4) Responsible Entity and Responsibilities
The Group has internally implemented a "Personal Data Protection Commission", which is responsible for ensuring compliance and adaptation to GDPR standards.
This Commission consists of the Responsible for the Protection of Personal Data of each company of the Group, representatives of the Department of Information Technologies, representatives of the Legal Area, as well as representatives of the Department of Human Resources and Department of Organization and Quality.
You can contact the Commission on any issues relating to this privacy policy by:
- Email address: dpd@ideiasdinamicas.com or – from the contact details referred to below (from 9am to 12pm and from 2pm to 6pm):
- Postal Address: Grupo Ideias Dinâmicas
Commission for the Protection of Personal Data
Rua Álvaro Castelões, 821 – 2o, sala 2.2
4450-043 Matosinhos - Phone: +351 229 398 320
5) Data Collection and Processing
The Group shall collect only the data considered essential, making the processing necessary for the purpose.
The collection of your data, including personal data, takes place in interactions with the Group in particular:
- Contacts;
- General requests for information;
- Download documentation;
- Business process;
- Sales process;
- Customer management process;
- Accounting, tax and administrative management;
- Compliance with legal and regulatory obligations;
- Litigation management;
- Human resources management process;
- Marketing and event management (face-to-face and/or online);
- Information security control;
- Other data that is in the documentation delivered to the company or obtained as a consequence of the relationship established.
Depending on the nature of the interaction, and only when necessary, the Group may request some personal data, such as: name, email address, address/location, telephone number, mobile phone, citizen/passport card number, tax identification (both in physical and digital support), date of birth, nationality, marital status, academic qualifications, profession, bank details, and, in general, any documentation and information of contacts held with the customer by different means, including marketing campaigns.
The processing of data for marketing purposes will be carried out according to the consent option expressed by the data subject. Consent must be prior, free, informed, specific and unequivocal, expressed in a written, oral or through the validation of an option. The data subject may owe the processing of data for marketing purposes at any time and by any means.
Optionally, the data subject may authorize the collection of complementary data that can assist the Group in providing a better and more personalized service or service provision.
6) Purpose of The Processing of Personal Data
The personal data provided by the data subject or generated in relation to the service provided will be processed, and stored informationally, intended to be used by the Group.
The Group collects and processes the strictly necessary data, which is only requested when related to the purpose in question, and for legitimate purposes such as:
- Provide an appropriate and targeted response to requests for information/proposal;
- Communicate better with the holders of personal data, for relevant matters and only as often as necessary, according to the characterization of their data and their preferences;
- Comply with business purposes, namely statistical data to improve the performance of the various services provided;
- Meet the assumptions of human resources management;
- Comply with legal or regulatory requirements, on which depends on the validity of the certificates of some of the services provided, namely training actions;
- Bill services/products.
Personal data are processed by the Group only for the period necessary to achieve the defined purpose.
The Group collects and processes the strictly necessary data, which is only requested when related to the purpose in question, and for legitimate purposes such as:
– Human Resources Management
It includes the processing of data necessary for the conclusion, fulfillment and termination of an employment contract, management of working times, absences and vacations, processing of wages and other benefits, relationship with the Tax Administration and Social Security, promotions and career development, training, evaluation, expenses of representation and communication with workers, exercise of disciplinary power.
– Internal and Business Management
Includes activities such as project planning, job recording, company asset management, provision of centralized services to increase the efficiency of operations, conducting audits and investigations, implementation of management controls, use of internal databases, file management, insurance, prevention, preparedness and conflict management.
– Safety, Hygiene and Health at Work
It includes activities related to safety, hygiene and health at work, the protection of workers and company assets, employee authentication and access management.
– Analysis and Management
Includes activities such as satisfaction questionnaires, management of merger processes, acquisitions and sales of business units and the processing of employee data for reporting and analysis purposes.
– Compliance with Legal Obligations
It includes the processing of personal data strictly necessary for the fulfilment of its legal obligations, such as the disclosure of data following judicial mandates, collaboration with regulators and the defense of the legitimate interests of the Group.
– Protection of Vital Interests
The processing of personal data for the protection of the vital interests of workers.
– Recruitment
Includes recruitment activities such as research and selection, as well as related activities. In this context, data relating to wage processing and human resources management will also be processed.
– Execution of Contracts
It includes activities such as entering contracts with customers and partners, as well as communication with third parties involved in contracts (insurance companies, beneficiaries, intermediaries).
– Development and Improvement of Services
It includes activities necessary for the development and improvement of the services provided by the Group, activity analysis and processing for statistical and scientific purposes.
7) Automated Decisions
To justify and execute the business relationship, the Group generally does not use decision-making procedures solely based on automated processing, as provided in the RGDP. If you have or will use this procedure, data subjects will be informed.
8) Access and Sharing of Personal Data
Within the Group, the employees who need them to comply with the contractual/pre-contractual and legal procedures or obligations, or treatments for which explicit and informed consent exist, have access to the data.
Data may be used in the Group's companies in the context of the provision of shared services between the Group's companies and for the purpose of internal reporting, always preserving the principle of lawfulness of processing.
Suppliers and other subcontracting entities which, under the RGDP, may access the data for these specific purposes but subject to data protection guarantee measures and acting on behalf and on behalf of the Group may also be made available to suppliers and to other subcontractors.
In certain circumstances, certain personal data may need to be communicated to public authorities, such as the Working Conditions Authority, health regulator, courts and security forces.
The transmission of data to other countries (countries outside the European Union) only takes place if the holder of the personal data has granted an express authorisation for this purpose or if this is necessary by legal requirement. Where recourse to third-country service providers is required, they will be obliged to comply with the written instructions in this regard for compliance with the level of data protection applicable in the European Union.
9) Data Retention Time
Personal data are kept for different periods of time, depending on the purpose for which they are intended and considering legal criteria, need and minimization of storage time, or for periods legally defined for investigation and criminal proceedings or medical-legal criteria.
At the end of the retention period, the personal data is destroyed.
10) Rights of Personal Data Holders
The Group guarantees all the rights of data subjects in relation to the processing of their data and at any time. Namely:
- Lawfulness of the treatment and conditions applicable to consent (Art. 6 and Art. 7)
- Right of access of the data subject (art. 15)
- Right of rectification (Art. 16)
- Right to the payment (art. 17)
- Right to limit the processing of data (Art. 18)
- Right of opposition (Art. 21)
- Right of portability (art. 20th)
Furthermore, without prejudice to the possibility of complaining to the Group, the data subject may lodge a complaint directly with the Data Protection Supervisory Authority using the following channels:
- Phone: +351 21 392 84 00
- Web: http://www.cnpd.pt/
- Mail: Comissão Nacional de Proteção de Dados – CNPD Ava D. Carlos I, 134 – 1o 1200-651 Lisboa
At any time, customers, or potential customers of the Group, as data subjects, may withdraw previous data consents and exercise any of the above rights.
The exercise of rights may be requested by:
- Email address: dpd@ideiasdinamicas.com;
- Postal address: Grupo Ideias Dinâmicas
Comissão de Proteção de Dados Pessoais
Rua Álvaro Castelões, 821 – 2o, sala 2.2
4450-043 Matosinhos
Phone: +351 229 398 320
11) Obligation to Provide Personal Data
In the context of the commercial relationship, you will have to submit the personal data necessary to establish and create a business relationship and to comply with the pre-contractual and contractual obligations and procedures derived and those that are legally obliged to collect. Without this data, the Group will, as a general rule, refuse to conclude the contract or, still, will not be able to keep the contract and must resolve it.
12) Security of Personal Data
The Group protects your personal data from destruction, loss, accidental or unlawful alterations and unauthorized disclosure or access. To this end, the Group uses security systems, rules, and other procedures to ensure the protection of personal data, as well as to prevent unauthorized access to data, misuse, disclosure, loss or destruction.
13) Changes to the privacy policy
The Group may change this Privacy Policy at any time and without notice. According to the defined practices, this policy is reviewed at least once a year.
The changes will be properly published (website).
Where a change in the Privacy Policy has a substantial impact on processing carried out based on your consent, the Group will contact the data subjects or make efforts to make this change clear if the individual contact is impractical, to obtain new consent.
14) Cookies
We use cookies to improve your experience on this website. We use Session cookies and Third Party Cookies. Session cookies serve to improve the functionality of the website and third-party cookies allow us social networking and traffic analysis features.
Third-Party Cookies:
- - Facebook;
- - Linkedin;
- - Google Analytics;