Privacy Policy
Last updated:
This is a translation. The Portuguese version is the one that binds, and prevails in case of any discrepancy.
This policy explains what personal data we process when you visit the website, ask us for a proposal, book a meeting or engage our services: why, on what legal basis, for how long, who we share it with and how you can exercise your rights.
We process only the data we need to design architecture with you. We do not sell data, we do not advertise, and we do not use analytics or tracking tools on the website.
In short
- We ask for the data needed to prepare your proposal and, if you accept it, to carry out the project and issue invoices.
- We do not use your data for marketing, nor pass it to anyone else for that purpose.
- Invoices are kept for 10 years, because tax law requires it. Everything else is kept only for as long as it is needed.
- You may ask us for access to, correction of or erasure of your data at any time, by email.
- If you are not satisfied with our response, you may complain to the CNPD, the Portuguese data protection authority.
This summary is a guide to the text, not a substitute for it. If in doubt, the full text applies.
1. Data controller
- Controller
- SÓ ARQUITETOS – ATELIER DE ARQUITETURA, LDA.
- NIPC (company tax number)
- 516 215 850
- Address
- Estrada dos Portões Vermelhos, n.º 20, Sala 12, 9560-350 Lagoa, São Miguel, Açores, Portugal
- Telephone
- +351 912 299 424 (call to a Portuguese mobile network)
We have not appointed a data protection officer, because our activity does not require one (Article 37 GDPR). Any question about your data may be sent to geral@soarquitetos.com.
2. What data we process
| When | What data |
|---|---|
| You request a proposal on the website | Your name, email address and, if you provide it, mobile number; the location and features of the property and the project — type of works, areas, number of floors, rooms, anticipated construction budget, when you would like to start and other preferences; any notes you write; any documents and photographs you upload. |
| You prefer to talk to us before requesting a proposal | Your name, email address and a summary of your answers, which are passed to Calendly's booking page when you click “Book a meeting”, so that the booking is filled in for you. |
| You book a meeting | The data Calendly asks you for: your name, email address, the date and time you choose and anything you write in the booking. |
| You accept a proposal | Name, company (where applicable), tax identification number (NIF), address, postcode, town, country and billing email address; the date and time of acceptance, the version of the proposal you accepted, and the IP address and browser from which you accepted it, which serve as evidence of acceptance. |
| You contact us by email, telephone or WhatsApp | Your contact details and the content of your messages. |
| During the project | The data that applications to the public authorities require: the identity of the applicant and of the owners, the property documents — such as the land registry certificate and the property tax record (caderneta predial) — and any other information the law requires. |
| You visit the website | Technical connection data, such as your IP address, browser type and the pages requested, which are needed to deliver the pages and to protect the website against abuse. |
Without your name and email address we cannot respond to your request, and without billing details the proposal cannot be accepted, because the law requires us to issue an invoice. All other data is optional, but the more we know, the more accurate the proposal can be.
If you give us data about other people — a co-owner, a family member or a company — please make sure you are entitled to do so and make them aware of this policy.
3. What we use the data for
| Purpose | Legal basis (GDPR) |
|---|---|
| Reviewing your request, preparing the proposal and contacting you about it. | Steps taken at your request prior to entering into a contract — Article 6(1)(b) GDPR. |
| Recording acceptance, entering into and performing the contract: developing the project, communicating with you and submitting applications to the competent authorities. | Performance of the contract — Article 6(1)(b); compliance with the legal obligations of planning and building procedures — Article 6(1)(c). |
| Issuing invoices and meeting our accounting and tax obligations. | Legal obligation — Article 6(1)(c). |
| Keeping the version of the accepted proposal, proving what was agreed and defending our rights in the event of a dispute. | Legitimate interests — Article 6(1)(f). |
| Protecting the website against abuse, for example by limiting the number of requests made from the same IP address. | Legitimate interests — Article 6(1)(f). |
| Storing the draft of your request and your chosen language on your device. | Your request — Article 6(1)(b). See the Cookie Policy. |
We do not use your data for marketing. Should we ever wish to send you news, we will ask for your consent first.
We do not take decisions about you based solely on automated processing. The figures in a proposal are calculated from your answers using internal tools, but every proposal is reviewed by one of the studio's architects before it is sent to you.
4. Who we share the data with
Your data is processed by the studio's team and shared only to the extent necessary with:
- Cloudflare, Inc. — website hosting, database, storage of the files you upload and network protection;
- Calendly LLC — meeting bookings, where you choose to use it;
- WhatsApp (Meta) — when you contact us that way, subject also to that service's own policy;
- IT service providers who develop and maintain the website and the studio's internal tools;
- our certified accountant and the invoicing software we use;
- engineers and other technical consultants who prepare the engineering designs for the projects;
- municipal councils, departments of the Autonomous Region of the Azores and other public authorities to which applications must be submitted, and the Autoridade Tributária (the Portuguese Tax Authority);
- courts, authorities and lawyers, where necessary to comply with the law or to defend rights.
Anyone who processes data on our behalf does so only on our instructions, under a duty of confidentiality and under a contract providing the guarantees required by Article 28 GDPR.
5. Transfers outside the European Union
Cloudflare and Calendly are headquartered in the United States and may process data outside the European Economic Area. Those transfers take place under the EU–US Data Privacy Framework and, where it does not apply, under standard contractual clauses approved by the European Commission. You may ask us for further information about these safeguards.
6. How long we keep the data
| Data | Period |
|---|---|
| A request for a proposal that does not lead to a contract, including uploaded files | 12 months after the last contact, so that we can resume the request or answer questions about it. |
| The contract, the accepted proposal and the project file | For the duration of the contract and 10 years after it ends, so that we can answer questions about the project and the works. |
| Invoices and billing details | 10 years, as required by tax law. During that period we cannot erase them, even at your request. |
| Email and WhatsApp messages | For as long as they are needed for the request or project they relate to, and never beyond the periods above. |
| Meeting bookings | 12 months after the meeting. |
| Technical logs of connections to the website | The short period set by the hosting provider, for security purposes. |
| The draft of your request on your device | Until you send the request, start the form again or clear your browser data. |
At the end of the period, the data is erased or anonymised. If a dispute is pending, we keep it until the dispute is resolved.
7. Your rights
Under Articles 15 to 22 GDPR, you may at any time:
- find out what data of yours we process and obtain a copy of it;
- ask us to correct inaccurate or incomplete data;
- ask us to erase your data, except where the law requires us to keep it, as is the case with invoices;
- ask us to restrict processing while a concern you have raised is being looked into;
- receive the data you gave us in a structured, commonly used format, or ask us to send it to another organisation;
- object to processing based on our legitimate interests;
- withdraw any consent you have given us, without affecting what was done before.
To exercise any of these rights, write to geral@soarquitetos.com or to Estrada dos Portões Vermelhos, n.º 20, Sala 12, 9560-350 Lagoa, São Miguel, Açores, Portugal. It is free of charge. We respond within one month, which may be extended by two further months for complex requests, in which case we will let you know. We may ask you to confirm your identity before responding.
If you believe your data is not being processed lawfully, you may lodge a complaint with the Comissão Nacional de Proteção de Dados (the Portuguese data protection authority).
8. How we protect the data
- The website operates only over an encrypted connection (HTTPS), and the studio's internal tools are accessible only to the team, with authentication.
- Proposal links use a long, random code that cannot be guessed. Anyone who has the link can view the proposal: do not publish it or share it with anyone who should not see it.
- The draft of your request for a proposal is stored in the browser of the device you used. On a shared computer, send the request or start the form again before you leave, so as not to leave your data behind.
- We will never ask you for passwords, or to pay into an account other than the one shown on the invoice.
9. Children
The website and the studio's services are intended for people aged 18 or over. We do not knowingly collect data from children.
10. Changes to this policy
We may update this policy; the date at the top of the page shows the version in force. If a change is relevant to existing clients, we will let them know by email. See also the Terms and Conditions.