Skip to content
BattGrade
Legal

Data Processing Terms

Last updated 4 October 2026

1. Scope

BattGrade is a brand administered and managed by TOPFED WEB S.R.L., a limited liability company registered in the Republic of Moldova under IDNO 1026023125543, with its registered office at s. Pepeni, r-nul Sîngerei, MD-6234, Republic of Moldova.

These Data Processing Terms form part of the Terms of Service between TOPFED WEB S.R.L. (“BattGrade”, “we”) and the business that uses BattGrade (“you”). They apply when we process personal data on your behalf, as a processor under Article 28 of the EU General Data Protection Regulation (GDPR) and the corresponding rules of the Law of the Republic of Moldova No. 195/2024 on personal data protection.

You are the controller of that data. If you act for another controller, you confirm that you are authorised to give us instructions for it. If these terms conflict with the Terms of Service about personal data, these terms prevail.

2. Details of the processing

  • Subject matter: storing the customer data you enter in the app, using it to deliver the certificates you issue, and showing it to you in your account.
  • Duration: for as long as you use the service, until the data is deleted under section 10.
  • Nature of the processing: storage, organisation, retrieval, display to the authorised users of your account, transmission by email, and erasure.
  • Purposes: to issue certificates, to deliver them to your customers by email, to show you your test history, and to support you.
  • Data subjects: your customers (vehicle owners or keepers, buyers or other people who ordered a test) and any person named in a private vehicle name.
  • Personal data: customer name, email address and preferred language; the private vehicle name; the record of emails sent (recipient address and name, language, time, delivery status and any error returned by the email provider); and, while it is linked to a customer, the vehicle data of the test, including the VIN and the odometer reading.
  • Special categories of data: none. Do not enter special categories of personal data, or data about criminal convictions, in BattGrade.

3. Your instructions

We process the data only on your documented instructions. These terms, the Terms of Service and your use of the app's functions (for example sending a certificate to a customer) are your instructions. We will tell you if we believe that an instruction breaks data protection law.

We process the data for other purposes only where the law requires it. In that case we will tell you before we do so, unless that law forbids it.

4. Confidentiality

Only the people who need access to run or support the service can access the data, and they are bound by confidentiality.

5. Security

We protect the data with the measures below and review them as the service changes:

  • All connections to our website, our servers and the app are encrypted with HTTPS (TLS).
  • Every request from the app is authenticated with a sign-in token that our servers check. An account sees only its own company's certificates, and a team member sees only the certificates they issued.
  • Our internal administration pages are protected by a secret access token known only to the people who operate the service.
  • Our database runs on servers in Germany operated by Hetzner Online GmbH.
  • Customer data is never part of a certificate's public page, public PDF or signed data.
  • The private key that signs certificates is kept on our server and is never sent to the app.
  • Request limits protect our public forms and our API against automated abuse.

6. Sub-processors

You give us general authorisation to use the sub-processors listed on our Sub-processors page. We will bind each of them by written terms that protect the data at least as well as these terms, as far as their work for us requires, and we remain responsible to you for them.

We will announce a new or replaced sub-processor on that page, and by email to account owners, at least 30 days before it starts processing customer data. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may stop using the service and delete your account before the change.

7. International transfers

We are established in the Republic of Moldova. The European Commission has not adopted an adequacy decision for Moldova, so if you are established in the European Union or the European Economic Area, providing customer data to us is a transfer of personal data to a third country under Chapter V of the GDPR.

Our database is hosted in Germany. The Sub-processors page shows where each provider is established and which of them receive customer data.

We do not currently offer signed standard contractual clauses. If your organisation needs a transfer agreement before it sends customer data to us, contact us at [email protected] before you start.

8. Help with your obligations

Taking into account the nature of the processing, we will help you respond to requests from your customers who exercise their rights of access, rectification, erasure, restriction, portability and objection. If a customer contacts us directly about data we process for you, we will forward the request to you and tell the customer that we have done so.

We will also give you the information you reasonably need, as far as it concerns our processing, for a data protection impact assessment or a consultation with a supervisory authority.

9. Personal data breaches

If we become aware of a personal data breach affecting customer data, we will notify the account owner by email without undue delay. As the information becomes available, we will describe what happened, the categories and approximate number of people and records concerned, the likely consequences, and the measures taken or proposed, so that you can meet your own obligations under Article 33 GDPR.

10. Deletion

While you use the service, you can ask us at [email protected] to delete the customer data of a particular certificate or customer. We will delete it and confirm.

When the account owner deletes the account, we delete the customer data on the company's certificates and the record of emails sent to customers, as part of the deletion. If you want a copy, ask us for it before you delete the account (Terms of Service, section 18).

The public record of each certificate, its signature and the raw data of its test contain no customer data. They stay available after deletion so that the certificate can still be verified, and we keep them as controller, as described in the Privacy Policy. Emails already delivered to your customers remain in their mailboxes.

11. Information and audits

We will make available the information necessary to show that we meet our obligations under Article 28 GDPR: mainly this document, the Sub-processors page and written answers to your reasonable questions. If that is not enough, you may audit our compliance once a year, with at least 30 days' written notice, during business hours, at your own cost and under confidentiality. An audit may not give access to other customers' data.

12. Your responsibilities

You are responsible for having a lawful basis for the customer data you enter, for informing your customers as described in section 6 of the Terms of Service, and for the accuracy of the data.

13. Liability

Each party's liability under these terms is subject to the limitations in the Terms of Service, as far as the law allows.