Privacy policy
How we collect, use and protect your personal data.
Publication draft prepared: 1 August 2026
Last updated: 1 August 2026
1. ABOUT THIS PRIVACY POLICY
This Privacy Policy explains how "Bus System BS" S.R.L. ("Bussystem", "we", "us" or "our") processes personal data in connection with the WGO software platform and related services.
WGO is a technology platform for passenger transport companies, ticket sellers, dispatchers, drivers, business partners and passengers. Unless a booking flow expressly identifies Bussystem as the carrier for a specific journey, WGO is not the carrier and does not itself perform the passenger transport service.
This Privacy Policy applies, as relevant, to:
- WGO websites, web applications, passenger portals and administrative tools;
- WGO passenger, driver, dispatcher and other mobile applications;
- ticket searches, reservations, purchases, ticket issuance, changes, cancellations and refunds;
- WGO accounts and authentication;
- customer relationship management (CRM), support and feedback functions;
- Telegram bots, Telegram Mini Apps and other enabled messaging channels;
- telephone, IVR, call-centre and PBX integrations;
- payment initiation, payment-status, reconciliation and fraud-prevention functions;
- e-mail, SMS, push notifications and service communications;
- WGO APIs, webhooks, callbacks, imports, exports and partner integrations; and
- security, monitoring, analytics and service-improvement activities associated with the above (the "Services").
This Privacy Policy does not replace the privacy notice of a carrier, transport operator, ticket seller, employer, WGO business customer, payment provider or other organisation that independently determines the purposes and means of its processing. Where another organisation is the controller, its identity and privacy notice should be shown at the relevant point of collection.
2. WHO IS RESPONSIBLE FOR PERSONAL DATA
2.1 Bussystem as an independent controller
Bussystem acts as a controller where it independently determines why and how personal data is processed. This may include:
- registration, authentication and administration of a direct WGO account;
- operation, security, availability and improvement of the WGO platform;
- management of Bussystem's direct customer, supplier and partner contracts;
- Bussystem billing, accounting, tax and legal compliance;
- enquiries or complaints addressed directly to Bussystem;
- Bussystem's own marketing, provided the required lawful basis exists;
- prevention of fraud, abuse and unauthorised access affecting WGO;
- establishment, exercise or defence of Bussystem's legal claims; and
- platform-level analytics for Bussystem's own purposes, but only within the limits disclosed in this Policy and agreed with the relevant business customers.
2.2 Bussystem as a processor
For many ticketing, CRM, dispatch, passenger-support, PBX, messaging and integration activities, a carrier, ticket seller, employer or other WGO business customer determines the purposes and essential means of processing. That organisation is the controller and Bussystem acts as its processor, processing personal data only on documented instructions and under a Data Processing Agreement.
If personal data is held in a WGO tenant, carrier account, CRM workspace, telephone line, Telegram channel or ticketing environment controlled by a WGO business customer, that customer's privacy notice is normally the primary notice for that processing. Bussystem will assist that controller with data- subject requests, security and other legal duties as required by law and contract.
2.3 Carriers and ticket sellers
The carrier performing a journey normally acts as controller for:
- entering into and performing the passenger transport contract;
- passenger manifests and boarding control;
- route operations, journey changes and safety communications;
- identity, visa, border, customs or immigration requirements;
- complaints, incidents, lost property, insurance and transport claims; and
- compliance with transport and public-authority obligations.
The booking page, ticket or booking confirmation must identify the relevant carrier or ticket seller and provide access to that organisation's privacy notice and contact details.
2.4 Other independent controllers
Payment providers, acquiring banks, card schemes, telecommunications operators, Telegram and certain integration partners may act as independent controllers for their own processing. Their own privacy notices and legal obligations apply to that processing.
2.5 Joint controllers
If Bussystem and another organisation jointly determine the purposes and means of a processing operation, they will document their respective responsibilities in an arrangement required by applicable law and make the essence of that arrangement available to affected persons.
3. PERSONAL DATA WE PROCESS
Depending on the Service used and the role of the relevant controller, the following categories may be processed.
3.1 Identity and passenger data
- first name, last name, preferred name and title;
- date of birth, age, gender, nationality and country of residence where required for the journey, fare or applicable law;
- customer number, passenger identifier and signature where required;
- identity-card, passport or travel-document type, number, issuing country, issue date and expiry date;
- visa, residence-permit or border-document information where required;
- passenger category, discount eligibility and accompanying-person details;
- the minimum assistance information required for a requested journey; and
- an image or copy of an identity or travel document only in the limited circumstances described in Section 9.
3.2 Contact and communication data
- telephone number;
- e-mail address;
- postal or billing address;
- Telegram user ID, username, display name, chat ID and other messaging identifiers provided by the selected channel;
- preferred language and communication channel; and
- messages, attachments and communication history.
3.3 Account and authentication data
- account ID, username, tenant and organisation affiliation;
- securely hashed password or other authentication credential;
- one-time codes, access tokens and session data;
- role, permissions and administrator settings;
- login history, security events and account-recovery information; and
- records of acceptance, notice delivery, consent and withdrawal.
3.4 Booking, ticket and travel data
- origin, destination, route, stops, date and time of travel;
- carrier, journey, vehicle, driver, boarding and disembarkation points;
- order, reservation, ticket and transaction identifiers;
- seat, luggage, fare, discount, promotion and service selections;
- booking, check-in, boarding, change, cancellation and refund status;
- fellow passengers included in the same booking;
- booking source, sales agent and sales channel; and
- complaint, incident, lost-property and claim information relating to the journey.
3.5 Payment and financial data
- amount, currency, payment time, method and status;
- masked card digits and card brand where returned by the payment provider;
- payment token, transaction ID, authorisation and fraud results;
- billing, invoice, reconciliation, chargeback and refund records; and
- merchant, terminal or mobile point-of-sale identifiers where applicable.
Complete card numbers and card verification values are intended to be handled by authorised payment providers and are not stored by WGO. If this changes, affected persons will receive a specific notice and the legally required payment-security controls will be implemented before collection begins.
3.6 CRM, support and feedback data
- enquiries, requests, complaints, feedback and survey responses;
- correspondence with passengers, customers, dispatchers and support staff;
- case notes, tags, priority, status, assigned agent and resolution;
- photos, files, voice messages and other attachments voluntarily submitted;
- source and history of interactions across enabled channels; and
- information necessary to investigate and resolve a request or dispute.
3.7 Telephone and PBX data
- incoming and outgoing numbers and caller ID;
- date, start time, end time, duration, queue and IVR selections;
- transfers, missed calls, call disposition and assigned agent;
- links between a telephone number, CRM record, booking and prior support history;
- call audio, but only where recording is enabled and lawful; and
- transcripts, summaries and quality notes, but only where separately enabled and disclosed.
3.8 Device, network, cookie and technical data
- IP address, device identifiers and advertising identifiers where permitted;
- device model, operating system, application and browser version;
- language, time zone, approximate location derived from IP and regional settings;
- cookie, SDK, local-storage and session identifiers;
- page views, referral source, events and interaction data;
- API, webhook, callback, delivery, error and audit logs;
- crash, performance and diagnostic information; and
- security signals, suspected abuse and fraud indicators.
3.9 Location data
Where enabled and permitted, a mobile application may process approximate or precise location for nearby boarding points, navigation, driver operations, journey progress, fraud prevention or safety. Precise location is collected only after the required device permission and legal basis are obtained. The specific app notice must explain whether location is used in the foreground, background or both.
3.10 Business-user and workforce data
For drivers, dispatchers, employees, contractors, sales agents and business- customer representatives, data may include:
- employer, organisation, role and work contact details;
- work schedule, route, assigned vehicle and operational status;
- permissions, actions performed in WGO and audit history;
- training, support and operational performance information; and
- business correspondence and contract-administration records.
The employer or business customer is normally responsible for providing the required workforce privacy notice.
3.11 Special-category and other highly sensitive data
Health, disability, biometric, genetic, religious or other special-category data is not intentionally requested unless it is strictly necessary for a requested assistance service, accessibility, safety, an emergency, a legal claim or another legally authorised purpose. Such processing requires both an ordinary legal basis and the additional condition required for special- category data, such as explicit consent, vital interests, legal claims or a specific legal authorisation.
WGO does not use identity-document images for facial recognition or biometric identification unless a separate notice, valid legal basis and required impact assessment are in place before the feature is enabled.
Do not submit complete card data, identity-document images, health information or unrelated sensitive data through free-text fields, calls or messaging channels unless specifically requested and necessary.
4. PURPOSES, CONTROLLER ROLES, LEGAL BASES AND RETENTION
The correct legal basis depends on the specific controller and purpose. A list of legal bases does not permit personal data to be used for unrelated purposes. The following processing map is the baseline for WGO.
4.1 Journey search and fare display
Purpose: search routes, dates, availability and fares. Typical data: search criteria, language, currency, approximate location if used. Controller: the entity operating the search service; identify it in the search interface. Bussystem may be controller for a direct WGO search service or processor where a business customer operates the service. Legal basis: steps requested before a contract; legitimate interests for strictly necessary service operation and security. Recipients: selected carriers, schedule providers and hosting providers only where necessary. Retention: search requests are kept only for the technical log and analytics period stated in Sections 13 and 21.
4.2 Booking, ticketing, journey changes and refunds
Purpose: create and perform the passenger transport transaction. Typical data: identity, contact, itinerary, ticket, payment status and required passenger information. Controller: normally the carrier and/or ticket seller identified during checkout. Bussystem normally acts as processor for that controller. Legal basis: performance of the passenger transport or ticket-sale contract; steps requested before that contract; legal obligations applicable to the carrier or seller. Recipients: carrier, authorised ticket seller, payment provider, operational partners and authorities where legally required. Retention: the controller's documented transport, accounting and claims schedule; identity data must not be kept merely because storage is convenient.
4.3 Direct WGO account
Purpose: create, authenticate, secure and administer a WGO account requested by the user. Typical data: contact, login, authentication, preference and account history. Controller: Bussystem. Legal basis: performance of the account service contract; legitimate interests in security, auditability and abuse prevention; consent for optional features where required. Recipients: authentication, hosting, security and support providers. Retention: account lifetime plus up to three years after closure, except that security or legal-claim records may be kept for the applicable limitation period.
4.4 Business-customer administration
Purpose: provide SaaS accounts, permissions, billing and contractual support to carriers and other business customers. Typical data: representative name, work contacts, role, permissions, audit and billing records. Controller: Bussystem for its direct business relationship; the employer or business customer for its workforce administration. Legal basis: contract; legal obligation; legitimate interests in administration, security and audit. Recipients: hosting, accounting, e-mail, support and professional advisers. Retention: contract term plus the applicable accounting and legal-claims period.
4.5 CRM and passenger support
Purpose: receive, route, investigate and resolve enquiries or complaints and maintain an appropriate support history. Typical data: contact, booking, communication, case notes and relevant payment- status information. Controller: the organisation operating the support channel. Bussystem is controller for enquiries addressed directly to Bussystem and normally processor for carrier-operated support. Legal basis: contract or steps requested by the person; legitimate interests in efficient support, quality and dispute management; legal obligation where a complaint must be handled under law. Recipients: authorised support staff, relevant carrier, communications and support providers. Retention: normally three years after closure of the case, or a shorter period configured by the relevant controller; longer only for an unresolved dispute, legal duty or legal claim.
4.6 Caller recognition, call routing and PBX metadata
Purpose: route calls, identify an existing customer record, display relevant travel/support history to authorised staff and document handling of a request. Typical data: telephone number, call metadata, CRM match, booking history and assigned agent. Controller: normally the owner of the telephone line and support operation. Bussystem normally acts as processor for that controller. Legal basis: steps requested by the caller; performance of a service contract; legitimate interests in efficient support, security and audit, supported by a documented balancing assessment where required. Recipients: telecommunications/PBX provider, authorised support staff and WGO as processor. Retention: call metadata is normally retained for up to 12 months, unless a shorter business-customer setting applies or a legal claim requires longer.
4.7 Call recording, transcription and AI-generated summaries
Purpose: document instructions, investigate complaints or fraud, protect legal rights, and, where proportionate, review service quality. Typical data: call audio, transcript, summary, speaker information and review notes. Controller: the organisation that decides to enable recording or transcription. Legal basis: the basis specifically disclosed before recording begins. This may be consent, a documented legitimate interest or another legal ground expressly permitted by law. Consent must not be used where it cannot be freely refused. Special-category data requires an additional legal condition. Recipients: authorised quality/support personnel and the identified recording or transcription provider. Retention: routine quality/training recordings are retained for no more than 90 days by default. A recording linked to an unresolved complaint, fraud investigation, legal obligation or legal claim may be isolated and retained for the period necessary for that matter. Transcripts must not be kept longer than the source purpose requires.
Before every recorded call, the caller must receive a clear notice identifying the controller, the fact and purpose of recording and where to find this Policy. Where recording relies on consent, a reasonably accessible non-recorded channel must be offered. The provider name, processing country, international-transfer mechanism and whether data is used to train provider models must be disclosed in the current Subprocessor List or a specific notice. Provider training with WGO call data is not permitted unless separately assessed, contractually authorised and transparently disclosed.
4.8 Payments, reconciliation, fraud and refunds
Purpose: initiate payment, receive payment status, reconcile funds, process refunds and prevent payment abuse. Typical data: amount, currency, token, transaction identifier, masked card data, status, fraud signals and billing information. Controller: the merchant, payment provider and/or acquiring bank according to their roles. Bussystem is controller only for its independently determined payment administration and processor where it acts on a business customer's instructions. Legal basis: contract; legal obligation; legitimate interests in fraud prevention and legal claims. Recipients: payment processor, bank, merchant, accounting provider and fraud- prevention provider. Retention: transaction and accounting records for the legally required period; fraud data only while necessary and proportionate.
4.9 Platform security, logs and abuse prevention
Purpose: authenticate users, protect tenants, detect attacks, investigate abuse, maintain audit trails and restore service. Typical data: account, IP, device, session, access, event, error and security logs. Controller: Bussystem for WGO platform security; business customer for security activities it independently controls. Legal basis: legitimate interests in protecting users, systems, information and legal rights; contract; applicable security obligations. Recipients: hosting, cybersecurity, monitoring and incident-response providers. Retention: raw technical and security logs normally up to 12 months; relevant records may be isolated for an active incident or legal claim.
4.10 Essential website and application technologies
Purpose: authentication, session continuity, security, load balancing, language/currency preferences and other functionality requested by the user. Typical data: cookies, local storage, session identifiers, preferences and security signals. Controller: operator of the relevant website or application. Legal basis: performance of the requested service and/or legitimate interests; storage or access on the user's device only under the specific electronic- communications rule that permits it. Retention: as stated for each technology in the Cookie Policy.
4.11 Non-essential analytics
Purpose: measure audiences, navigation, product performance and feature usage. Typical data: online identifiers, device/browser details, referral, pages, events and approximate location. Legal basis: prior consent where required. Analytics must not be loaded before valid consent where the applicable law requires consent. Recipients: the enabled analytics providers listed in the Cookie Policy and Subprocessor List. Retention: the period configured for each tool and disclosed in the Cookie Policy.
4.12 Direct marketing
Purpose: send offers, promotions, product news or newsletters. Typical data: name, contact channel, language, consent and campaign interaction. Controller: organisation identified when marketing consent is requested. Legal basis: prior consent, unless a specific statutory exception demonstrably applies. Consent to marketing is separate from acceptance of Terms and is not a condition of receiving unrelated Services. Recipients: authorised marketing personnel and identified e-mail, SMS, push or messaging providers. Retention: until consent is withdrawn, the person objects or the campaign purpose ends; minimal suppression-list evidence may be retained to respect the opt-out.
4.13 Legal compliance, public-authority requests and claims
Purpose: comply with a binding legal duty or lawful request and establish, exercise or defend legal claims. Typical data: only the information necessary for the specific obligation, request or dispute. Controller: the organisation subject to the obligation or claim. Legal basis: legal obligation; legitimate interests in legal claims; another ground expressly provided by law. Recipients: competent authorities, courts, lawyers, auditors and insurers. Retention: the statutory period or the time necessary for the claim, including applicable limitation periods.
4.14 Platform improvement using tenant data
Where Bussystem acts as processor, it does not use identifiable tenant passenger data for Bussystem's independent product development, marketing or model training merely because the data is available in WGO. Any independent reuse requires a compatible purpose or other valid legal basis, appropriate contract terms, a clear notice and, where required, consent or anonymisation. Truly anonymous and aggregated statistics may be used as described in Section 16.
5. HOW WE COLLECT PERSONAL DATA
Personal data may be collected:
- directly from you when you create an account, search, book, pay, contact support, call, use an enabled messaging channel or complete a survey;
- from a person who makes a booking or enquiry for you;
- from a carrier, ticket seller, dispatcher, driver, sales agent, employer or other authorised WGO business customer;
- from payment providers, acquiring banks and fraud-prevention providers;
- from Telegram and other enabled messaging or authentication platforms;
- from telecommunications operators, PBX and call-centre systems;
- automatically from browsers, devices, applications, cookies, SDKs, logs and security systems, subject to the required permissions and consent;
- from integrated marketplaces, partner systems, APIs, webhooks and feeds;
- from competent authorities or lawful public sources where necessary; and
- by generating operational information from use of the Services, such as case status, audit events and security alerts.
If you provide data about another person, including a fellow passenger, child, employee or customer, you must be authorised to do so and must give that person any privacy information required by law. Only accurate and necessary data should be submitted.
6. WHEN DATA IS REQUIRED
Some data is required by a carrier, payment provider, law or contract. Required fields are identified in the interface or are apparent from the requested service.
Without required data, it may be impossible to create an account, issue a valid ticket, process a payment or refund, comply with passenger-manifest or border requirements, authenticate a user or resolve a support request.
Optional data may be refused without affecting unrelated core Services, but the specific optional feature may then be unavailable.
7. TICKETING, CARRIERS AND INTERNATIONAL TRAVEL
WGO may facilitate a booking between a passenger and an identified carrier or ticket seller. The required personal data may be provided to that carrier, its authorised agents, terminals, ticket sellers and operational providers.
For international journeys, the carrier or applicable law may require limited passport, identity, visa, nationality, date-of-birth or passenger-manifest data. Such data may be disclosed to border, customs, immigration, police, transport or other competent authorities only where required by law or necessary to provide the requested journey.
The carrier is responsible for the transport service, journey rules, operational safety and its own use of passenger data. The carrier may contact a passenger regarding boarding, delays, cancellations, document requirements, safety or other matters necessary for the transport contract.
8. DATA ABOUT OTHER PASSENGERS
A person booking for others must provide only the information needed for the journey, must ensure that the information is accurate and must inform the other passengers about the relevant controller and this processing. Data concerning a minor must be provided by a parent, guardian or otherwise authorised person unless applicable law and carrier rules permit the minor to act independently.
9. IDENTITY AND TRAVEL DOCUMENTS
The number and essential details of an identity or travel document may be processed where required for an international journey, passenger manifest, border obligation, discount eligibility or another lawful and specified purpose.
An image or copy of an identity or travel document is collected or stored only where this is expressly required or authorised by applicable law. Operational convenience alone is not sufficient. Before collection, the responsible controller must identify:
- the legal requirement or authorisation;
- why document details are insufficient and an image is necessary;
- which fields or parts of the document are required;
- who will receive the image;
- whether it is transferred directly to the carrier or authority; and
- the deletion deadline.
Where technically possible, unnecessary fields must be masked and the image must be encrypted and access-restricted. Unless a longer period is legally required or a documented dispute exists, document images must be deleted as soon as verification or authorised transfer is complete and, as an operational maximum, within 30 days after completion of the relevant journey. The actual carrier-specific period must be stated at collection.
10. PAYMENTS
Payments may be provided by third-party processors, banks, acquiring institutions, mobile point-of-sale providers or digital wallets. Information entered in a hosted payment field or provider interface may be collected directly by that provider under its privacy notice and terms.
WGO may receive limited information such as transaction identifiers, masked card data, status, amount, currency, fraud results, chargeback and refund data. This information is used for booking completion, reconciliation, fraud prevention, support, accounting and legal compliance.
The payment provider, merchant and bank remain responsible for their independent obligations under payment-services, anti-fraud and card-security requirements.
11. TELEGRAM AND OTHER MESSAGING CHANNELS
When a WGO Telegram bot or Mini App is used, Telegram may provide information permitted by its platform and the user's settings, such as Telegram user ID, display name, username, language code, chat ID, start parameter, message content and interaction data.
Depending on the enabled flow, this data may be used to authenticate or recognise a user, provide ticketing or news, create a CRM request, route a request to an authorised dispatcher, prevent abuse and maintain an appropriate support history.
Telegram processes data under its own privacy notice. Users should not share unnecessary personal or sensitive information in a bot, group or chat. Where a carrier or other WGO customer operates the channel, that organisation normally acts as controller and Bussystem normally acts as processor.
12. CRM AND CUSTOMER SUPPORT
Authorised personnel may combine an enquiry with relevant account, booking, travel, payment-status and earlier interaction information to avoid duplicate work, route the request and provide consistent support. Staff may add case notes, status, labels, response times, outcomes and follow-up tasks.
Access is limited by tenant, organisation, role and job need. A staff member must not browse passenger history without a legitimate work reason. Access and changes should be logged and periodically reviewed.
Feedback may be used to answer the person, improve support and prepare aggregated performance reports. Identifiable feedback will not be published without permission or another valid legal basis.
13. COOKIES, SDKS, ANALYTICS AND SIMILAR TECHNOLOGIES
The Services may use cookies, local storage, pixels, mobile SDKs and similar technologies for essential operation, authentication, session management, security, preferences, performance measurement and analytics.
Strictly necessary technologies are used only to provide or secure a service requested by the user or where another specific legal exemption applies. Non-essential analytics or advertising technologies are not loaded until valid consent has been obtained where required by applicable law. Refusing non- essential technologies must be as easy as accepting them. Withdrawal must be available at any time and must not affect the lawfulness of earlier processing.
14. SERVICE COMMUNICATIONS AND MARKETING
14.1 Service communications
Authentication codes, tickets, receipts, payment status, schedule changes, boarding details, security alerts, support updates and legally required notices are service communications. They are sent only as necessary for the account, booking, request, legal obligation or security purpose and must not contain disguised advertising.
14.2 Marketing
Promotional e-mail, SMS, push, telephone or Telegram messages are sent only after the required prior consent has been obtained, unless the responsible controller has documented a specific statutory exception. Marketing consent:
- is separate from acceptance of Terms and the transport contract;
- is specific to the organisation, channel and purpose;
- is recorded with the wording, time and method of collection;
- may be withdrawn free of charge and as easily as it was given; and
- is not a condition for receiving unrelated ticketing or support Services.
An unsubscribe or objection will be honoured promptly. Minimal suppression-list data may be retained so that marketing is not restarted accidentally.
15. AUTOMATION, ROUTING AND PROFILING
Automated rules may validate forms and availability, display carrier-provided fares, route support requests, detect duplicates or suspicious activity, prioritise operational alerts, remember preferences and generate optional call or support summaries.
Unless a specific notice states otherwise, WGO does not make decisions based solely on automated processing that produce legal or similarly significant effects. A fraud or security alert may temporarily delay a transaction or trigger verification. Human review will be available where required by law.
Where qualifying automated decision-making is used, the specific notice will describe the logic in meaningful terms, its importance and expected effects, and the available rights, including human intervention and the opportunity to express a point of view and contest the decision.
16. ANONYMOUS AND AGGREGATED INFORMATION
Statistical, aggregated or anonymous information may be created for capacity planning, product improvement, research, reporting and commercial planning. Information is treated as anonymous only where a person is not reasonably identifiable, taking account of data reasonably available to Bussystem or another likely recipient. Pseudonymised data remains personal data.
Properly anonymised data may be used for lawful purposes. Bussystem will not attempt to re-identify it except to test anonymisation controls or where law expressly permits it.
17. WHO MAY RECEIVE PERSONAL DATA
Personal data may be disclosed only where necessary and lawful to:
- the carrier, ticket seller, terminal, sales agent or journey partner;
- the WGO business customer controlling the relevant tenant, CRM workspace, channel or telephone line;
- authorised dispatchers, drivers, support staff and tenant administrators;
- payment processors, acquiring banks, card schemes, digital wallets and fraud- prevention providers;
- Telegram and enabled e-mail, SMS and push-notification providers;
- telecommunications, PBX, call-routing, recording and transcription providers;
- hosting, database, storage, backup, CDN, cybersecurity and monitoring providers;
- analytics providers enabled with the required consent;
- identity or eligibility-verification providers where expressly lawful;
- auditors, lawyers, insurers, accountants and professional advisers;
- border, customs, immigration, transport, tax, law-enforcement, judicial and other competent authorities where legally required;
- parties to a proposed or completed financing, investment, merger, acquisition, restructuring, asset sale or business transfer, subject to due diligence safeguards and confidentiality; and
- another recipient at the person's direction or with valid consent.
Processors acting on behalf of Bussystem or a WGO business customer must be bound by a written contract addressing instructions, confidentiality, security, subprocessors, assistance, deletion/return and audit rights as required by law.
WGO does not sell or rent personal data for money. A disclosure necessary to provide a requested ticket, journey, payment, integration or support service is not a sale.
18. APIS, WEBHOOKS AND PARTNER INTEGRATIONS
WGO may exchange schedules, availability, fares, bookings, passenger data, ticket status, payment status, refunds, messages and operational updates through APIs, webhooks, callbacks, imports or exports.
The organisation configuring an optional integration must establish its authority and legal basis, minimise the shared fields, configure access correctly and inform affected persons. Bussystem applies appropriate authentication, authorisation, logging and security controls. An independent recipient is responsible for its subsequent processing.
API credentials must not be shared with unauthorised persons. Business customers must promptly revoke obsolete credentials and notify Bussystem of suspected compromise.
19. INTERNATIONAL DATA TRANSFERS
WGO is operated from the Republic of Moldova and may use infrastructure or providers in Moldova, the European Economic Area and other countries. Personal data may therefore be processed outside the country in which it was collected.
As of 1 August 2026, the European Commission has not adopted an adequacy decision for the Republic of Moldova. Where the GDPR applies to a transfer from the EEA to Moldova, the responsible exporter must use an appropriate transfer mechanism unless a narrow statutory derogation applies. Depending on the roles, this normally includes the European Commission's Standard Contractual Clauses:
- controller-to-processor clauses where an EEA carrier or other controller uses Bussystem as a processor in Moldova;
- controller-to-controller clauses where both parties independently determine their processing; or
- another appropriate SCC module matching the actual relationship.
The parties will also complete a Transfer Impact Assessment and apply supplementary safeguards where needed, such as encryption, strict access controls, data minimisation and pseudonymisation.
Transfers governed by Moldovan law will use the mechanism required by the law in force at the time of the transfer, including Law No. 133/2011 before its repeal and Law No. 195/2024 from 23 August 2026.
The Subprocessor List must identify each material provider, service, processing country and applicable transfer mechanism. A copy or summary of the relevant safeguards may be requested through the contact in Section 30, subject to redaction of confidential information.
An international passenger journey may require the carrier to send necessary passenger information to a destination country or authority. Any contract- necessity derogation is interpreted narrowly and is not used for repetitive, structural outsourcing.
20. CURRENT PROVIDERS AND PROCESSING LOCATIONS
Service: Website/application hosting Processing country/region: Republic of Moldova Role: processor/subprocessor
Service: Database, cache, search and backups Processing country/region: Republic of Moldova Role: processor/subprocessor
Service: Cloudflare CDN/security/R2, if enabled Processing country/region: Republic of Moldova Role: processor and/or independent controller for limited data
Service: Resend e-mail delivery, if enabled Processing country/region: Republic of Moldova Role: processor/subprocessor
Service: Google Tag Manager / Google Analytics 4, if enabled Processing country/region: Republic of Moldova
Service: Rybbit analytics, if enabled Processing country/region: Republic of Moldova Role: processor/subprocessor or self-hosted component
Service: Telegram bot / Mini App Processing country/region: Republic of Moldova Role: independent controller and/or processor depending on the function
Service: Moldcell PBX/telecommunications, if enabled Processing country/region: Republic of Moldova
Service: Call transcription or AI summaries, if enabled Processing country/region: Republic of Moldova Role: processor/subprocessor Provider-model training: YES
Service: Payment processing/acquiring Processing country/region: Republic of Moldova Role: independent controller and/or processor
Service: SMS and push notifications Processing country/region: Republic of Moldova Role: processor/subprocessor
21. RETENTION AND DELETION
Personal data is retained only for the time necessary for the stated purpose, the controller's documented instructions and applicable legal, accounting, tax, transport, payment, security and limitation-period requirements.
Unless a shorter period is configured or a specific law requires another period, the WGO operational baselines are:
- direct WGO account/profile: account lifetime plus up to three years after closure;
- booking, ticket, invoice and payment-status data: the period required by the relevant carrier/merchant's accounting, transport and legal-claims schedule;
- passenger-manifest and document details: only for the route-specific legal period and otherwise the shortest period necessary for the journey;
- identity-document images: as soon as verification or authorised transfer is complete and normally no later than 30 days after the journey, unless a law or documented dispute requires longer;
- CRM, support and messaging records: normally up to three years after case closure;
- PBX metadata: normally up to 12 months;
- routine quality/training call audio and transcripts: no more than 90 days;
- raw technical, access and security logs: normally up to 12 months;
- precise location: Republic of Moldova, and no longer than the operational purpose requires;
- marketing data: until withdrawal, objection or purpose expiry;
- consent, opt-out and privacy-request evidence: for the compliance and legal- claims period;
- deleted data in backups: isolated from ordinary use until overwritten under the backup cycle, normally within 90 days.
A record may be kept longer only for a documented legal obligation, unresolved complaint, fraud/security investigation, debt recovery or legal claim. Access must be restricted during the extended period. Legal holds must be recorded and removed when the reason ends.
Where Bussystem acts as processor, deletion is controlled by the relevant business customer's documented instructions and contract. At the end of the service, data is deleted or returned as instructed, unless law requires continued storage.
22. DATA SECURITY
Risk-appropriate technical and organisational measures are used to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Depending on the context, these include:
- encryption in transit and, where appropriate, at rest;
- tenant separation, role-based access and least privilege;
- multi-factor authentication for privileged access where supported;
- access, change and security logging;
- backup, recovery and service-continuity controls;
- secure software development, code review and vulnerability management;
- secrets management and credential rotation;
- processor/vendor due diligence and contractual security terms;
- confidentiality duties and personnel training;
- incident-response procedures; and
- periodic access, retention and security reviews.
No internet service is completely secure. Users must protect credentials, use secure devices, limit account access to authorised persons and promptly report suspected compromise. Business customers are responsible for lawful and secure configuration of users, permissions, integrations and uploaded data.
23. PERSONAL DATA BREACHES
Bussystem maintains procedures to detect, assess, contain, document and respond to personal data breaches.
Where Bussystem is controller, it will notify the competent supervisory authority within the deadline required by the law then applicable, including within 72 hours where that deadline applies, unless the statutory conditions for notification are not met. Where a breach is likely to create a high risk to affected persons, those persons will also be informed without undue delay unless a lawful exception applies.
Where Bussystem is processor, it will notify the relevant controller without undue delay after becoming aware of a breach and will provide the information and assistance required by law and contract. The controller remains responsible for regulatory and data-subject notifications unless the law or contract validly provides otherwise.
24. DATA PROTECTION IMPACT ASSESSMENTS
Before enabling processing likely to result in a high risk, the responsible controller will assess whether a Data Protection Impact Assessment is required. This assessment is particularly relevant to:
- large-scale linking of telephone numbers, CRM profiles and travel history;
- systematic recording, transcription or AI analysis of calls;
- large-scale or systematic tracking of drivers or passengers;
- special-category data or identity-document images;
- significant automated decisions or profiling;
- new technologies involving systematic monitoring; and
- combining datasets in ways people would not reasonably expect.
If residual high risk cannot be reduced to an acceptable level, the competent supervisory authority will be consulted where the applicable law requires it.
25. YOUR DATA PROTECTION RIGHTS
Subject to applicable law and lawful limitations, a person may have the right to:
- receive clear information about processing;
- obtain confirmation whether their data is processed;
- access personal data and receive a copy;
- correct inaccurate data and complete incomplete data;
- request deletion where no lawful ground for retention remains;
- request restriction of processing;
- receive qualifying data in a structured, commonly used and machine-readable format and transmit it to another controller;
- object to processing based on legitimate interests or a public-interest task;
- object at any time to direct marketing;
- withdraw consent at any time where consent is the basis;
- request human intervention for qualifying automated decisions;
- lodge a complaint with a competent supervisory authority; and
- exercise any additional right provided by applicable law.
Rights are not absolute. Data may be retained where required by law or necessary for accounting, transport duties, security, fraud prevention, another person's rights or legal claims. Information concerning another person may be redacted.
26. HOW TO EXERCISE YOUR RIGHTS
A request may be submitted through the privacy contact in Section 30. The request should identify the relevant WGO account, booking, telephone number, Telegram interaction, carrier or other business customer so that the correct controller and data can be located.
Reasonable information may be requested to verify identity and authority. It will be used only to handle the request and maintain the required compliance record. An authorised representative may be asked for proof of authority.
Where Bussystem acts only as processor, the request may be referred to the relevant carrier, employer or business customer. Bussystem will assist that controller; receiving the request does not transfer the controller's legal responsibility to Bussystem.
Response deadlines depend on the law in force and applicable to the request:
- while Law No. 133/2011 applies, requests will be handled within the deadline established by that law, including the 15-day period applicable to the access right under Article 13;
- from 23 August 2026, where Law No. 195/2024 applies, requests will ordinarily be answered within one month, subject to any lawful extension; and
- where the GDPR applies, requests will ordinarily be answered within one month, subject to any lawful extension.
If an extension, fee or refusal is legally permitted, the person will receive the required explanation and information about complaint and judicial-remedy rights.
27. CHILDREN AND MINORS
WGO is not intended to enable a child to enter independently into a contract where the child lacks legal capacity. A parent, guardian or otherwise authorised adult should make and manage the booking unless the law and carrier rules allow otherwise.
A minor's name, age, date of birth, itinerary, required travel-document details, guardian details and necessary assistance information may be processed to provide the journey, comply with law or protect the child. Only necessary data may be collected.
Where an optional information-society service is offered directly to a child and relies on consent, parental authorisation will be obtained at the age and in the manner required by the applicable law. Children's data is not knowingly used for behavioural advertising.
28. THIRD-PARTY SERVICES AND LINKS
The Services may link to or interoperate with carrier sites, payment pages, Telegram, maps, social networks, app stores and other third-party services. Those third parties may independently process personal data under their own notices and terms.
This Privacy Policy does not control an independent third party's processing. Users should review the relevant third-party notice. Nothing in this section excludes responsibility that cannot lawfully be excluded.
29. CHANGES TO THIS PRIVACY POLICY
This Policy may be updated to reflect changes in Services, processing, providers, security or law. The current version will be published with its "Last updated" date.
If a change materially affects rights or use of personal data, additional notice will be provided where required through the website, app, account, e-mail or another appropriate channel. If a new purpose requires consent, consent will be requested. Continued use is not treated as consent where valid consent is legally required.
30. CONTACT DETAILS, DPO AND EU REPRESENTATIVE
Data controller/company: "Bus System BS" S.R.L
Product/platform: WGO
Website: wgo.info
General contact e-mail: doschinescudan@wgo.md
Privacy/data-protection e-mail: doschinescudan@wgo.md
For processing performed on behalf of a carrier or another WGO business customer, that organisation may also be contacted through the details on the ticket, booking confirmation, relevant website, application or communication channel.
31. APPLICABLE LEGAL FRAMEWORK AND COMPLAINTS
This Policy is intended to operate consistently with the mandatory law that applies to the specific processing, including:
- Republic of Moldova Law No. 133/2011 on Personal Data Protection, until its repeal;
- Republic of Moldova Law No. 195/2024 on Personal Data Protection, entering into force on 23 August 2026;
- Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR), where its territorial scope applies;
- Republic of Moldova Law No. 284/2004 on information-society services/electronic commerce, including the applicable rules for commercial communications;
- Republic of Moldova Law No. 72/2025 on electronic communications, including applicable rules on storing information or accessing information on a user's terminal equipment; and
- applicable transport, border, consumer, accounting, tax, payment and electronic-communications rules.
Until 23 August 2026, Law No. 133/2011 remains the principal Moldovan personal- data law. From 23 August 2026, Law No. 195/2024 enters into force and Law No. 133/2011 is repealed. If a provision of this Policy conflicts with mandatory law, mandatory law prevails.
A complaint may be lodged with the National Centre for Personal Data Protection of the Republic of Moldova (CNPDCP):
Website: https://datepersonale.md/ Address/contact page: centru@datepersonale.md
Where the GDPR applies, a person may also complain to the competent supervisory authority in the EU/EEA Member State of habitual residence, place of work or the alleged infringement.
Contacting Bussystem first may help resolve the issue, but it does not restrict the right to contact a supervisory authority or seek a judicial remedy.
32. OFFICIAL LEGAL SOURCES
Republic of Moldova Law No. 195/2024:
https://www.legis.md/cautare/getResults?doc_id=144681&lang=roCNPDCP guidance confirming entry into force on 23 August 2026:
https://datepersonale.md/legea-nr-195-2024-privind-protectia-datelor-cu-caracter-personal-principalele-prevederi-si-noutati-legislative/Republic of Moldova Law No. 133/2011:
https://www.legis.md/cautare/getResults?doc_id=126192&lang=roRepublic of Moldova Law No. 284/2004:
https://www.legis.md/cautare/getResults?doc_id=107529&lang=roRepublic of Moldova Law No. 72/2025:
https://www.legis.md/cautare/getResults?doc_id=151455&lang=roRegulation (EU) 2016/679 (GDPR):
https://eur-lex.europa.eu/eli/reg/2016/679/oj/engEuropean Commission adequacy decisions:
https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_enEuropean Commission Standard Contractual Clauses:
https://commission.europa.eu/publications/standard-contractual-clauses-international-transfers_en