Skip to main content
EUROBRIDGE Ukraine–Moldova — Funded by the European Union
About the project Transparency News Gallery
Log in Register

Privacy Policy

Version 1.0 · Effective date: 22 June 2026

1. Introduction

This Privacy Policy (the "Policy") describes how the personal data of users of the EUROBRIDGE UA MD online platform (the "Platform"), available at https://eurobridge-uamd.org, is processed.

The Platform serves the cross-border cooperation grant programme between the Republic of Moldova and Ukraine, the Project EUroBRIDGE_UA_MD: Building Collaborative Pathways for Regional Development and Improved Administrative Capacity for EU Cohesion Policy Adoption in Ukraine and Moldova (the "Programme"), funded by the European Union and jointly managed by the Regional Development Agency of Odesa Region (RDAOR), Ukraine, the Municipal Centre for the Development of Entrepreneurship (CMDA / MCDE), Republic of Moldova (the "Managing Authorities"), and the consultancy company Hygia Consult (Romania).

This Policy supplements the Platform's Terms and Conditions of Use and must be read together with them. Data is processed in compliance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality.

2. Applicable legal framework

Processing is carried out in accordance with the applicable data protection legislation, in particular:

  • Regulation (EU) 2016/679 of 27 April 2016 (GDPR), insofar as it is applicable;
  • the legislation of the Republic of Moldova: Law No. 133/2011 on the protection of personal data, until 23 August 2026, and Law No. 195 of 25 July 2024, which enters into force on 23 August 2026 and fully transposes the GDPR into national legislation, replacing Law No. 133/2011;
  • the legislation of Ukraine in the field of personal data protection;
  • the rules and obligations applicable to European Union funding.

3. The data controller and the data protection officer

3.1. The data controllers are the Managing Authorities, within the limits of their respective responsibilities under the Programme. Where they jointly determine the purposes and means of processing, they act as joint controllers.

3.2. For any question regarding the processing of data and for the exercise of rights, data subjects may contact the controller at: info@cmda.md.

3.3. Where a data protection officer (DPO) is appointed, the contact details are: info@cmda.md.

4. Definitions

Personal data: any information relating to an identified or identifiable natural person. An identifiable person is one who can be identified, directly or indirectly, by reference to an identification number or to one or more factors specific to their physical, physiological, mental, economic, cultural or social identity.

Processing: any operation performed on personal data, by automated or non-automated means, such as collection, recording, organisation, storage, retention, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, combination, blocking, erasure or destruction.

Data subject: the natural person whose data is processed (for example, the representative of an applicant or of a partner, an evaluator or a member of staff of a programme body).

Controller: the person or entity that determines the purposes and means of processing.

Processor: the person or entity that processes data on behalf of the controller (for example, a hosting service provider).

Recipient: the person or entity to whom the data is disclosed, including evaluators and the persons responsible for receiving the submitted materials.

5. Categories of data processed

Depending on the user's role and the stage of the Programme, the following categories of data may be processed:

  • identification and contact data: surname, first name, position, the organisation represented, email address, telephone number;
  • account and authentication data: username, login data, activity logs;
  • data from the grant application and its annexes: information about the applicant and partners, the description of the project, the budget and supporting documents;
  • data relating to contracting, reporting and monitoring: signed grant contracts, financial and narrative reports, monitoring documents;
  • technical data: IP address, device and browser type, data collected through cookies strictly necessary for the operation of the Platform.

Please do not include in the uploaded documents special categories of data (for example, health data) unless this is strictly necessary and required under the Programme.

6. Purposes and legal bases of processing

The Managing Authority processes your personal data solely for the implementation of the Project EUroBRIDGE_UA_MD, for the following purposes and on the following legal bases:

6.1. Creating and administering accounts and ensuring the operation of the Platform. Legal basis: the performance of a contract or of pre-contractual measures and the legitimate interest in ensuring the security and proper functioning of the Platform.

6.2. Managing grant applications, evaluation, contracting, reporting and monitoring. Legal basis: the performance of a task carried out in the public interest related to the implementation of the Programme and the performance of the grant contract.

6.3. Compliance with legal, control, audit and reporting obligations, including towards the Managing Authorities, the European Commission and other authorised bodies. Legal basis: the legal obligation and the conditions of European Union funding.

6.4. Communicating with users regarding applications, projects and technical matters. Legal basis: the legitimate interest or the performance of the contract.

6.5. Where processing is based on consent, the data subject may withdraw their consent at any time, without affecting the lawfulness of processing carried out prior to the withdrawal.

7. Who has access to data. Obligations of recipients

7.1. Access is limited to the persons who need the data to carry out their tasks under the Programme, on the basis of a system of roles and permissions.

7.2. Data may be accessed by or disclosed to: the authorised staff of the Platform Operator and of the Managing Authorities; the appointed evaluators; as well as the persons responsible for receiving, verifying and administering the submitted materials.

7.3. The persons responsible for receiving the materials, the evaluators and any other persons who, by virtue of their role, access the applications, reports and supporting documents are obliged to comply with this Policy and the applicable legislation. They process the data solely for the purpose of their tasks, are bound by the obligation of confidentiality, and may not use, disclose or transmit the data for other purposes. The obligation continues even after the capacity on the basis of which access was obtained has ended.

7.4. Data may also be processed by processors (for example, hosting and maintenance providers), who act solely on the basis of the controller's instructions and under agreements that impose adequate safeguards.

7.5. Data may be disclosed to the competent public authorities, control and audit bodies, and courts, where the law requires this or where it is necessary for the establishment, exercise or defence of a right.

8. Cross-border data transfers

8.1. By its nature, the Programme involves an exchange of data between the Republic of Moldova, Ukraine and, where applicable, the member states of the European Union. The data may be subject to cross-border transfers between these jurisdictions.

8.2. In the case of transfers, all the parties involved (the Platform Operator, the Managing Authorities, the evaluators, the persons responsible for receiving the materials and the processors) comply with the requirements of the competent national data protection authority and with the adequate safeguards provided for by the legislation applicable to each party.

8.3. Transfers are carried out only under the conditions permitted by law, on the basis of an adequacy decision, of adequate safeguards (for example, standard contractual clauses) or of other legal bases. Upon request, data subjects may obtain information about the safeguards applied.

9. Retention period

9.1. Data is retained only for the period necessary to fulfil the purposes for which it was collected, including for the duration of the Programme and for the archiving, control and audit periods required by the rules on European Union funding and by national legislation.

9.2. Upon expiry of the retention periods, the data is erased, destroyed or anonymised under secure conditions.

10. Data security

10.1. The controller and the hosting and maintenance providers implement appropriate technical and organisational measures to protect the data against unauthorised access, loss, alteration or disclosure, including role-based access control, secure data transmission and activity logging.

10.2. Users contribute to security by keeping their authentication credentials confidential and by notifying without delay any suspicion of unauthorised use of the account.

11. Rights of data subjects

Under the conditions and within the limits provided for by the applicable legislation, data subjects have the following rights:

  • the right of access to their own data: to request and receive a response regarding the processing of the data and, if so, access to the data and information about how it is processed;
  • the right to rectification of inaccurate or incomplete data, without undue delay; the rectification is communicated to each recipient, except where this is impossible or involves disproportionate effort;
  • the right to erasure of data (the "right to be forgotten"), under the conditions of the law, where you withdraw your consent and there is no other legal basis for processing;
  • the right to restriction of processing; once restricted, the data may be processed only with your consent;
  • the right to object to processing, where it serves a public interest or a legitimate interest of the controller; in the case of direct marketing, you may object at any time;
  • the right to data portability, where applicable: to receive the data in a structured, commonly used and machine-readable format, and to transmit it directly to another controller, where technically feasible;
  • the right to withdraw consent, where processing is based on consent;
  • the right to lodge a complaint with the competent supervisory authority.

11.1. To exercise these rights, the data subject may send a request to the contact details indicated in Article 3. The controller responds within the time limits provided for by the applicable legislation.

12. Supervisory authorities

12.1. Data subjects have the right to lodge a complaint with the competent national supervisory authority, in particular:

  • in the Republic of Moldova: the National Centre for Personal Data Protection (CNPDCP);
  • in Ukraine: the competent national authority (Ukrainian Parliament Commissioner for Human Rights).

13. Cookies and similar technologies

13.1. The Platform uses cookies that are strictly necessary for its operation (for example, for authentication and security). Cookies that are not strictly necessary are installed only on the basis of the user's consent, in accordance with the applicable legislation.

14. Amendment of the Policy

14.1. This Policy may be updated periodically, in particular to reflect changes to the Platform, to the Programme or to the applicable legislation, including the entry into force, on 23 August 2026, of Law No. 195/2024 of the Republic of Moldova.

14.2. The updated version is published on the Platform, indicating the date of entry into force.

15. Contact

For any question regarding this Policy or the processing of personal data, you may contact us at: info@cmda.md. Further information about the Programme is available at https://eurobridge-uamd.org/info/.

This website was produced with the support of the European Union. Its contents are the sole responsibility of the author(s) and do not necessarily reflect the views of the European Union. Neither the European Union nor the granting authority can be held responsible for them.

Back to home

EUROBRIDGE UA MD

Cross-border cooperation grant programme between the Republic of Moldova and Ukraine. Platform for application, contracting, reporting and monitoring.

Managing Authorities: RDAOR (Odesa Oblast, Ukraine) and MCDE (Moldova).

Regional Development Agency of Odesa Region CMDA — Centrul Municipal pentru Dezvoltarea Antreprenoriatului

Programme

Home

Communication & visibility

Access

Log in

Register

Legal

Terms and Conditions of Use

Privacy Policy

Funded by the European Union. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union. Neither the European Union nor the granting authority can be held responsible for them.