Privacy Policy
ANDGINJA DIGITAL SERVICES, LDA is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you visit andginja.com or engage our services. We comply with the General Data Protection Regulation (GDPR) and applicable Portuguese data protection laws.
1. Data Controller
The data controller responsible for your personal data is:
2. Data We Collect
We collect a limited amount of personal data necessary to provide our services and respond to your inquiries:
- ▸Name — provided when you submit a contact or lead form
- ▸Email address — provided when you submit a contact or lead form
- ▸Company name — optionally provided in our forms
- ▸Project details — information you share about your project needs
- ▸IP addresses — automatically collected for rate limiting and security purposes
3. Purpose of Processing
We process your personal data for the following purposes:
- â–¸To respond to your inquiries and contact requests
- â–¸To prepare proposals and provide our services
- â–¸To communicate with you about active or potential projects
- â–¸To protect our website from abuse through rate limiting
4. Legal Basis for Processing
We process your personal data based on the following legal grounds under the GDPR:
- ▸Consent — when you voluntarily submit your information through our contact or lead forms (Article 6(1)(a) GDPR)
- ▸Contractual necessity — when processing is required to fulfil a service agreement or to take pre-contractual steps at your request (Article 6(1)(b) GDPR)
- ▸Legitimate interest — for website security and rate limiting to protect against abuse (Article 6(1)(f) GDPR)
- ▸Website analytics — legitimate interest for counting page views without cookies or identifiers, which you can object to at any time (Article 6(1)(f) GDPR); consent for analytics cookies, only if you accept them (Article 6(1)(a) GDPR)
5. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected. Contact form submissions and project inquiries are retained for up to 24 months after the last communication. Data related to active projects is retained for the duration of the project and for 5 years thereafter for legal and accounting purposes.
IP addresses collected for rate limiting are retained for no longer than 30 days.
Analytics and cookies
Essential storage supports sign-in, secure downloads and your privacy choice. The analytics choice (andginja:analytics-consent) is stored in this browser for 180 days. Until you accept analytics cookies, the _pt_consent marker in local storage keeps them off; it holds no identifier. We use Pipetrace, an analytics service that processes data on our behalf, to understand how andginja.com is used. Before you choose, and if you reject analytics cookies, we count page views without cookies and without storing any identifier in your browser. For each page view we record the page address (without its query, except campaign tags), the referring website, campaign tags (UTM), your country, device type, browser family and language. We count actions such as an enquiry or a checkout step only after you accept analytics cookies. We do not record an identifier for you. Your IP address is used to look up your country and, briefly, to protect the service from abuse; it is not stored. Where the GDPR applies, we measure visits before consent on the basis of our legitimate interest in understanding and improving our website (Art. 6(1)(f) GDPR). You can object at any time by contacting us, or by turning on Global Privacy Control in your browser. Analytics cookies and browser storage are used only with your permission: they stay off until you accept them, and rejecting them does not prevent browsing or buying. If you accept, Pipetrace stores a random identifier (_pt_vid) in a first-party cookie that expires 2 years after your last visit, and in local storage and IndexedDB, which have no expiry date, to recognise your later visits; _pt_ session keys hold session and campaign information, and _pt_failed can hold unsent events. On the same day, if that identifier is missing, Pipetrace’s server may also recognise your visit from a code derived from your IP address and browser details with that day’s secret key. Pipetrace then records the full page address and title, the referring page, campaign tags, your country, device type, browser, operating system, connection type, time zone, language and screen details, time on page, repeated or unresponsive clicks, performance, and the names and details of the actions we count, including consented enquiry and checkout events. We do this only with your consent (where the GDPR applies, Art. 6(1)(a) GDPR). Our consent expires after 180 days, when cookie-based analytics stops and its browser identifiers are removed on your next visit. Withdrawing consent stops cookie-based analytics and removes those browser identifiers; your page views are then counted without cookies again. It does not automatically erase events already received; use the privacy contact for deletion requests. Analytics data is deleted automatically after 25 months. Purchase, admin and private-report pages are excluded from analytics. If your browser sends the Global Privacy Control (GPC) signal, Pipetrace collects nothing from you. If it sends the Do Not Track signal, Pipetrace does not keep cookies or identifiers for you, even if you accept (if your browser sends the Do Not Track header without exposing it to scripts, identifiers created on a page are deleted as soon as the server reports it): at most, your page views are counted without them. There are no advertising trackers. Use Cookie settings in the footer to accept or withdraw consent. Stripe’s hosted checkout has its own privacy and cookie information.
andginja Shop
For shop purchases, we store your checkout email, order and payment references, totals, consent record and delivery status. Stripe processes payments; we do not store full card details. Resend sends purchase confirmations and sign-in codes. Better Auth runs on our server to manage verified-email sessions. Essential cookies keep you signed in; codes expire after 10 minutes and sessions after seven days. We use this data to perform the purchase contract, prevent abuse and fulfil legal accounting duties. Purchase records are retained as required for those duties; access records are kept only as needed for support and security. We record file requests, download response outcomes and email attempts for support, with operational records deleted after 90 days by a daily cleanup. Buying does not enrol you in marketing. Contact [email protected] to exercise your data rights; legally required records may need to be retained.
6. Data Sharing
We do not sell, rent, or trade your personal data to third parties. We do not share your data with third-party advertisers or marketing platforms.
We share necessary information with service providers that process payments, deliver transactional email and host our services, as explained for each feature. We may also disclose data when required by law or to protect legal rights and safety.
7. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- ▸Right of access — obtain a copy of the personal data we hold about you
- ▸Right to rectification — request correction of inaccurate or incomplete data
- ▸Right to erasure — request deletion of your personal data when it is no longer necessary
- ▸Right to restriction — request limitation of how we process your data
- ▸Right to data portability — receive your data in a structured, commonly used, machine-readable format
- ▸Right to object — object to our processing of your data based on legitimate interest
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.
You also have the right to lodge a complaint with the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD), at www.cnpd.pt.
8. International Data Transfers
We use hosting, database, payment and email providers, including Cloudflare, Stripe and Resend. Depending on the service and its subprocessors, personal data may be processed outside the European Economic Area. International transfers require a valid GDPR transfer mechanism, such as an applicable adequacy decision or standard contractual clauses. Contact [email protected] for information about the safeguards applicable to your data.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include encrypted communications (HTTPS), secure server infrastructure, and access controls. However, no method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
10. Children's Privacy
Our website and services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us so we can take appropriate action.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The updated version will be posted on this page with a new revision date. We encourage you to review this policy periodically.
12. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
ANDGINJA DIGITAL SERVICES, LDA
Lisbon, Portugal
[email protected]Portuguese Data Protection Authority (CNPD): www.cnpd.pt