Legal
GDPR Compliance
Effective Date: July 22, 2025
·Last Updated: July 22, 2025
At Vasiliu Ștefan-Alexandru AI ("we", "us", "our"), Independent Entrepreneur (Antreprenor Independent) registered in the Republic of Moldova, we are firmly committed to protecting the privacy and security of your personal data. This dedicated GDPR compliance page details the fundamental principles on which we base our data processing, the measures we have implemented, and your rights in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR").
Although Vasiliu Ștefan-Alexandru AI is registered in the Republic of Moldova, we recognize our obligations to comply with GDPR, especially considering that our services are accessible and used by individuals from the European Union (EU) and the European Economic Area (EEA), including from Romania. Moldova's data protection legislation (Law No. 133/2011 and the future Law No. 195/2024) is in the process of aligning with EU standards, reflecting our commitment to adhere to the highest data protection standards.
1. Our Commitment to GDPR
Vasiliu Ștefan-Alexandru AI fully complies with the key principles of GDPR, ensuring that your personal data is:
- Processed lawfully, fairly, and transparently: We clearly inform you about what data we collect and how we use it.
- Collected for specified, explicit, and legitimate purposes: We do not process data in a manner incompatible with the stated purposes.
- Adequate, relevant, and limited to what is necessary: We collect only the essential data needed to provide our services.
- Accurate and, where necessary, kept up to date: We take reasonable steps to ensure data accuracy.
- Kept in a form that permits identification of data subjects only as long as necessary: We implement strict retention periods.
- Processed in a manner that ensures appropriate security of the data: We protect data against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
Accountability: We are responsible for and can demonstrate compliance with GDPR principles.
2. Legal Basis for Data Processing
We process your personal data only on the basis of a valid legal ground, as defined by Article 6 of GDPR. For Vasiliu Ștefan-Alexandru AI, the main legal grounds include:
- Consent (Art. 6(1) lit. a GDPR): When you have given us explicit permission for a specific purpose, such as for direct marketing or for processing certain voice data for optional model improvement purposes. You have the right to withdraw your consent at any time.
- Contractual Necessity (Art. 6(1) lit. b GDPR): When processing is necessary for the performance of a contract to which you are a party (e.g., to provide access to our platform, process payments, offer support) or to take steps at your request prior to entering into a contract.
- Legal Obligation (Art. 6(1) lit. c GDPR): When we are legally required to process data, for example, to comply with tax, accounting requirements, or to respond to requests from authorities.
- Legitimate Interest (Art. 6(1) lit. f GDPR): When processing is necessary for our legitimate interests (or those of a third party), provided that your fundamental rights and freedoms do not override these interests. Examples include service improvement, network security, and fraud prevention. For text and voice inputs, we may process this data based on legitimate interest to operate and improve our core AI models and services, with appropriate safeguards (e.g., anonymization or pseudonymization where possible, use of zero-data retention policies from our providers).
3. Your Rights as a Data Subject
GDPR grants you powerful rights over your personal data. We are committed to facilitating the exercise of these rights, and our privacy team is available to assist you. You can exercise any of the following rights by contacting us at support@lorvis.md:
- Right of Access (Art. 15): You have the right to request a copy of the personal data we hold about you and information about how we process it.
- Right to Rectification (Art. 16): You have the right to request correction of any inaccurate or incomplete data we hold about you.
- Right to Erasure ("Right to be Forgotten") (Art. 17): You can request deletion of your personal data in certain circumstances (e.g., if the data is no longer necessary or you have withdrawn consent).
- Right to Restriction of Processing (Art. 18): You have the right to request restriction of processing of your data under certain conditions, for example, if you contest the accuracy of the data.
- Right to Data Portability (Art. 20): You have the right to receive your data in a structured, commonly used, and machine-readable format, and to transmit it to another controller, if the processing is based on consent or contract.
- Right to Object (Art. 21): You have the right to object to processing of your personal data for direct marketing purposes or when processing is based on our legitimate interests.
- Right to Withdraw Consent (Art. 7(3)): If processing is based on your consent, you can withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal.
- Rights related to Automated Individual Decision-Making, including Profiling (Art. 22): You have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you.
Request Process: To exercise any of these rights, please contact us at support@lorvis.md. To protect your privacy and security, we may ask you to verify your identity. We will respond to your request within one month, with the possibility of extending by a further two months for complex requests, in which case we will inform you.
4. Data Collection and Use in Compliance with GDPR
We collect only the data necessary for legitimate, explicit, and determined purposes:
- Data Minimization: We collect only the minimum amount of personal data necessary for the processing purpose.
- Purpose Limitation: Data is collected and used only for the purposes stated in our Privacy Policy.
- Limited Retention Periods: We retain personal data only as long as necessary for the purposes for which it was collected and in accordance with legal requirements. Once data is no longer necessary, it is securely deleted or anonymized.
- Consent and Control: We request your explicit consent for processing personal data for purposes that are not strictly necessary for service provision or legal compliance (e.g., marketing cookies, certain uses of voice data). We provide tools for you to manage your privacy and cookie preferences.
5. Data Security and Privacy by Design and by Default
We implement advanced technical and organizational measures to ensure a level of data security appropriate to the risk:
- Encryption: Data in transit is encrypted using TLS 1.2+ and HTTPS. Data at rest is encrypted where necessary.
- Access Controls: Access to personal data is strictly limited to authorized personnel, based on the "need to know" principle.
- Pseudonymization and Anonymization: Where possible, we use pseudonymization techniques (e.g., for user identifiers associated with AI inputs) and anonymization (for aggregated datasets for analysis).
- Infrastructure Security: We use secure and robust cloud hosting services with internationally recognized compliance certifications.
- Audits and Assessments: We conduct regular security risk assessments and penetration testing to identify and remediate vulnerabilities.
- Incident Response Plan: We have a well-defined plan for promptly managing any personal data breach, including notification of supervisory authorities and data subjects, in accordance with Articles 33 and 34 of GDPR.
Privacy by Design and by Default: We integrate privacy principles into the development of our Service, ensuring that data protection is a fundamental feature, not an afterthought. By default, our settings respect the highest privacy standards.
6. Third-Party Relationships and Data Processing
When we share data with third-party processors (service providers acting on our behalf), we ensure they provide sufficient guarantees to implement appropriate technical and organizational measures and to ensure processing in accordance with GDPR. Our primary AI sub-processors are <strong>OpenAI, Inc.</strong> (USA — GPT-series language models and text embeddings), <strong>Anthropic, PBC</strong> (USA — Claude-series language models), and <strong>Google LLC</strong> (USA — Gemini-series language models), all bound by Data Processing Agreements and Standard Contractual Clauses.
- Data Processing Agreements (DPA): We enter into Data Processing Agreements (DPAs) with all third-party service providers who process personal data on our behalf. These DPAs impose strict contractual obligations regarding data security, confidentiality, and processing purposes.
- Careful Vendor Selection: We select partners and vendors with a solid reputation in data security and GDPR compliance.
- International Transfers: Any transfer of data to countries outside the EEA or the Republic of Moldova is carried out only with the implementation of adequate safeguards, such as the European Commission's Standard Contractual Clauses (SCC) or adequacy decisions.
7. Supervision and Contact Authorities
We are transparent about our legal obligations and fully cooperate with supervisory authorities.
For users from the European Union/European Economic Area (including Romania):
If you have concerns about how we process your data, you have the right to lodge a complaint with the competent supervisory authority in the EU/EEA member state of your residence or the place of the alleged violation.
For Romania, the supervisory authority is the National Supervisory Authority for Personal Data Processing (ANSPDCP).
For users from the Republic of Moldova:
The supervisory authority is the National Center for Personal Data Protection (CNPDCP).
8. Contact Us
For any additional questions, clarifications, or requests related to our GDPR compliance or data protection practices, please contact us at:
Email: support@lorvis.md