Data protection · version 2.0
Privacy Policy
Last updated: 30/07/2026. This policy explains what data is processed, why, how long it is needed and how to exercise your rights.
Use the index to navigate. Material changes are identified by the date and version above.
Controller and contact
Alcides Catroga, Lda., Portuguese tax number 505 941 520, at Zona Industrial, Rua C, Lote 67, 2090-242 Alpiarça, is the controller. Privacy enquiries may be sent to geral@alcidescatroga.pt.
Data, source and required fields
Data is provided by the individual through forms or direct contact. Name, email, message and acknowledgement of the privacy information are needed to respond; other fields are optional unless marked otherwise.
- Commercial enquiries: identity, contact, organisation, product and message data.
- Applications: identity, contact, location, experience and CV.
- Security: network address, date, reference and minimum abuse signals.
Purposes and legal bases
Contacts are processed to respond, prepare a possible contract and manage communications. Applications are assessed at the candidate’s request. Minimum technical data supports the legitimate interest of protecting the service. Consent may be withdrawn without affecting earlier lawful processing.
Retention
Data is retained only for the purpose, follow-up and legal obligations. Until the company approves a formal retention schedule, no fixed period is published that could be misleading; records should be reviewed and deleted when no longer needed.
Recipients and transfers
Access is limited to authorised staff and necessary hosting and email providers under confidentiality and instructions. Data is not sold. Transfers outside the EEA may occur only with a GDPR basis and safeguards.
Rights and complaints
You may request access, rectification, erasure, restriction, objection and portability where applicable, or withdraw consent. Proportionate information may be requested to verify identity. You may complain to Portugal’s data protection authority, CNPD.
Protective measures
Forms use encrypted transport, server validation, a temporary signed session, request limits, automation detection and attachment checks. These controls reduce risk, but no Internet service can promise zero risk.
