PRIVACY POLICY (RGPD)

Poliopticas Lda

Poliopticas Lda is committed to protecting the privacy and personal data of its customers and users, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR”) and other applicable legislation.

1. Identification of the Data Controller

Data Controller: Poliopticas Lda
Tax ID (NIPC): 507984196
Address: Av. da Boavista, Ed. Príncipe do Minho, Loja 136, Monção
Contact for data protection matters: poliopticaslda@gmail.com

2. What Personal Data We Collect

Depending on the use of the website or services, we may process the following categories of data:

  • Identification and contact data: name, email, phone number, address;

  • Billing and order data: Tax number (when applicable), purchase and delivery history;

  • Customer account data: preferences, saved addresses and account history;

  • Communication data: enquiries, complaints or messages sent;

  • Technical and browsing data: IP address, cookies and online identifiers.

Poliopticas does not generally request special categories of personal data (e.g., political opinions, religious beliefs, health data, sexual life or ethnic origin).

3. Purposes and Legal Basis for Processing

Personal data is processed for the following purposes:

a) Order processing and customer relationship management
Includes billing, delivery, support and after-sales assistance.
Legal basis: performance of a contract and compliance with legal obligations.

b) Creation and management of customer accounts
Allows users to view purchase history, manage data and speed up future orders.
Legal basis: performance of a contract and legitimate interest.

c) Communication with customers and management of requests or complaints
Legal basis: performance of a contract and legitimate interest.

d) Website security and fraud prevention
Legal basis: legitimate interest in protecting systems and users.

e) Newsletter and promotional communications
Only sent when the user gives explicit consent (opt-in).
Legal basis: consent.

f) Analytical cookies (Google Analytics)
Only used with user consent via the cookie manager.
Legal basis: consent.

Poliopticas does not carry out automated decision-making or profiling with legal effects on users.

4. Customer Account

When a user creates an account on the website, additional data such as order history, preferences and saved addresses may be stored.

This data is retained while the account remains active or until a deletion request is made, except where legal retention obligations apply.

5. Google Analytics and Browsing Data

The website uses Google Analytics 4 to collect aggregated statistics about website usage.

  • Data is processed in aggregated form;

  • IP anonymisation is applied whenever possible;

  • Analytical cookies are only activated with user consent.

Some data may be processed on servers outside the European Economic Area, subject to GDPR safeguards.

6. Sharing Data with Third Parties

Personal data may be shared with service providers necessary for Poliopticas’ operations, such as:

  • Carriers and logistics providers;

  • Payment service providers;

  • Hosting and technology maintenance services;

  • Accounting services;

  • Public authorities when legally required.

These entities act as processors and only process data according to Poliopticas’ instructions.

7. International Data Transfers

Where necessary, transfers outside the European Economic Area will only occur based on appropriate legal mechanisms such as Standard Contractual Clauses or adequacy decisions under the GDPR.

8. Data Retention Period

Personal data is retained only for as long as necessary, namely:

  • Billing and order data: up to 10 years, in accordance with tax obligations;

  • Customer account: while active or until deletion request;

  • Direct marketing: until consent is withdrawn;

  • Requests and support: for the time necessary to manage and defend legal rights.

9. Data Subject Rights

Under the GDPR, data subjects may exercise the following rights:

  • Access;

  • Rectification;

  • Erasure;

  • Restriction of processing;

  • Objection;

  • Data portability.

Requests must be sent to:

Email: poliopticaslda@gmail.com
Address: Av. da Boavista, Ed. Príncipe do Minho, Loja 136, Monção

Poliopticas will respond within the legal maximum period of 1 month.

10. Commercial Communications and Newsletter

Promotional communications are only sent with user consent.

Users may unsubscribe:

11. Data Security

Poliopticas implements appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, loss or disclosure, including secure HTTPS/SSL connections and internal access controls.

12. Right to Lodge a Complaint

Data subjects may lodge a complaint with the competent supervisory authority:

Portuguese Data Protection Authority (CNPD)
www.cnpd.pt