This Policy describes how personal data collected through the website correiacrespo-advogados.pt (the «Website») are processed, in compliance with Regulation (EU) 2016/679 (GDPR), Portuguese Law no. 58/2019 of 8 August, and other applicable legislation.
1. Data controller
| Controller | Luís Correia Crespo, lawyer |
|---|---|
| Professional licence | Portuguese Bar Association no. 67709L |
| Designation | Correia Crespo — Advogados |
| Tax ID (NIF) | 238 543 382 |
| Address | Rua do Sol Nascente, no. 2, 2530-804 Lourinhã |
| correiacrespo-67709L@adv.oa.pt | |
| Telephone | +351 914 376 903 |
2. Scope
This Policy applies exclusively to processing carried out through the Website. It does not cover processing in the context of legal services to clients, which is subject to separate rules and professional confidentiality (see section 10).
3. Principles
We apply the principles of lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, and integrity and confidentiality. We process only the data necessary for the stated purposes and only for as long as strictly required.
4. Data processed, purposes, legal basis and retention
| Activity | Data | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Website operation and security | Technical connection data (e.g. IP address, date/time of request) | Make the Website available and ensure its security and stability | Legitimate interest — Art. 6(1)(f) GDPR | For the logging period defined by the hosting provider |
| Audience measurement (Google Analytics 4) | Identifiers and usage data, with IP anonymised | Understand, in aggregate, how the Website is used and improve it | Consent — Art. 6(1)(a) GDPR | Up to 14 months |
| Contact form | Name, email, optional phone, subject and message content | Respond to contact and consultation booking requests | Pre-contractual steps at the data subject's request — Art. 6(1)(b) GDPR | If no contractual relationship results, up to 12 months; if it does, for the duration of the mandate and applicable legal obligations |
The form is for initial contact. Documents, identification numbers, bank details or extensive confidential information should not be sent at this stage.
5. Cookies and similar technologies
The Website uses analytics (Google Analytics 4) identifiers only with your prior consent, collected in the notice shown on first visit, where you may accept or reject. Without consent, audience measurement tools are not loaded. When analytics is active, we configure IP address anonymisation.
Your choice is stored in the browser's local storage and respected on later visits. You may withdraw consent at any time by clearing browsing data/local storage, which will show the notice again on the next visit.
6. Processors and recipients
We do not sell or transfer personal data. We use providers that process data on our behalf under processing agreements, strictly for the purposes described:
- Google — audience measurement (Google Analytics), only with consent.
- Web3Forms — processing and delivery of messages submitted through the contact form.
- GitHub, Inc. — website hosting.
7. International data transfers
Some of the providers listed may process data outside the European Economic Area, including in the United States. Such transfers rely on mechanisms provided for in the GDPR, in particular standard contractual clauses approved by the European Commission and, where applicable, the EU–U.S. Data Privacy Framework, under each provider's policies.
8. Retention periods
Data are kept only for as long as necessary for the purposes for which they were collected and to comply with applicable legal obligations, after which they are deleted or anonymised, in line with the periods in section 4.
9. Data subject rights
You have the right to access your data, rectification, erasure, restriction of processing, portability and objection. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
To exercise these rights, contact the controller using the details in section 1. We may request information to confirm your identity.
10. Professional confidentiality
Data transmitted in the context of a mandate or provision of legal services are subject to the lawyer's professional secrecy, under the Portuguese Bar Association Statute, and are processed under that framework, distinct from use of the Website described in this Policy.
11. Data protection officer
No data protection officer has been appointed, as this is not legally required for the present activity. Questions on data protection may be addressed to the controller through the contacts in section 1.
12. Right to lodge a complaint
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with the competent supervisory authority:
Comissão Nacional de Proteção de Dados (CNPD)
Av. D. Carlos I, 134, 1.º — 1200-651 Lisboa
Tel.: +351 213 928 400 · Email: geral@cnpd.pt · www.cnpd.pt
(Complaints are submitted through the form available on the CNPD website.)
13. Security
We adopt appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction, including encrypted transmission via HTTPS.
14. Changes to this Policy
This Policy may be updated. The version in force is the one published on the Website, with the last update date shown at the top.