Privacy Policy
Last updated on
1. Scope of this Policy
This policy applies exclusively to personal data collected by Loominary through the website loominary.pt, where we act as data controller.
When we provide services to institutional clients (clinics, practices, healthcare professionals), we act as a data processor under Data Processing Agreements entered into with each client. In that capacity:
- We do not determine the purposes or the means of the processing
- We do not collect data directly from the end data subjects (e.g. the clinics' patients)
- We process the data exclusively on the documented instructions of the respective client
- Each client maintains its own privacy policy and collects the data subjects' consent
If you are a patient, service user or end customer of an entity that uses our services, you should consult that entity's privacy policy and address your requests to the respective data controller.
For the provision of WhatsApp messaging services to institutional clients, Loominary acts as a Business Solution Provider (BSP) / Tech Provider of Meta Platforms Ireland Ltd., under the WhatsApp Business Platform programme. Messages exchanged between institutional clients and their end users are processed by Meta's WhatsApp Cloud API infrastructure, on the documented instructions of the respective institutional client, which remains the data controller towards its end users.
2. Data Controller
Jorge Ferreira, sole trader, operating under the trading name Loominary, established in the Porto district, Portugal.
Contacts:
- Email for privacy matters: privacidade@loominary.pt
- Website: https://loominary.pt
Under Article 37 of the GDPR, the formal appointment of a Data Protection Officer (DPO) will be made as the volume of processing evolves, namely according to the number of institutional clients and the scope of the associated processing. Until then, GDPR-related requests may be addressed to the email above.
3. Personal Data Collected
Through the website loominary.pt we may collect the following categories of data:
3.1 Data provided directly by the data subject
Collected in contact forms, demo scheduling, newsletter sign-up or email communications:
- Name
- Email address
- Telephone number
- Company or clinic name
- Job title or role
- Content of the message or specific request
- Communication preferences
3.2 Data collected automatically
While browsing the website, collected through cookies and similar technologies (with your consent, where applicable):
- IP address (pseudonymised in analytics services)
- Device identifier and user agent
- Browser type, operating system and screen resolution
- Pages visited, traffic source and visit duration
- Interactions with page elements (clicks, scroll, form submissions)
- Conversion and advertising campaign attribution data
4. Purposes of Processing
Personal data is processed for the following purposes:
- Handling contact requests and pre-contractual steps: replying to requests for information, quotes or demo scheduling
- Commercial relationship: lead follow-up, service proposals, performance of contracts
- Direct marketing communications: only with prior consent, with the possibility to object at any time
- Website usage analysis: performance measurement, identification of friction points, experience optimisation
- Advertising campaign measurement: measuring the effectiveness of advertising spend and remarketing
- Compliance with legal and tax obligations
- Defence of rights in judicial or extrajudicial proceedings
5. Legal Bases
Processing is based on the following legal bases under Article 6(1) of the GDPR:
| Purpose | Legal basis |
|---|---|
| Replying to contact requests, demo scheduling | Pre-contractual steps (point (b)) |
| Provision of contracted services | Performance of a contract (point (b)) |
| Non-essential cookies (analytics, marketing) | Consent (point (a)) |
| Marketing communications to leads | Consent (point (a)) |
| Commercial communications to existing clients | Legitimate interest (point (f)) |
| Website security, fraud prevention | Legitimate interest (point (f)) |
| Tax and accounting obligations | Legal obligation (point (c)) |
6. Data Processors and Data Sharing
Your personal data is not sold to third parties. It may be shared with the following processors, bound by data processing agreements (Article 28 GDPR):
| Processor | Purpose | Location | Transfer safeguards |
|---|---|---|---|
| Vercel Inc. | Website hosting | USA | Data Privacy Framework + SCCs |
| Supabase Inc. | Authentication and application database | USA / EU | Data Privacy Framework + SCCs |
| Calendly LLC | Demo scheduling | USA | Data Privacy Framework + SCCs |
| Google LLC (Google Analytics) | Website usage analysis | USA | Data Privacy Framework + SCCs |
| Meta Platforms Ireland Ltd. | Meta Pixel: measurement and remarketing | Ireland (EEA) | Not applicable (processing in the EEA) |
| Meta Platforms Ireland Ltd. | WhatsApp Business Platform (Cloud API): sending and receiving messages on behalf of institutional clients | Ireland (EEA) | Not applicable (processing in the EEA) |
The WhatsApp Business Platform row applies exclusively to services provided to institutional clients (where Loominary acts as data processor), and not to personal data collected directly through the website loominary.pt. In that capacity, Loominary operates as a Meta BSP / Tech Provider, as described in Section 1.
Transfers of data to countries outside the European Economic Area are carried out under the following safeguards of Chapter V of the GDPR:
- Data Privacy Framework (DPF): applicable to transfers to the United States where the recipient is a certified participant
- Standard Contractual Clauses (SCCs): European Commission Implementing Decision (EU) 2021/914
We may also share data with competent public authorities when legally required to do so.
7. Retention Periods
Personal data is kept only for as long as necessary for the purposes for which it was collected, or for the period required by law:
| Category | Period |
|---|---|
| Contact requests not converted | 2 years after the last contact |
| Lead data with marketing consent | Until consent is withdrawn or 3 years of inactivity |
| Contractual and tax data | 10 years (Article 123 of the Portuguese Corporate Income Tax Code) |
| Analytics and marketing cookies | Maximum 13 months |
| Website security logs | 12 months |
Once these periods end, the data is deleted or irreversibly anonymised.
8. Rights of the Data Subject
Under Articles 15 to 22 of the GDPR, the data subject has the right to:
- Access (Art. 15): obtain confirmation of the processing of their data and a copy of it
- Rectification (Art. 16): correct inaccurate or incomplete data
- Erasure (Art. 17): request the deletion of their data, under the applicable conditions
- Restriction of processing (Art. 18): in certain legally defined circumstances
- Portability (Art. 20): receive the data in a structured, commonly used and machine-readable format
- Objection (Art. 21): object to processing for direct marketing or based on legitimate interests
- Withdraw consent (Art. 7(3)): at any time, without affecting the lawfulness of prior processing
- Not to be subject to automated decisions with significant effects (Art. 22): the website loominary.pt does not use automated decisions with legal or similarly significant effects on data subjects
To exercise any of these rights, contact us at privacidade@loominary.pt. We will reply within a maximum of 30 days (extendable by a further 60 days in complex cases, with prior notice to the data subject).
9. Cookies
The website loominary.pt uses cookies and similar technologies. You can manage your preferences at any time through the cookie banner or your browser settings.
9.1 Essential cookies
Necessary for the basic operation of the website. They do not require consent.
- Authentication and session maintenance (Supabase)
- Interface preferences and record of cookie consent
9.2 Analytics cookies
Help us understand how visitors use the website. Only activated with prior consent.
- Google Analytics 4 (Google LLC): audience measurement, session duration, conversion funnels
9.3 Marketing cookies
Used to measure the effectiveness of advertising campaigns and for remarketing. Only activated with prior consent.
- Meta Pixel (Meta Platforms Ireland): conversion measurement and custom audiences on Facebook and Instagram
Consent can be withdrawn through the "Cookie preferences" link in the website footer or by deleting the cookies directly in your browser.
10. Security
We implement technical and organisational measures appropriate to the risk to protect personal data, including:
- Encryption of data in transit (TLS 1.2 or higher)
- Role-based access control and the principle of least privilege
- Logging and monitoring of access to sensitive systems
- Regular backups
- Regular review of processors and their security safeguards
In the event of a personal data breach likely to result in a high risk to the rights and freedoms of data subjects, we will notify the CNPD (Portuguese Data Protection Authority) within 72 hours and, where applicable, the affected data subjects, under Articles 33 and 34 of the GDPR.
11. Complaints
Without prejudice to any other administrative or judicial remedy, the data subject has the right to lodge a complaint with the competent supervisory authority:
- Comissão Nacional de Proteção de Dados (CNPD)
- Address: Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, Portugal
- Telephone: (+351) 213 928 400
- Email: geral@cnpd.pt
- Website: www.cnpd.pt
12. Changes to this Policy
We reserve the right to update this Privacy Policy whenever necessary, namely as a result of legislative changes, new processing activities or new processors.
Where changes are substantive, we will take care to communicate them appropriately (e.g. by email to registered contacts or by a visible notice on the website).
The version in force is always the one published on this page, with the respective date of last update.
13. Applicable Law
This Policy is governed by Portuguese and European data protection law, namely:
- Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR)
- Law no. 58/2019 of 8 August, implementing the GDPR in Portugal
- Law no. 41/2004 of 18 August, on privacy in electronic communications