1. Optimizer’s Commitment
In the context of its operational and commercial activities, Optimizer – Serviços e Consultadoria Informática Lda, (here after Optimizer), processes personal data and ensures rigor, effectiveness and security protection of all the data it collects and treats, according to its Information Security Management System implemented and certified on the ISO/IEC 27001 standard.
2. Data processing controller
In the scope of its activities and attributions, Optimizer is the entity responsible for the collection and processing of personal data, which are processed and stored in an automated and non-automated manner.
Optimizer does not have a function called a Data Protection Officer, but rather an ISMS Manager (CISO) (Information Security Management System) which already has these responsibilities.
The ISMS Manager is responsible, in particular, for monitoring the compliance of the activities involving the processing of data, with the applicable legal and regulatory standards, being also the point of contact between Optimizer and the National Control Authority and other legal entities regarding security and privacy issues, as well as between Optimizer and its customers and users in matters relating the processing of personal data and information security subjects.
3. Personal Data, data holders and personal data categories
What is personal data?
Personal data is any information of any nature, collected on any type of medium, relating to a unique person, identified or identifiable. Its considered identifiable the set of information that may lead to the identification of a particular person, namely by reference to an identifier (such as an identification number or a location data).
From whom do we collect personal data from?
In face of Optimizer’s activities, most of the data are processed from corporate entities (companies and associations). However, in order to carry out its activities, data from singular persons may be collected and processed (non-exhaustive list):
• Optimizer collaborators;
• Clients / investors and their collaborators;
• Service providers and their collaborators;
• Candidates and trainees;
• Participants in events promoted by Optimizer;
• Facilities visitors.
What personal information do we collect and how do we collect it?
Optimizer only collects data that is appropriate, relevant and limited to what is necessary in relation to the purposes for which it is processed.
The collection of your data can be done orally, in writing (in particular through forms and contracts), as well as through the website optimizer.pt. As a general rule, we collect your data directly, however personal data may also be collected from public sources (such as official websites and public lists).
For different purposes, we may collect and process the following types of personal data:
• identification data (such as name, citizenship, citizen’s card or date of birth);
• contact information (such as mobile phone number, address or e-mail);
• qualification data and professional situation (such as level of education and CV);
• bank, financial and transaction data (such as IBAN or tax identification number);
• location data (such as IP address);
• event recording or videoconferencing images;
• Images collected through video surveillance systems.
As a rule, Optimizer does not store special data, such as health data or data related to criminal misconduct.
4. Fundamentals and Purposes of personal Data treatment
Why and on what grounds do we use your personal data?
All data collected and processed by Optimizer are based on one of the following legitimacy conditions
• The Consent: When the collection is preceded by your express, specific and informed consent, through written or web support.
We collect your consent, for example, to subscribe to a newsletter or to subscribe to events promoted by Optimizer;
• Execution of contract or pre-contractual procedures: when the treatment is necessary for the execution of a contract or for pre-contractual procedures. This condition will be fulfilled when we treat your data for protocols of cooperation or contracts of supply and services;
• The fulfillment of legal obligations: when the treatment is necessary to fulfill a legal obligation. This includes, for example, reporting to public (national and community EU), tax or judicial bodies;
• Legitimate Interest: when treatment proves necessary for the pursuit of the legitimate interests of the treating entity or third parties, without prejudice to the rights and freedoms of third parties, your customers and/or users. This includes all treatments that result from attributions conferred by law, namely internal and external disclosure of Portuguese entities, at national and international level.
What are the purposes for which we collect your data?
Personal data collected by Optimizer is only processed for specific, explicit and legitimate purposes. Where personal data are collected, they are intended solely for the specific purposes identified at the time of collection. Here we outline the main purposes that justify the collection of personal data by Optimizer
• Employment contracts and their legal implications, such as salary payments and insurances;
• Acquisitions of supply and service contracts;
• Contractualisation and management of cooperation programs and protocols;
• Management of events promoted by Optimizer;
• Disclosure of newsletters/publications;
• Physical and logical security of facilities and people.
5. Period of retention of personal data
Optimizer treats and stores your data only for as long as is necessary for the completion of the purposes of the treatment for which they are intended, in compliance with the maximum time limits to comply with contractual, legal or regulatory obligations.
As a general rule, and when there is a contract that legitimizes the processing of your data, Optimizer will maintain such data as long as such contractual relationship is maintained. Other circumstances exist, such as legal or regulatory obligations (for example, for tax purposes invoices must be kept for a maximum period of ten years from the date of the act), as well as the pending legal proceedings, which may justify keeping your data for a longer period of time.
At the end of the maintenance period, Optimizer will delete these data.
6. Rights of data subjects
Under the terms of the legislation in place, as soon as we collect and process your data, there is a set of rights that you can exercise at any given moment with Optimizer.
What are your rights?
Right of access: right to obtain information on the processing of your data and its characteristics (in particular the type of data, the purpose of the processing, to whom your data may be communicated, storage periods and what data you need to know explicitly or optionally).
Right of rectification: right that allows you to request the rectification of your data, requiring that these are accurate and current, such as when you consider that they are incomplete or outdated.
Right to be deleted or “Right to be forgotten”: a right that allows you to request the deletion of your data when you consider that there are no valid grounds for data retention and provided there is no other valid basis for such treatment (the execution of a contract or the fulfillment of a legal or regulatory obligation).
Right to Limitation: right that allows you to suspend treatment or limitation of treatment to certain categories of data or purposes.
Right to Portability: right through which you can request the sending of your data, in a digital format and in current use, that allows the re-use of such data. Alternatively, you may request the transmission of your data to another entity that becomes responsible for the processing of your data.
Right of Opposition: right that allows it to oppose certain purposes, provided that there are no other legitimate interests that prevail over your interests. One of the examples of this right concerns opposition to direct marketing purposes.
Right to Withdraw Consent: right that allows you to withdraw your consent, but which can only be exercised when your consent is the only condition of legitimacy.
How can you exercise your rights?
All rights described above may be exercised, provided that they are correctly identified, with the limitations set forth in the applicable legislation, upon written request, to be sent by letter to Optimizer’s headquarters address: Praça Dr. Francisco Sá Carneiro, 219, 2º Esq. 4200 – 313 Porto, Portugal or through electronic mail using the address: privacy@optimizer.pt.
In the same way you can send questions related to the treatment of your data, directly to the Manager of the ISMS, through the email indicated in the previous paragraph.
You can also submit any complaint to the National Control Authority.
7. Data transmission
With whom do we share your personal data?
In view of Optimizer’s activities, and depending on its purpose, data may be shared with third parties, which include national and international public bodies and private entities for the fulfillment of legal or regulatory obligations, contractual obligations or functions of public interest.
Your data may also be accessed by Optimizer service providers, deemed necessary for the purposes described above, in particular as regards information security and archiving services. Optimizer guarantees that it only resorts to service providers that present the guarantees of execution of technical and organizational measures necessary and adequate to protect personal data.
Transfers of personal data from outside the EEA – European Economic Area
Optimizer may, exceptionally, transfer your personal data to third countries (outside the EEA – European Economic Area). In such cases, Optimizer will ensure that data transfers are carried out in strict compliance with applicable legal regulations.
8. Electronic Cookies Policy
What are cookies?
Cookies are small text files with relevant information that is downloaded by your access device (computer, mobile phone/smartphone or tablet), through the browser, when a site is visited by the user, and used to store information about visits.
Cookies, depending on how long the user stays on the page, can be classified as session or permanent cookies. The first type of cookies expires when the user closes the browser. The second type of cookies expires when your goal is completed or when they are manually turned off.
The cookies used by Optimizer on the site optimizer.pt do not collect personal information to allow identify the user.
Typically, the existing types of cookies are:
• Analytics – collects information about users browsing experience on web pages, anonymously, although sometimes they also allow a user to be uniquely identified to obtain information about the user’s interests in the services provided by the web page;
• Advertising – persistently active but for a limited period of time in order to collect user information on Internet browsing habits so that the advertisement displayed by the user matches their needs and interests;
• Third-party – allow the site to remember browsing preferences, language, region, and collect user information to direct advertising to your interests.
The cookies used on the site optimizer.pt are intended for:
• Customize the website according to location/language preferences so that it is more convenient for users to browse this website;
• Respond to requests for contact from users;
• Collect and analyze anonymous traffic data, via external statistics services, that allow us to improve this website;
• The data collected on this website is not provided by Optimizer to external entities and is used only to satisfy user requests, respond to contacts or product communication.
The site optimizer.pt uses cookies to collect statistical information, in order to analyze the operation of the site and the browsing experience of users, and evaluate the effectiveness of advertising and promotional campaigns.
On this website, when authorized by the user, the following cookies are used:
• Customization cookies – allow us to remember your preferences for your location / language. Thus, on subsequent visits the user will not have to be always selecting these options, making the visit easier.
• Statistics Cookies – let us understand by collecting usage statistics, how users navigate our website, and how we can improve your website experience and functionality. The information collected, such as pages visited or time spent on the website, does not allow to identify specific users since the visits are anonymous
For any question about privacy or cookies please contact us via email: privacy@optimizer.pt.
Disable the use of cookies
All browsers allow the user to accept, reject or delete cookies by selecting the appropriate settings in their browser. Therefore, users can disable the use of cookies at any time by modifying browser settings.
However, it is important to note that disabling cookies may prevent some web services operating correctly, affecting all or part of the navigation.
9. Legislation
The processing of personal data of users and clients carried out by Optimizer, as well as the sending of commercial communications carried out by electronic means are in conformity with the national and Community legislation in force, namely by the General Data Protection Regulation.