Privacy Policy
Last updated: 30.07.2026

1. Introduction

Norwis SRL (“Norwis”, “we”, “us”) respects your privacy and is committed to protecting personal data in accordance with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable legislation of the Republic of Moldova.

This Privacy Policy explains how we process personal data when you visit our website norwis.md, contact us, or use our accounting, bookkeeping, and back-office services.

2. Data Controller and Data Processor Roles

Website visitors and business contacts
Norwis SRL does not directly collect or store personal data from website visitors through forms, registrations, or direct online submissions. The website does not request or collect visitors’ names, email addresses, or other contact details.

The website uses third-party analytics and cookie technologies provided by Google Analytics and Tilda analytical tools to collect statistical information about website usage, performance, and visitor interactions. This information is collected and processed by these third-party service providers in accordance with their respective privacy policies. Norwis SRL does not have direct access to identifiable personal data collected through these analytical tools.

If visitors contact Norwis SRL through direct communication channels (such as email or other means), any personal data voluntarily provided by them will be processed solely for the purpose of responding to inquiries and managing business communications.

Services provided to clients

When Norwis provides accounting, bookkeeping, and back-office services to Norwegian companies and accounting firms, we generally act as a data processor.
In these cases, our clients remain the data controllers and determine the purposes and means of processing. Norwis processes personal data only according to the client’s documented instructions and applicable data processing agreements.

3. Personal Data We Process
Depending on the nature of our relationship, we may process the following categories of personal data:

Website and business communication:
  • emails;
  • company name;
  • email address;
  • telephone number;
  • information included in correspondence.

Accounting and back-office services:
  • accounting records;
  • tax-related information;
  • invoice information;
  • employee and customer/supplier records provided by our clients;
  • other financial documentation necessary to perform contracted services.

We do not intentionally collect special categories of personal data unless such information is necessary for providing services and is provided by our clients according to applicable legal requirements.

4. Purposes of Processing

We process personal data for the following purposes:
  • providing accounting, bookkeeping, and back-office services;
  • communicating with clients and business partners;
  • fulfilling contractual obligations;
  • maintaining business records;
  • improving our services and website;
  • ensuring information security and preventing misuse.

5. Legal Basis for Processing

Depending on the situation, processing may be based on:
  • performance of a contract;
  • compliance with legal obligations;
  • legitimate interests in managing business relationships and improving services;
  • consent, where required.
  • When acting as a data processor, Norwis processes personal data based on instructions from the relevant client.

6. Service Providers and Sub-processors

Norwis may use trusted third-party providers necessary for business operations, including:
  • Microsoft 365;
  • accounting software platforms;
  • CRM systems;
  • website analytics providers.
  • Such providers may process personal data only according to appropriate agreements and security requirements.

7. International Data Transfers

Norwis is located in the Republic of Moldova.
Where personal data is transferred between Norway, Moldova, and other countries, we apply appropriate safeguards required by applicable data protection laws, including contractual arrangements and other legally recognized transfer mechanisms where necessary.

8. Data Security

Norwis applies appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, alteration, or disclosure.
Security measures include access controls, confidentiality obligations, secure systems, and controlled access to client information.

9. Data Retention

Personal data is retained only for as long as necessary for the relevant purpose, including legal, contractual, accounting, and regulatory requirements.
When acting as a processor, retention periods are determined by the client’s instructions and applicable agreements.

10. Your Rights

Depending on your relationship with Norwis and applicable law, you may have the right to:
  • request access to your personal data;
  • request correction of inaccurate information;
  • request deletion of personal data where applicable;
  • request restriction of processing;
  • object to certain processing activities;
  • request data portability where applicable.

To exercise your rights, contact us at:
info@norwis.md

11. Complaints
If you believe your personal data has been processed unlawfully, you may contact us or submit a complaint to the competent data protection authority.
For residents of Norway, complaints may be submitted to the Norwegian Data Protection Authority (Datatilsynet).

12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The latest version will always be available on our website.

Contact:
Norwis SRL
Email: info@norwis.md
  • Privacy Policy
Made on
Tilda