Privacy Policy

Last updated: February 2026

Introduction

This Privacy Policy describes how Jônata Guimarães, Attorney at Law (hereinafter "Data Controller"), collects, uses, stores and protects the personal data of users of this website and legal services, in compliance with the General Data Protection Regulation (GDPR - EU Regulation 2016/679), Portuguese Law No. 58/2019 of August 8 (which ensures GDPR implementation in Portugal), Law No. 41/2004 (privacy in electronic communications) and the Portuguese Bar Association Statute (Law No. 145/2015).

1. Data Controller

Name
Jônata Guimarães
Profession
Attorney at Law
Professional License
OA No. 64089L (Portuguese Bar Association)
Professional Address
Av. Casal Ribeiro 15, 4.º-B, 1000-090 Lisbon, Portugal
Phone
(+351) 912 899 235

2. Data Processing Map

The following table details all personal data processing activities:

Activity/ChannelPurposeData CollectedLegal Basis (GDPR)RecipientsRetention Period
Contact FormRespond to information requests and initial screeningName, email, phone (optional), messageArt. 6(1)(b) - Pre-contractual steps at data subject's requestManus (hosting), Formspree (form processing)Non-converted inquiries: 6 months; Clients: mandate duration + 5 years
Consultation SchedulingBooking and management of legal consultationsName, email, phone, area of interest, availabilityArt. 6(1)(b) - Contract performance or pre-contractual stepsManus (hosting and database)Unrealized consultations: 3 months; Clients: mandate duration + 5 years
WhatsAppQuick communication and schedulingPhone number, name, exchanged messagesArt. 6(1)(b) - Pre-contractual stepsMeta Platforms Ireland Ltd. (WhatsApp)Non-converted conversations: 6 months; Clients: mandate duration + 5 years
Legal Services ProvisionMandate execution and legal representationIdentification data, case documents, communicationsArt. 6(1)(b) - Contract performanceCourts, registries, public entities (as necessary)Mandate duration + 20 years (deontological obligation)
Billing and AccountingInvoice issuance and tax complianceName, tax ID, billing addressArt. 6(1)(c) - Legal obligationTax Authority, certified accountant10 years (tax obligation)
Free Tools (Calculators)Provide informative estimatesUser-entered data (not permanently stored)Art. 6(1)(a) - Implied consent through useManus (hosting)Browser session only
Newsletter/ContentSend legal articles and updatesEmailArt. 6(1)(a) - ConsentManus (hosting)Until subscription cancellation
Analytics and LogsWebsite usage analysis and securityIP address (anonymized), browser type, pages visited, timestampsArt. 6(1)(f) - Legitimate interest (security and service improvement)Manus Analytics (internal)Security logs: 12 months; Analytics: 26 months

3. International Transfers

Your data may be transferred to countries outside the European Economic Area (EEA) when we use third-party services. In such cases, we ensure adequate safeguards exist:

  • Meta Platforms (WhatsApp): Transfers to the USA under the EU-US Data Privacy Framework
  • Manus: Servers located in the European Union
  • CDN (Cloudflare): Standard Contractual Clauses approved by the European Commission

4. Mandatory Data Provision

Providing personal data is voluntary but necessary for:

Contact form
Without name and email, we cannot respond to your request
Consultation scheduling
Without contact details, we cannot confirm the booking
Service provision
Without identification data and documents, we cannot execute the mandate
Billing
Without tax ID, we cannot issue an invoice (legal obligation)

5. Data Subject Rights

Under the GDPR, you have the following rights:

Access (Art. 15)

Obtain confirmation that your data is processed and access it

Rectification (Art. 16)

Correct inaccurate data or complete incomplete data

Erasure (Art. 17)

Request data deletion, except where legal retention obligations apply

Restriction (Art. 18)

Restrict processing in certain circumstances

Portability (Art. 20)

Receive data in a structured, commonly used format

Objection (Art. 21)

Object to processing based on legitimate interest or direct marketing

Withdraw consent

When processing is based on consent, you may withdraw it at any time

To exercise these rights, send a request by email to [email protected], identifying yourself and specifying the right you wish to exercise. We will respond within 30 days.

6. Security Measures

We implement appropriate technical and organizational measures to protect your data:

Technical Measures

  • SSL/TLS encryption for all communications
  • Secure authentication with JWT tokens
  • HTTP security headers (HSTS, CSP, X-Frame-Options)
  • Rate limiting and protection against automated attacks
  • hCaptcha for human verification in forms
  • Regular encrypted backups

Organizational Measures

  • Professional secrecy (Art. 92 of the Bar Statute)
  • Data access restricted to when necessary
  • Continuous data protection training
  • Security incident response procedures

7. Sub-processors

The following service providers (sub-processors) may access personal data in the course of their technical functions, under contracts ensuring GDPR compliance:

Sub-processorFunctionData AccessedLocationSafeguards
Manus (Butterfly Effect PTE)Web hosting, database and authenticationAll website data (forms, sessions, messages)EU (Singapore — HQ)Standard Contractual Clauses (SCCs)
Cloudflare, Inc.CDN, DDoS protection and DNSIP address, HTTP headersUSA / GlobalEU-US Data Privacy Framework
hCaptcha (Intuition Machines)Anti-bot verification in formsIP address, browser fingerprintUSAStandard Contractual Clauses (SCCs)
Google LLC (Analytics)Web traffic analysis (consent required)IP address (anonymized), browsing dataUSAEU-US Data Privacy Framework
Umami (self-hosted via Manus)Privacy-focused website analytics (consent required)Aggregated browsing data (no personal data)EUNo personal data transfer
Meta Platforms (WhatsApp)Client communication channelPhone number, messagesUSAEU-US Data Privacy Framework

8. Supervisory Authority

Without prejudice to any other remedy, you have the right to lodge a complaint with the competent supervisory authority:

National Data Protection Commission (CNPD)

Morada:
Av. D. Carlos I, 134 - 1.º, 1200-651 Lisbon
Telefone:
(+351) 213 928 400
Website:
www.cnpd.pt

9. Policy Changes

This policy may be updated periodically. Any significant changes will be communicated through the website. We recommend regularly consulting this page.

10. Data Protection Contact

For any questions regarding the processing of your personal data or to exercise your rights, contact:

[email protected]

Subject: Personal Data Protection

Open chat
WhatsApp (initial contact — no document sharing)