Privacy Policy

This Policy describes how Haide collects, uses and protects your personal data in accordance with the EU General Data Protection Regulation (2016/679) and the laws of the Republic of Moldova.

1. Data controller

The controller is A.O. ERVA, Chisinau, Republic of Moldova. Data protection contact: info@haide.md.

2. Data we collect

Account data (name, email, phone, hashed password), booking data, messages between guests and hosts, IP address, language preferences, product usage data.

We never store card details. Payments are processed by PCI-DSS certified providers.

3. Purposes & legal basis

Contract performance (booking management), legitimate interest (fraud prevention, anonymised analytics), consent (marketing, non-essential cookies), legal obligation (tax, accounting).

4. Recipients

Hosts (only the minimum needed for the booking), hosting/email/payments/analytics providers, public authorities when legally required.

5. International transfers

Some providers sit outside the EEA. We rely on EU Standard Contractual Clauses in those cases.

6. Retention

Account data is kept while the account is active and up to 7 years after the last booking (tax law). Messages are erased after 2 years of inactivity.

7. Your rights

Access, rectification, erasure, restriction, objection, portability, consent withdrawal, complaint to a supervisory authority.

Requests: info@haide.md. We reply within 30 days.

8. Cookies

We use essential cookies and, with your consent, analytics and marketing cookies. Preferences can be changed anytime from the banner or your account.

9. Security

HTTPS in transit, password hashing, role-based access, audit logs. Serious incidents reported to authorities within 72 hours.

Last updated: 2026. Questions: info@haide.md