PRIVACY POLICY – SICRO TRAVEL

Document version: 2.0
Last updated: 26 August 2026

This Privacy Policy explains how SICRO TRAVEL collects, uses, stores and transfers personal data in connection with the use of the sicro.md website, requests for offers, bookings, the purchase and provision of travel services, communications with clients and related activities.

Personal data are processed in accordance with Law No. 195/2024 on the Protection of Personal Data and other applicable legislation.

The personal data controller is:

S.R.L. SICRO TRAVEL

Trade names: SICRO Travel and Cunoaște-ți Țara
IDNO: 1019600049121
Registered office: 118 Suceava Street, Apt. 59, Chișinău Municipality, Republic of Moldova
Office / place of business: 102 Mitropolit Dosoftei Street, Office 4, Chișinău Municipality, Republic of Moldova, MD-2012
Official telephone numbers: +373 60 61 41 41, +373 22 01 11 41, +373 68 27 27 72
General e-mail: contact@sicro.md
Data protection e-mail: datepersonale@sicro.md
Website: www.sicro.md

The address datepersonale@sicro.md is the dedicated channel for requests concerning personal data protection.

SICRO TRAVEL seeks to ensure that personal data are:

  • processed lawfully, fairly and transparently;
  • collected for specified, explicit and legitimate purposes;
  • limited to what is necessary for the relevant purpose;
  • accurate and, where necessary, kept up to date;
  • retained only for as long as necessary;
  • protected through appropriate technical and organisational measures.

We do not intentionally request more data than are necessary for the relevant service or purpose.

Depending on the service requested and the way in which you interact with SICRO TRAVEL, we may process:

  • first name and surname;
  • telephone number;
  • e-mail address;
  • data necessary to identify and manage the booking;
  • information regarding the trip, destination, travel period, accommodation and selected services;
  • date of birth and nationality, where necessary;
  • data from a passport, identity card or other travel documents where required for transport, accommodation, insurance, visas, tickets or border crossing;
  • information concerning payments, invoices, receipts and other financial or accounting documents;
  • requests, messages, complaints and correspondence with SICRO TRAVEL;
  • recordings of telephone conversations made through the IP telephony system where recording is active;
  • preferences relating to commercial communications and information necessary to demonstrate the giving, amendment or withdrawal of consent;
  • photographs and video recordings made during trips;
  • technical information relating to website use, such as IP address, device type, browser, technical logs and cookie-related information, depending on the technologies used and the preferences expressed.

Important: for online payments, SICRO TRAVEL does not request that full bank card details, CVV/CVC codes or other banking authentication information be sent by e-mail, messaging applications or ordinary forms.

In most cases, the data are provided directly by you.

In certain situations, we may also receive data:

  • from a person making a booking for several travellers;
  • from a family member or representative;
  • from a company or organisation purchasing travel services for participants;
  • from an agency, tour operator or other partner involved in the booking;
  • from suppliers involved in providing the service where this is necessary for the management of the booking.

If you make a booking for other persons and provide us with their data, please ensure that the information is accurate and that those persons are aware that their information will be used for the organisation of the trip.

5.1. Offers, enquiries and bookings

We may use personal data for:

  • responding to enquiries;
  • preparing offers;
  • checking availability;
  • making and managing bookings;
  • preparing contracts and related documentation;
  • organising transport, accommodation, transfers, insurance, excursions and other services;
  • communicating information required before and during the trip.

Legal basis: Article 6(1)(b) of Law No. 195/2024 – performance of a contract or taking steps at the request of the individual before entering into a contract.

5.2. Legal, tax and accounting obligations

Personal data may be used for issuing and retaining tax, accounting and payment documents and for complying with other obligations established by law.

Legal basis: Article 6(1)(c) – compliance with a legal obligation to which SICRO TRAVEL is subject.

5.3. Complaints, prevention of abuse and protection of rights

We may use the information necessary for:

  • handling complaints and disputes;
  • verifying services provided;
  • preventing fraud and abuse;
  • protecting systems and communications;
  • establishing, exercising or defending legal rights.

Legal basis: depending on the circumstances, performance of the contract, compliance with a legal obligation and/or the legitimate interests of SICRO TRAVEL under Article 6(1)(f) of Law No. 195/2024.

5.4. Correspondence and communications with SICRO TRAVEL

When you contact us by e-mail, website forms, telephone, messaging applications or other official channels, we may process and retain your message, contact details, the date and time of the communication, attached documents and the responses provided.

This information is used to handle your request, manage your booking and, where necessary, retain a record of communications between the parties.

5.5. Marketing

Promotional communications are sent only through the channels for which the individual has validly expressed a preference to receive such communications.

These may include, as applicable:

  • WhatsApp;
  • Viber;
  • SMS;
  • e-mail;
  • marketing telephone calls;
  • direct messages through Facebook;
  • direct messages through Instagram;
  • direct messages through TikTok.

Legal basis: Article 6(1)(a) – the consent of the data subject.

Consent may be amended or withdrawn at any time.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Important: communications relating to the contract, payment, required documents, departure time and location, coach number, guide details, changes to the programme or other information necessary for the trip are not marketing communications.

Not all data requested by SICRO TRAVEL are mandatory.

However, certain information is necessary for entering into or performing the contract or for complying with legal obligations.

For example, without certain information contained in travel documents, we may be unable to:

  • issue a ticket;
  • make a hotel booking;
  • arrange insurance;
  • request a transport service;
  • complete formalities required for international travel.

In such circumstances, failure to provide the required information may make it impossible to provide the relevant service.

Data requested solely for marketing purposes are optional. Refusing or withdrawing marketing consent does not affect your ability to book or take part in a trip.

When organising trips, we may process personal data relating to minors where necessary for booking, transport, accommodation, insurance, issuing documents or other travel services.

As a rule, such data are provided by a parent, legal representative or the person responsible for the booking.

SICRO TRAVEL seeks to limit the processing of minors' data to the information necessary to provide the service and comply with applicable legal obligations.

Personal data may be disclosed only to the extent necessary to provide the service, manage the booking or comply with legal obligations.

Depending on the service booked, recipients may include:

  • hotels and other accommodation providers;
  • transport operators;
  • airlines;
  • guides and local service providers;
  • tour operators and partner agencies;
  • insurance companies;
  • operators or administrators of services or attractions included in the trip;
  • payment processors and banking institutions;
  • IT and hosting providers;
  • telephony and communications providers;
  • CRM providers and other systems used to manage customer relationships;
  • processors acting on behalf of SICRO TRAVEL;
  • public authorities where disclosure is required or permitted by law.

SICRO TRAVEL seeks to provide recipients only with the information necessary for the service in which they are involved.

SICRO TRAVEL does not sell or rent customer databases or customers' personal data to third parties.

For certain payments, SICRO TRAVEL uses services provided by banking institutions and/or payment processors, including PAYNET and MAIB, depending on the payment method selected.

The information required to authorise an online payment is entered into the technical environment provided by the payment processor or banking institution.

SICRO TRAVEL does not request that customers send CVV/CVC codes, banking passwords, authentication codes or other confidential card security information by e-mail, WhatsApp, Viber or other ordinary communication channels.

The organisation of international travel sometimes requires personal data to be transferred outside the Republic of Moldova.

For example, information required for a booking may be transferred to a hotel, transport provider, tour operator, airline, insurer, guide or local service provider in the country where the relevant service will be provided.

International transfers are carried out in accordance with Chapter V of Law No. 195/2024.

Depending on the circumstances, a transfer may take place on the basis of an adequacy decision, appropriate safeguards or another situation permitted by law.

Where necessary for organising the trip, the transfer may also take place where it is necessary for the performance of a contract with the Traveller or for entering into or performing a contract with a supplier in the Traveller's interest.

SICRO TRAVEL seeks to ensure that only the personal data necessary for the provision of the relevant service are transferred.

Personal data are not retained for longer than necessary for the purpose for which they were collected, except where a longer period is required to comply with a legal obligation, handle a complaint or defend a legal right.

11.1. Bookings and contracts

Data relating to bookings, contracts and services provided are retained for the period necessary to perform the contractual relationship and thereafter for as long as required to comply with legal obligations, handle complaints and protect the rights of the parties.

11.2. Financial and accounting documents

Invoices, tax documents, payment records and other financial and accounting documents are retained for the periods required by applicable law.

11.3. Passports and travel documents

Data and copies of travel documents are retained only for as long as necessary for booking, providing the service, complying with legal obligations or resolving matters relating to the trip.

Where retention of the full document is no longer necessary, it may be deleted or access to it may be restricted, as appropriate.

11.4. Correspondence

Messages, e-mails, enquiries and complaints may be retained for as long as necessary to handle them and thereafter for a period justified by the nature of the customer relationship, the need to evidence communications and any applicable legal obligations.

11.5. Telephone call recordings

Recordings of calls made through the IP telephony system are retained for a period of no more than 365 days from the date of recording.

If a specific recording is required to handle a complaint, investigate an incident or defend a right, it may be extracted and retained separately for as long as necessary to resolve the relevant matter.

11.6. Marketing

Personal data used for commercial communications are processed until consent is withdrawn or preferences are changed.

Following withdrawal, SICRO TRAVEL may retain a minimal record of the preference expressed, including information necessary to demonstrate the withdrawal and prevent the unintentional resumption of marketing communications.

11.7. Cookies and technical data

Such information is retained in accordance with the lifespan of the relevant technology or cookie and the configuration of the preference management system available on the website.

Once the applicable period expires, the data are deleted, anonymised or, where a legal obligation exists, retained with restricted access.

Acceptance of commercial communications is separate from the purchase of a travel service.

You may choose the channels through which you wish to receive information about trips, offers and promotions and may later amend those preferences.

Withdrawal of consent may be requested through the mechanisms made available by SICRO TRAVEL or by sending a message to:

datepersonale@sicro.md

After marketing consent has been withdrawn, SICRO TRAVEL may continue to send communications necessary for existing bookings or contracted services.

During SICRO TRAVEL trips, photographs and video recordings may be made for the purpose of documenting activities and presenting organised trips.

Participation in group photographs is optional.

If you do not wish to appear in a group photograph, you may choose not to enter the frame or may step out of it without this affecting your participation in the trip.

The use of images in which an individual is identifiable is carried out according to the context and purpose and in accordance with personal data protection legislation and image rights.

If you recognise yourself in material published by SICRO TRAVEL and no longer wish your image to be used, you may request its removal or, where possible, blurring by contacting:

datepersonale@sicro.md

You do not need to provide a reason in order for the request to be considered.

Calls made to and from SICRO TRAVEL's official telephone numbers:

may be recorded through the IP telephony system.

Recordings may be used for:

  • improving service quality;
  • verifying information communicated;
  • handling misunderstandings and complaints;
  • protecting the security of communications;
  • establishing or defending rights.

Where recording is active, the caller is informed by a voice message at the beginning of the call.

The legal basis is, depending on the circumstances, performance of the contract and/or SICRO TRAVEL's legitimate interests in service quality, communication security and protecting the rights of the company and its clients.

The sicro.md website uses cookies and similar technologies.

Strictly necessary cookies may be used for the operation and security of the website.

Cookies that are not strictly necessary, including those used for statistics or marketing, are used according to the choices expressed through the cookie management tool available on the website.

Cookie preferences may be changed later.

Further information is available in the cookie declaration or policy displayed on the website.

SICRO TRAVEL applies technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration, disclosure or accidental or unlawful destruction.

SICRO TRAVEL employees' access to data and systems is limited according to each employee's duties and responsibilities.

Employees have access only to the information necessary for performing their work-related tasks.

Depending on the system used, the measures applied may include:

  • use of secure HTTPS connections;
  • individual user accounts;
  • authentication before access to systems is granted;
  • limiting access rights according to role;
  • separating levels of access between employees;
  • maintaining technical logs of access and activity where supported by the system;
  • creating backups where appropriate;
  • updating and protecting information systems;
  • limiting access to authorised persons;
  • internal organisational measures governing the use and communication of data.

The sicro.md website uses a secure HTTPS connection, which protects the transmission of information between the user's device and the website server.

Accounts and data relating to SICRO TRAVEL's corporate e-mail service are hosted on infrastructure located in the Republic of Moldova, according to the current configuration of the service used.

SICRO TRAVEL also seeks to ensure that suppliers processing data on its behalf implement appropriate security measures and comply with applicable contractual and legal obligations.

No information system can guarantee the absolute elimination of all risks; however, SICRO TRAVEL seeks to apply measures proportionate to the nature of the data and the risks associated with processing.

Under Law No. 195/2024, you may, as applicable, have the following rights:

  • the right to be informed;
  • the right of access to personal data;
  • the right to obtain a copy of the personal data processed;
  • the right to rectification of inaccurate or incomplete data;
  • the right to erasure in the circumstances provided by law;
  • the right to restriction of processing;
  • the right to data portability where the legal conditions are met;
  • the right to object;
  • the right to object to direct marketing at any time;
  • the right to withdraw consent where processing is based on consent;
  • the right not to be subject to a decision based solely on automated processing under the conditions provided by law;
  • the right to lodge a complaint with the National Centre for Personal Data Protection;
  • the right to apply to the competent court.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Important: the right to erasure does not mean that all information must automatically be deleted in every situation. Certain data may continue to be retained where a legal obligation or another lawful basis justifies such retention.

To request access, rectification, updating, erasure, objection or to exercise any other right concerning your personal data, you may submit a request to:

datepersonale@sicro.md

or in writing to:

SICRO TRAVEL S.R.L.
102 Mitropolit Dosoftei Street, Office 4
Chișinău Municipality, Republic of Moldova, MD-2012

The request should contain sufficient information to enable identification of the individual and the personal data to which the request relates.

Where there are reasonable doubts concerning the identity of the person making the request, SICRO TRAVEL may request additional information strictly necessary to confirm identity.

Requests are handled without undue delay and within no more than one month of receipt, under the conditions provided by law.

Depending on the complexity and number of requests, this period may be extended by up to two months. In such circumstances, the individual will be informed of the extension and the reasons for it within the period provided by law.

The exercise of rights is, in principle, free of charge. Measures permitted by law may be applied in the case of manifestly unfounded or excessive requests.

If you believe that the processing of your personal data infringes data protection legislation, you may contact us at:

datepersonale@sicro.md

so that we may review the matter.

This does not limit your right to contact directly:

the National Centre for Personal Data Protection of the Republic of Moldova (CNPDCP)

or the competent court, in accordance with the law.

In its ordinary activities relating to booking and providing travel services, SICRO TRAVEL does not use decision-making processes based solely on automated processing that produce legal effects concerning an individual or similarly significantly affect that individual.

If such processes are introduced in the future, data subjects will be informed in accordance with the applicable legal requirements.

SICRO TRAVEL may use aggregated or anonymised information to analyse its activities, prepare internal statistics, evaluate services and improve its offers.

Where information has been effectively anonymised so that an individual can no longer be identified, such information no longer constitutes personal data.

This Privacy Policy may be amended where legislation, services offered, suppliers used, information systems or the way in which SICRO TRAVEL processes personal data change.

The updated version will be published on sicro.md together with the date of the most recent update.

Where significant changes affect the way personal data are used, SICRO TRAVEL may also use other reasonable methods of informing individuals where appropriate.

Contact details

SICRO TRAVEL S.R.L.

IDNO: 1019600049121

Registered office:
118 Suceava Street, Apt. 59, Chișinău Municipality, Republic of Moldova

Office / place of business:
102 Mitropolit Dosoftei Street, Office 4, Chișinău Municipality, MD-2012, Republic of Moldova

General e-mail: contact@sicro.md
Data protection: datepersonale@sicro.md
Website: www.sicro.md

Document version: 2.0
Last updated: 26 August 2026