Legal
Privacy Policy
This document applies to ventospt.com and to the services provided by Ventos Arqueáveis Unipessoal Lda.
Who We Are
Ventos Arqueáveis Unipessoal Lda, NIPC 519153529, Rua D. Afonso Henriques, nº 132, 4950-854 Cortes, Monção, Viana do Castelo, Portugal, is the controller for the personal data described in this policy. Questions and requests go to info@ventospt.com.
What We Collect
We collect only what we need to answer you and to run the service:
- Contact data you submit through forms on this site: name, email address, company, country, subject and the content of your message.
- Service data processed on behalf of a client under a data processing agreement: the documents, matters and user accounts inside their tenancy.
- Technical data written by the web server: IP address, user agent, requested URL and timestamp, kept in access logs.
- Contract and billing data for clients: company details, tax identifiers and invoice records.
Why We Process It, and On What Basis
Every purpose below is tied to a legal basis under Article 6 GDPR.
- Answering enquiries — steps taken at your request before entering into a contract, Article 6(1)(b).
- Providing the service — performance of the contract with the client, Article 6(1)(b). Where we process client content we act as a processor on the client's documented instructions.
- Security and abuse prevention — our legitimate interest in keeping the service available and free from misuse, Article 6(1)(f).
- Accounting and tax records — compliance with a legal obligation under Portuguese law, Article 6(1)(c).
How Long We Keep It
Enquiries that do not lead to a contract are deleted after 24 months. Server access logs are kept for 12 months. Client service data is retained for the term of the agreement and deleted or returned within 30 days of termination, unless a longer period is agreed in writing. Accounting records are kept for the period Portuguese tax law requires.
Where It Is Processed
Personal data is processed inside the European Union by default. We do not transfer personal data outside the EEA without an adequacy decision or standard contractual clauses in place, and clients are told in advance which sub-processors are involved.
Sub-Processors
We use a small number of providers for hosting, email delivery and error monitoring. Each is bound by a written processing agreement with confidentiality and security obligations no weaker than ours. A current list is available to clients on request, and we give notice before adding a new one.
Your Rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy;
- have inaccurate data corrected without undue delay;
- have data erased where we no longer have a basis to keep it;
- restrict or object to processing based on our legitimate interests;
- receive data you provided in a portable, machine-readable format;
- withdraw consent at any time, where processing rests on consent.
To exercise any of these, write to info@ventospt.com. We respond within one month. If a request concerns data we process for a client, we will refer you to that client as controller and assist them in answering you. You may also lodge a complaint with the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD), or with the authority where you live.
Security
Data is encrypted in transit and at rest. Access is limited to the staff who need it, logged, and reviewed periodically. We test for common web vulnerabilities before each release, and we notify affected clients without undue delay if a personal data breach occurs.
Changes
If this policy changes materially, we will update the date at the top and notify clients before the change takes effect.