Privacy Policy — Equigerminal
Equigerminal · Legal

Privacy & Data Protection Policy

Last updated: January 2024 GDPR Compliant Regulation (EU) 2016/679
GDPR · Regulation (EU) 2016/679 · Portuguese Law 58/2019
01

Identity of the Data Controller

Equigerminal, Lda. is the data controller responsible for the personal data collected through this website and related services, in accordance with Regulation (EU) 2016/679 of the European Parliament (GDPR) and Portuguese Law No. 58/2019.

Company
Equigerminal, Lda.
Registered Address
Penela, Portugal
02

Data We Collect

We only collect personal data that is strictly necessary for the purposes described in this policy. This may include:

  • Identification data: name, email address, phone number.
  • Technical data: IP address, browser type, device information, and access logs collected automatically when you visit our website.
  • Communication data: messages, feedback or complaints submitted through our contact forms.
  • Professional data: institutional affiliation, professional role — only when relevant to the service requested.
  • Transactional data: records of products or services purchased, where applicable.

We do not collect sensitive categories of personal data (such as health data, genetic data or biometric data) unless explicitly required by a specific service and with your explicit prior consent.

03

Purpose of Data Processing

Your personal data is collected and processed for the following specific, explicit and legitimate purposes:

  • Responding to enquiries, feedback, or complaints submitted via our website.
  • Managing and fulfilling orders, subscriptions, or service agreements.
  • Sending informational communications or newsletters — only with your explicit consent.
  • Complying with legal and regulatory obligations applicable to our activity.
  • Improving the performance, usability and security of our digital services.
  • Conducting scientific research and R&D activities — always under a separate, specific consent framework.
04

Legal Basis for Processing

All processing of personal data by Equigerminal is grounded in one of the following lawful bases under Article 6 of the GDPR:

  • Consent (Art. 6(1)(a)): where you have freely given, specific, informed and unambiguous consent (e.g. newsletter subscriptions).
  • Contractual necessity (Art. 6(1)(b)): where processing is necessary for the performance of a contract to which you are a party.
  • Legal obligation (Art. 6(1)(c)): where processing is required to comply with a legal obligation applicable to Equigerminal.
  • Legitimate interests (Art. 6(1)(f)): where processing is necessary for our legitimate business interests, provided these are not overridden by your rights and freedoms.
05

Data Retention Periods

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law:

  • Contact and communication data: up to 24 months from the date of last interaction.
  • Commercial and contractual records: 10 years, in compliance with Portuguese commercial and tax law.
  • Consent records: retained for the duration of the consent and for a period of 5 years thereafter as proof of compliance.
  • Website analytics data: anonymised and retained for up to 26 months.

Upon expiry of the applicable retention period, data is securely deleted or irreversibly anonymised.

06

Your Rights

Under the GDPR, you hold the following rights in relation to your personal data. We are committed to facilitating the exercise of each of these rights promptly and transparently.

Art. 15
Right of Access

You may request a copy of all personal data we hold about you, along with information about how it is processed.

Art. 16
Right to Rectification

You may request correction of any inaccurate or incomplete personal data we hold.

Art. 17
Right to Erasure

Also known as the "Right to be Forgotten" — you may request deletion of your data where there is no compelling reason for its continued processing.

Art. 18
Right to Restriction

You may request that we restrict the processing of your data in certain circumstances.

Art. 20
Right to Portability

You may receive your data in a structured, machine-readable format and transmit it to another controller.

Art. 21
Right to Object

You may object to processing based on legitimate interests or for direct marketing purposes at any time.

To exercise any of these rights, please contact us at geral@equigerminal.pt. We will respond within 30 days. You also have the right to lodge a complaint with the Portuguese supervisory authority, the CNPD (Comissão Nacional de Proteção de Dados).

07

Security Measures

Equigerminal implements appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

  • End-to-end encryption of data in transit (TLS 1.3) and at rest.
  • Role-based access control — data is accessible only to personnel with a strict operational need.
  • Regular security audits and penetration testing of digital infrastructure.
  • Automated anomaly detection and intrusion monitoring systems.
  • Regular staff training on data protection and information security best practices.
  • Incident response protocol aligned with GDPR Article 33 — notification to CNPD within 72 hours of a confirmed breach.
08

Third Parties & International Transfers

We do not sell, rent or trade your personal data. Data may be shared with carefully selected third-party processors solely for the purposes described in this policy, under strict data processing agreements:

  • Technology and hosting providers operating within the European Economic Area (EEA).
  • Payment processors — subject to PCI-DSS compliance and independent GDPR obligations.
  • Logistics and fulfilment partners, where applicable.
  • Professional advisors (legal, financial) bound by duties of confidentiality.

Where transfers outside the EEA are necessary, they are conducted only to countries recognised by the European Commission as providing an adequate level of protection, or under Standard Contractual Clauses (SCCs) approved by the Commission.

09

Cookies & Tracking Technologies

Our website uses cookies and similar technologies to enhance your browsing experience and analyse usage patterns. Cookies are categorised as follows:

  • Strictly necessary cookies: essential for the website to function. These cannot be disabled.
  • Performance cookies: collect anonymised data about how visitors use the site (e.g. pages visited, time spent). Used to improve the website.
  • Functional cookies: remember your preferences (e.g. language, region) to personalise your experience.
  • Marketing cookies: used only with your explicit prior consent to deliver relevant communications.

You may manage or withdraw your cookie consent at any time through our cookie preference centre or your browser settings. Withdrawal does not affect the lawfulness of processing before the withdrawal.

10

Policy Updates

We may update this Privacy Policy from time to time to reflect changes in legislation, our practices, or the services we offer. When we make material changes, we will notify you by email (where we hold your address) or by posting a prominent notice on our website prior to the changes taking effect.

We encourage you to review this policy periodically. The date at the top of this page indicates when it was last revised.

Continued use of our website or services after an update constitutes acceptance of the revised policy. If you do not agree with the changes, please discontinue use and contact us to exercise your data rights.

11

Contact the Data Protection Officer

For any questions, requests or concerns regarding the processing of your personal data, please contact our Data Protection Officer directly:

Postal Address
Equigerminal, Lda.
Penela, Portugal
Response Time
Within 30 calendar days
Supervisory Authority

Login

Hai dimenticato la password?

Non hai ancora un conto?
Creare un profilo