Privacy Policy
How Desene.md collects, uses, protects and retains personal data.
Last updated: 2026-09-03Desene.md is operated by A.O. CHILD DREAMS. This policy explains in clear language what personal data we process when you use the website, account, online coloring, collections, image search and other features.
Data controller
A.O. CHILD DREAMS, IDNO: 1019620000300, is the controller of personal data processed through Desene.md.
You can exercise your rights through the Data Rights Center.
Data we may process
- Account: first and last name, email, password only as a secure hash, account creation and login information.
- Profile: optional avatar and account preferences.
- Activity: favorites, likes, collections, saved coloring projects, downloads, prints and feedback.
- Technical/security: IP address or technical identifiers, user-agent, session and security logs.
- Image search: the uploaded file is processed to find similar drawings and is not intended to be permanently stored by the search feature.
- Privacy requests: email, request type and message.
Purposes and legal bases
- providing the account and requested functionality — performance of the service/contractual relationship;
- saved colorings, collections and preferences — service performance and, where applicable, consent;
- security, abuse prevention and logs — legitimate interests and legal obligations;
- account communications — service performance;
- optional cookies, analytics or personalized advertising — consent when such modules are enabled.
Children and consent
The service is also intended for children, but account features involving personal data must be used responsibly. When processing relies on consent for information society services offered directly to a child, Law No. 195/2024 allows the child to consent from the age of 14; below that age consent or authorization by the legal representative is required.
Recipients and providers
Data may be accessed, only where necessary, by providers of hosting/infrastructure, email, backup and security, and by analytics or advertising services only when enabled and legally permitted.
If a provider involves a transfer outside the Republic of Moldova, the transfer must comply with Law No. 195/2024 and the applicable transfer mechanism must be documented.
Retention
We retain data only as long as needed for the purpose, while the account remains active or as required for legal/security purposes. After account deletion, technical backup copies may remain temporarily until overwritten under the backup rotation policy.
Your rights
Subject to applicable law, you may request information, access, rectification, erasure, restriction, portability, object to processing and withdraw consent. Use the Data Rights Center. Logged-in users also have direct export and account deletion tools.
Requests are generally handled within one month, subject to the extensions allowed by law.
Security and incidents
We use risk-appropriate technical and organizational measures including password hashing, secure sessions, administrative access control, CSRF protection, logging and file validation. Where a breach is likely to create a high risk and the law requires it, affected persons will be informed.
Supervisory authority
You may lodge a complaint with the National Center for Personal Data Protection of the Republic of Moldova (NCPDP).