Last updated:
1. Who we are (the data controller)
The controller of your personal data is SMART HYDRO FARM SRL, a legal entity registered in the Republic of Moldova, IDNO 1022600044896, with its registered office at 13/3 Miron Costin St., apt. 52, Chișinău, MD-2014, Republic of Moldova, operating under the CityFarm trademark through the cityfarm.md website and the related subscription-based home delivery of fresh greens.
For any questions, requests or concerns about how your personal data is processed, you can reach us at info@cityfarm.md or through the contact form at cityfarm.md/en/contact. We respond within the legal deadlines set out below, in the section on your rights.
For questions strictly about personal data protection, CityFarm's contact person is reachable at info@cityfarm.md. Note on the Data Protection Officer (DPO): SMART HYDRO FARM SRL keeps under continuous review whether it must appoint a DPO under Legea 195/2024 (in particular for regular and systematic monitoring or large-scale processing). If, given the scale of processing, appointment becomes mandatory, we will publish the DPO's name and contact details right here in this section.
2. What data we collect
We process only the data needed to deliver the service to you and to meet our legal obligations. Depending on how you interact with us (visitor, account holder, delivery subscriber, newsletter subscriber), the categories of data we process are:
- Identification data: first name, last name, phone number, email address, account username (if you create an account).
- Delivery data: full delivery address (street, number, building, entrance, apartment), sector / locality, specific delivery instructions (e.g. "leave with the concierge", preferred time window), landmark.
- Transaction data: your order history, chosen subscription plan (frequency, product mix), billing data (billing name, billing address, optionally company details for a tax invoice), transaction amount, the transaction ID assigned by maib, the last 4 digits of the card used (to identify the transaction). We never collect or store your full card number, expiry date or CVV code - these are processed exclusively by maib, on their secure pages, in line with PCI-DSS standards.
- Technical data: IP address, device identifier, browser type and version, operating system, browser language, pages visited, time and duration of the visit, traffic source (referrer), access and error logs, cookies (see the Cookies and similar technologies section).
- Marketing data: your newsletter preferences, whether you open our emails (if tracking is enabled in your email client), clicks on newsletter links, the channels that brought you to our site, answers to satisfaction surveys (if you choose to take part).
Note on profiling: we carry out limited profiling for marketing purposes - analyzing newsletter opens and clicks to personalize content. This processing produces no legal effects concerning you and does not similarly significantly affect you, within the meaning of Art. 22 of Law 195/2024. You have an unconditional right to object to this profiling at any time, at info@cityfarm.md or via the unsubscribe link.
We do not intentionally collect special categories of data (health data, ethnic origin, political opinions, religious beliefs, sex life, etc.). Please do not send us such data through forms or correspondence.
3. Where the data comes from
The data we process comes from three clearly identifiable sources:
- Directly from you - the data you give us when you create an account, place an order, subscribe to a delivery plan, fill in a contact form, sign up for the newsletter, email us or call us.
- Automatically, as you use the site - technical data (IP address, device, browser, access logs) and data collected through cookies, in line with the consent you expressed in the cookie banner.
- From our processing partners, strictly within the service they provide - mainly from maib (our payment processor), from whom we receive only the transaction status (authorized / declined), the last 4 digits of the card used (so you can spot the transaction in your history) and, if you choose a subscription plan with recurring payment, a payment token (a cryptographic reference issued by maib that enables recurring charges without us ever knowing your card details).
We do not buy contact lists, do not aggregate data from public sources and do not use data scraped from social networks.
4. Purposes and legal basis
Every processing operation has a well-defined purpose and a matching legal basis. The table below sums up the main processing operations:
| Purpose | Legal basis | Data categories | Retention period |
|---|---|---|---|
| Creating and managing your customer account | Performance of contract - Art. 6(1)(b) GDPR / equivalent in Legea 195/2024 | Identification, delivery, transaction | Life of the account + 3 years after the last activity |
| Processing and delivering orders (one-off and subscriptions) | Performance of contract - Art. 6(1)(b) | Identification, delivery, transaction | Duration of the contract + the periods below |
| Transactional communications (order confirmations, delivery notifications, subscription changes) | Performance of contract - Art. 6(1)(b) | Identification, delivery, transaction | Duration of the contract |
| Customer support and complaint handling | Performance of contract - Art. 6(1)(b) / legitimate interest - Art. 6(1)(f) | Identification, transaction, correspondence content | 3 years after the complaint is resolved |
| Invoicing and accounting | Legal obligation - Art. 6(1)(c) | Identification, billing, transaction | 5 years (Moldovan tax law) |
| Responding to requests from competent authorities | Legal obligation - Art. 6(1)(c) | As applicable | As required by the applicable legal requirement |
| Site security, fraud prevention, infrastructure protection | Legitimate interest - Art. 6(1)(f) | Technical, access logs | 12 months |
| Improving the service through aggregated / pseudonymized analytics | Legitimate interest - Art. 6(1)(f) | Technical (aggregated), transaction (aggregated) | Raw data: 12 months; aggregated: indefinitely |
| Post-purchase communications to existing customers about similar products | Legitimate interest - Art. 6(1)(f), with the right to object | Identification, transaction history | Until you object |
| Marketing newsletter | Consent - Art. 6(1)(a) | Identification, marketing | Until you unsubscribe, or after 3 years of inactivity |
| Analytics and marketing cookies | Consent - Art. 6(1)(a) | Technical, marketing | For the lifetime of each cookie (see the banner) |
| Satisfaction surveys and optional studies | Consent - Art. 6(1)(a) | Identification, answers | Until the study ends or consent is withdrawn |
Legitimate interest assessment (LIA) summary. For every processing operation based on legitimate interest we carried out a written assessment. In short:
- Site security and fraud prevention - the legitimate interest: protecting the infrastructure and accounts against unauthorized access and attacks; necessity: minimal technical logs, kept for a maximum of 12 months; impact on you: minimal; right to object: yes, via info@cityfarm.md.
- Aggregated / pseudonymized analytics for service improvement - legitimate interest: product development; necessity: pseudonymized data, no re-identification; impact: minimal; right to object: yes.
- Post-purchase communications to existing customers about similar products - our interest: giving you relevant recommendations; necessity: limited to content similar to the products you bought; we ALWAYS give you a clear, free way to opt out at the time of your first order (an unticked box in the shopping cart) and in every subsequent message (unsubscribe link); the unconditional right to object can be exercised at any time.
The full LIA documentation is available on request from the DPO or the data protection contact person.
Regarding processing based on legitimate interest: for each such processing operation we ran a balancing test, assessing whether your fundamental rights and freedoms override our legitimate business interests. You have the right to object to these processing operations at any time - see the Your rights section.
Regarding processing based on consent: you can withdraw your consent at any time, as easily as you gave it (unsubscribe link in every marketing email, cookie preference manager in the site footer, a request at info@cityfarm.md). Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
5. Who we share data with
We do not sell your data. We share it only with the processors and recipients strictly needed to deliver the service or to meet our legal obligations. The categories are:
- maib (B.C. "MOLDOVA-AGROINDBANK" S.A., Republic of Moldova) - an independent data controller for payment data, which it processes in its own name under its own legal obligations (AML, PCI-DSS, banking supervision). We share with maib only the data strictly needed to authorize the transaction. Your full card details (PAN, expiry, CVV) are processed and stored exclusively by maib, under PCI-DSS - SMART HYDRO FARM SRL has no access to them.
- Hosting provider: ADM.TOOLS (Ukraine) - stores the site's data and the customer database on secure servers, under contract terms requiring adequate technical and organizational measures.
- Email provider (transactional and newsletter): ADM.TOOLS (Ukraine) - from our hosting server we send order confirmations, delivery notifications, the newsletter signup confirmation link, and other operational and consent-based marketing messages. We do not use an outside email marketing provider (ESP) - every email is sent from our own server.
- Internal operational notifications: Telegram (Telegram Messenger Inc., United Arab Emirates) - our team receives a notification for each order (name, phone, address, order contents) in a secured internal group, in order to prepare and deliver the order. Access is limited to delivery and admin staff.
- WhatsApp messages to customers: order confirmations on WhatsApp are sent through a WAHA instance hosted on our own server and delivered over the WhatsApp network (WhatsApp LLC / Meta Platforms, USA). We share only your phone number and the content of the confirmation message.
- Analytics provider: Google Analytics 4 - Google Ireland Limited (Ireland) / Google LLC (USA) - collects site usage statistics, only if you have given consent via the cookie banner.
- Experience analytics provider: Microsoft Clarity - Microsoft Corporation (USA) - interaction maps and anonymized sessions, only if you have given consent via the cookie banner.
- Advertising provider: Meta Pixel (Meta Platforms Ireland Ltd. / Meta Platforms Inc., USA) - campaign measurement and relevant advertising, only if you have given consent to the marketing category via the cookie banner. We do not currently use TikTok Pixel or any other additional advertising pixel.
- Professional advisers - accountants, auditors, lawyers, strictly within their engagement and bound by confidentiality.
- Public authorities - exclusively under a legal obligation (for example, Serviciul Fiscal de Stat - the State Tax Service - for invoices and tax reporting; criminal investigation bodies under a reasoned lawful request).
Home delivery is carried out by CityFarm's own staff (SMART HYDRO FARM SRL) - your delivery data (name, phone number, address, specific instructions) is not passed to any third-party courier.
The detailed list of processors involved in international transfers (name, jurisdiction, purpose of transfer, safeguards) is published in the 6. Transfers outside the Republic of Moldova section below, and is updated whenever a provider changes; a history of major changes is kept with the DPO.
The up-to-date list of our processors is available on request - write to us at info@cityfarm.md. All our processors are contractually bound, through data processing agreements (DPAs), to comply with the applicable data protection standards, to process data only on our instructions and to implement adequate technical and organizational measures.
6. Transfers outside the Republic of Moldova
Some of the services we use (for example cloud hosting, transactional email, marketing email, analytics) may involve transfers of personal data to European Union member states or to other states outside the Republic of Moldova.
For every cross-border transfer, we publish and keep updated a table with the following information:
| Recipient | Destination country/area | Transfer mechanism | Applicable documentation |
|---|---|---|---|
| ADM.TOOLS (Ukraine) - hosting, transactional email and newsletter | Ukraine | Standard contractual clauses | Available at info@cityfarm.md |
| Google Analytics 4 - Google Ireland Limited / Google LLC | Ireland / USA | Standard contractual clauses · EU-US Data Privacy Framework | Available at info@cityfarm.md |
| Telegram Messenger Inc. - internal order notifications | United Arab Emirates | Legitimate interest · data minimised to what delivery strictly requires | Available at info@cityfarm.md |
| WhatsApp LLC / Meta Platforms - order confirmations to customers | USA | Standard contractual clauses · EU-US Data Privacy Framework | Available at info@cityfarm.md |
| Microsoft Clarity - Microsoft Corporation (only with consent) | USA | Standard contractual clauses · EU-US Data Privacy Framework | Available at info@cityfarm.md |
| Meta Pixel (only with consent, marketing category) | Ireland / USA | Standard contractual clauses · EU-US Data Privacy Framework | Available at info@cityfarm.md |
Transitional regime (until August 23, 2026): cross-border transfers are carried out under Legea nr. 133/2011 and the applicable CNPDCP authorizations. From August 23, 2026 onwards: we apply the regime set by Legea nr. 195/2024 (CNPDCP standard contractual clauses, adequacy decisions, or other legal safeguards).
We do not transfer data to states that do not ensure an adequate level of protection except on the basis of binding legal safeguards. The full list of destination countries and applicable safeguards, together with the text of the standard contractual clauses, is available to you on request at info@cityfarm.md.
7. How long we keep your data
We keep your data only as long as needed for the purposes it was collected for, or to meet our legal obligations. The specific periods are:
- Active customer account: for the life of the account plus 3 years after the last significant activity - this reflects the general limitation period for contractual obligations in the Republic of Moldova; when it expires, the account is deleted or anonymized.
- Invoices and accounting documents: the periods set by the accounting and financial reporting law and the Tax Code of the Republic of Moldova (usually 5 years from the end of the financial year; some categories may have longer periods).
- Newsletter: until you unsubscribe or after 3 years of inactivity, whichever comes first.
- Technical and security logs: 12 months, except logs involved in a security incident, which are kept for the duration of the investigation and any subsequent legal proceedings.
- Complaints and support correspondence: 3 years after the complaint is fully resolved - reflecting the general limitation period.
- Recurring payment token for subscriptions: until the subscription is canceled or the card expires (held by maib).
- Consent-based data: until consent is withdrawn or the specific period expires.
When the applicable period expires, data is either permanently deleted or irreversibly anonymized (in the latter case, the data can no longer be linked to any identified or identifiable person and may be kept for aggregate statistics).
8. Your rights
Under Legea 195/2024 (aligned with the General Data Protection Regulation - GDPR), you have the following rights over your personal data:
- Right of access - to obtain confirmation of whether or not we process data about you and, if so, a copy of that data, together with information about purposes, categories, recipients and retention periods.
- Right to rectification - to ask us to correct inaccurate data or complete incomplete data we hold about you.
- Right to erasure ("right to be forgotten") - to ask us to delete your data when it is no longer needed for the purposes it was collected for, when you withdraw your consent, when you object to the processing and there are no overriding legitimate grounds, or in other cases provided by law.
- Right to restriction of processing - in certain situations, to ask us to mark your data as restricted and process it only under limited conditions.
- Right to data portability - to receive the data you provided to us in a structured, commonly used, machine-readable format, or to have it transmitted directly to another controller, where the processing is based on consent or on the performance of a contract and is carried out by automated means.
- Right to object - to object at any time to processing based on legitimate interest (including profiling for that purpose) and, unconditionally, to processing for direct marketing.
- Right to withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
- Right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects or similarly significantly affects you. SMART HYDRO FARM SRL does not currently use any such automated decision-making.
How to exercise these rights: send a request to info@cityfarm.md, clearly stating (i) who you are (so we can verify your identity without asking for excessive data) and (ii) which right you are exercising. We respond within a maximum of 30 calendar days of receiving the request. For complex or numerous requests, the deadline may be extended by a further 60 days - in that case we will notify you within the first 30 days, explaining the extension.
Exercising these rights is free of charge. For manifestly unfounded or excessive requests (especially repetitive ones), we may charge a reasonable fee based on administrative costs, or refuse the request with reasons.
Identity verification. To protect your data, we verify identity by asking you to confirm details we already hold about you (the email address linked to the account, the number of a recent order). If doubt remains, we may ask for an identity document, without keeping it after verification.
Reasoned refusal and the right to challenge. If we refuse to act on your request, we inform you in writing within a maximum of 30 days, giving the reasons and telling you about your right to lodge a complaint with the CNPDCP and to go to court. You may act through a representative (a lawyer, a rights-protection NGO) with a written mandate.
Manifestly unfounded or excessive requests. We consider manifestly excessive: repeated requests on the same subject within a 6-month period, requests plainly aimed at obstructing our activity, or requests submitted after receiving a complete answer. In these cases, we may charge a reasonable administrative fee or refuse with reasons under Art. 12(5) GDPR / Legea 195/2024.
9. Cookies and similar technologies
The cityfarm.md site uses cookies and similar technologies (local storage, pixels, device identifiers) to make the site work and, with your consent, to improve the service. The categories we use are:
- Strictly necessary - the site does not work without them (session, sign-in, security, shopping cart, cookie consent preference, language preference, delivery region). Legal basis: performance of contract / legitimate interest. No consent required.
- Analytics - pseudonymized or anonymous data. Legal basis: explicit consent via the cookie banner.
- Marketing and advertising - Legal basis: explicit consent via the cookie banner.
Cookie banner rules:
- analytics and marketing cookies are blocked until consent is given;
- the banner shows the "Accept all" and "Decline all" buttons at the same visual level, one click each, with no extra steps to refuse;
- refusing does not limit access to content or to shopping (we do not use cookie walls);
- consent can be withdrawn as easily as it was given, via the preference manager accessible in the site footer.
The list of cookies and similar technologies we use:
| Name | Provider | Purpose | Duration | Category |
|---|---|---|---|---|
cf-consent |
CityFarm (first party, local storage) | Remembers your choice of cookie categories (analytics / marketing) | Until you change your choice or clear your browser data | Strictly necessary |
cf-lang |
CityFarm (first party, local storage) | Remembers your chosen site language (RO/RU/EN) | Persistent, until you clear your browser data | Strictly necessary |
cf_newsletter_dismissed |
CityFarm (first party) | Stops the newsletter signup window from reappearing once you've closed it | 14 days | Strictly necessary |
cf_newsletter_subscribed |
CityFarm (first party) | Stops the newsletter signup window from reappearing once you've subscribed | 10 years | Strictly necessary |
_ga, _ga_<container ID> |
Google (Google Analytics 4) | Distinguishes unique visitors and sessions for site-usage statistics | ~13 months | Analytics |
_clck |
Microsoft Clarity, on the cityfarm.md domain | Identifies the user for interaction maps and session replays | 1 year | Analytics |
_clsk |
Microsoft Clarity, on the cityfarm.md domain | Links multiple page views to the same session | 1 day | Analytics |
CLID |
Microsoft Clarity (clarity.ms, third party) | Project-level Clarity user identifier | 1 year | Analytics |
MUID |
Microsoft (clarity.ms and bing.com, third party) | Microsoft identifier, synced by Clarity with the Bing network for measurement | ~13 months | Analytics |
MR |
Microsoft (clarity.ms and bing.com, third party) | Renews the MUID identifier | 7 days | Analytics |
SRM_B |
Microsoft / Bing (bing.com, third party) | Technical Microsoft identifier, set as part of the Clarity-Bing sync | ~13 months | Analytics |
ANONCHK |
Microsoft Clarity (clarity.ms, third party) | Checks whether the MUID identifier can be stored for the current visitor | ~10 minutes | Analytics |
SM |
Microsoft Clarity (clarity.ms, third party) | Technical sync between Clarity and the Bing network | Session (cleared when the browser closes) | Analytics |
_fbp, _fbc |
Meta Pixel, on the cityfarm.md domain | Identifies the browser for Meta advertising measurement and, if present, keeps the Meta ad click that brought you to the site | ~90 days | Marketing |
Withdrawing consent, and a technical limit we want to be upfront about. When you decline or withdraw consent, we immediately stop any new collection (Google Analytics, Microsoft Clarity and Meta Pixel no longer start) and delete the cookies above that belong to the cityfarm.md domain. The CLID, MUID, MR, SRM_B, ANONCHK and SM cookies are set directly by Microsoft on the clarity.ms and bing.com domains - for browser-technical reasons a site cannot delete another domain's cookies, so these expire on their own, within the durations shown above, rather than being removed instantly. Withdrawal stops any further collection through them; if you want to remove them right away, you can always do so manually in your browser settings ("Clear browsing data").
10. Security
We implement adequate technical and organizational measures to protect your data against unauthorized access, loss, alteration, disclosure or accidental or unlawful destruction. These include, without being limited to:
- Encryption in transit via HTTPS / TLS on every page of the site and for all internal APIs.
- Role-based access control - each team member can access only the data needed for their duties.
- Strong authentication for staff with access to internal systems, with session monitoring.
- Access log monitoring and alerts for abnormal behavior.
- Regular backups, stored separately and encrypted, with periodic restore tests.
- Regular staff training in data protection and cybersecurity.
- Data processing agreements (DPAs) concluded with every processor, imposing equivalent security standards.
- Internal policies for incident management, retention and data deletion.
Security breach notification. We notify the CNPDCP within a maximum of 72 hours of becoming aware, with reasonable certainty, of a breach. When a breach is likely to create a high risk to the rights and freedoms of the people affected, we notify you directly, without undue delay, through the contact channels we have. If individual notification would involve disproportionate effort, we use public communication through the site's channels, in line with Legea 195/2024. We keep an internal register of all security breaches, available to the CNPDCP on request.
That said, no security measure is absolute. If you suspect an incident involving your account or your data, contact us immediately at info@cityfarm.md.
11. Children's data
Minimum age for using the services. CityFarm services (opening an account, placing orders, subscriptions) are meant exclusively for people with full legal capacity (as a rule, at least 18 years old, under the law of the Republic of Moldova). We do not knowingly collect personal data from minors under 18 through the order or account forms.
For certain limited, commercially neutral services (for example, subscribing to the informational newsletter), the minimum age of consent for data processing is 16, under Legea 195/2024. For minors under 16, the consent of a legal representative is required.
If you learn that we have collected data about a minor under 16 without valid consent from their legal representative, please contact us immediately at info@cityfarm.md - we will delete that data without delay.
12. Complaints to the supervisory authority
You have the right to lodge a complaint with the competent supervisory authority if you believe that the processing of your personal data by SMART HYDRO FARM SRL breaches the applicable law.
The competent supervisory authority in the Republic of Moldova is:
The National Center for Personal Data Protection - Centrul Național pentru Protecția Datelor cu Caracter Personal (CNPDCP)
- Website: www.datepersonale.md
- Address: Str. Serghei Lazo 48, MD-2004, Chișinău, Republic of Moldova
- Phone: 022 820 801
- Email: centru@datepersonale.md
We do encourage you, though, to contact us first at info@cityfarm.md - in many cases we can resolve your concern quickly and completely, without a formal procedure before the supervisory authority.
13. Applicable law
This Privacy Policy is drafted in accordance with Legea nr. 195/2024 - the Republic of Moldova's personal data protection law, which enters into force on August 23, 2026 and is substantially aligned with the General Data Protection Regulation (EU) 2016/679 (GDPR).
The transitional regime, in plain terms:
- Until August 23, 2026, Legea nr. 133/2011 - the current personal data protection law - applies. This policy complies with that regime too.
- From August 23, 2026 onwards, Legea nr. 195/2024 applies. This policy is already drafted to meet that stricter regime, so the transition is transparent for you, with no reduction in the level of protection.
Where processing involves data subjects located in the European Union, or where we offer services within the territorial scope of the GDPR, we also apply the standards of Regulation (EU) 2016/679.
14. Changes
We may update this Privacy Policy to reflect changes in the law, in our services or in our processing practices. The current version is always available at /en/privacy/ on cityfarm.md, together with the date of the last update.
For changes that affect consent-based processing or introduce new processing purposes, we will ask for fresh, explicit consent before applying the change. Silence does not count as consent. For changes that do not alter the purposes or the legal basis (editorial clarifications, contact updates), continuing to use the services after advance notice counts as acceptance.
Continuing to use CityFarm services after the changes take effect means you accept them. If you do not agree with the changes, you have the right to close your account or cancel your subscription, and your rights under the Your rights section remain fully applicable.