PRIVACY POLICY (RGPD)
Poliopticas Lda
Poliopticas Lda is committed to protecting the privacy and personal data of its customers and users, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR”) and other applicable legislation.
1. Identification of the Data Controller
Data Controller: Poliopticas Lda
Tax ID (NIPC): 507984196
Address: Av. da Boavista, Ed. Príncipe do Minho, Loja 136, Monção
Contact for data protection matters: poliopticaslda@gmail.com
2. What Personal Data We Collect
Depending on the use of the website or services, we may process the following categories of data:
-
Identification and contact data: name, email, phone number, address;
-
Billing and order data: Tax number (when applicable), purchase and delivery history;
-
Customer account data: preferences, saved addresses and account history;
-
Communication data: enquiries, complaints or messages sent;
-
Technical and browsing data: IP address, cookies and online identifiers.
Poliopticas does not generally request special categories of personal data (e.g., political opinions, religious beliefs, health data, sexual life or ethnic origin).
3. Purposes and Legal Basis for Processing
Personal data is processed for the following purposes:
a) Order processing and customer relationship management
Includes billing, delivery, support and after-sales assistance.
Legal basis: performance of a contract and compliance with legal obligations.
b) Creation and management of customer accounts
Allows users to view purchase history, manage data and speed up future orders.
Legal basis: performance of a contract and legitimate interest.
c) Communication with customers and management of requests or complaints
Legal basis: performance of a contract and legitimate interest.
d) Website security and fraud prevention
Legal basis: legitimate interest in protecting systems and users.
e) Newsletter and promotional communications
Only sent when the user gives explicit consent (opt-in).
Legal basis: consent.
f) Analytical cookies (Google Analytics)
Only used with user consent via the cookie manager.
Legal basis: consent.
Poliopticas does not carry out automated decision-making or profiling with legal effects on users.
4. Customer Account
When a user creates an account on the website, additional data such as order history, preferences and saved addresses may be stored.
This data is retained while the account remains active or until a deletion request is made, except where legal retention obligations apply.
5. Google Analytics and Browsing Data
The website uses Google Analytics 4 to collect aggregated statistics about website usage.
-
Data is processed in aggregated form;
-
IP anonymisation is applied whenever possible;
-
Analytical cookies are only activated with user consent.
Some data may be processed on servers outside the European Economic Area, subject to GDPR safeguards.
6. Sharing Data with Third Parties
Personal data may be shared with service providers necessary for Poliopticas’ operations, such as:
-
Carriers and logistics providers;
-
Payment service providers;
-
Hosting and technology maintenance services;
-
Accounting services;
-
Public authorities when legally required.
These entities act as processors and only process data according to Poliopticas’ instructions.
7. International Data Transfers
Where necessary, transfers outside the European Economic Area will only occur based on appropriate legal mechanisms such as Standard Contractual Clauses or adequacy decisions under the GDPR.
8. Data Retention Period
Personal data is retained only for as long as necessary, namely:
-
Billing and order data: up to 10 years, in accordance with tax obligations;
-
Customer account: while active or until deletion request;
-
Direct marketing: until consent is withdrawn;
-
Requests and support: for the time necessary to manage and defend legal rights.
9. Data Subject Rights
Under the GDPR, data subjects may exercise the following rights:
-
Access;
-
Rectification;
-
Erasure;
-
Restriction of processing;
-
Objection;
-
Data portability.
Requests must be sent to:
Email: poliopticaslda@gmail.com
Address: Av. da Boavista, Ed. Príncipe do Minho, Loja 136, Monção
Poliopticas will respond within the legal maximum period of 1 month.
10. Commercial Communications and Newsletter
Promotional communications are only sent with user consent.
Users may unsubscribe:
-
via the link included in each email;
-
or by contacting poliopticaslda@gmail.com.
11. Data Security
Poliopticas implements appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, loss or disclosure, including secure HTTPS/SSL connections and internal access controls.
12. Right to Lodge a Complaint
Data subjects may lodge a complaint with the competent supervisory authority:
Portuguese Data Protection Authority (CNPD)
www.cnpd.pt