This policy explains how personal data is processed for WebFundament services offered internationally. We follow applicable data protection laws, including Law 195/2024 of the Republic of Moldova and the GDPR where they apply to you or to our processing.
1. Operator and contact
The operator for this site is Dioartis Grup SRL (IDNO 1011600003727), MD-2020, mun. Chișinău, str. Calea Orheiului 109/3, Republic of Moldova. Website: webfundament.com. Client Area: clients.webfundament.com.
Privacy and data-subject requests: support@webfundament.com (this is the operational mailbox; a dedicated privacy alias is not published). Abuse: abuse@webfundament.com.
We have not appointed a Data Protection Officer. Requests are handled by the operator’s privacy contact above.
2. Two roles
- Controller (operator) — client accounts, billing, fraud prevention, security of our platforms, marketing where consented, and the contractual relationship.
- Processor (împuternicit) — personal data that you host on our servers as part of your websites, email or applications, processed on your documented instructions under the DPA.
3. Processing matrix
| Activity | Data | Purpose | Legal basis | Recipients | Retention | Transfers |
|---|---|---|---|---|---|---|
| Website visit | Technical logs, language/theme, consent record | Operate and secure the site | Legitimate interest / contract steps | Hosting infrastructure | Limited operational period | May involve EU/US locations as used for the service |
| Analytics | GA identifiers after consent | Audience measurement | Consent | Per Google defaults until withdrawn | Google (may be outside MD/EU) | |
| Client Area | Identity, auth, invoices | Provide the account | Contract; legal obligation (tax) | WHMCS platform, payment providers | Account life + legal/tax | As needed for providers |
| Payments | Payment references (card data handled by providers) | Collect fees, antifraud | Contract; legitimate interest | maib, PayPal, Blockonomics | Per provider + accounting | Provider locations |
| Domains | Registrant data you supply | Register/renew domains | Contract; registry legal duty | Registrar/registry | Per registry rules | Registry locations |
| Hosting / VPS | Service config, server logs, hosted content | Deliver hosting | Contract; processor role for hosted PII | Infrastructure; subprocessors listed | Service life + backup window | Product location (as sold) |
| Support / Amevia | Tickets, optional chat | Support | Contract; consent for optional chat features | Amevia (chat) | While useful for the support relationship | Amevia locations |
| Contact / Solutions forms | Name, email, message, optional budget/domain | Respond / quote | Pre-contract steps / legitimate interest | Internal mail | As needed to handle the request | Mail hosting |
| Public tools | URL/domain/IP you submit; share payloads | Run the tool | Legitimate interest in providing the tool | See Tools Terms | Share links ~24 hours | Depends on the tool |
4. Website and analytics
Google Analytics (G-J7M31K09N8) loads only after Analytics consent. See the Cookie Policy and Cookie preferences.
5. WHMCS, accounts and login
The Client Area runs on WHMCS. We process account and invoice data to deliver services and prevent fraud. Google Identity / social login is used only if that feature is offered on the login page at the time you use it.
6. Billing and payments
Payment processors currently used include maib card payments, PayPal, and Blockonomics (Bitcoin and USDT), as offered at checkout. Card data is handled by the payment provider, not stored by us as full PAN.
7. Domains and WHOIS
Domain registration requires sharing registrant data with the registrar/registry as required. WHOIS or privacy-proxy availability depends on TLD rules — see Domain Terms.
8. Hosting, VPS, email and backups
We process technical data needed to operate servers, email and backups. WHMCS product descriptions currently list weekly backups for Starter Hosting and daily backups for Pro, Business and Enterprise hosting. You remain responsible for application-level data and your own copies.
9. Ticketing and Amevia
Tickets and optional Amevia chat messages are processed to provide support. Do not send passwords or secrets in chat. Amevia analytics/personalization/resume follow cookie preferences (default deny). Authenticated identity is not enabled automatically for chat.
10. Contact and Solutions forms
Contact and Solutions forms are submitted by POST. We use the data to respond to the enquiry or to prepare a quote. Marketing emails require a separate, unticked checkbox. reCAPTCHA may run on those forms when configured, which involves a transfer to Google.
11. Abuse reports
Abuse reports sent to abuse@webfundament.com are processed to investigate and take action. Provide URLs/IPs and evidence; do not send unrelated personal data.
12. Public tools and share links
Public tools may process URLs, domains, IPs, DNS or text you submit. Some tools run in the browser; others query our servers. Share links, where offered, are stored for about 24 hours. Do not submit confidential data. See Free Tools Terms.
Domain name “AI suggestions” on this website are generated locally from keywords in the browser; they are not sent to an external LLM.
13. Logs, IP and antifraud
We process IP addresses, timestamps and security events to operate and protect the platform and to prevent fraud. These are kept for a limited operational period.
14. Recipients
Confirmed categories: payment providers (PayPal, maib, Blockonomics); Amevia chat; Google (Analytics after consent; reCAPTCHA on protected forms); WHMCS Client Area platform; registrar/registry for domains. See Subprocessors.
15. International transfers
Services may involve infrastructure in the EU and other locations as marketed. Where personal data is transferred internationally, we rely on lawful transfer tools required by applicable law (for example adequacy decisions or standard contractual clauses). Details of subprocessors appear on the Subprocessors page.
16. Retention
We retain account and billing data while the account is active and afterwards as needed for legal, tax, accounting and dispute purposes. Support records are kept while useful for the support relationship. Platform backups follow the Backup Policy. We do not publish unverified day-counts as if they were contractual.
17. Automated decisions
Fraud and abuse systems may use automated signals (risk scoring, captcha). They do not produce solely automated legal effects about you without human review where required by law.
18. Your rights
Depending on applicable law (Law 195/2024 and the GDPR where it applies), you may request access, rectification, erasure, restriction, objection and portability where available. We respond within one month, with lawful extensions where permitted. Submit requests to support@webfundament.com.
19. Complaints
You may lodge a complaint with the National Center for Personal Data Protection of the Republic of Moldova (CNPDCP) at datepersonale.md, or with another competent supervisory authority (including your local authority in the EU/EEA where applicable).
20. Security and incidents
We apply technical and organisational measures appropriate to risk. Personal data breach notification follows legal deadlines (including the 72-hour authority notification duty where applicable).
21. Children
Services are directed to adults and businesses. We do not knowingly collect data from children for marketing.
22. Updates
We will post updates with a new version and effective date. Material changes may also be notified by email or Client Area notice.