Skip to main content

SMARTIDIOM

Privacy Policy

1. Identification of the data controller

  • Company: SMARTIDIOM, LDA
  • Head Office: Avenida Dom João III, Edifício 2002, Entrada A, 3.º andar, Fração BC, 2400-164 Leiria, Portugal
  • Tax and corporate ID (NIPC): 510300251
  • Telephone number: 244 832 015
  • Email: [email protected]
  • Data Protection Officer: Patrícia Lopes, who can be contacted at [email protected]

2. Legal framework

Law No. 58/2019 of 8 August, which implements the General Data Protection Regulation in Portuguese law, and the General Data Protection Regulation (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, hereinafter “GDPR”) ensure the protection of natural persons with regard to the processing of personal data and the free movement of such data.

Under the provisions of the law, personal data is considered to be any “information relating to an identified or identifiable natural person (“the data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an item such as a name, an identification number, location data, an online identifier or to one or more items specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

This Privacy Policy tells you how we process your personal data. The legal basis for each processing activity is set out in section 3. Where a processing activity depends on your consent, that consent is asked of you separately, specifically and for that purpose: accepting this policy does not replace it.

SMARTIDIOM keeps a database of its clients, comprising the personal details each client has provided.

Under no circumstances will personal data on racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, data relating to health, genetic data or biometric data, or data relating to sex life or sexual orientation be requested. Under no circumstances will SMARTIDIOM undertake any of the following activities with the personal details provided through this website, without the prior express consent of the data subject:

  • Disclose to other persons or entities;
  • Transfer outside the European Economic Area, other than under the conditions described in section 5 (Transfers outside the European Economic Area).

3. Purposes for processing personal data and legal bases

We process personal data collected through this website, and also in the course of our relationship with clients, suppliers and applicants, for the following purposes:

  • Communication and queries, and processing information and quotation requests: steps taken at your request prior to entering into a contract;
  • Delivery of the services contracted: performance of the contract;
  • Processing complaints: compliance with a legal obligation and our legitimate interest in answering you;
  • Processing applications: steps prior to a contract and our legitimate interest in maintaining a pool of professionals;
  • Invoicing and accounting and tax obligations: compliance with a legal obligation;
  • Statistical analysis of website use: your consent, given through cookies;
  • Monitoring, maintenance and development of our systems: our legitimate interest in keeping them secure and operational;
  • Promotional communication and direct marketing: your consent.

SMARTIDIOM guarantees the confidentiality of all provided data. It should be noted that collecting data on open networks allows personal details to circulate without security, with the risk of them being seen and used by unauthorised third parties.

Filling in the fields marked as mandatory is necessary for us to be able to reply to you: if you do not complete them, we cannot respond to your request.

4. Who else processes your data

To provide our services, we rely on organisations that process personal data on our behalf and on our instructions, under contracts that bind them to the same confidentiality and security obligations as ourselves.

  • External translators, revisers and interpreters, to carry out translation, revision and interpreting work: worldwide;
  • XTRF, for project management: Germany;
  • TOConline, for accounting and invoicing: Portugal;
  • Microsoft 365, for email and documents: European Union, with support access from other countries;
  • Web hosting provider, for hosting the website and its backups: Portugal;
  • Cloudflare, for website security and performance: United States;
  • ActiveCampaign, to send the newsletter and commercial communications: United States;
  • Slack, for internal communication: United States;
  • CookieYes, to record your cookie consent: Ireland;
  • Google, for website usage statistics: United States.

We may also disclose data to our certified accountant, to our lawyers, and to public authorities where the law requires it.

Website usage statistics are only collected if you consent to the corresponding cookies, and you can change that choice at any time in our Cookies Policy.

We do not sell your personal data, nor do we pass it on to third parties for them to use for their own purposes, beyond what is described in this section.

5. Transfers outside the European Economic Area

Yes. Some of your data is processed by our providers based outside the European Economic Area (EEA), mainly in the United States. And because we translate from and into languages from all over the world, the documents you entrust to us may be worked on by external translators and revisers based in any country.

These transfers always take place under the safeguards provided for in the GDPR: where an adequacy decision of the European Commission covers the provider, that decision applies; in all other cases, the standard contractual clauses approved by the Commission apply.

If you would like to know which safeguard applies to a particular transfer, or to receive a copy of it, write to us by the means set out in section 9 (Exercise of rights).

6. How long we keep your data

We keep your data only for as long as is necessary for the purposes for which it was collected, and for the periods the law requires of us.

  • Invoicing and supporting accounting documents: 10 years, counted from the end of the year to which they relate, because the VAT Code, the Corporate Income Tax Code and the Commercial Code require us to keep them;
  • Client contact details and translation project files: the period agreed with each client, because in those projects we process the data on the client’s behalf;
  • Information and quotation requests that did not lead to a project: 2 years from the last contact, so that we can pick up the conversation again if you need us;
  • Applications from translators, revisers and other professionals, and speculative job applications, including CV and contact details: 10 years, because we maintain a pool of professionals by language pair and by specialism, and a combination we do not need today may be exactly the one a future project calls for;
  • Newsletter subscribers: until you unsubscribe, and after that for as long as we need to be able to demonstrate that you gave us your consent.

When we provide translation services, the personal data inside the documents is not processed on our own initiative: the controller is the client, and we process it on their behalf and on their instructions. If you wish to exercise your rights over that data, the request goes to that client; if you contact us, we will pass it on.

You can ask us at any time to erase your data before these periods, except where we are required to keep it by law or in order to defend a legal claim.

Your right to object

Some of these processing activities rely on our legitimate interest: maintaining a pool of external professionals we may come to work with, being able to resume contact with those who asked us for a quotation, and keeping our systems secure. You have the right to object to any of them, at any time and without having to give a reason, by writing to us by the means set out in section 9. If you do, we will stop processing that data for those purposes.

Where a processing activity relies on your consent, you can withdraw it at any time, without affecting what was done beforehand on that basis.

We do not take automated decisions about you, nor do we carry out profiling that produces legal effects concerning you or similarly significantly affects you. Decisions on applications and on commercial proposals are taken by people.

7. Security measures

SMARTIDIOM declares that it has established and will continue to implement the technical and organisational security measures deemed necessary to guarantee the safety of the personal data provided to it, in order to prevent its alteration, loss, unauthorised processing and/or access, taking into account the current state of technology, the nature of the stored information and the risks to which it is exposed.

All data is transmitted over an encrypted connection. You can confirm this if the address of this website begins with https.

Personal data is processed with the level of protection legally required to guarantee its security and prevent its alteration, loss, processing or unauthorised access, considering the technological state of the art, and you acknowledge and accept that Internet security measures are not unbreakable.

Whenever SMARTIDIOM accesses personal data, it undertakes to:

  • Store it by means of legally required security measures, of a technical and organisational nature, which guarantee its safety, thus preventing alteration, loss, processing or unauthorised access, in accordance with the technological state of the art at any given time, the nature of the data and the possible risks to which it is exposed;
  • Use the data exclusively for the purposes previously defined;
  • Make sure that the information is only processed by employees whose intervention is necessary to fulfil the request to which the data relates, who are bound by the duty of secrecy and confidentiality.

Should it be possible for the information to be disclosed to third parties for the aforementioned purposes, the latter shall be obliged to observe due confidentiality in compliance with the provisions of this document.

8. Commercial and promotional communications

One of the purposes for which your personal data is processed is to send electronic communications with commercial and promotional information.

All communications of this type are addressed exclusively to those who have given their express prior authorisation.

If you wish to stop receiving commercial or promotional communications from SMARTIDIOM, you may object at any time by sending an email to [email protected].

9. Exercise of rights

In compliance with the provisions of Law No. 58/2019 and the GDPR, you may exercise your rights to information, access, rectification, erasure, limitation, portability and objection, at any time, by submitting a written request to SMARTIDIOM by the following means:

  • By post: Avenida Dom João III, Edifício 2002, Entrada A, 3.º Andar, Fração BC, 2400-164 Leiria, Portugal
  • Email: [email protected]

10. Supervisory authority

Under the legal provisions, you have the right to file a complaint regarding the protection of personal data with the competent supervisory authority, the National Data Protection Commission (CNPD): www.cnpd.pt.