“We”, “us” or “our” means ‘Ethiack, Lda’, with its registered office at Rua Pedro Nunes - Instituto Pedro Nunes, S/N 3030-199 Coimbra, Portugal. We act as controller for the personal data we gather through your use of our website.
Personal data is defined as any information relating to an identified or identifiable natural person. Identifiable refers to identifiers (such as name, identification number, location data, etc.), that can be used to directly or indirectly identify a natural person.
All personal data that the customer provides will be part of an automated personal file of which Ethiack is responsible. The personal data collected will be kept only for as long as is necessary for the purpose for which they are collected, except for data which, by law, must be kept for a longer period. For the purposes of managing the contact provided by the customer, automated operations may be carried out, namely profile definition, ensuring, however, that they are carried out within the limits imposed by the applicable legislation. Your personal data may be communicated to other Group companies and to Ethiack customers (in this case, limited to personal contact and identification data, for the purposes of access control and management of information requested by each customer). They may also be communicated to third parties for the purpose of complying with legal obligations, as well as to other entities deemed necessary for the purposes described above, namely insurers, banking institutions, computer service providers, regulators and inspectors, and document archives.
The personal data we collect, is collected and used for the purposes as listed hereunder:
The following categories of data can be distinguished:
We will process your personal information lawfully, fairly and in a transparent manner. We collect and process information about you only where we have legal bases for doing so. These legal bases depend on the services you use and how you use them, meaning we collect and use your information only when it is necessary for the fulfillment of a contract to which you are a party or to take steps at your request before entering into such a contract. The direct marketing campaign is based on legitimate interest and your consent.
Your personal information will not be kept for longer than is necessary for a specific purpose. However, considering it is not possible for us to specify a period in advance, the period of retention will be determined depending on the duration of an active submission, the type of data collected and the legal requirement for retaining the data.
While we retain this information, we will protect it within commercially acceptable means to prevent loss and theft, as well as unauthorised access, disclosure, copying, use or modification. That said, we advise that no method of electronic transmission or storage is 100% secure and cannot guarantee absolute data security. If necessary, we may retain your personal information for our compliance with a legal obligation or in order to protect your vital interests or the vital interests of another natural person.
When you consent to our use of information about you for a specific purpose, you have the right to change your mind at any time (but this will not affect any processing that has already taken place). In the event you withdraw your consent or you object to our use of your personal data, and such objection is successful, we will remove your personal data from our databases. Please note that we will retain the personal data necessary to ensure your preferences are respected in the future.
The foregoing will, however, not prevent us from retaining any personal data if this is necessary to comply with our legal obligations, in order to file a legal claim or defend ourselves against a legal claim, or for evidential purposes.
If we process your personal data solely on the legitimate interest ground we will keep you data only for 1 year.
To make our websites available to you, we work with service providers to process and store your personal data. These providers enable us to offer a better experience online. Therefore we may disclose information to (without limitation) IT service providers, data storage, hosting and server providers, ad networks, analytics, error loggers, debt collectors, maintenance or problem-solving providers, marketing or advertising providers, professional advisors and payment systems operators; our employees, contractors and/or related entities; sponsors or promoters of any competition we run; credit reporting agencies, courts, tribunals and regulatory authorities, in the event you fail to pay for goods or services we have provided to you; courts, tribunals, regulatory authorities and law enforcement officers, as required by law, in connection with any actual or prospective legal proceedings, or in order to establish, exercise or defend our legal rights; third parties, including agents or sub-contractors, who assist us in providing information, products, services or direct marketing to you; and third parties to collect and process data.
We shall also disclose your personal data in the event such disclosure is necessary in order to fulfil a legal obligation. We may also disclose personal data in order to protect your vital interests or the vital interest of another natural person.
In some circumstances, you have the right to the erasure of your personal data without undue delay. You can also unsubscribe from our email database or opt-out of communications (including marketing communications), please contact us using the details in section 1 or opt-out using the opt-out facilities provided in the communication. On the other hand, we have the commitment to notify you if any security breach happens that can compromise the disclosure of your personal information. We will comply with the laws applicable to us in respect of any data breach and you will be the first to know about it.
You have the right to object to the processing of your personal data on grounds relating to your particular situation, but only to the extent that the legal basis for the processing is that the processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, or for the performance of a task carried out in the public interest or in the exercise of any official authority vested in us.
If you make such an objection, we will cease to process the personal information unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is for the establishment, exercise or defense of legal claims.
You have the right to object to our processing of your personal data for direct marketing purposes (including profiling for direct marketing purposes). If you make such an objection, we will cease to process your personal data for this purpose.
If you consider that our processing of your personal information infringes data protection laws, you have a legal right to lodge a complaint with a supervisory authority responsible for data protection. You may do so in the EU member state of your habitual residence, your place of work or the place of the alleged infringement. In Portugal, you can submit a complaint to CNPD.
The personal information we collect is stored and processed in Portugal, or where we or our partners, affiliates and third-party providers maintain facilities. By providing us with your personal information, you consent to the disclosure to these overseas third parties.
We will ensure that any transfer of personal information from countries in the European Economic Area (EEA) to countries outside the EEA will be protected by appropriate safeguards, for example by using standard data protection clauses approved by the European Commission, or the use of binding corporate rules or other legally accepted means.
When we transfer personal information from a non-EEA country to another country, you acknowledge that third parties in other jurisdictions may not be subject to similar data protection laws to the ones in our jurisdiction. There are risks if any such third party engages in any act or practice that would contravene the data privacy laws in our jurisdiction and this might mean that you will not be able to seek redress under our jurisdiction’s privacy laws.
The processing of user personal data by Ethiack, as well as the sending of commercial communications by electronic means are in conformity with the existing national and Community legislation, in particular with the recent EU Regulation 2016 / 679 (General Regulation on Data Protection).