Privacy Policy

Effective date: 12 September 2026 · Version 2.3

This page explains what happens to your personal data when you write to us: through the website corneliuscurtu.md, the chat window on it, the contact form, or the Moldova4You Tours messaging assistant that answers on WhatsApp, Instagram and Facebook Messenger. We wrote it the way we would explain it out loud, so you can read it once and know where you stand.

Who is responsible for your data

Corneliu Scurtu works as a licensed guide within a company, and that company is the controller of everything described here. We handle your data under Law of the Republic of Moldova No. 195/2024 on the protection of personal data.

What we collect

When you write to us

On WhatsApp, Instagram, Facebook Messenger, in the site chat or by email, we end up with:

  • your name, or the profile name the messaging platform shows;
  • the contact details you give us: a phone number, an email address, a messaging account;
  • the content of your messages, including the trip details you choose to share: dates, group size, language, where to pick you up, what you would like to see.

When you send the form on this site

The fields you filled in reach us as an email. Our server adds three technical items to that email: your IP address, the Referer (the page the form was sent from) and the User-Agent (the browser and device string your browser announces). They are there for one reason, to tell a real inquiry from an automated one, and they live inside that email and nowhere else. Before the form goes out, a Cloudflare Turnstile check confirms that it is being sent by a person and not by a script; for that, Cloudflare receives your IP address and technical signals from your browser, and nothing of what you typed.

When you tap a WhatsApp button

The site sends our server a short note that the button was pressed, so that we know a conversation is about to start. The note carries the page you were on, the page you arrived at and the site that sent you there (a search engine, a social network, or nothing if you typed the address yourself), any campaign tags in the address, your browser language and time zone, how long you had been on the page, and the same IP address and User-Agent as the form. Our server also asks ipinfo.io which country the IP address belongs to. To remember the arrival page while you browse, the site keeps one entry called cc_src in your browser's session storage, and it is gone as soon as you close the tab. All of this lands in one internal email and serves the same single purpose as the form items: to tell a real traveler from an automated visit. The WhatsApp conversation itself never passes through the site.

When you open the chat window

The chat saves one entry called cs_chat in your browser's local storage: a session number and a timestamp, so your conversation is still there if you reload the page. It expires after 30 days, and clearing your browser data removes it right away. The messages themselves go to our own server.

What we never ask for

We do not ask for payment card numbers. We do not ask for identity documents: at the border you show your own passport yourself, and it never passes through us. We do not collect health data, religious or political views, or anything else the law treats as a special category, and we would rather you did not send such things to us either.

Why we use it, and on what grounds

  • To answer your inquiry and put together an offer. This is the run-up to a contract, at your own request.
  • To organize and run the tour you booked. This is the contract between us.
  • To issue documents and keep the books. This is a legal obligation the company has to meet.
  • To keep the contact form and the WhatsApp buttons usable. Our legitimate interest in knowing that an inquiry comes from a person and not from a script, which is what the technical items above and the Cloudflare check are for.

We do not build advertising profiles, we do not target ads at you, and we do not sell or rent your data to anyone.

Who else sees it

  • The platform you wrote from. A conversation on WhatsApp, Instagram or Messenger passes through that platform under its own terms.
  • Our hosting provider. The site and the chat run on our own server, placed with a hosting provider; up-to-date information on where that server is located is available on request.
  • Anthropic PBC (USA), the AI provider that drafts our replies. It processes the text of a message on our instructions and for us, as a processor, not for its own purposes. Under Anthropic's commercial terms, what we send through its API is deleted within 30 days and is never used to train its models.
  • Partners involved in your particular tour. A winery expecting your group, a hotel holding a room, a colleague driving a second car, and only what they need in order to do it.
  • Our second company mailbox, vetok@carpoint.md, which receives a copy of every message sent through the site form so that no inquiry is lost.
  • ipinfo.io, which receives the IP address from a WhatsApp click, returns the country it belongs to, and gets nothing else from us.
  • Cloudflare, Inc. (USA), whose Turnstile check runs on the booking form before it is sent: it receives your IP address and technical signals from your browser in order to tell a person from a script, and does not see what you typed into the form.

That is the whole list. Nobody receives your data for their own marketing.

Data that leaves the country

Four things happen outside the Republic of Moldova, and we would rather say so plainly than hide it in a footnote:

  • messaging platforms store and process your conversation on their own infrastructure abroad, under their own terms, which you accepted when you installed them;
  • Anthropic PBC (USA), the AI service that drafts our replies, processes the text of your message on its servers outside the country, as our processor; under its commercial terms the data is deleted within 30 days and is not used to train models;
  • ipinfo.io (USA) looks up the country of an IP address on its own servers abroad;
  • Cloudflare (USA) runs the anti-spam check on the form on its own servers abroad.

For these transfers we rely on the contractual safeguards the providers offer, including the standard contractual clauses adopted by the European Commission where the provider includes them in its terms (Article 46 of Law No. 195/2024); Anthropic includes them in its commercial terms. If our server turns out to be hosted outside the Republic of Moldova, the same rules apply to it. You can ask us for a copy of the safeguards that apply to a particular provider.

If you would rather not use any of them, call +373 60 721 721 or write to corneliu.scurtu@carpoint.md, and we will handle your request that way instead.

How long we keep it

  • Correspondence and contact details: while we are handling your inquiry and for as long as the trip that follows from it needs them, and no longer than 12 months after your last message. Conversations from the site chat and the messaging assistant are deleted from our server automatically once that period is over; documents issued for a booking stay with the accounting records (next item).
  • IP, Referer and User-Agent from the form, and the technical items from a WhatsApp click: they exist only inside the notification email and go when that email goes.
  • Invoices and accounting documents: for the period set by the accounting legislation of the Republic of Moldova.
  • The cs_chat entry in your browser: 30 days, or until you clear your browser data, whichever comes first.
  • The cc_src entry in your browser: until you close the tab.

Cookies, chat storage and tracking

This site has no analytics, no advertising pixels and no third-party trackers. The fonts are served from our own server. The one outside call happens on pages with a booking form, where the Cloudflare Turnstile check loads to keep spam out; it may keep a technical entry in your browser for the duration of the check and identifies no one. Two entries live in your browser: cs_chat, described above, which exists solely to keep your own chat open in front of you, and cc_src, which holds nothing but the address you arrived from and disappears when you close the tab. Neither identifies you or follows you to other sites, so there is no consent banner here to click away.

AI, and who actually answers you

An AI assistant prepares a draft reply to your message. A human, Corneliu or someone from his team, reads and approves every reply before it reaches you. Nothing is sent automatically. No decision about you is made by a machine alone: the price, the availability and the answer to your request are decided by people.

Your rights

Whatever channel you wrote from, you can ask us to:

  • tell you what data we hold about you and give you a copy of it;
  • correct it, if something is wrong;
  • delete it;
  • restrict what we do with it while a question about it is open;
  • stop processing you object to, where we rely on our legitimate interest;
  • hand back the data you gave us in a machine-readable form so you can take it elsewhere;
  • withdraw a consent you gave, which does not undo what was lawful before you withdrew it.

One email is enough: write to corneliu.scurtu@carpoint.md and say what you want done. If you are not happy with how we handled it, you can complain to the National Center for Personal Data Protection of the Republic of Moldova (str. Serghei Lazo 48, MD-2004 Chișinău, datepersonale.md). If you live in the European Union, you can also turn to the supervisory authority of your own country.

Changes to this policy

When something changes in the way we handle data, we change this page along with the effective date and the version number at the top of it. Nothing is edited quietly.

Contact

CAR POINT GROUP S.R.L., Chișinău, Republica Moldova.
Data questions: corneliu.scurtu@carpoint.md
Phone: +373 60 721 721