Următorii pași
Accesați cabinetul personal

Pay ONLINE - get a 15% discount and priority service!

Coșul meu

Notificare

Serviciul necesită

Adăugați servicii

Privacy policy

Privacy Policy for Personal Data Processing – Invitro Diagnostics SRL

Data Controller

• Full name: Invitro Diagnostics SRL
• Address: Republic of Moldova, Chișinău, str. Nicolae Testemițanu, 19/1, MD-2025
• Email: [email protected]
• Phone: +373 22 903 999
• Website: www.invitro.md

1. Policy Purpose

This policy establishes the legal framework and procedures through which Invitro Diagnostics SRL collects, processes, stores, and protects the personal data of individuals using our services or accessing our platforms. Processing is carried out in accordance with:

  • Law No. 133 of 08.07.2011 on the protection of personal data – until 22.08.2026
    Starting from 23.08.2026 Law No. 195 of 25.07.2024 on the protection of personal data;
  • Regulation (EU) 2018/1725 – GDPR;
  • Other applicable national and international regulations.

2. Objectives and Methods of Personal Data Processing

Invitro Diagnostics SRL collects and processes personal data only for specific, legal purposes based on recognized legal grounds: consent, contract execution, legitimate interest, or legal obligation.

Main purposes include:

  • Provision of requested medical services and execution of related contracts;
  • Compliance with legal obligations regarding data retention and archiving (invoices, registers, security records);
  • Protection of the Operator’s legitimate rights and interests and fraud prevention;
  • Direct marketing and communications with explicit consent of the data subject;
  • Statistical analysis and service optimization, using anonymized data whenever possible;
  • Management of IT system security and personnel.

3. Security Measures Applied

  • Data is stored and transmitted through encrypted and secure channels;
  • Access to data is allowed only for authorized personnel and is monitored through audit logs;
  • Data is not shared with third parties without legal basis or consent, except as required by law (subpoena, court order, competent authorities).

4. Data Subject Rights

Data subjects have the right to request:

  • Access to their personal data;
  • Rectification or completion of incomplete data;
  • Deletion of personal data (“right to be forgotten”), as permitted by law;
  • Restriction of data processing;
  • Data portability;
  • Objection to data processing, including for direct marketing purposes.

Requests can be sent via email to [email protected] or by registered letter to the operator’s office. Responses will be provided within the legal timeframe of 30 days.

5. Data Collected via Website and Services

Invitro Diagnostics SRL may collect:

  • Identification data (name, surname, date of birth, identification number if required);
  • Contact information (email, phone, address);
  • Technical data regarding platform interaction (IP address, pages visited, cookies) for security, administration, and direct marketing with consent;
  • Other data necessary for service provision or legal compliance.

6. Services and Methods of Data Processing

6.1. Medical services – consultations, investigations, tests, and other services provided on the platform.

6.2. Website – management of visits to www.invitro.md for security, administration, and statistical analysis; collection of technical data (IP address, visited pages) and use of cookies for user experience personalization and digital marketing campaigns (Google Analytics, Google Ads, Facebook).

6.3. Newsletter – sending commercial and informational messages (offers, promotions, news). Data subjects can unsubscribe via a link in every email. Data is stored for a maximum of 365 days from last interaction.

6.4. CRM Subscription – contact data and service interactions are retained in the CRM system for up to 3 years from last interaction.

6.5. Legal Archiving – legally required data, including invoice information, is retained for 10–15 years, in accordance with applicable legislation.

7. Legal Basis for Processing

Data is processed based on one of the following legal grounds:

  • Explicit and voluntary consent of the data subject;
  • Execution of a contract or legal obligations;
  • Legitimate interest of the operator, within legal limits;
  • Other grounds provided by national and international data protection legislation.

Medical service users have the right to withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.

8. Responsibility of the Data Subject

  • The data subject is responsible for providing accurate data and using services only for declared purposes;
  • Any unauthorized access or misuse of provided data is solely the responsibility of the user who registered the data;
  • The user guarantees that they have obtained legal consent from third parties for processing any personal data provided through the services.

9. Purpose of Processing

Data collected via our services is processed for:

  • Provision of requested services;
  • Administration and security of platforms and interactions;
  • Direct marketing and communications with data subject consent;
  • Statistical analysis and service optimization, anonymized where possible;
  • Compliance with legal or contractual obligations.

10. Consent Statement and Legal Grounds

10.1. Explicit and Voluntary Consent

I hereby voluntarily and explicitly consent to the processing of my personal data provided in the context of:

  • Visiting and using Invitro Diagnostics electronic platforms (www.invitro.md);
  • Newsletter subscription;
  • Participation in digital marketing campaigns (Facebook, Google).

I declare that I have reached the required age to receive medical services and to conclude legal acts, and that I have the necessary legal capacity; or, if I represent a legal entity or an organization without legal personality, that I have the appropriate authorization to provide consent on its behalf.

10.2. Restrictions on Sensitive Data

I declare that I will not provide data revealing:

  • Racial or ethnic origin;
  • Political, religious, or philosophical beliefs;
  • Social affiliation;
  • Health status or sexual life;
  • Criminal convictions, coercive measures, or administrative sanctions.

10.3. Right to Withdraw

Consent may be withdrawn at any time without affecting the lawfulness of processing performed before withdrawal, via:

10.4. Contact and Communication

Invitro Diagnostics SRL is authorized to contact me via:

  • Phone;
  • Email;
  • Postal correspondence;
  • Invitations to events for commercial and marketing purposes within the limits of consent given.

10.5. Legal Grounds for Processing

a) Legitimate Interest
If data is provided via a form and there is interest in Invitro Diagnostics services, it may be processed for:

  • Preparation of contractual relationships;
  • Statistical, historical, or research purposes, provided the data is anonymized.

b) Contractual
If I request services from Invitro Diagnostics, my data is processed based on the contract under GDPR and national law. Withdrawal of consent does not affect processing necessary for contract execution. After contract termination, processing is performed on other applicable legal grounds.

10.6. Note

Changing the legal ground of processing does not alter the method of data processing but only the legal justification depending on context (legitimate interest, contract, consent).

11. Rights of the Data Subject

In accordance with Regulation (EU) 2018/1725 (GDPR) and Law No. 133/2011 on the protection of personal data, in force until 22.08.2026, as well as pursuant to Law No. 195 of 25.07.2024 on the protection of personal data, effective from 23.08.2026, the data subject has the following rights:

11.1. Right to Information

The data subject may request information regarding the personal data processed by Invitro Diagnostics SRL, including:

  • Categories of data;
  • Source of the data;
  • Purpose and legal basis of processing;
  • Processing period;
  • Recipients of the data;
  • Any automated decisions or international transfers.

Requests can be submitted via:

  • Registered letter with acknowledgment of receipt to the operator’s address;
  • Email at [email protected] (only from the registered email address or accompanied by proper identification).

Invitro Diagnostics SRL is obliged to respond within a maximum of 1 month from receiving the request.

11.2. Right of Access

The data subject may request access to their personal data being processed, including the purpose, categories of data, recipients, retention period, and other legal information regarding processing.

11.3. Right to Rectification

The data subject may request the correction or completion of incomplete or inaccurate personal data, by registered letter or email at [email protected].

11.4. Right to Erasure (“Right to be Forgotten”)

The data subject may request the deletion of personal data, except in cases where processing is legally justified for:

  • Exercising the right to freedom of expression;
  • Public or legal interest;
  • Fair private interest (e.g., asserting or defending legal claims).

If the request is denied, the reason will be provided. Once deleted, data cannot be restored.
Unsubscribing from the newsletter can be done via the link in each email.

11.5. Right to Restrict Processing

The data subject may request restriction of processing:

  • If the accuracy of the data is contested, for the period of verification;
  • If processing is unlawful but the data subject opposes deletion;
  • If data is no longer necessary, but processing is required for asserting, exercising, or defending legal claims.

During the restriction period, data may only be processed with the data subject’s consent or for legal purposes.

11.6. Right to Data Portability

The data subject may request the transfer of personal data provided automatically to themselves or to another controller, in a structured, commonly used format (e.g., XML, XLS, CSV).

11.7. Right to Object

The data subject may object to the processing of personal data:

  • For direct marketing, surveys, or scientific research;
  • For the performance of a task in the public or legal interest.

Invitro Diagnostics will assess the objection and, if justified, will cease processing, block the data, and inform the data subject and previously notified third parties.

12. Purpose of Data Processing

Invitro Diagnostics SRL processes the personal data of clients and users for the following purposes:

  1. Protection of rights and interests – ensuring respect for the rights of the data subject.

  2. Identification and communication – maintaining contact, verifying entitlements, and authentication on our platforms.

  3. Personalization of content and messages – tailoring communications and marketing messages according to your interests and declared objectives.

  4. Customer support and consulting – providing assistance for inquiries, requests, and issue resolution.

  5. Presentation of services and offers – informing about relevant services, offers, and promotions.

  6. Analysis and statistics – performing statistics, evaluations, and analyses to optimize content, products, and services.

  7. Product and service development and improvement – adapting and improving services to better meet client needs.

  8. Ensuring quality and service safety – monitoring and improving contractual conditions and service safety.

  9. Compliance with legal obligations – in accordance with national and international legislation.

13. Categories of Processed Data

13.1. Data provided by the data subject

  • First and last name
  • Email address
  • Date of birth
  • Phone number
  • Home address (for home visits)
  • Legal or postal address (for invoicing in the case of legal entities)

13.2. Automatically collected data for security and operation

  • Viewed pages or functionalities
  • IP address
  • Browser cookies

13.3. Data for building a marketing profile

  • Preferences and service requirements
  • Main decision-making objectives

13.4. Call and interaction history

  • Call metadata (who, when, with whom communication occurred)
  • Recordings of calls received on the central number, used exclusively for security, internal evaluation, and customer service team training

14. Web Analysis and Tracking (Cookies and Analytics)

Invitro Diagnostics SRL uses external technologies and programs to observe and analyze visitors to www.invitro.md, to evaluate campaign effectiveness and optimize user experience, in compliance with personal data protection legislation.

14.1. Programs used

  • Google Analytics – collects statistical data about user visits (number of visitors, visit duration, pages visited, anonymized IP address to differentiate new and returning visitors). Purpose: statistics and service improvement.
  • Google Remarketing – enables displaying Invitro Diagnostics ads on other websites based on previous visits. Data collected via cookies does not allow direct identification.
  • Google Ads/Google Tag Manager (conversion tracking) – measures online advertising campaign effectiveness through cookies expiring after 30 days.
  • Meta Ads(Facebook/Instagram) – the Facebook pixel tracks browser activity to show relevant ads, without directly identifying individuals.

14.2. Data Collection

By accessing the website, the user consents to the collection and processing of data via the above programs, which may include:

  • Browser-stored cookies
  • Interactions with web pages
  • User behavior information

14.3. Right to object and cookie control

Users may refuse or limit the recording and storage of cookie data at any time through browser settings or tools provided by service providers (Google, Facebook).

14.4. Legal compliance

All programs used (Google Analytics, Google Remarketing, Ads, Facebook Remarketing) comply with data protection authority requirements and national legislation. Collected data does not allow direct identification and is not shared with third parties without legal grounds.

15. Blocking and Managing Cookies

Users have the right to manage cookies and restrict data collection in their browser. Settings can be accessed depending on the browser: Tools > Settings > Privacy > Cookies/Tracking Functions.

  • To block Google Analytics data collection, users can download the official Google Analytics Opt-out extension.
  • This extension prevents visit information from being sent to Google and stops participation in content experiments.

16. General Principles of Data Processing

  1. Legality and Transparency – Personal data is processed in accordance with good faith, transparency, and applicable legislation.

  2. Purpose Limitation – Processing is carried out exclusively for the purposes specified in this policy and with the data subject’s explicit consent.

  3. Proportionality – The amount and type of data collected is limited to what is necessary for the processing purpose.

  4. Protection of Minors – The data of persons under the age of 14 will be processed in accordance with the provisions of the applicable legislation, and the conclusion of legal acts shall be carried out with the consent of a parent or legal representative.

  5. Confidentiality and Security – The operator implements technical and organizational measures to prevent unauthorized access, loss, alteration, or disclosure of data.

  6. Third-Party Transfers – Data is not disclosed to third parties, except external service providers mentioned or for anonymized statistics without identifying individuals.

  7. Legal Provisions and Judicial Procedures – Data may be provided to authorities or courts in accordance with the law for the protection of operator rights or legal obligations.

  8. Data Authenticity and Integrity – The operator ensures data integrity and access is limited to authorized personnel only.

17. Confidentiality of Processing

  • Data is processed confidentially and used only for service operation, including email or SMS communications to the provided data.
  • Data will not be sold or transferred to third parties for marketing purposes.
  • In case of legal requests (subpoena, court decision, judicial procedures), data will be provided strictly according to the law.
  • Invitro Diagnostics exercises legal rights and obligations for data protection and the right to defend itself in court if necessary.

18. Employee Access to Data

  • Access to personal data by Invitro Diagnostics colleagues and staff is strictly limited to information necessary for performing job duties.
  • All access is logged for auditing, and access to saving or modifying data functionalities is restricted and monitored.

19. Data Retention Period

  • Data is processed for defined periods for each data category, in accordance with national legislation and GDPR.
  • Detailed security logs are kept for at least 90 days, other security logs for at least 365 days.
  • Personal data is retained for at least 365 days from the last interaction, except when law or contracts require a longer period.
  • Detailed information on data retention periods and processing purposes for various services is presented in the “Our Services” section.

20. Data Transfer

  • Invitro Diagnostics is required to transfer personal data to competent authorities under the law or upon a court order. The operator cannot be held liable for legal consequences of this transfer.
  • In the event of partial or total outsourcing of services to third parties, personal data may be transferred without prior consent, with notification to the data subject, ensuring no additional disadvantage. The data subject may object before the transfer.
  • The operator keeps records of transfers, including date, legal basis, recipient, categories of data transferred, and other legally required information.

21. Information Updates

  • The data processing policy is continuously reviewed and updated to comply with legislation and competent authority recommendations.
  • The updated version is permanently available on www.invitro.md, under the “Terms and Conditions” section.

22. Questions and Contact

For any questions regarding personal data processing, users may contact Invitro Diagnostics at [email protected].

Definitions

  • Data Processing: any operation or set of operations performed on personal data, including collection, recording, storage, use, transmission, distribution, disclosure, modification, restriction, or deletion.
  • Personal Data: any information relating to an identified or identifiable natural person.
  • Data Processor: a service provider processing personal data on behalf of the controller; in the context of services, Invitro Diagnostics SRL.
  • GDPR: General Data Protection Regulation (Regulation 2018/1725), applicable in the EU and adopted into national law through Law No. 133/2011 and Government Decision No. 1123/2010 on personal data security.

 

 

Achită online cu 15% reducere la analize!
call close
Banner
Sănătate în buzunarul tău
Descărcați aplicația mobilă InvitroZen app logo
Background decor image
Comandă apel

Întroduceți datele dvs. și vă vom contacta

Ora convenabilă
-
Orele de lucru al Call-centrului:

Luni - Vineri

07:00 - 19:00

Sâmbătă

07:30 - 16:00

Duminică

07:30 - 14:00