Privacy Policy
Last updated: 3 September 2026
This policy explains what data we process, why, where we keep it and what rights you have. The data controller is „DIGITALENTER” S.R.L., IDNO 1013609000055, MD-3601, str. Mihai Viteazul 2, ap. C, mun. Ungheni, Republica Moldova, contact support@glucose.md.
1. Two kinds of data
YOUR data, as a visitor or customer: name, company, phone, email, what you filled in the form and where you came to the site from.
YOUR CUSTOMERS’ data, which you enter into the system yourself: contacts, messages, tasks, files. For these you are the controller and we merely process them on your behalf, on your instructions. We do not use them for any other purpose.
2. What we collect on this site
From the demo request form: name, company, phone, email, number of managers, and whether you are coming from another CRM.
Visit source: campaign parameters from the address (utm_source, utm_medium and similar) and the page you came from, if any. It is kept in your browser’s session storage until you submit the form.
The site does not use Google Analytics, Meta Pixel or other trackers, does not load fonts or scripts from third parties, and sets no advertising cookies. That is also why there is no cookie banner.
3. Why we use it
To answer your demo request and prepare an offer — the basis is performance of a contract, or steps taken at your request before entering one.
To issue invoices and keep accounting records — the basis is a legal obligation.
To keep the service running, prevent abuse and improve the product — the basis is our legitimate interest.
4. Where the data sits
On servers in the Netherlands (European Union), operated by INTROSERV. Backups are taken daily and stay in the same space.
We do not transfer data outside the European Union, except where you yourself connect a service that processes it elsewhere — a messaging platform, for example.
5. Who else can touch the data
We use providers that help us deliver the service. Each receives only what it needs and has no right to use the data for its own purposes:
Meta Platforms Ireland Ltd. — messages from WhatsApp, Facebook and Instagram
Telegram Messenger — messages from Telegram
Google Ireland Ltd. — files attached through Google Drive
Anthropic or OpenAI — the content of messages Glucose AI replies to, where enabled
ElevenLabs — speech synthesis and transcription, where enabled
the SIP telephony provider — calls and their recordings
the payment processor and the bank — billing data
INTROSERV (Netherlands) — server hosting
We do not sell data to anyone and do not share it for advertising.
6. WhatsApp, Facebook and Instagram
When you connect a WhatsApp Business number or a Facebook page to GlucoseCRM, we act as a Meta technical provider, while you remain the controller of your own conversations. You authorise the connection yourself and can break it at any time in Settings → Chats & messengers.
From Meta we receive, and store in your account: the customer’s phone number or identifier, the name they display, message content and attached files, the time of sending, and the delivery status (sent, delivered, read, failed). We use this only to show you the conversation inside the CRM and to deliver your reply.
We do not use WhatsApp, Facebook or Instagram data for advertising, do not sell it, do not combine it with other customers’ data, and do not train artificial-intelligence models on it. Every organisation is isolated at the database level.
Deletion: write to support@glucose.md and we delete the requested conversations within 30 days at the latest. Requests arriving through Facebook (“Delete my data”) are processed automatically and receive a tracking code. Once you disconnect the number or the page, we receive nothing further from Meta.
7. How long we keep it
Contact form data: up to 24 months from the last interaction, if you do not become a customer.
Account data and your customers’ data: for the term of the contract and one further month after it ends, for export. Then it is permanently deleted.
Accounting documents: for the period required by the tax law of the Republic of Moldova.
8. How we protect it
Encrypted connection (HTTPS) on all traffic, passwords stored as cryptographic hashes, roles and permissions inside the account, isolation between organisations at the database level, daily backups, and an action log on every lead card.
No system is perfect. If a breach occurs that may affect your data, we will notify you without undue delay.
9. Your rights
You may request access to your data, correction, deletion, restriction of processing, a copy in a portable format, or object to processing based on legitimate interest.
Write to support@glucose.md and we will answer within 30 days at the latest. If our answer does not satisfy you, you may contact the National Center for Personal Data Protection of the Republic of Moldova.
10. Changes
If we change this policy, the new version is published here and the date at the top is updated. Material changes are announced by email at least 30 days before they take effect, and if you disagree you may cancel the subscription before that date — the same rules as for changes to the Terms.