Legal

Privacy Policy

Last updated: 2026-05-14

This policy explains what personal data is collected through this website, why, on what legal basis, and how long it is kept. It applies to visitors and to anyone who submits the contact form.

1. Data controller

The data controller is Andreia Cirne, trading as Andreia Cirne Consulting, based in Faro, Portugal. For any privacy request, write to hello@andscirne.com.

2. Data collected through the contact form

When you submit the contact form, the following data is collected:

  • Name
  • Email address
  • Company (optional)
  • Selected service / type of support (optional)
  • Budget range (optional)
  • Message content
  • Whether you requested a discovery call
  • Site language (EN or PT)
  • Form source (which page the form was submitted from)
  • Browser user agent (technical, used to filter abuse)
  • An anti-spam honeypot field labelled "website" — invisible to humans; submissions that fill it are silently discarded
  • Timestamp confirming you accepted these legal terms, plus the policy version that was in force at that moment

No financial data, identification numbers or special categories of data are requested.

3. Purpose of processing

The data is used to read your inquiry, reply with the most useful next step, and keep a record of past conversations so future replies have context. The legal acceptance record is kept as evidence that consent to these terms was given.

4. Legal basis

  • Pre-contractual measures (GDPR Art. 6(1)(b)): processing is necessary to respond to a request that may lead to an engagement.
  • Legitimate interest (GDPR Art. 6(1)(f)): keeping a basic record of past conversations to provide useful continuity.

5. Retention

Contact form submissions are kept for up to 24 months from the last interaction. Submissions tied to an active client relationship are kept for the duration of that engagement and for the legal retention periods that apply to the underlying contract and accounting records.

6. Recipients

Personal data is processed by Andreia Cirne. It is not sold, rented, or shared with third parties for marketing purposes. It may be processed by trusted technical providers acting as sub-processors (see next section).

7. Third-party tools (sub-processors)

  • Hosting & database: the site and the contact submissions database are hosted on infrastructure operated by trusted cloud providers, with data stored within the EU/EEA where possible.
  • Analytics: Google Analytics 4 / Google Tag Manager are used in anonymised mode (IP anonymisation, ads data redaction). They are only loaded after analytics consent is granted in the cookie banner.
  • Email: replies are sent through standard email providers.

8. Analytics and cookies

The site uses cookies only after explicit consent through the cookie banner. Analytics events do not include your name, email, phone number or message content — only anonymous parameters such as form name, project type, budget range and language. Consent can be changed at any time through the "Cookie preferences" link in the footer.

9. International transfers

Where a sub-processor processes data outside the EU/EEA, that transfer is covered by the European Commission's Standard Contractual Clauses or an equivalent safeguard.

10. Your rights under GDPR

You have the right to:

  • Access the data held about you;
  • Request correction of inaccurate data;
  • Request deletion of your data;
  • Restrict or object to processing;
  • Data portability;
  • Withdraw consent at any time, where processing is based on consent;
  • Lodge a complaint with the Portuguese supervisory authority, CNPD — Comissão Nacional de Protecção de Dados.

11. Exercising your rights

To exercise any of these rights, write to hello@andscirne.com. Requests are answered within one month.

12. Security

Reasonable technical and organisational measures are in place to protect personal data — including encrypted transport (HTTPS), role-based access to the submissions database, and minimum data collection. No system is ever fully immune to incidents; in the event of a breach affecting your rights, you will be informed.

13. Updates to this policy

This policy may be updated as the business or applicable law evolves. The version in force is always the one published on this page; material changes will be reflected in the "Last updated" date above.

Drafted in plain language for transparency. A qualified legal review is recommended before relying on this policy for production use.