$ cat privacy.txt
PRIVACY POLICY Last Updated: July 30, 2026 Effective Date: July 30, 2026 This Privacy Policy describes how we collect, use, process, and protect your personal data when you visit our website, communicate with us, or order our remote information technology (IT) services. We operate in compliance with the European Union General Data Protection Regulation (GDPR - Regulation EU 2016/679), the Portuguese Data Protection Law (Lei n.º 58/2019), and other applicable European data protection legislation. 1. DATA CONTROLLER For the purposes of applicable data protection laws, the Data Controller responsible for processing your personal data through this website is: • Name / Business Status: [Insert Full Legal Name], registered as a Self-Employed Professional (Trabalhador Independente) in Portugal. • Postal Address: [Insert Registration Address, Portugal] • Email: [Insert Business Email Address] • Website: [Insert Website URL] 2. PERSONAL DATA COLLECTED We collect only the minimum amount of personal data necessary to provide our Services and ensure the secure operation of our website. We may collect the following categories of data: 2.1. Identity and Contact Data: Full name, email address, phone number (if provided), and communication history. 2.2. Business and Invoicing Data: Company name, corporate legal address, and tax identification or VAT number (required for accounting, legal billing, and European VAT compliance). 2.3. Technical and Usage Data: Internet Protocol (IP) address, browser type and version, operating system, server access logs, and generic interactions with this website. 2.4. Payment Metadata: Transaction status, invoice reference codes, and timestamps. We do not collect or store credit card numbers, bank account numbers, or private cryptocurrency keys. 2.5. User Messages: Any information or technical project notes you submit directly to us via our online contact, inquiry, or order forms. 3. PURPOSES AND LEGAL BASES FOR PROCESSING We process your personal data under the following legal grounds as defined by Article 6 of the GDPR: Data Category Purpose of Processing GDPR Legal Basis Contact, Identity, & Invoicing To execute, deliver, and manage remote IT services, software development, cloud infrastructure setup, server administration, or advisory orders. Article 6(1)(b): Performance of a contract or taking pre-contractual steps. Invoicing & Business Data To comply with mandatory Portuguese tax regulations, corporate accounting standards, and EU VAT reporting laws. Article 6(1)(c): Compliance with a legal obligation. Identity & User Messages To respond to technical consultations, requests, troubleshooting inquiries, or client support issues submitted via the website. Article 6(1)(f): Our legitimate interest in providing high-quality client communication. Technical & Usage Data To detect, prevent, and troubleshoot technical errors, malicious activity, server downtime, and unauthorized configurations. Article 6(1)(f): Our legitimate interest in ensuring network security and stability. Cookies To optimize website performance and understand basic user browsing patterns. Article 6(1)(a): Your explicit consent (via our cookie banner). 4. COOKIES 4.1. This website uses cookies—small text files stored on your device—to ensure base site functionality, preserve system preferences, and gather generic traffic analytics. 4.2. We use essential (functional) cookies to keep our website operational and secure. Non-essential cookies (such as analytics tools) are disabled by default and will only be activated if you provide explicit, affirmative consent via our cookie banner. You can manage or revoke your cookie choices at any time through your web browser configuration. 4.3. Where a separate Cookie Policy is provided on this website, it shall be deemed a complementary supplement to this Privacy Policy. 5. THIRD-PARTY SERVICES 5.1. To deliver our remote IT services—including software engineering, DevOps automation, cloud configuration, server management, and system monitoring—we may utilize specialized external services. 5.2. These tools and infrastructure platforms generally include cloud hosting providers, business email and messaging platforms, version control repositories, and technical logging tools necessary for secure infrastructure support. 6. DATA PROCESSORS 6.1. Where personal data is transferred to external vendors or service providers acting on our behalf, such entities are engaged strictly as Data Processors in accordance with Article 28 of the GDPR. 6.2. All Data Processors are bound by binding contractual agreements that restrict data processing to our documented instructions, mandate appropriate technical and organizational security measures, and ensure compliance with European data protection requirements. 7. PAYMENT PROVIDERS 7.1. All billing settlements executed through this website are processed directly by licensed third-party payment providers or regulated cryptocurrency payment gateway providers. 7.2. When you settle an order, your credit card details, payment metrics, or digital wallet logs are collected directly by those licensed external financial platforms. The cryptocurrency gateway provider assumes direct responsibility for anti-money laundering (AML) and know-your-customer (KYC) verifications. 7.3. We only receive transaction metadata (such as success confirmations, reference numbers, and payment dates) needed to issue your tax invoice and initiate your IT project hours. 8. AUTOMATED DECISION-MAKING 8.1. We do not use your personal data to make decisions based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you under Article 22 of the GDPR. 9. INTERNATIONAL DATA TRANSFERS 9.1. We provide remote IT consultation services globally. If your personal data needs to be transferred to or accessed by third-party processors located outside the European Economic Area (EEA), we verify that appropriate safety mechanisms are established beforehand. 9.2. All international transfers are structured on the basis of European Commission Adequacy Decisions or by executing Standard Contractual Clauses (SCCs) to guarantee that your personal data is handled outside Europe with an adequate level of data protection as required by the GDPR. 10. DATA RETENTION 10.1. We retain your personal data only for as long as necessary to fulfill the primary purposes for which it was collected, or to satisfy applicable legal, tax, accounting, and professional reporting obligations. 10.2. Invoicing data, corporate records, and contract-related personal data will be kept for the period required by applicable Portuguese tax and accounting legislation, which is generally ten (10) years. 10.3. Generic contact inquiries and consultation logs that do not result in a formal service contract will be retained for a reasonable period necessary to manage the relationship, in accordance with applicable statutory limitation periods. 10.4. Temporary system snapshots, data configuration files, or logs analyzed during our troubleshooting or monitoring work shall be destroyed within a reasonable timeframe following project closure, as determined by professional technical standards and operational requirements. 11. SECURITY MEASURES 11.1. We implement appropriate technical and organizational security measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. 11.2. All traffic passing through this website is encrypted using Secure Sockets Layer/Transport Layer Security (SSL/TLS) protocols. Furthermore, operational server credentials, software keys, and diagnostic assets shared during the execution of our IT tasks are managed under strict access controls, utilizing encrypted storage and industry-standard security practices. 12. YOUR GDPR RIGHTS Under Chapter III of the GDPR, data subjects whose personal data is processed under the GDPR possess the following specific statutory data privacy rights: • Right of Access: You may request validation of whether your personal data is being processed, along with a copy of your stored records. • Right to Rectification: You may request the correction of inaccurate, obsolete, or incomplete personal data. • Right to Erasure ("Right to be Forgotten"): You may request the deletion of your personal data, provided it is no longer required for executing contracts or satisfying mandatory Portuguese legal retention laws. • Right to Restriction of Processing: You may request that we temporarily suspend processing your data under specific statutory conditions. • Right to Data Portability: You may request that we transfer your personal data to you or another controller in a structured, commonly used, and machine-readable layout. • Right to Object: You may object to the processing of your personal data based on our legitimate interests. • Right to Withdraw Consent: If processing is based on your explicit consent, you have the right to withdraw it at any time without affecting the lawfulness of processing before the withdrawal. 13. EXERCISING YOUR RIGHTS 13.1. To exercise any of your statutory GDPR rights, please submit a clear written request directly to us at our business email address indicated in Section 16. 13.2. We do not charge fees for processing legitimate privacy requests. We commit to reviewing and responding to your inquiry within thirty (30) calendar days from receipt. To guarantee data safety, we may request that you verify your identity before we disclose or modify any records. 13.3. In accordance with Article 77 of the GDPR, if you believe that our data processing methods infringe upon data protection legislation, you have the statutory right to file a formal complaint with a national supervisory authority. In Portugal, the competent authority is the National Data Protection Commission (CNPD - Comissão Nacional de Proteção de Dados, website: www.cnpd.pt). 14. CHILDREN'S PRIVACY Our website and IT services are not intended for individuals under the age of sixteen (16). We do not intentionally or knowingly collect, track, or process personal data from children under sixteen. If we identify that a minor under sixteen has provided personal data to us, it will be deleted from our servers without undue delay. 15. CHANGES TO THIS PRIVACY POLICY We reserve the right to modify or update this Privacy Policy to reflect operational amendments, structural shifts in our IT services, or updates to European legislation. Any updates will be published directly on this page with an updated "Last Updated" timestamp. We encourage you to review this page periodically to stay informed about how we protect your personal data. 16. CONTACT INFORMATION If you have any questions, compliance concerns, or specific requests regarding this Privacy Policy or our internal data management practices, please contact us via the following details: • Data Controller: [Insert Full Legal Name] • Business Status: Self-Employed Professional (Trabalhador Independente) • Country: Portugal • Email: [Insert Business Email Address] • Website: [Insert Website URL] For privacy-related requests, please use the email address above.PRIVACY POLICYprivacy.txt