Privacy and security policy
Last updated: 24.09.2026.
Vault2Trust Privacy and Security Policy
This Privacy and Security Policy explains how Vault2Trust collects, uses, stores, protects and, where applicable, transfers the personal data of users, clients, company representatives and other persons whose data is entered into or managed through the Vault2Trust Platform.
This document has been prepared in accordance with Law No. 133 of 8 July 2011 on Personal Data Protection of the Republic of Moldova, as well as the generally applicable principles of data protection. From the date on which Law No. 195/2024 on Personal Data Protection enters into force, this Policy shall be interpreted and applied in accordance with the new applicable legal framework.
By creating an account, accessing the Platform, using the services, uploading data, inviting users or purchasing a subscription, the user confirms that they have read and understood this Policy.
1. Personal Data Controller
Name: "Zei Invest I" SRL
Registered office: Republic of Moldova, municipality of Chișinău
Website: https://vault2trust.com
Contact email: [email protected]
In this Policy, Vault2Trust SRL shall hereinafter be referred to as “Vault2Trust”, the “Controller”, the “Provider” or the “Platform”, as applicable.
2. Vault2Trust’s Role: Controller and Processor
Vault2Trust may act in two different capacities depending on the type of data and the purpose of processing.
2.1. Data Controller
Vault2Trust acts as a data controller for data collected directly in connection with:
a) account creation and administration;
b) user identification;
c) subscription administration;
d) invoicing and payment processing;
e) Platform security;
f) operational communications;
g) commercial communications, where the user has provided consent when required;
h) technical support;
i) the contractual relationship;
j) compliance with legal, accounting, tax and security obligations.
In these situations, Vault2Trust determines the purposes and means of processing the data.
2.2. Processor
Vault2Trust may act as a processor for personal data entered, uploaded or managed by the Client through the Platform concerning the Client’s own clients, employees, collaborators, beneficiaries, suppliers or other persons.
In this case, the Client determines the purposes and means of processing, while Vault2Trust processes the data in accordance with the Client’s instructions, the Terms and Conditions, this Policy and the Data Processing Agreement.
The Client is responsible for informing data subjects, obtaining the necessary consents, establishing the lawful basis for processing and ensuring that the data entered into the Platform is collected and used lawfully.
3. Categories of Data Processed
Vault2Trust may process the following categories of personal data:
3.1. Identification Data
a) first name and last name;
b) company name;
c) IDNP, in the case of natural persons, where necessary;
d) IDNO, in the case of legal entities;
e) the position or capacity of the representative;
f) data contained in documents uploaded to the Platform.
3.2. Contact Data
a) email address;
b) telephone number;
c) postal address;
d) country, city, street and postal code;
e) other contact information provided by the Client or Authorised Users.
3.3. Authentication Data
a) email address;
b) account password;
c) session tokens;
d) authentication-related data.
Passwords are stored exclusively as cryptographic hashes. Vault2Trust does not have access to passwords in plain text.
3.4. Platform Activity Data
a) logins;
b) date and time of access;
c) actions carried out through the account;
d) documents uploaded;
e) documents generated;
f) tasks, activities, statuses, notes and comments;
g) timestamps;
h) change history;
i) roles and permissions granted to users.
3.5. Payment Data
Vault2Trust may process information regarding subscription payments, including:
a) order number;
b) bank transaction identifier;
c) amount paid;
d) payment currency;
e) date and time of the transaction;
f) payment status;
g) the last four digits of the card, where these are transmitted by the payment processor.
Vault2Trust does not store the full bank card number, CVV code or other sensitive card information. Such data is processed exclusively by VictoriaBank or the payment processor used, through their respective infrastructure.
3.6. Technical Data
a) IP address;
b) browser user agent;
c) device type;
d) operating system;
e) preferred language;
f) technically necessary cookies;
g) session information;
h) technical security logs.
3.7. Data Entered by the Client About Other Persons
The Platform may allow the Client to enter data concerning natural persons, including, without limitation:
a) first name, last name, email address, telephone number and address;
b) IDNP, identification data, company data and position;
c) accounting, tax, legal or commercial documents;
d) documents uploaded by the Client or Authorised Users;
e) data concerning activities, tasks, deadlines, notes, comments, statuses and operational history;
f) technical metadata concerning access, changes and actions carried out through the Platform.
Vault2Trust processes such data exclusively for the provision of the Platform, security, backups, technical support, operational auditing, prevention of abuse, compliance with legal obligations and performance of the agreement with the Client.
4. Purposes of Processing
Vault2Trust processes personal data for the following purposes:
a) providing the contracted CRM services;
b) creating, administering and securing the account;
c) identifying and authenticating users;
d) administering roles and permissions;
e) processing subscription payments;
f) issuing payment documents, invoices or other required records;
g) communicating technical information and account notifications;
h) sending notifications regarding subscriptions, security, support or amendments to the terms;
i) providing technical support;
j) investigating errors, technical incidents or security issues;
k) improving the Platform;
l) creating backups;
m) preventing fraud, abuse and unauthorised access;
n) complying with legal, accounting, tax and archiving obligations;
o) defending the rights and legitimate interests of Vault2Trust;
p) sending commercial communications only under the conditions permitted by law.
5. Lawful Basis for Processing
Vault2Trust processes personal data on the basis of the lawful grounds provided by applicable legislation, including:
a) the consent of the data subject, where required;
b) performance of the agreement or taking steps prior to entering into the agreement;
c) compliance with the Controller’s legal obligations;
d) the Controller’s legitimate interest in Platform security, fraud prevention, service administration, technical support, defence of rights and maintenance of Platform functionality;
e) other lawful grounds permitted by applicable legislation.
For commercial or marketing communications, Vault2Trust shall request separate consent where required by applicable legislation.
6. Sensitive Data and Special-Category Data
The Client must not enter sensitive data or special-category data into the Platform unless it has a clear lawful basis and implements appropriate protective measures.
Depending on applicable legislation, sensitive data may include:
a) health-related data;
b) racial or ethnic origin;
c) political opinions;
d) religious or philosophical beliefs;
e) biometric data;
f) genetic data;
g) trade union membership;
h) sex life or sexual orientation;
i) criminal convictions;
j) other categories protected by law.
Where the nature of the Client’s activities requires the processing of such data, the Client is responsible for verifying the lawfulness of the processing and informing Vault2Trust if additional contractual or technical measures are required.
Vault2Trust reserves the right to suspend or limit the processing of certain data where there is a legal, technical or security risk.
7. Data Processing Agreement
For clients that use the Platform to enter or manage the personal data of other persons, this Policy is supplemented by the Data Processing Agreement.
The Data Processing Agreement establishes:
a) the subject matter and duration of processing;
b) the nature and purpose of processing;
c) the types of personal data;
d) the categories of data subjects;
e) the Client’s obligations;
f) Vault2Trust’s obligations;
g) the rules applicable to subprocessors;
h) security measures;
i) the procedure applicable in the event of security incidents;
j) the return, export or deletion of data;
k) the assistance provided to the Client in complying with the rights of data subjects.
By accepting the Terms and Conditions and using the Platform, the Client also accepts the Data Processing Agreement.
8. Recipients of the Data
Personal data may be accessed by or transferred, to the extent necessary, to the following categories of recipients:
a) authorised Vault2Trust personnel;
b) VictoriaBank or the payment processor used, for payment processing;
c) providers of infrastructure, hosting, cloud, email, backup, security, technical monitoring and support services;
d) IT service providers involved in maintenance, security or operation of the Platform;
e) consultants, accountants, auditors, lawyers or other professionals, where necessary for compliance with legal obligations or the defence of Vault2Trust’s rights;
f) public authorities, courts, tax authorities, supervisory authorities or other competent institutions, where there is a legal obligation or a valid lawful request.
Vault2Trust does not sell personal data and does not transfer data to third parties for commercial, marketing or behavioural advertising purposes without a lawful basis or express consent, as applicable.
9. Subprocessors
Vault2Trust may use third-party providers to deliver the Platform, including hosting, cloud infrastructure, email, payment processing, backup, security, technical monitoring and support services.
These providers may have limited access to personal data only to the extent necessary to provide the services contracted by Vault2Trust.
Vault2Trust shall use reasonable efforts to engage subprocessors that provide appropriate guarantees regarding security, confidentiality and data protection.
Vault2Trust may publish a list of its principal subprocessors or provide such a list upon request.
The Client may submit a reasoned objection regarding a new subprocessor where that subprocessor creates a genuine and documented risk to data protection.
10. International Data Transfers
Vault2Trust is established in the Republic of Moldova. Technical infrastructure, cloud services, email, payments or other ancillary services may involve data transfers to or access from other countries, including Member States of the European Union, the European Economic Area or other jurisdictions.
Where data is transferred to a jurisdiction that does not provide an adequate level of protection under applicable legislation, Vault2Trust shall, where necessary, implement appropriate contractual, technical and organisational safeguards, including contractual clauses, security measures, access limitations and confidentiality obligations.
The Client understands that use of the Platform may involve data processing through international digital infrastructure to the extent necessary to provide the service.
11. Retention Period
Vault2Trust retains personal data only for as long as necessary for the purposes for which it was collected, for performance of the agreement, compliance with legal obligations, defence of rights and Platform security.
The general retention periods are:
a) account data — for the duration of the account and contractual relationship, plus the period required for legal, accounting and tax obligations or the defence of rights;
b) payment data — for at least five years or another period required under applicable tax and accounting legislation;
c) documents and data entered by the Client — for the duration of the subscription and thereafter for the period necessary for export, deletion, backup or compliance with legal obligations;
d) access and security logs — generally for up to 12 months, with the possibility of longer retention where necessary for security, incident investigation, fraud prevention or the defence of rights;
e) session cookies — generally until the session expires or up to 120 minutes after the last activity, depending on the Platform’s technical settings;
f) backup data — temporarily, until overwritten or deleted during the ordinary backup cycle.
After the applicable retention periods expire, the data may be deleted, anonymised or retained in a restricted form where permitted or required by law.
12. Rights of Data Subjects
Under applicable legislation, data subjects may have the following rights:
a) the right to be informed;
b) the right of access to personal data;
c) the right to rectify inaccurate or incomplete data;
d) the right to erasure, under the conditions provided by law;
e) the right to restriction of processing;
f) the right to object;
g) the right to data portability, where applicable;
h) the right to withdraw consent where processing is based on consent;
i) the right not to be subject to a decision based solely on automated processing, where applicable;
j) the right to lodge a complaint with the competent data protection authority.
For data processed by Vault2Trust as Controller, requests must be sent to [email protected].
For data entered by the Client into the Platform concerning its own clients, employees, collaborators, suppliers or other persons, data subject requests should primarily be addressed to the Client because the Client determines the purposes and means of processing.
Vault2Trust shall provide reasonable assistance to the Client in responding to such requests, to the extent permitted by the Platform’s functionalities and applicable law.
Requests received directly by Vault2Trust shall generally be handled within a maximum of 30 calendar days, except where the law permits or requires a different period.
13. Security Incidents
Vault2Trust implements reasonable technical and organisational measures to protect data. However, no digital system can guarantee absolute security.
In the event of a security incident affecting personal data, Vault2Trust shall analyse the incident, take measures to limit its effects and notify the Client, data subjects or the competent authority, as applicable, within the period required by applicable legislation.
The Client is responsible for notifying data subjects and competent authorities where it has such a legal obligation in its capacity as data controller.
Vault2Trust may retain logs, technical evidence and relevant information for the investigation of incidents, prevention of future incidents and defence of its rights.
14. Security Measures
Vault2Trust may implement the following security measures:
a) HTTPS/TLS encryption for communications between the browser and the server;
b) storage of passwords as cryptographic hashes;
c) use of a unique salt or similar technical mechanisms for password protection, where applicable;
d) role- and permission-based access control;
e) logging of significant actions within the Platform;
f) periodic backups;
g) regular security updates for software components;
h) restriction of internal access to data;
i) authentication and password policies;
j) technical monitoring for errors, abuse and suspicious activity;
k) separation of access between client accounts;
l) restoration procedures in the event of a technical incident;
m) payment processing through the infrastructure of the bank or payment processor;
n) training of authorised personnel or restriction of their access;
o) measures to prevent unauthorised access.
Vault2Trust may modify its security measures over time, provided that it does not materially reduce the overall level of protection afforded to Client Data.
The Client is responsible for the security of its own devices, passwords, email accounts, networks, invited users and permissions granted through the Platform.
15. Children and Minors
The Platform is intended for professional use by adults, companies, organisations and Authorised Users.
The Platform is not intended for children and must not be used by persons who have not reached the legal age required to enter into an agreement.
The Client must not enter data relating to minors unless it has a clear lawful basis and complies with applicable legislation.
16. Cookies
Vault2Trust uses cookies and similar technologies that are necessary for the operation of the Platform.
The Platform may generally use:
a) a session cookie necessary to maintain the authenticated state;
b) a cookie for language preferences;
c) cookies or technical tokens necessary for account security and functionality.
Vault2Trust does not use tracking, marketing or behavioural advertising cookies unless this is expressly indicated and user consent is requested where required by law.
The user may control cookies through browser settings. However, disabling technically necessary cookies may affect the operation of the Platform.
17. Operational and Commercial Communications
Vault2Trust may send operational communications necessary for the operation of the account, including notifications concerning security, subscriptions, invoicing, amendments to terms, support, incidents and important functionalities.
These communications are necessary for the provision of the service and cannot be fully disabled while the account remains active.
Commercial or marketing communications shall be sent only under the conditions permitted by law and, where necessary, on the basis of the user’s separate consent.
The user may unsubscribe from commercial communications by using the mechanism available in the message or by contacting Vault2Trust at [email protected].
18. Supervisory Authority
In the Republic of Moldova, data subjects may lodge complaints with:
National Centre for Personal Data Protection of the Republic of Moldova
Website: https://datepersonale.md
For persons located in the European Union, European Economic Area, United Kingdom or other jurisdictions, competent local authorities may exist under applicable legislation.
19. Amendments to the Policy
The current version of this Policy is published at:
https://vault2trust.com/privacy
Vault2Trust reserves the right to amend this Policy to reflect legislative, technical, operational, commercial or security-related changes.
Material amendments shall be announced by email, Platform notification or another reasonable method at least 30 days before entering into force, except in urgent cases required by law, security considerations or Platform operation.
Continued use of the Platform after the amendments enter into force constitutes acceptance of the updated version of the Policy, except where the law requires express consent.
20. Contact
For any questions, requests, complaints or enquiries concerning personal data protection, users may contact Vault2Trust at:
Email: [email protected]
Registered office: Republic of Moldova, municipality of Chișinău
Website: https://vault2trust.com
Requests concerning access, rectification, deletion, objection, restriction of processing or other rights relating to personal data must be sent to [email protected].