature is available, or we decide not to release it — and in any case for no longer than 24 months from the request.

Once these periods expire we delete the data or irreversibly anonymise it.

11. Your rights

Under art. 13-22 of Law no. 195/2024 and the corresponding GDPR articles, you have the following rights:

  • the right to be informed about processing — which we honour through this document;
  • the right of access to your data and to a copy of it;
  • the right to rectification of inaccurate or incomplete data;
  • the right to erasure ("the right to be forgotten"), under the conditions set by law;
  • the right to restriction of processing;
  • the right to data portability;
  • the right to object to processing based on legitimate interest, on grounds relating to your particular situation;
  • the right not to be subject to an automated individual decision — which we do not carry out in any case;
  • the right to withdraw consent at any time, where a processing activity is based on consent (for example a newsletter you subscribed to separately).

12. How to exercise your rights

Send us a request at privacy@tsync.pro. We reply within one month of receiving it at the latest; if the request is complex we may extend that period, informing you beforehand of the reasons.

Exercising your rights is free of charge. We may ask for additional information only if we have reasonable doubts about your identity, strictly to avoid disclosing data to an unauthorised person.

13. Right to lodge a complaint

If you believe we have infringed your rights, please write to us first at privacy@tsync.pro — we can usually resolve the matter directly.

You are nevertheless always entitled to lodge a complaint with the supervisory authority: National Center for Personal Data Protection of the Republic of Moldova (CNPDCP), str. Serghei Lazo 48, MD-2004, Chișinău, tel. +373 22 820 801, email centru@datepersonale.md, datepersonale.md.

If you are located in the European Union, you may equally address the supervisory authority of your member state of residence, place of work or place of the alleged infringement.

14. Data security

We apply technical and organisational measures appropriate to the risk (art. 32 of Law no. 195/2024 and art. 32 GDPR):

  • TLS encrypted connections for the site and for form submission;
  • message delivery over authenticated SMTP, with SPF, DKIM and DMARC email authentication;
  • mailbox access limited to the people who need it, with unique passwords;
  • anti-spam and anti-abuse protection of the form;
  • regular software updates and backups.

15. Security incidents

If a security incident affects your personal data and presents a risk to your rights and freedoms, we notify the supervisory authority within 72 hours of becoming aware of it and inform you directly where the risk is high, in line with art. 33-34 of Law no. 195/2024 and of the GDPR.

16. Children's data

Our site and services are addressed to organisations and professionals. We do not knowingly collect children's data. If you learn that a child has sent us personal data, write to us and we will delete it without delay.

17. Changes to this statement

We may update this statement when the way we process data or the applicable legal framework changes. We always publish the version in force on this page, together with the date of the last update. The current version is dated 2026-09-08.