Novalines Logo
RO
Novalines Logo
RO

Privacy Policy

and Personal Data Processing Policy

Data ControllerNova Lines Operation Center S.R.L.
IDNO1024600005505
Headquarters6 Decebal Blvd., Chișinău municipality, Republic of Moldova
Privacy Contactprivacy@novalines.com
Version / Effective DateVersion 1.1 / 23.08.2026

Important note for website users

Accessing the website does not, in itself, constitute consent for any type of processing and does not grant the Company a general or unlimited right over the data. Each processing activity must have a specific, explicit, and legitimate purpose, an appropriate legal basis, and be limited to the necessary data.

1. Purpose and scope

This Policy explains how Nova Lines Operation Center S.R.L. (the “Company”, “we”) collects, uses, stores, transmits, and protects personal data through the website, electronic forms, email addresses, and other digital channels managed by the Company.

The Policy applies to website visitors, persons contacting us, candidates, clients, potential clients, suppliers, partners, and their representatives, insofar as their data is collected or transmitted to the Company.

This Policy is an information notice regarding data processing. It does not transform website access into general consent and does not replace the distinct agreements that may be necessary for certain optional processing activities.

1.1. Distinction from internal notices and regulations

This Policy primarily refers to data collected through the website, forms, emails, and other public or digital channels associated with the website. Processing carried out within employment relationships is additionally governed by separate internal notices and documents, communicated to data subjects according to their category. Technical details regarding security architecture, system configurations, internal access rules, and audit logs are not published in full to avoid creating additional security risks.

2. Data Controller

In relation to data collected through the website and the channels managed by the Company, Nova Lines Operation Center S.R.L. generally acts as a data controller, as it determines the purposes and means of the processing. In certain situations, the Company may process data as a data processor, based on the instructions of a client or contractual partner. In such cases, the processing may also be governed by the notices or policies of that respective controller.

3. Categories of data subjects

  • website visitors and users
  • persons submitting messages, requests, or complaints
  • candidates and persons submitting CVs
  • clients, potential clients, suppliers, and partners
  • representatives, employees, or contact persons of certain organizations
  • persons subscribing to communications or participating in events
  • persons whose data is included in documents submitted to the Company

4. Data we may process

  • first and last name
  • email address, phone number, and other contact details
  • company, job title, experience, and other professional data
  • content of the message, request, or complaint
  • data included in the CV, including the voluntarily submitted photograph
  • data regarding contracts, services, communications, and commercial relationships
  • IP address, device, browser, and session identifiers
  • data regarding website access and usage
  • technical data regarding website security, performance, and operation
  • data collected through cookies or similar technologies, according to the dedicated section

We do not request the submission of sensitive data unless strictly necessary, there is a legal basis, and they are used in accordance with applicable legislation. Individuals are kindly requested not to submit through forms or email any medical data, banking data, data about criminal convictions, or other sensitive information that is not explicitly requested.

4.1. Source of data

Data is generally collected directly from the data subject. To the extent permitted by law, data may also originate from representatives of an organization, clients, partners, suppliers, professional platforms, public sources, or authorized service providers. When data is not collected directly from the data subject, the Company will provide the necessary information under the conditions and within the timeframe provided by law, except in situations where a legal exception applies.

5. Purposes of processing

Depending on the actual activity, the channel used, and the relationship with the person, data may be processed for the following purposes:

  • operation, administration, maintenance, and security of the website
  • identifying and fixing technical errors
  • preventing cyber-attacks, fraud, abuse, and unauthorized access
  • responding to requests, messages, complaints, and inquiries
  • communicating with clients, potential clients, suppliers, partners, and their representatives
  • preparing, concluding, and executing contracts
  • providing services and managing commercial relationships
  • providing call-center, dispatch, operational support, and communication services with drivers, clients, and brokers
  • managing data regarding vehicle movement, location, speed, and activity, when necessary for providing the services
  • recruiting and evaluating candidates
  • verifying CVs, experience, and qualifications
  • communicating with candidates and organizing interviews
  • retaining CVs for future professional opportunities, in accordance with the law
  • managing employment relationships, training, and performance evaluation
  • calculating and paying salaries, bonuses, and other rights
  • fulfilling tax, accounting, social security, and labor record-keeping obligations
  • preventing and investigating fraud, disciplinary offenses, information theft, and unauthorized data use
  • controlling access to the premises and securing persons, property, and information
  • using CCTV systems, audio-video recordings, and, if justified, biometric systems
  • monitoring the use of the Company’s IT systems, networks, accounts, devices, and applications
  • recording and controlling calls for operational, training, documentation, and quality assurance purposes
  • managing incidents, security breaches, and emergency situations
  • ensuring occupational health and safety
  • managing medical data strictly to the extent permitted by law and necessary for fulfilling employer obligations
  • managing internal reports and whistleblowing reports
  • establishing, exercising, and defending the Company’s rights in disputes, investigations, or administrative procedures
  • fulfilling requests from public authorities and legal obligations
  • conducting internal and external audits
  • managing relationships with suppliers, processors, and service providers
  • using email, cloud, hosting, VPN, software, security, and IT support services
  • storing, archiving, recovering, and in a controlled manner destroying data
  • ensuring business continuity and disaster recovery
  • making international data transfers when necessary for the Company’s activity
  • communicating commercial information, offers, and marketing materials, under the law
  • managing subscriptions and unsubscriptions from communications
  • conducting statistical and performance analyses
  • improving services, processes, and user experience
  • testing and developing new products, services, applications, or processes
  • using automated tools and artificial intelligence solutions, in compliance with transparency, security, and human oversight requirements
  • organizing events, training, and representation activities
  • publishing photos or materials about the Company’s activity, only based on an appropriate legal basis
  • fulfilling corporate governance, risk management, and compliance requirements
  • evaluating corporate transactions, reorganizations, mergers, acquisitions, or due diligence processes
  • using cookies and similar technologies, according to the Cookie Policy
  • protecting the rights, property, reputation, and legitimate interests of the Company
  • any other purpose permitted by law, provided it is specific, explicit, legitimate, and communicated to the individual prior to processing

The list above is a list of possible purposes, not an automatic authorization to use all data for all purposes. The Company will activate and use only those processing activities that are actually necessary for the business and documented in its internal registers and procedures.

5.1. Purposes and legal bases depending on the category of the person

a) If you are a website visitor — We may process technical data, such as IP address, session identifiers, and browser data, for operation, security, and abuse prevention. The legal basis can be technical necessity and/or the legitimate interest of the Company. Refusing non-essential cookies does not prevent access to the core content of the website.

b) If you are a client, potential client, or representative of an organization — Data may be processed to initiate, negotiate, and execute the contractual relationship, provide services, manage communications, invoicing, support, security, and defend the Company’s rights. The legal basis is, as applicable, the contract, a legal obligation, or legitimate interest.

c) If you are a candidate — The data from the CV, message, and recruitment communications are processed to evaluate the application, verify professional information, organize interviews, and communicate the result. The legal basis may be taking steps prior to entering into a contract, legitimate interest, or consent. Retaining the CV for future opportunities is a separate and optional processing activity.

d) If you subscribe to commercial communications — Contact data may be used to send commercial information only in accordance with the law and, where applicable, based on consent. Providing data for this purpose is voluntary and you can opt out at any time.

e) If you are a supplier, service provider, or partner — Data may be processed for supplier selection and evaluation, contract management, payments, communications, audit, security, and compliance with legal obligations. The legal basis may be the contract, a legal obligation, or the legitimate interest of the Company.

6. Legal bases for processing

Depending on the situation, processing may be based on:

  • execution or preparation for the execution of a contract
  • compliance with a legal obligation
  • the legitimate interest of the Company, following an assessment of necessity and proportionality
  • the consent of the individual, when required
  • the establishment, exercise, or defense of legal claims before authorities or courts
  • protecting the life, physical integrity, or security of persons or property, in situations permitted by law

The Company will not use consent as a legal basis when the processing can be legally carried out based on the execution of a contract, a legal obligation, or a documented legitimate interest.

7. Website access and voluntary data submission

Accessing the website does not constitute consent for any type of processing and does not grant the Company the right to use the data for unlimited purposes. By browsing the website, technical data strictly necessary for its operation and security may be processed.

The voluntary submission of a message, email, CV, photograph, or other document allows the Company to receive and use that data to review the request, communicate with the person, and carry out related steps. This submission does not authorize the use of the data for incompatible, unlimited, or unforeseen purposes in this Policy.

8. CVs, photographs, and recruitment

  • CV data is used to evaluate the application and communicate with the person
  • information may be consulted by departments involved in recruitment
  • data may be transmitted to hosting, email, storage, recruitment, or IT support providers, when necessary
  • the CV may be kept for the period established in the internal retention policy
  • retaining the CV for future opportunities is done separately, based on an appropriate legal basis or consent, as applicable
  • submitting a photograph in the CV does not grant the Company the right to publish or use it in marketing; for such uses, a separate agreement may be necessary

9. Disclosure of data to third parties

Data may be accessed or disclosed, as appropriate, to:

  • authorized employees and departments, within the limits of their duties
  • hosting, email, cloud, IT maintenance, security, and technical support providers
  • recruitment, analytics, or communication service providers
  • consultants, auditors, lawyers, and other authorized service providers
  • clients or partners, when disclosure is necessary for a contractual purpose
  • public authorities, courts, or investigative bodies, when required or permitted by law

The Company does not sell personal data. If a supplier processes data on behalf of the Company, they will act only based on documented instructions and contractual obligations regarding confidentiality and security.

10. International transfers

Some services used by the Company may involve storing or accessing data outside the Republic of Moldova, including through cloud services, email, hosting, security applications, VPNs, or IT providers. International transfers are carried out only when necessary for the Company’s activity and in compliance with applicable legislation, based on adequate contractual, technical, and organizational safeguards. The list of providers and applied mechanisms is managed in the Company’s internal registers.

11. Retention period

Data is kept only as long as necessary for the purpose of collection, contract execution, compliance with legal obligations, dispute resolution, or defending the Company’s rights.

CategoryIndicative period
Messages and requests24 months from the last communication
CVs for current recruitment12 months, unless there is a legal reason for a longer period
CVs for future opportunities12 months or the period indicated in the person’s agreement
Contractual and accounting dataThe period provided by applicable legislation
Technical and security logs36 months
CookiesAccording to the Cookie Policy

Upon expiration of the period, data is deleted, anonymized, or archived, according to applicable legislation and internal procedures.

12. Data subjects' rights

Under the law, the individual may request:

  • access to their data
  • rectification of incorrect or incomplete data
  • erasure of data, when legal conditions are met
  • restriction of processing
  • objection to certain processing activities
  • data portability, when applicable
  • withdrawal of consent, without affecting the lawfulness of prior processing
  • information regarding purposes, legal bases, recipients, and retention period
  • to challenge a decision based solely on automated processing, if applicable

The request can be submitted to privacy@novalines.com or at the Company’s headquarters. To protect data, the Company may request additional information to verify the applicant’s identity.

13. Data security

The Company applies reasonable technical and organizational measures to protect data, including access control, individual accounts, passwords and appropriate authentication, limiting access to what is strictly necessary, backups, incident monitoring, staff training, and breach response procedures. No method of electronic transmission or storage can be guaranteed to be absolutely secure. Individuals are kindly requested not to send via email or forms data that is not necessary for the purpose of the request.

14. Automated tools and artificial intelligence

The Company may use automated tools or artificial intelligence solutions for administrative operations, analysis, security, recruitment, support, or service improvement. Confidential or sensitive data will not be inputted into unauthorized AI tools. Automated tools will not be used to make decisions with legal effects or significant impact on a person without assessing the legality, transparency, proportionality, and the possibility of human intervention.

15. Cookies and similar technologies

The website may use strictly necessary cookies, functionality cookies, analytics cookies, marketing cookies, and similar technologies. Strictly necessary cookies may be used for the operation and security of the website. Analytics, marketing, or third-party cookies will be activated only after a valid choice has been made, when applicable legislation requires it.

CookieProviderPurposeDuration
_gaGoogle AnalyticsDistinguish unique users2 years
_gidGoogle AnalyticsDistinguish users (session)24 hours
_ga_*Google AnalyticsPersist session state2 years
cookie_consentnovalines.mdStore consent preference1 year (localStorage)

You can withdraw consent at any time by clearing localStorage in your browser. Learn more: policies.google.com/privacy.

16. Commercial communications

The Company may send commercial information, offers, or news only under the conditions permitted by applicable legislation. The individual can opt out of commercial communications at any time by using the unsubscribe option or by sending a request to the indicated contact address.

17. Complaints and competent authority

If the individual believes that the processing of their data violates the legislation, they can contact the Company at privacy@novalines.com. The individual also has the right to file a complaint with:

National Center for Personal Data Protection of the Republic of Moldova
180 Ștefan cel Mare și Sfânt Blvd., Chișinău, MD-2004
www.datepersonale.md

18. Policy modification

The Company may update this Policy to reflect legislative, technical, or organizational changes. The updated version will be published on the website and will indicate the date of the modification. In case of substantial changes, the Company may use additional means of information when necessary.