Privacy policy

Last updated: 2026-08-03

Who we are

This policy describes how Hélder Maravilha Ferreira, Unipessoal LDA ("Privava", "we", "us"), registered at Rua Mário Martins, n6 1E, 2810-399 Almada, tax number (NIF) 518708489, processes personal data in connection with the Privava service.

For any question about this policy, or to exercise the rights described below, contact us at heldermferreira.91@gmail.com.

Two roles: controller and processor

Privava acts as a controller for the account, organization profile, and session data described in this policy, the data that identifies you as a user of the service.

Privava acts as a processor for the content our customers enter about their own organizations and the data subjects they deal with, for example questionnaire answers, generated privacy and cookie policies, records of processing (ROPA), data subject access requests, incident records, and cookie consent records. That content is processed strictly on the customer instructions to provide the service, and is never used for our own purposes. A data processing agreement covering that processing is available on request at heldermferreira.91@gmail.com.

Data we collect as controller

As controller, we collect the following categories of personal data.

  • Account data: your name, email address, password hash, language preference, and, if you enable it, your two-factor authentication secret.
  • Organization profile data you enter: company name, NIF/VAT number, country, sector, DPO contact details, and the client contact email and language you set for a workspace.
  • Session and security data: a truncated IP address (the last octet, or the last 80 bits for IPv6, is discarded before storage), browser user agent, and sign-in timestamps.
  • Audit log entries: metadata about actions taken in the service (who, what, when), never the content of what was changed.
  • Emails we send you: verification, password reset, invitation, and notification emails, sent through our email provider.
  • Invitation data: the email address of a colleague you invite to a workspace, and the status of that invitation.

Legal bases for processing

We rely on the following legal bases under the GDPR.

  • Performance of a contract: to create your account and provide the service you asked for.
  • Legitimate interest: to keep the service secure, prevent abuse, and maintain an audit trail of actions taken.
  • Legal obligation: where applicable, for example responding to a lawful request from a supervisory authority.

Cookies

We use a strictly necessary session cookie and a two-factor challenge cookie (both set by our authentication library), and a "ui-locale" preference cookie, valid for one year, that stores only the language you chose.

We do not use analytics cookies, tracking cookies, or third-party cookies. Our cookies are either strictly necessary or set only as the direct result of a choice you make yourself (the language cookie), so no consent banner is required.

Where your data is stored

Your data stays within the EU. The service is hosted on servers operated by Hetzner in Germany and Finland. Transactional email is delivered through Brevo, based in France.

We do not transfer personal data outside the EU/EEA.

Security measures

Data is encrypted in transit. Especially sensitive fields, such as data subject contact details in data subject access requests and incident narratives, are additionally encrypted at the application layer (AES-256-GCM) before being stored.

Tenant isolation between customer workspaces is enforced at the database level (row-level security), access to production systems is controlled, and automatic server-level backups are kept for a limited rolling period.

How long we keep data

We keep account data for as long as your account exists. Accounts that never verify their email address are automatically deleted after 7 days.

Sessions expire automatically after 7 days without renewal. Audit metadata is kept for the life of the workspace it belongs to. Server-level backups are kept for a limited rolling period before being replaced.

No automated decision-making

We do not use automated decision-making or profiling. The service contains no artificial intelligence features; documents are generated by fixed rules from the answers you provide.

Your rights

You have the right to access, rectify, erase, port, restrict, and object to the processing of your personal data. To exercise any of these rights, email heldermferreira.91@gmail.com.

You also have the right to lodge a complaint with the CNPD (Comissão Nacional de Proteção de Dados, www.cnpd.pt), or with the supervisory authority of the EU member state where you live or work.

Changes to this policy

If we change this policy, the updated version will be posted here with a new date at the top of the page.

Privacy policy | Privava