Salient Website Privacy Policy
This is the privacy policy for the Salient marketing website, where Salient acts as the data controller for the personal data it collects through the site.
Last updated: [EFFECTIVE_DATE]
Draft notice
This document is a draft placeholder template prepared for internal use. It is provided for informational purposes only, is pending review by a qualified Moldovan lawyer, and does not constitute legal advice. Do not treat it as final or rely on it until it has been reviewed and approved, and until the placeholders below have been completed with accurate information.
1. Who we are
Salient is a cybersecurity consultancy based in the Republic of Moldova. We operate this website to present our services and those of our sister product, Salient.sec, and to let visitors contact us. For the personal data described in this policy, Salient is the data controller, meaning we decide why and how that data is processed.
Controller: Salient, a company registered in the Republic of Moldova under registration number (IDNO) [IDNO], with its registered address at [ADDRESS]. Website: [WEBSITE]. General contact email: [EMAIL].
For any question about this policy or about how we handle your personal data, you can reach our data-protection contact at [DPO_CONTACT].
2. What this policy covers
This policy explains what personal data we collect through the Salient marketing website, why we process it, the legal bases we rely on, who we share it with, and the rights you have.
It covers only the public Salient website at [WEBSITE]. It does not cover the separate processing we carry out as a service provider or processor for our clients (including in connection with the Salient.sec product), where the client is the controller and that processing is governed by the relevant client agreements and their own notices.
3. What we collect
We keep data collection to the minimum needed to run the site and respond to you. We do not run non-essential analytics or advertising trackers at launch.
- Contact-form data: the name, work email address, company name, and message content you submit when you contact us through the site.
- Server logs: basic technical information automatically recorded by our hosting, such as your IP address, the pages requested, timestamps, and your browser/user-agent. These logs support site operation, security, and abuse prevention.
- Cookies: only strictly necessary (essential) cookies required for the site to function and to keep it secure. We do not set analytics, marketing, or profiling cookies at launch.
4. Why we process it and our lawful basis
We process personal data only where we have a lawful basis under Law No. 133/2011 on the protection of personal data (the current Moldovan law), Law No. 195/2024 on personal data protection (which applies from 23 August 2026 and aligns Moldovan law more closely with the EU GDPR), and, where applicable, the EU General Data Protection Regulation, Regulation (EU) 2016/679 (the GDPR).
- Contact-form data (legitimate interests): we process this to read, respond to, and follow up on your enquiry. Our legitimate interest is in handling enquiries about our services and running our business; we balance this against your interests, rights, and freedoms.
- Server logs (legitimate interests): we process these to operate the website reliably, keep it secure, and detect and prevent abuse.
- Essential cookies (necessary to provide the service): strictly necessary cookies are used only to deliver the website you have requested and keep it secure.
- Legal obligation: where the law requires us to retain or disclose certain data, we process it to comply with that obligation.
- Consent (only if introduced later): we do not rely on consent today because we run no non-essential cookies or trackers. If we introduce analytics or other non-essential cookies in the future, we will ask for your consent before setting them, and you will be able to withdraw that consent at any time.
5. Who we share it with
We do not sell your personal data and we do not share it for advertising. We share it only with trusted service providers who process it on our behalf and on our documented instructions (processors), under written agreements requiring appropriate confidentiality and security.
The categories of recipients are set out below. The specific providers will be identified once selected and can be confirmed on request via [DPO_CONTACT].
- Hosting provider: the provider that hosts the website and its server logs.
- Email provider: the provider that handles the delivery and storage of messages sent through the contact form.
- Public authorities: where we are legally required to disclose data, for example in response to a lawful request from a competent authority.
6. International transfers
Our processors may be located in, or transfer data to, the European Union or the European Economic Area. We seek to work with providers that apply data-protection standards consistent with the GDPR.
If personal data is transferred outside the Republic of Moldova or the EU/EEA, we will seek to rely on an appropriate safeguard or an adequacy basis recognised under the applicable law (Law No. 133/2011 now, Law No. 195/2024 from 23 August 2026, and the GDPR where it applies), with the aim of keeping your data protected. We can provide details of the safeguards used on request via [DPO_CONTACT].
7. How long we keep it
We keep personal data only for as long as needed for the purpose for which it was collected, after which we delete or anonymise it.
- Contact-form data: kept for the duration of our correspondence and for a reasonable follow-up period afterwards; if the enquiry does not lead to an engagement, we delete it once it is no longer needed.
- Server logs: kept for a short retention period for security and operational purposes, then deleted or anonymised.
- Where we are required to keep certain records to meet a legal obligation, we retain them for the period that the relevant law requires.
8. Your rights
Subject to the conditions and exceptions in the applicable law (Law No. 133/2011 now, Law No. 195/2024 from 23 August 2026, and the GDPR where it applies), you have the following rights over your personal data:
- Access: to know whether we process your data and to obtain a copy of it.
- Rectification: to have inaccurate or incomplete data corrected.
- Erasure: to have your data deleted where there is no longer a valid reason to keep it.
- Restriction: to limit how we process your data in certain circumstances.
- Objection: to object to processing based on our legitimate interests.
- Data portability: to receive certain data in a structured, commonly used, machine-readable format, or to have it transmitted to another controller where technically feasible.
- Withdrawal of consent: where we rely on consent, to withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Complaint: to lodge a complaint with the supervisory authority (see below).
How to exercise your rights and complain
To exercise any of these rights, contact our data-protection contact at [DPO_CONTACT] or write to us at [EMAIL]. We may need to verify your identity before acting, and we will respond within the time limits set by the applicable law.
If you believe we have not handled your data correctly, you have the right to lodge a complaint with the National Center for Personal Data Protection (Centrul Național pentru Protecția Datelor cu Caracter Personal, CNPDCP), the supervisory authority in the Republic of Moldova. If you are in the EU/EEA, you may also have the right to complain to the supervisory authority in your country of residence.
9. Cookies
At launch, the Salient website uses only strictly necessary (essential) cookies that are required for the site to work and to keep it secure. These do not track you across sites and are not used for analytics, advertising, or profiling.
If we later introduce analytics or other non-essential cookies, we will add a consent mechanism and will set those cookies only after you have given consent, which you will be able to refuse or withdraw at any time.
10. Security
As a cybersecurity consultancy, we apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, or disclosure. These include access controls, encryption in transit, limiting access to staff who need it, and working only with processors who commit to suitable security standards.
No system is perfectly secure. If a personal data breach occurs, we will handle it in line with our legal obligations. From 23 August 2026, Law No. 195/2024 introduces a breach-notification regime aligned with the GDPR, under which we would notify the CNPDCP without undue delay and, where feasible, within 72 hours of becoming aware of a breach that is likely to result in a risk to affected individuals, and inform affected individuals where required.
11. Children
The Salient website and our services are directed at businesses and professionals, not at children. We do not knowingly collect personal data from children through this site. If you believe a child has provided us with personal data, please contact [DPO_CONTACT] and we will take appropriate steps to delete it.
12. Changes to this policy
We may update this policy from time to time to reflect changes in our practices or in the law, including the entry into application of Law No. 195/2024 on 23 August 2026. When we make material changes, we will update the effective date below and, where appropriate, provide a more prominent notice on the site.
Effective date: [EFFECTIVE_DATE].
13. How to contact us
If you have any questions about this policy or about how we process your personal data, you can contact us:
Controller: Salient, [ADDRESS], Republic of Moldova. General email: [EMAIL]. Data-protection contact: [DPO_CONTACT]. Website: [WEBSITE].