Privacy policy
Draft. To be approved by the client's lawyer before launch. Version of 10.09.2026.
1. Who processes the data
Controller: SIMETTOM S.R.L. (Eurooptica optical chain), Chișinău, Republic of Moldova, e-mail: info@eurooptica.md. Processing follows Law No. 195/2024 on personal data protection.
2. What data and why
- Orders, reservations and requests: name, phone, e-mail, delivery address, order content — to fulfil the contract and stay in touch. Kept 3 years after the last order.
- Account: phone (SMS code sign-in), order history — for account access. Kept while the account exists.
- Prescriptions and medical data (vision parameters): only with your separate consent at first sign-in; used to fit lenses and glasses. You can delete them at any time.
- Analytics and advertising (cookies, device identifiers): only after consent in the cookie banner; you can withdraw it in the footer (“Cookie settings”).
- Technical data (IP address, security logs): fraud protection, 12 months.
3. Who we share with
Courier services (delivery), SMS provider (sign-in codes), Bitrix24 CRM (order and customer contact processing), Google and Meta analytics and advertising services (with consent). Data is never sold to third parties.
- Virtual try-on: the photo you upload for a try-on is sent to Google Gemini (Google Ireland Ltd.) solely to generate the image with the chosen frame. We store neither the original photo nor the result on our servers; the result stays only in your browser. The try-on is available after signing in with your phone number; by pressing the sign-in button you accept these terms. Google processes the data under its API terms (no use for model training on the paid tier).
4. Your rights
Access, rectification, erasure, restriction, portability, withdrawal of consent, objection to marketing. Requests: info@eurooptica.md — we reply within 30 days. The account can be deleted on request from the account phone number. Complaints can be lodged with the National Center for Personal Data Protection (CNPDCP).
5. Cookies
Necessary cookies (cart, session, consent) always work. Analytics (GA4, Clarity) and marketing (Google Ads, Meta) only with consent. Consent is stored for 6 months.
6. Security
HTTPS, role-based staff access, admin action logging, backups.