We use the information you submit through the website to respond to your enquiry, arrange a consultation, and maintain the operation and security of the website. Below we explain what data we process, who may receive it, and what rights you have.

Who controls the data

The data controller is Cabinetul Avocatului "Colenco Aureliu", IDNO 44819029. The controller operates this website under the Colenco Legal brand and determines how enquiries submitted through it are handled. You can contact us at counsel@colenco.legal, by phone at +373 60 770 787, or at Strada Mihai Eminescu 70, of. P106, Chișinău, Moldova.

What data we process

When you submit the form, we process your name, phone number, message, optional email address, language and minimal page context. Name, phone number and message are required to submit the form; email is optional. The IP address and request information are processed transiently for connection, protection and abuse prevention, but are not retained in a separate website access log.

Purposes and legal grounds

To answer a request for legal assistance and arrange a consultation, we process data as necessary to take steps at your request before entering into a contract; submitting the form is not consent to advertising. Website security and minimal technical statistics rely on our legitimate interest in protecting and administering the site. Optional analytics, interaction recording, advertising technologies and the map rely on your consent choices. We keep mandatory information and evidence of compliance to meet legal obligations. Special-category data and information about offences are assessed separately, only on an applicable legal basis and to the extent necessary for legal assistance or legal claims. Do not use the initial form to send documents or details unnecessary for the first response.

Without a name, phone number and message the form cannot be submitted and we cannot respond through this channel. The website does not make decisions producing legal or similarly significant effects on you solely by automated means.

Providers and third-party services

The browser sends form data only to the colenco.legal server hosted by HOSTKEY B.V. in Frankfurt, Germany. The transactional email service Brevo (Sendinblue SAS) delivers form submissions, after which the message is stored in the business service Google Workspace (Google). Messages sent directly to the domain address are also delivered directly to Google Workspace. The server also passes the enquiry to the Colenco Legal bot to send a card to the private staff Telegram group. The full text is stored in the bot database under the established enquiry retention period.

Optional services are enabled only in line with your choices: Google Analytics for visit statistics; Microsoft Clarity for ease-of-use assessment, session replay and click/scroll heatmaps; and Google and Meta for measuring promotion results and presenting more relevant information about our services. Google Tag Manager is used only to manage permitted services. Joint responsibility with Meta may apply only to the limited Pixel collection and transmission phase, after which Meta acts independently.

Clarity receives a reconstruction of the page DOM, clicks, scrolling, pointer movements, device and browser information and pseudonymous online identifiers. This is not a camera video recording. Microsoft masks input fields and our enquiry forms are additionally marked for masking; we do not send our own client identifiers to Clarity. If both “Interaction recordings” and “Promotion effectiveness” are allowed, Clarity receives separate advertising permission and may share data with Microsoft Ads for retargeting and campaign and conversion measurement; in every other combination Clarity advertising permission is denied. Under the Clarity Terms, Microsoft and the practice are independent controllers. The Microsoft Privacy Statement also applies.

Google Maps belongs to the separate stored “Interactive map” category. If you select “Accept” or enable this category in the site settings, the map is loaded lazily when you approach it on the page. If this category is disabled, the “Show map” button grants, including after selecting “Decline”, one-time permission to load the map on the current page only; navigating away or reloading requires another action.

When the map loads, your browser establishes a direct connection with Google. Google may receive your IP address, browser and device information, and information about the requested place or page, and may use its own cookies or similar technologies in accordance with the Google Privacy Policy and the Google Maps/Google Earth Additional Terms of Service.

Your choices are stored in the necessary colenco_site_settings cookie for up to 180 days. The cookie contains the settings version, save time, interface language and category states, but not information entered in the enquiry form. You can change or withdraw your choices through “Site settings” in the footer.

Before a choice is made, a same-origin endpoint records only a hash of a random banner-exposure identifier, the notice version and language, the local display date and the banner's first outcome. This is needed to verify that the notice is shown, understandable and technically intact; it does not activate external analytics. IP address, User-Agent, URL and form data are not recorded. The exposure record is deleted after 90 days, technical deduplication data after 14 days, and the current-choice mirror after 180 days.

Regardless of choices for optional services, a same-origin endpoint counts only anonymised daily totals of contact actions: successful form hand-offs, opening and starting the form, and clicks on phone, email and Telegram links. To prevent duplicate delivery, the browser creates a separate random identifier for each event; the server retains only its hash and local date for no more than 14 days, and the daily totals for no more than 800 days. This mechanism does not use cookies, link actions into sessions, or record IP address, User-Agent, URL, path/query, the exact action time or form data. It is used to verify that contact channels work and does not activate external services.

To demonstrate a valid permission, the server retains for up to 911 days (the maximum 180-day choice lifetime plus two calendar years, including an allowance for a possible leap day) a minimal pseudonymous history of its grant, change and withdrawal: a hash of the random choice identifier, server time, the version and language of the displayed text, and the permitted categories. It does not include IP address, User-Agent, URL or form data. A simple refusal that was not preceded by permission is not retained in this history.

HOSTKEY and Brevo host the processing relevant to this website in the European Economic Area. Google, Meta and Microsoft may also process data in other countries. Where applicable, published contractual safeguards and standard contractual clauses are used; Microsoft states that Microsoft Ireland Operations Limited is the Clarity contracting party for EU customers and that standard contractual clauses apply to onward intra-group transfers to the United States. You may ask the controller for information about a particular transfer or an available copy of its safeguards.

If you choose Telegram, WhatsApp or Viber, the conversation passes through that service, rather than the website form and Brevo. We receive available profile information, contact details, messages and attachments you send so we can respond and arrange assistance. The messenger provider processes data under its own terms and may use infrastructure outside the EEA. These links do not load messengers automatically. Please agree an appropriate channel with us before sending confidential documents. Service privacy policies: Telegram, WhatsApp, Viber.

Cookies and local storage

  • Necessary: colenco_site_settings (up to 180 days) stores the choice; colenco_consent_exposure_v5 and technical reporting markers operate only in sessionStorage until the tab/session is closed.
  • Visit statistics: after permission, Google Analytics may set _ga and _ga_<container-id> with a default lifetime of up to two years; the browser may shorten that period.
  • Interaction recordings: after separate permission, Clarity may use first-party _clck, _clsk and Microsoft cookies CLID, ANONCHK, MR, MUID, SM to associate interactions and sessions pseudonymously. Their current purposes are listed in the Clarity cookie documentation.
  • Promotion: after marketing permission, Meta/Google identifiers including _fbp, _fbc and _gcl_* may be used. Clarity-to-Microsoft Ads sharing is allowed only when both ease-of-use and promotion permissions are enabled.
  • Map: Google may set its own cookies only after stored or one-time permission to load the map.

Retention and security

An enquiry that does not become a client matter is deleted from the final mailbox 12 months after the last substantive contact, unless a dispute or another duty requires longer retention. If a client matter begins, its documents are moved to a separate professional environment and retained under the rules applicable to legal practice. Email and transfer to the bot use separate encrypted queues: each retains an untransferred enquiry for no more than 24 hours and deletes it after acceptance by its recipient or expiry. Content-free delivery statuses are retained for 30 days, Brevo logs for no more than one month without content previews, and server privacy backups for no more than 30 days.

GA4 user and event data are retained for 14 months after the identifier's latest activity; Meta states a maximum of two years for Event Data; Clarity playback data are available for 30 days, while click/heatmap data and labelled or favourited sessions are available for up to 9 months. Data shared with Microsoft Ads follow Microsoft's retention criteria and the settings of the relevant advertising service. We use reasonable organisational and technical measures, but no online transmission can be guaranteed completely secure.

The 12-month rule covers copies we control of enquiries that did not become client matters: the corporate group archive, recipients’ mailboxes and work messenger conversations. We do not control copies held by senders or providers’ independent retention; their terms and applicable law govern those copies.

Your rights

You may request information about your data and, where applicable, ask for access, correction, deletion, restriction, portability, objection or withdrawal of consent. Withdrawal does not affect processing already performed lawfully. We may need to verify your identity and may retain information where the law or professional duties require it. You also have the right to lodge a complaint with the CNPDCP and, where the GDPR applies to the processing, with the competent EEA supervisory authority.

Updates

We may update this notice when our services or legal requirements change. The current version was updated on 10 September 2026.

Contacts

Cabinetul Avocatului "Colenco Aureliu"
IDNO: 44819029
Trading as: Colenco Legal
Tel.: +373 60 770 787
Website: colenco.legal