Data Protection Policy
1- Commitment to Data Protection and Privacy
2- Definitions
3- Entity Responsible for Data Processing
4- Contact details of the Data Officer
5- Collection and Processing of Personal Data
6- Categories of Personal Data Processed and Data Subjects
7- Legal Principles
8- Foundations of Legitimacy
9- Purpose of Treatment
10- Data Processing Information Sheets
11- Data Retention Periods
12- Use of Cookies
13- Data Communication to Other Entities
14- Data Recipients
15- International Data Transfers
16- Security Measures
17- Exercising the Rights of Personal Data Holders
18- Complaints or Suggestions
19- Incident Reporting
20- Modification of the Data Protection Policy
21- Express Consent and Acceptance
22- Special Data Protection Policies
23- Data Protection Officer
24- Versions of the Data Protection Policy
Commitment to Data Protection and Privacy
EPDSI complies with all applicable EU and national legal standards regarding data protection, privacy, and information security.
EPDSI has implemented a Personal Data Protection System and an Information Security System to ensure regulatory compliance and demonstrate institutional responsibility regarding data protection and information security, implementing all necessary technical and organizational measures deemed appropriate, both to comply with the general legal regime of the current Data Protection Law and to comply with the special legal regime of the General Data Protection Regulation, applicable since May 25, 2018.
For any clarification or additional information, or to exercise your rights in this regard, please contact the Data Protection Officer of EPDSI via email at protecaodedados@epdsi.pt.
Definitions
“Personal data”
“Personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier. Personal identifiers include, for example, a name, an identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
“Processing of Personal Data”
“Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
«Cookies»
“Cookies” are small text files containing relevant information that devices used for access (computers, mobile phones or portable mobile devices) load, through the internet browser, when a website is visited by the Client or User.
Entity Responsible for Data Processing
EPDSI – Prestação de Serviços a Empresas, Lda, a legal entity with tax identification number 504 526 146, hereinafter referred to as EPDSI, is the entity responsible for the online sites, systems or computerized applications, hereinafter referred to as channels or applications, through which Users, Service Recipients or Clients have remote access to the EPDSI services that are presented or provided, at any time, through them, and is considered the entity responsible for the processing of personal data.
The use of channels, systems or applications by any User, Service Recipient or Client may involve the processing of personal data, the protection, privacy and security of which is ensured by EPDSI, as the entity responsible for the respective processing, in accordance with the terms of this Data Protection Policy.
