Privacy Policy
This Policy describes how Haide collects, uses and protects your personal data in accordance with the EU General Data Protection Regulation (2016/679) and the laws of the Republic of Moldova.
1. Data controller
The controller is A.O. ERVA, Chisinau, Republic of Moldova. Data protection contact: info@haide.md.
2. Data we collect
Account data (name, email, phone, hashed password), booking data, messages between guests and hosts, IP address, language preferences, product usage data.
We never store card details. Payments are processed by PCI-DSS certified providers.
3. Purposes & legal basis
Contract performance (booking management), legitimate interest (fraud prevention, anonymised analytics), consent (marketing, non-essential cookies), legal obligation (tax, accounting).
4. Recipients
Hosts (only the minimum needed for the booking), hosting/email/payments/analytics providers, public authorities when legally required.
5. International transfers
Some providers sit outside the EEA. We rely on EU Standard Contractual Clauses in those cases.
6. Retention
Account data is kept while the account is active and up to 7 years after the last booking (tax law). Messages are erased after 2 years of inactivity.
7. Your rights
Access, rectification, erasure, restriction, objection, portability, consent withdrawal, complaint to a supervisory authority.
Requests: info@haide.md. We reply within 30 days.
8. Cookies
We use essential cookies and, with your consent, analytics and marketing cookies. Preferences can be changed anytime from the banner or your account.
9. Security
HTTPS in transit, password hashing, role-based access, audit logs. Serious incidents reported to authorities within 72 hours.
Last updated: 2026. Questions: info@haide.md