BIRP SOFTWARE S.R.L.
birp.io · sistemerp.md · BIRP Platform
Version 3.2 · Effective date: 23 August 2026
Previous version: 19 May 2026
Preamble
This Policy describes how BIRP SOFTWARE S.R.L. ("BIRP", "we") processes the personal data of visitors to its websites, of its prospects, of the contact persons of its clients, suppliers and partners, and of the users of the BIRP Platform.
BIRP is a company incorporated under Moldovan law. Regulation (EU) 2016/679 (the "GDPR") applies to the processing operations for which BIRP acts as controller and which fall within its territorial scope, in particular under its Article 3(2)(a), as BIRP offers its services to persons located in the European Union. BIRP complies with it in full, and data subjects benefit from all the rights and safeguards of the Regulation.
The territorial applicability of the GDPR to the processing operations carried out by BIRP as processor is assessed separately, on a processing-by-processing basis.
BIRP also applies Law No. 195/2024 of the Republic of Moldova on the protection of personal data, applicable since 23 August 2026, as well as the national rules applicable to electronic communications and trackers.
This Policy covers the processing operations for which BIRP acts as controller. Processing carried out on behalf of a client using the Platform is governed by the contract and the data processing agreement concluded with that client (section 4.2).
Where to find each item of information required by Articles 13 and 14 of the GDPR
| Information | Reference | Section |
|---|---|---|
| Identity of the controller and of its representative | 13.1.a) / 14.1.a) | 1 |
| Data protection contact and data protection officer, where applicable | 13.1.b) / 14.1.b) | 2 |
| Categories of data | 14.1.d) | 5 |
| Origin of data collected indirectly | 14.2.f) | 5.3 |
| Time limit for informing you in the event of indirect collection | 14.3 | 5.4 |
| Purposes and legal bases | 13.1.c) / 14.1.c) | 6 |
| Legitimate interests pursued | 13.1.d) / 14.2.b) | 7 |
| Further processing for a new purpose | 13.3 / 14.4 | 6.2 |
| Recipients | 13.1.e) / 14.1.e) | 8 |
| International transfers and safeguards | 13.1.f) / 14.1.f) | 9 |
| Retention periods or criteria | 13.2.a) / 14.2.a) | 10 |
| Whether providing your data is mandatory or optional | 13.2.e) | 12 |
| Rights of data subjects | 13.2.b) / 14.2.c) | 13 |
| Withdrawal of consent | 13.2.c) / 14.2.d) | 13.7 |
| Complaint to a supervisory authority | 13.2.d) / 14.2.e) | 13.11 |
| Automated decision-making and profiling | 13.2.f) / 14.2.g) | 15 |
1. Controller and representative in the Union
1.1 Controller
BIRP SOFTWARE S.R.L.
A limited liability company incorporated under Moldovan law
IDNO: 1026602001952
5 Miorița Street, MD-2065 Chișinău, Republic of Moldova
Websites: birp.io · sistemerp.md
Data protection: privacy@birp.io
Support: support@birp.io
1.2 Representative in the European Union
For BIRP’s processing operations subject to Article 3(2) of the GDPR and for which Article 27 of the GDPR applies, BIRP has designated, by written mandate, a representative established in the European Union:
Victor Ungurean
55 avenue Marceau, 75016 Paris, France
privacy@birp.io
The representative is BIRP’s point of contact in the Union for data subjects and for supervisory authorities, with regard to any matter relating to processing falling under the GDPR. The representative acts under a written mandate from BIRP.
This designation limits neither BIRP’s liability nor the right of a data subject or a supervisory authority to contact BIRP directly.
2. Data protection
Any question relating to data protection may be addressed to privacy@birp.io.
As at the effective date of this Policy, BIRP has not designated a data protection officer within the meaning of Articles 37 to 39 of the GDPR. The address above is its contact point in this respect. If BIRP subsequently makes a formal designation, the officer’s contact details will be published in this Policy.
3. Who this Policy is addressed to
It concerns:
- visitors to BIRP’s websites;
- prospects and persons contacting BIRP;
- the professional contact persons of its clients, prospects, suppliers and partners;
- users with professional access to the BIRP Platform.
The websites and the Platform are intended for professional use. BIRP does not knowingly collect data relating to minors.
4. Capacities in which BIRP acts
4.1 BIRP as controller
BIRP determines the purposes and means of the processing, and this Policy applies, for:
- visitors to its websites and the audience measurement of its pages, where the user has consented to it;
- prospects and the handling of contact and demonstration requests;
- the management of its commercial relationships;
- the contact persons of its clients, suppliers and partners;
- user authentication, the security of the Platform, technical logging and the administration of its infrastructure;
- invoicing and contract management;
- its own support activities.
Where a client decides to create, modify or remove an employee’s access to the Platform, that decision belongs to the client, which remains responsible for it. BIRP is the controller only for the operations whose purposes it determines itself.
4.2 BIRP as processor
The data that a client enters, imports, generates or hosts in the Platform ("Client Data") is processed by BIRP on behalf of that client and in accordance with its documented instructions. It may concern the client’s employees, customers, suppliers, partners and counterparties.
In the modules relating to human resources and payroll, certain Client Data may include special categories of data within the meaning of Article 9 of the GDPR.
Such processing is governed by the contract and by the data processing agreement concluded in accordance with Article 28 of the GDPR, and not by this Policy.
4.3 If your data appears in Client Data
If you are an employee, customer, supplier or counterparty of a company using BIRP and your data has been entered into the Platform by that company, your point of contact for exercising your rights is the company that entered your data or, as the case may be, the controller on whose behalf it acts. BIRP provides the required assistance in accordance with Article 28 of the GDPR.
5. Data processed and origin
5.1 Data you provide to us directly
| Category | Data |
|---|---|
| Contact and prospecting | Surname, first name, company, position, business e-mail address, business telephone number, content of exchanges |
| User account | Name, business e-mail address, organisation, application role, preferences, information necessary for authentication |
| Contract and invoicing | Company information, contact persons, contractual and invoicing details |
| Support | Content of requests, correspondence, information necessary for their resolution |
5.2 Data collected automatically
When the websites or the Platform are used:
- IP address;
- date and time of connection;
- technical information relating to the browser and the device;
- authentication events and security events;
- technical logs and access logs;
- information collected by the trackers to which you have consented (section 11).
5.3 Data obtained indirectly
BIRP may obtain business contact details without collecting them directly from the data subject.
Categories concerned: surname, first name, position, company or organisation, business e-mail address, business telephone number, publicly accessible professional information, professional profile, context of the contact.
Sources:
- the company or organisation you represent;
- a client, supplier or partner that has designated a contact person;
- your company’s business website;
- LinkedIn;
- business pages and accounts accessible on other social networks;
- conferences, trade fairs and professional events in which BIRP participates;
- a telephone exchange, a direct professional contact or a professional introduction.
Company websites and certain professional profiles constitute, depending on their settings, publicly accessible sources. BIRP collects only the information reasonably relevant to a professional relationship, and does not use personal accounts for prospecting purposes.
5.4 Time limit for informing you in the event of indirect collection
In accordance with Article 14(3) of the GDPR, BIRP provides you with the required information:
- within a reasonable period after obtaining the data, and at the latest within one month;
- where the data is used to communicate with you, at the latest at the time of the first communication;
- where disclosure to another recipient is envisaged, at the latest when the data is first disclosed.
These time limits apply subject to the exceptions provided for in Article 14(5).
5.5 Special categories of data
For its own activities, BIRP does not deliberately collect, and does not pursue the collection of, special categories of data within the meaning of Article 9 of the GDPR. We ask you not to provide such data spontaneously in free-text fields or contact requests.
As a processor, BIRP may process special categories of data contained in Client Data, where this is necessary for the features chosen by the client and under the client’s responsibility.
BIRP does not sell personal data.
6. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Responding to a request for information or a demonstration made directly by a person likely to enter into a contract | Art. 6(1)(b) - pre-contractual measures |
| Providing the service to a person who is directly a party to the contract | Art. 6(1)(b) - performance of the contract |
| Managing the relationship with a professional contact person acting on behalf of a company | Art. 6(1)(f) - legitimate interest |
| Authenticating users and technically administering the Platform | Art. 6(1)(f) - legitimate interest |
| Ensuring the security of the Platform, logging access, preventing and handling incidents | Art. 6(1)(f) - legitimate interest, in conjunction with Art. 32 |
| Invoicing, accounting and obligations arising from Union or Member State law | Art. 6(1)(c) - legal obligation |
| Compliance with the legal, accounting and tax obligations to which BIRP is subject in the Republic of Moldova | Art. 6(1)(f) - legitimate interest (Art. 6(3) reserves Art. 6(1)(c) for obligations arising from Union or Member State law) |
| Professional commercial prospecting | Art. 6(1)(f) - legitimate interest, subject to the national rules applicable to electronic communications (section 6.1) |
| Marketing communications based on voluntary sign-up | Art. 6(1)(a) - consent |
| Audience measurement of the websites | Art. 6(1)(a) - consent, supplemented by the rules applicable to trackers |
| Handling complaints and defending BIRP’s rights | Art. 6(1)(f) - legitimate interest |
6.1 Commercial prospecting
BIRP carries out professional prospecting, by business e-mail, telephone, professional social networks, company websites and professional events.
- Where the applicable national law permits professional prospecting on the basis of legitimate interest (as is the case in France, under the conditions of Article L. 34-5 of the Postal and Electronic Communications Code), BIRP contacts a professional where the message has a reasonable connection with that person’s role or activity, after informing them and with the ability to object.
- Where the applicable national law requires prior consent, BIRP obtains that consent before any sending.
- Where the person contacted is likely to qualify as a consumer, in particular a sole trader reached on a personal line, BIRP applies the prior consent regime.
Anyone may object to prospecting at any time, free of charge and without giving reasons. Every electronic prospecting message includes a simple means of exercising this objection, which is also available at the time of collection.
6.2 Further processing
If BIRP envisages processing for a purpose other than that for which the data was collected or obtained, it informs the data subject beforehand and provides the information required by Articles 13(3) and 14(4) of the GDPR.
7. Legitimate interests pursued
Where BIRP relies on Article 6(1)(f), the interests pursued are as follows.
| Processing | Interest pursued |
|---|---|
| Management of professional contact persons | Identifying the persons necessary for managing the relationship with a client, prospect, supplier or partner company. The processing is limited to the professional information reasonably necessary |
| Security of the Platform | Preserving the confidentiality, integrity, availability and traceability of accounts and infrastructure, detecting illegitimate access and documenting incidents |
| Compliance with Moldovan obligations | Enabling BIRP to comply with the accounting, tax and regulatory rules to which it is subject in its country of establishment |
| Professional prospecting | Developing BIRP’s business with professionals who, by reason of their roles, may be interested in its services. Objection available at any time |
| Defence of rights | Retaining the information necessary for the establishment, exercise or defence of legal claims |
For each of these processing operations, a balancing assessment is documented, taking into account the nature of the data, the reasonable expectations of the data subjects and the impact of the processing on their rights and freedoms. It may be provided upon request addressed to privacy@birp.io.
8. Recipients
The data is accessible to authorised persons within BIRP (founders, support staff, staff in charge of technical administration, staff in charge of the contractual and commercial relationship) solely to the extent necessary for their duties.
It may also be disclosed to the following recipients.
| Recipient | Role | Establishment |
|---|---|---|
| OVHcloud | Hosting of the Platform and of the main infrastructure | France |
| Mistral AI | AI-assisted features (section 15) | France |
| Google Ireland Limited | Audience measurement and tag management, after consent (section 11). Capacity determined according to the services and settings actually activated | Ireland |
| Technical service providers | E-mail and communication, support and maintenance, backup and security | France |
| Banks and payment service providers | Invoicing and collection of payments | - |
| Professional advisers | Chartered accountants, lawyers, auditors, bound by an obligation of confidentiality | Moldova |
| Authorities | Administrative, judicial, tax or supervisory authority, where BIRP is legally required to do so or in the presence of a legally binding request | Moldova |
Where a recipient acts as BIRP’s processor, its obligations are governed by a contract compliant with Article 28 of the GDPR. The complete and up-to-date list of processors is kept in our register and provided upon request to privacy@birp.io.
Audience measurement services. Where Google acts as BIRP’s processor, the processing is governed in accordance with Article 28 of the GDPR. Where certain features or settings lead Google to act for its own purposes, its capacity as controller is indicated in the information relating to trackers.
9. Location and international transfers
9.1 Hosting
The main infrastructure of the BIRP Platform is hosted in France.
9.2 Access from the Republic of Moldova
As BIRP is established in the Republic of Moldova, certain data may be accessed from that country by its founders and authorised support staff, where necessary for providing the service, assisting a client, resolving an incident, technical administration or the security of the Platform. Such access is subject to the measures described in section 14.
Where BIRP acts as controller, such access by its own staff does not constitute a transfer within the meaning of Chapter V of the GDPR, in the absence of disclosure to a separate entity. The data remains fully subject to the GDPR.
9.3 Status of the Republic of Moldova
As at the date of this Policy, the Republic of Moldova does not benefit from an adequacy decision of the European Commission under Article 45 of the GDPR.
9.4 Transfers of Client Data
Where a client established in the European Economic Area makes Client Data available to BIRP, including through remote access, that operation constitutes a transfer falling under Chapter V of the GDPR, the exporter being the client, acting as controller or as processor as the case may be.
For the processing operations concerned, BIRP has documented its analysis of the territorial applicability of the GDPR and considers that the processing it carries out as processor on behalf of the client is not directly subject to Article 3(2) of the GDPR. Subject to that analysis remaining valid in the light of the circumstances of the processing, the standard contractual clauses provided for by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 are used as the transfer mechanism, under Article 46(2)(c), and are incorporated into the data processing agreement concluded with the client:
- Module 2 where the client acts as controller;
- Module 3 where the client itself acts as processor on behalf of its own customers.
These clauses are supplemented by the technical and organisational measures described in section 14, in particular encryption and access control. BIRP makes available to its clients the elements necessary for their transfer impact assessments.
9.5 Audience measurement
The audience measurement services used by BIRP are provided by Google Ireland Limited, whose capacity is determined according to the services and settings actually activated (section 8). They may involve the disclosure of data to Google LLC in the United States. Google LLC declares that it adheres to the EU-U.S. Data Privacy Framework, which is the subject of an adequacy decision of the European Commission of 10 July 2023. Where applicable, these transfers are supplemented by the European Commission’s standard contractual clauses.
Such processing takes place only after your consent (section 11).
9.6 AI-assisted features
The inference processing carried out by Mistral AI on behalf of BIRP is performed within the European Union.
9.7 Obtaining a copy of the safeguards
A copy of the safeguards applicable to a transfer may be requested from privacy@birp.io. Information covered by business secrecy or security requirements may be redacted to the strict extent necessary, in which case the reasons for the redaction are indicated.
10. Retention periods
BIRP retains data only for as long as necessary for the purpose pursued.
| Category | Period or criterion |
|---|---|
| Prospecting data | Until objection and, in any event, 3 years from the last exchange with the data subject |
| Professional contact persons | Duration of the relationship with the company concerned, then the period necessary for the preservation of evidence or the defence of a right |
| User accounts | Duration of activity of the account and of the relationship, then deletion or anonymisation within 3 years of closure |
| Contractual and invoicing data | Duration of the contractual relationship, then 1 year, without prejudice to the applicable limitation periods |
| Support | Duration of handling of the request, then 3 years for relationship follow-up and preservation of evidence |
| Technical and security logs | 365 days maximum, unless certain elements need to be kept longer for the investigation of an incident, a legal obligation or the defence of a right |
| Backups and technical archives | 365 days maximum |
| Proof of consent | 3 years from the withdrawal or last use of the consent |
| Requests to exercise rights | 3 years from the closure of the request |
| Applications received via the "Careers" page | 1 year from the last exchange, unless the person agrees to a longer retention |
| Audience measurement data | 1 year, according to the settings selected |
| Trackers | According to the periods indicated in section 11 |
10.1 Deletion of an account and Client Data
A client’s active data is retained for the duration of activity of the account and of the contractual relationship. Where deletion is requested or the account is permanently closed:
- the data ceases to be used in the normal course of the service;
- it is deleted or made inaccessible in the production environments;
- residual copies may remain in encrypted backups and archives for a maximum of 365 days;
- these copies are then overwritten or deleted in the normal backup cycle.
These copies are not used for any commercial purpose and are restored only where technically necessary, for security reasons or under a legal obligation.
11. Cookies and trackers
11.1 Strictly necessary trackers
Certain trackers are necessary for security, session continuity, authentication, the technical operation of the site, the storage of certain preferences and the recording of your choice regarding trackers. Where they meet the legal conditions for exemption, they are placed without prior consent.
11.2 Trackers subject to consent
BIRP uses a tag manager and an audience measurement tool provided by Google Ireland Limited. The corresponding trackers:
- are not placed or read before your acceptance;
- are not triggered if you refuse;
- are deactivated if consent is withdrawn.
BIRP does not use any advertising tracker or any cross-site tracking device. The advertising and data-sharing features of the audience measurement tool are disabled.
11.3 Your choice
Acceptance results from a positive action. Refusing is as easy as accepting, from the first level. Consent may be withdrawn at any time via the permanent "Manage my cookies" link in the footer. Your choice is kept for 6 months.
11.4 Trackers used
| Tracker | Purpose | Issuer | Lifetime | Consent |
|---|---|---|---|---|
| GTM | statistics | 365 days | yes | |
| Google Analytics | Statistics, marketing | 365 days | yes | |
| Facebook Pixel | Marketing | 365 days | yes |
12. Is the provision of your data mandatory?
| Situation | Nature | Consequence of refusal |
|---|---|---|
| Contact form or demonstration request | The fields marked as mandatory are necessary for handling the request | BIRP cannot respond to your request |
| Conclusion of a contract | Certain information is necessary for concluding the contract | The contract cannot be concluded |
| Use of an account | Certain data is necessary for authentication and for the secure provision of the service | Access to the Platform is not possible |
| Invoicing and accounting | Certain information is legally required | BIRP can neither invoice nor continue the relationship |
| Technical and security logs | Collection inherent in the secure operation of the service | This collection cannot be deactivated individually |
| Contact details of a professional contact person | Necessary for managing the relationship between BIRP and the company concerned | The company must designate another contact person |
| Marketing communications | Optional | No consequence on access to the service |
| Trackers that are not strictly necessary | Optional | No consequence on the essential functions of the site or the Platform |
Whether a piece of data is mandatory is indicated at the time of its collection.
13. Your rights
Subject to the conditions laid down by the applicable regulations, you have the following rights.
13.1 Right of access
To obtain confirmation as to whether processing concerning you is being carried out and, where the conditions are met, to receive a copy of the data. This right may not adversely affect the rights and freedoms of others (Art. 15).
13.2 Right to rectification
To have inaccurate data corrected or incomplete data completed (Art. 16).
13.3 Right to erasure
To obtain erasure in the situations provided for by the Regulation. This right does not apply where retention is necessary for compliance with a legal obligation or for the establishment, exercise or defence of legal claims (Art. 17).
13.4 Right to restriction
To obtain the temporary freezing of the processing where the legal conditions are met (Art. 18).
13.5 Right to data portability
Where the processing is based on your consent or on a contract and is carried out by automated means, to receive the data you have provided in a structured, commonly used and machine-readable format and, where technically feasible, to have it transmitted to another controller. This right covers neither processing based on legitimate interest or a legal obligation, nor data inferred or generated by BIRP (Art. 20).
13.6 Right to object
Where the processing is based on BIRP’s legitimate interest, to object on grounds relating to your particular situation. BIRP then ceases the processing, unless there are compelling legitimate grounds overriding your interests, or the processing is necessary for the defence of legal claims (Art. 21(1)).
Commercial prospecting. You may object to it at any time, without giving reasons. The objection is honoured immediately and unconditionally (Art. 21(2) and 21(3)).
13.7 Withdrawal of consent
Where processing is based on your consent, you may withdraw it at any time and as easily as you gave it, without affecting the lawfulness of prior processing: unsubscribe link in every communication, cookie manager, or request to privacy@birp.io (Art. 7(3)).
13.8 Post-mortem directives
Where French law applies to you, you may set directives concerning the retention, erasure and disclosure of your data after your death. This is a French national provision (Art. 85 of Law No. 78-17).
13.9 How to exercise your rights
Send your request to privacy@birp.io, or to BIRP’s representative in the European Union indicated in section 1.2.
- Time limit: response within one month of receipt, extendable by two months in the event of complexity or a high number of requests. In that case you are informed of the extension and of its reasons within the initial one-month period.
- Identity: in case of reasonable doubt, BIRP may request only the additional information necessary to verify your identity. No copy of an identity document is requested as a matter of principle.
- Cost: exercising your rights is free of charge. In the event of a manifestly unfounded or excessive request, in particular because of its repetitive character, BIRP may charge a reasonable fee or refuse to act on the request, giving reasons for its decision.
13.10 Client Data
Where your data has been entered into the Platform by a client company and BIRP acts solely as processor, your rights are exercised with that company. BIRP assists it so that it can respond to your request.
13.11 Complaints and remedies
You may lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement (Art. 77). Any competent supervisory authority may be seised.
By way of example, in France:
Commission Nationale de l’Informatique et des Libertés - CNIL
3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
You may also apply to the National Centre for Personal Data Protection of the Republic of Moldova (CNPDCP).
You also have a right to an effective judicial remedy (Arts. 78 and 79) and a right to compensation for material or non-material damage suffered as a result of an infringement of the Regulation (Art. 82).
14. Data security
BIRP implements technical and organisational measures designed to protect data against unauthorised access, disclosure, alteration, destruction, loss and unlawful processing.
Secure communications. Communications with BIRP services are protected by HTTPS/TLS.
Passwords. Passwords are protected by a hashing mechanism based on bcrypt. BIRP does not store any password in clear text.
Encryption. The relevant data in the database is encrypted using AES-256-GCM, in addition to the encryption of communications.
Data separation. Data is associated with the corresponding user and client organisation, in order to limit access between client environments.
Multi-factor authentication. BIRP uses multi-factor authentication to strengthen the protection of the relevant access.
Access rights management. Access is granted according to the roles and needs of the persons concerned.
Logging. BIRP keeps technical and security logs enabling access to be monitored, certain incidents to be detected and investigations to be facilitated. They are kept for a maximum of 365 days, subject to the exceptions mentioned in section 10.
Backups. BIRP performs backups and keeps encrypted archives, with a maximum retention cycle of 365 days.
Access from Moldova. The founders and authorised support staff established in the Republic of Moldova access data only in the course of their duties and where such access is necessary.
14.1 Personal data breaches
Where BIRP acts as controller, any breach likely to result in a risk to the rights and freedoms of individuals is notified to the competent supervisory authority within 72 hours of BIRP becoming aware of it (Art. 33). Where the breach is likely to result in a high risk, it is communicated to the data subjects concerned as soon as possible, in clear and plain language (Art. 34).
Where BIRP acts as processor, the client acting as controller is informed without undue delay after BIRP becomes aware of the breach, with the elements necessary for the performance of its own obligations, under the conditions laid down in the data processing agreement (Art. 33(2)).
BIRP keeps an internal register of breaches (Art. 33(5)).
15. Artificial intelligence and automated decisions
15.1 No decision falling under Article 22
BIRP does not take any decision based solely on automated processing, including profiling, which produces legal effects concerning a person or similarly significantly affects them, within the meaning of Article 22 of the GDPR.
There is therefore, for the processing described in this Policy, no automated decision-making logic whose consequences would have to be described under Articles 13 or 14.
15.2 AI-assisted features
Certain features of the Platform rely on artificial intelligence systems designed to assist the user in processing or interpreting information within the interface. BIRP uses Mistral AI for this purpose.
15.3 Location
The inference processing carried out by Mistral AI on behalf of BIRP is performed within the European Union.
15.4 Model training
Client Data and the other data transmitted by BIRP in the context of these features are not used to train the models of its provider. This exclusion results from the contractual and technical configuration chosen by BIRP.
15.5 Retention by the provider
In the configuration chosen by BIRP, the data transmitted to the provider is not retained by the provider beyond the processing necessary for inference.
The data stored within the Platform remains subject to the rules of section 10.
15.6 Protection within the Platform
The data used by the artificial intelligence features remains associated with the user and client organisation concerned, and benefits from the protection, encryption and access control measures described in section 14.
15.7 Transparency and human intervention
Where a user interacts with a conversational feature based on an artificial intelligence system, the user is informed of this, in accordance with Article 50(1) of Regulation (EU) 2024/1689, applicable since 2 August 2026.
The results produced by artificial intelligence are assistance tools subject to the user’s judgement. They are not used by BIRP to take automatically a legal decision or a decision significantly affecting a person.
16. Amendments to this Policy
BIRP may amend this Policy, in particular to reflect changes in its services, technologies, providers or the applicable legal framework.
The version in force and its effective date are available on BIRP’s websites. Previous versions are archived and provided upon request.
Where a substantial amendment affects the processing carried out in respect of users holding an account, BIRP informs them before it takes effect, via the Platform or by e-mail.
Where BIRP envisages further processing for a new purpose, the information provided for in section 6.2 is given beforehand.
17. Contact us
BIRP SOFTWARE S.R.L.
IDNO: 1026602001952
5 Miorița Street, MD-2065 Chișinău, Republic of Moldova
Data protection: privacy@birp.io
Support: support@birp.io
Websites: birp.io · sistemerp.md
Representative in the European Union
Ungurean Victor, 55 avenue Marceau, 75016 Paris, France, privacy@birp.io
