Zafirok · Auto Service System

Legal

Privacy Policy

Who we are, what we do with your data, on what legal ground, and how you exercise your rights.

Last updated: August 19, 2026

Who is responsible

The controller is CreativMaro SRL, registration number 1009600037044, str. Calea Iesilor 16, no. 3, ap. 8V, MD-2069, Chisinau, Republic of Moldova. Zafirok is the brand under which we provide this platform.

Subscriptions are billed by Create Go LLC, 7901 4th St N, STE 300, St. Petersburg, FL 33702, United States, which processes your name, email address and billing details for that purpose only. For everything else, the controller remains CreativMaro SRL.

Write to [email protected] for any request about your data. We reply within one month.

We process data under Law no. 195/2024 on personal data protection, applicable from 23 August 2026, and, for users in the European Economic Area, under Regulation (EU) 2016/679.

Two different roles, and why it matters

For your account data, we are the controller: your name, email, phone number, subscription and how you use the platform.

For the data your workshop enters about its own customers, vehicles and repairs, your business is the controller and we are only a processor. We process it on your instructions and do not use it for our own purposes.

In practice: if you are a car owner whose data was entered by a workshop, address your request to that workshop first. We will assist them, but the decision is theirs.

What we collect and on what ground

Account and workshop details, to provide the service. Ground: performance of the contract, art. 6(1)(b).

Phone number, verified by a one-time code, to secure sign-in. Ground: performance of the contract and our legitimate interest in preventing abuse, art. 6(1)(b) and (f).

Vehicle data, including registration number and VIN, and photographs of vehicle documents you choose to scan. Ground: performance of the contract.

Invoicing and payment records. Ground: legal obligation, art. 6(1)(c).

Technical logs and security events. Ground: legitimate interest, art. 6(1)(f).

Usage statistics and campaign measurement. Ground: your consent, art. 6(1)(a), which you can withdraw at any time from Cookie settings.

Who else processes the data

Google, for the database and authentication. Vercel, for hosting and access logs. Garage on Contabo servers located in France, for uploaded documents and photographs.

OpenAI, only when you scan a vehicle document, so the fields can be read automatically instead of typed. Images are sent with instructions not to be retained or used for model training.

Stripe for payments, Brevo for email, SMS.md and SMS.to for text messages, including the sign-in code.

Google and Meta receive data only if you accept statistics or marketing cookies. If you decline, they receive nothing.

Where the data is stored

Uploaded documents and photographs are stored on servers in France. Being within the European Economic Area, these transfers require no additional formality under art. 44(2).

Some providers process data in the United States. Those transfers rely on standard contractual clauses, a mechanism allowed without prior authorisation by art. 46(2)(c). You may request a copy of these safeguards.

How long we keep it

Active account: for the duration of the contract, plus 30 days.

Deleted account: purged within 30 days by an automated job.

Invoices and accounting records: for the statutory archiving period.

Technical logs: 90 days.

Backups: at most 35 days, after which deleted data is not reintroduced.

Your rights

You may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest, under art. 15 to 22. You may withdraw consent at any time, as easily as you gave it, under art. 7(3).

We do not make automated decisions producing legal effects about you, and we do not profile you.

If our answer does not satisfy you, you may complain to the National Centre for Personal Data Protection, str. Serghei Lazo 48, Chisinau MD-2004, datepersonale.md, or go to court.

Security incidents

If a personal data breach occurs, we notify the Centre without undue delay and, where feasible, within 72 hours of becoming aware of it, under art. 33(1). Where the breach is likely to result in a high risk to you, we inform you directly, under art. 34.

Contact

Questions about this policy?

[email protected]