PRIVACY POLICY

PRIVACY AND PERSONAL DATA PROTECTION POLICY
INTRODUCTION

With this privacy and personal data protection policy, ESTORÁGUEDA, LDA, a private limited company, registered at the Commercial Registry Office under registration and legal person number 502.183.683,with its head office at Raso do Salgueirinho, 3750-753, Travassô, Águeda, hereinafter abbreviated “ESTORÁGUEDA”, aims to inform customers/users of ESTORÁGUEDA’s policies and procedures regarding the collection, use, processing and disclosure of any personal data transmitted directly by its customers/users or through third parties, through the use of the website operated by ESTORÁGUEDA – www.estoragueda.pt.
ESTORÁGUEDA respects the privacy of its customers/users, and is committed to protecting the information it collects from them, as well as to complying with the legal rules in force defined by the General Data Protection Regulation (GDPR). Accessing and using the website, as well as subscribing to the services and products it offers, implies that users agree, accept and are bound by this privacy and data protection policy.

1. WHO ARE WE?
ESTORÁGUEDA is a commercial company operating in the sector of commercialization, assembly and installation of interior and exterior blinds. ESTORÁGUEDA is committed to protecting the personal data of the customers/users of the products and services it provides, as well as the personal data of the respective holders in all situations in which personal data is processed.

2. NECESSITY OF THIS POLICY
The purpose of this policy is to inform customers/users of the general rules governing the processing of personal data, which is collected and processed in strict respect and compliance with the provisions of the personal data protection legislation in force at any given time, namely Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016 (“GDPR”) as well as other legislation on this subject that is applicable or comes into force, in particular Law no. 58/2019, of 8 August. ESTORÁGUEDA is dedicated to the protection and confidentiality of personal data, and has adopted the measures it deems appropriate to ensure the accuracy, integrity and confidentiality of personal data, as well as all other rights that the respective holders of such personal data enjoy. ESTORÁGUEDA honors the best practices in the field of security and protection of personal data, and has adopted the necessary technical and organizational measures to comply with the GDPR and ensure that the processing of personal data is carried out lawfully, fairly, transparently and limited to the purposes authorized under the terms of the GDPR and other applicable legislation. The purpose of this privacy and data protection policy i salso to summarise the provisions on the protection and processing of personal data laid down in the contracts that customers/users have established or will establish with ESTORÁGUEDA, as well as the rules laid down in the terms and conditions governing the provisiono f the various services, which are duly advertised on our website.

3. PERSONAL DATA SECURITY MEASURES
ESTORÁGUEDA has always been concerned with ensuring the protection and security of the personal data made available to it. For that, ESTORÁGUEDA has implemented an internal safety policy and compliance with these rules is an obligation of all those who legally access them, namely their employees. These rules and security measures are of a technical and organisational nature and aim to protect personal data against its dissemination, loss, misuse, alteration, unauthorised processing or access, as well as against any other form of unlawful processing. In addition, third parties that, within the scope of providing services, process the customer’s/user’s personal data in the name and on behalf of ESTORÁGUEDA, are obliged, in writing, to implement appropriate technical and security measures that, at all times, meet the requirements provided for in the GDPR and other applicable legislation and aim to safeguard the rights of the data subject. As part of ESTORÁGUEDA’s internal security policy, all forms of online personal data collection are encrypted and stored securely, and physical and logistical security measures have also been implemented. However, this action by ESTORÁGUEDA does not dispense with the adoption of security measures by customers/users, particularly with regard to the use of online personal defense systems (firewall, antivirus, anti-spyware, tools to check the suitability of websites, etc.).

4. WHAT IS PERSONAL DATA?
For the purposes of Article 4(1) of the GDPR, “Personal data” means information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.”

5. PROCESSING OF PERSONAL DATA
For the purpose of Article 4(2) of the GDPR, “processing” means an operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.”

6. WHO IS THE DATA CONTROLLER?
ESTORÁGUEDA is responsible for processing personal data in accordance with the purposes and means of processing them at any given time. For the purposes set out in this policy or within the scope of the GDPR, should the holder of personal data need to contact ESTORÁGUEDA, he or she may do so via the email address resp.rgpd@estoragueda.pt or by written communication addressed to the company, to the registered office, whose address is: Raso do Salgueirinho, 3750-753, Travassô, Águeda.

7. IS THERE A DATA PROTECTION RESPONSIBLE?
ESTORÁGUEDA has appointed a data protection responsible. You can contact ESTORÁGUEDA’s data protection responsible, who in this case is Carlos Alberto Lopes Nunes, at the following email address: resp.rgpd@estoragueda.pt

8. TYPES OF PERSONAL DATA THAT MAY BE PROCESSED
Considering the activities carried out by ESTORÁGUEDA, it processes the personal data necessary to provide services, supply goods or in its social responsibility activities, processing personal data such as name, address, telephone number, e-mail address, the citizen´s card number or tax identification number. The information collected may be greater or lesser depending on the information provided by the customer/user. With the exception of an obligation arising from the fulfilment of a legal obligation, all data will be exclusively processed by ESTORÁGUEDA only to the extent that they are necessary for the development of its activity, also allowing the customer/user to have access, for example, to specific functionalities of the services, suggestions and proximity information services. Personal, traffic, geographic location, profile and/or consumption data may be processed for advertising purposes or dissemination of offers of goods or services by ESTORÁGUEDA, if the respective holder of the personal data has authorized/consented to this. If there is prior consent from the customer/user, it may be withdrawn at any time, without, however, the lawfulness of the processing carried out on the basis of the prior consent being called into question. To withdraw your consent, pleasw use the following email address: resp.rgpd@estoragueda.pt

9. CIRCUMSTANCES OF PROCESSING BY SUBCONTRACTORS
As part of its ativities, ESTORÁGUEDA uses third parties to provide certain types of services that may involve access by these entities to the personal data of customers/users. When this happens, ESTORÁGUEDA ensures tha subcontractors comply with the rules of the GDPR and any other applicable legislation, as well as compllying with certain standards that are similar to our internal security policy. If personal data is communicated to other subcontrsctors, ESTORÁGUEDA remains responsible for that personal data.

10. DESTINATION OF PERSONAL DATA
The personal data is intended only for ESTORÁGUEDA or its group companies and may only be used by third parties to fulfil legal obligations.

11. COLLECTION OF PERSONAL DATA
ESTORÁGUEDA only collects personal data by telephone, by email, by contract, through its website and always with the prior consent of the owners of the personal data. Please note that some personal data are essential to the execution of the contracts entered into and, in case of lack or insufficiency of the same, they may jeopardize the provision of services or the supply of goods by ESTORÁGUEDA. The rules of this policy apply to the holders of personal data who are not ESTORÁGUEDA customers/users. The personal data collected may be processed electronically and in an automated or non-automated way. ESTORÁGUEDA ensures compliance with the GDPR and other applicable legislation. Personal data is stored in specific databases created for this purpose. Personal data will never be used for any purpose other than that for which it was collected or for which consent has been given by the data subject.

12. PURPOSES
Generally speaking, the personal data collected is based on and intended for the management of the contractual relationship, the provision of the contracted services, the adaptation of the services to the needs and interests of the customer/user, information and publicity actions. As already stated above, personal data may also be processed for the purposes of complying with legal obligations. If the customer/user consents to this, ESTORÁGUEDA may use the personal data provided by the holder for other purposes, such as for the purposes of social responsibility actions, sending complaints and suggestions, to publicize campaigns, promotions, advertising and news about ESTORÁGUEDA’s products and/or services, as well as carrying out market research or evaluation surveys.

13. RETENTION OF PERSONAL DATA
The conservation and storage of personal data is necessarily related to the purpose for which the information was collected and is processed.
Except in cases where there may be a legal obligation to keep the personal data, such personal data will only be stored and kept for the minimum period necessary for the purpose for which it was collected.

14. TRANSFER OF PERSONAL DATA
ESTORÁGUEDA does not transfer personal data and, if it does, it will do so in accordance with the GDPR and any other applicable legislation. However, this does not affect the exercise of the right to portability by the holder of personal data.

15. YOUR RIGHTS AND HOW TO REALISE THEM
As the holder of personal data, ESTORÁGUEDA guarantees you, at any time, the right to access, rectify, update, limit and delete your personal data (except for data that are essential to the provision of services or the supply of goods in which the contractual relationship still lasts), the right to oppose the use of the same for commercial purposes by ESTORÁGUEDA and to withdraw consent, as well as the right to data portability. All the rights sent out in the Law that the holder of Personal Data may exercise are provided by ESTORÁGUEDA.

Last updated: 18/06/2021.