Last updated: 3 May 2026
Last reviewed: 7 May 2026
Summary
This page explains what personal data we collect when you visit luisferreira.pt or contact us, why we collect it, how long we keep it, and what rights you have over it.
The short version: we only collect what we need to talk to you and run the site. We don’t sell or profile your data, and we don’t share it outside the operational service providers listed below. If you contacted us, we’ll respond. If you didn’t, we delete inactive contact records after 12 months.
If you have questions about your data or want to exercise any of your rights, write to [email protected].
Who is responsible for your data
The data controller for luisferreira.pt is:
LuisFerreira Consulting OÜ
Registered office: Sepapaja tn 6, 15551 Tallinn, Harju Maakond, Estonia
Estonian registry code: 17408024
Email: [email protected]
Our Data Protection Officer is Luís Ferreira, contactable at [email protected] for any data protection matter, including the exercise of your rights, complaints, or general questions about how we handle personal data.
Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon — AKI), Tatari 39, 10134 Tallinn. If you reside in Portugal, you may alternatively lodge a complaint with the Portuguese Data Protection Authority (CNPD — Comissão Nacional de Proteção de Dados).
What data we collect and why
We collect the minimum personal data needed to operate the site and respond to legitimate contact.
When you send us a message through the contact form, we collect your name, your email address, and the content of your message. We use this only to respond to you. The legal basis is your consent (Article 6(1)(a) GDPR), which you give explicitly by ticking the consent box on the form before submission. You can withdraw this consent at any time by writing to [email protected] — we will then delete the message and any related correspondence, except where retention is required by law.
If you separately opt in to our newsletter (a feature we plan to enable in the future, alongside our blog), we will collect your name and email address to send you periodic content about IT strategy, governance, and related topics. The legal basis is your consent. You can unsubscribe at any time using the link in any newsletter email or by writing to us. Unsubscribing does not affect any other interaction you have with us.
When you visit the site, we use essential cookies to keep your session running and to protect the site against abuse. Our server also keeps technical logs (your IP address, browser type, the pages you requested, and timestamps) for security and troubleshooting. The legal basis for both is our legitimate interest in operating a secure and functional website.
If you become a client, the data we process for the engagement is governed by a separate contract and, where applicable, a Data Processing Agreement tailored to that engagement.
We do not use analytics cookies, advertising cookies, or any tracking that profiles you across the web.
How long we keep your data
We don’t keep data longer than we need to:
- Messages from the contact form, where we don’t end up working together, are deleted 12 months after the last interaction.
- Records related to client engagements (contracts, invoices, correspondence required for the work) are kept for the period required by applicable accounting and tax law.
- Newsletter subscriptions are kept until you unsubscribe.
- Essential cookies expire when you close your browser session.
- Server logs are kept for 6 months for security investigation purposes.
Who else processes your data
We use a small set of established service providers to run the site and our communications. They process data on our behalf, under data processing agreements, and only for the purposes we instruct.
By category:
- Hosting provider (EU-based) — runs the website infrastructure.
- Content delivery network and security provider (US-based) — protects the site against abuse and speeds up delivery; data transfers to the US are covered by Standard Contractual Clauses.
- Email service provider with data centres in the European Union — handles incoming and outgoing email.
- Cookie consent management provider (EU-based) — handles your cookie preferences.
- Security monitoring provider (US-based) — provides real-time threat intelligence and centralised security monitoring; data transfers to the US are covered by Standard Contractual Clauses.
- Functional plugins on the site that handle SEO, multilingual support, contact forms, and consent management — each processing only the data needed for its function.
We do not share data with third parties for marketing, advertising, or commercial purposes outside this list.
A current and named list of our subprocessors is available on written request to [email protected].
Your rights
You have the following rights regarding your personal data. We honour all of them, free of charge, and respond within 30 days (Article 12(3) GDPR):
- Access — you can ask what data we hold about you, and we’ll send you a copy.
- Rectification — if any data we hold is wrong, you can ask us to correct it.
- Erasure (“right to be forgotten”) — you can ask us to delete your data, subject to any legal obligations that require us to keep it.
- Restriction — you can ask us to limit how we process your data while we resolve a dispute about it.
- Portability — you can ask for a copy of your data in a structured, machine-readable format.
- Objection — you can object to processing based on our legitimate interest.
- Withdraw consent — where we process your data based on your consent, you can withdraw it at any time without giving a reason.
- Lodge a complaint with a supervisory authority (AKI in Estonia, CNPD in Portugal, or the authority in your country of residence within the EU).
To exercise any of these rights, write to [email protected]. We may need to verify your identity before acting on the request — verification typically means confirming that the request comes from the email address we have on file, or via a similarly reliable channel.
Cookies
We use only essential cookies on this site. For full details on what each cookie does and how long it lasts, see our Cookie Policy.
You can manage your preferences at any time using the cookie banner or via your browser settings.
Security
We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss, or alteration: encrypted connections (HTTPS), restricted administrative access, regular software updates, and infrastructure provided by reputable suppliers with their own security certifications.
No system is perfectly secure, and we don’t claim otherwise. If we ever discover a personal data breach that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and, where required, notify you directly.
International transfers
Some of our service providers are based outside the European Economic Area, primarily in the United States. All international transfers are subject to either an adequacy decision by the European Commission, Standard Contractual Clauses, or another transfer mechanism listed in Article 46 GDPR.
Minors
This site is intended for business audiences. If you believe a minor has submitted information, contact us at [email protected] for deletion.
Changes to this policy
If we change this policy, we will publish the updated version on this page and update the “Last updated” date at the top. We do not consider continued use of the site to constitute acceptance of material changes — you have the right to refuse them and ask for your data to be deleted.
Contact
For any question about this policy, your data, or to exercise any of your rights:
Email: [email protected]
Postal: LuisFerreira Consulting OÜ, Sepapaja tn 6, 15551 Tallinn, Harju Maakond, Estonia
