Legal
Privacy policy
How we handle the data submitted through this site.
1. Who is responsible. Personal data collected on this site is processed by Rabbit Would Do, Lda, NIPC 519 465 822, registered office at Campo Grande, 12, 1.º, Escritório 2, 1700-092 Lisboa, Portugal, which operates under the Quiron brand. For any question about this policy or about your data, the address is hello@quironlabs.pt.
2. Data protection officer. No data protection officer has been appointed, and none is required here: the activity does not involve regular and systematic monitoring of data subjects on a large scale, nor large-scale processing of special categories of data, which are the tests set out in article 37 of the GDPR. Requests are handled directly by the controller, at the address above.
3. What is collected. The site has a single point of data entry, which is the contact form. It asks for your name, your company, your email address, the subject (chosen from a list of four options) and your message. Every field is required and nothing else is asked for. The remaining pages are static and collect nothing.
4. IP address. When the form is submitted, the IP address the request comes from is used to limit how often submissions are accepted, currently three in any ten minutes. The address is held in memory by the process handling the request, is not written to a file or a database, is not linked to the content of the message, and disappears when that process ends. An IP address is personal data, so it is declared here even though the use is momentary.
5. Hosting logs. The site is hosted by Vercel. The hosting infrastructure keeps its own technical logs, which may include IP addresses, in order to run and protect the service. Those logs are created and retained by the provider under the provider rules, not by Quiron.
6. What the form data is used for, and on what basis. The data sent through the form is used to answer your request and, where relevant, to prepare a proposal. The legal basis is article 6(1)(b) of the GDPR: steps taken at the request of the data subject prior to entering into a contract. It is not used for marketing messages, is not passed to third parties for commercial purposes, and is not combined with other sources.
7. The authorisation box on the form. The form includes a box that has to be ticked before sending. It makes explicit that the submission is deliberate and that this policy was available beforehand. The legal basis remains the one in point 6, because the request for a reply comes from the person writing, and it does not cease to exist if the box is later unticked. What you can always do is ask for the data you sent to be erased, as described in point 16.
8. Measures against abuse of the form. In addition to the rate limit described in point 4, the form has a hidden field that only an automated program fills in, and a check on the time elapsed between the page opening and the submission. Neither collects additional data about the person writing. The legal basis is article 6(1)(f) of the GDPR, in the legitimate interest of keeping the contact channel usable and free of automated submissions.
9. Who receives the data. The message is delivered by email through Resend, which handles the sending, and arrives in the controller mailbox, hosted at [[CONFIRMAR: fornecedor da caixa de correio]]. The address you give on the form is set as the reply address on the message, so that the reply goes straight back to you. There are no other recipients, and no data is sold or shared for advertising. The content of messages is never written to the application technical logs.
10. Transfers outside the European Union. Resend and Vercel are companies headquartered in the United States, so data may be accessed from there. These transfers rest on the EU-US Data Privacy Framework, where the provider is certified, or on standard contractual clauses approved by the European Commission under article 46 of the GDPR. As at the date of this version, the certification status of each provider is unconfirmed: [[CONFIRMAR: certificação da Resend]] and [[CONFIRMAR: certificação da Vercel]].
11. How long the data is kept. The message and the data with it stay in the mailbox while the enquiry is being handled and, after that, for as long as the record remains useful to the relationship in question. The period applied is [[CONFIRMAR: prazo de conservação, proposta de 24 meses após o último contacto]]. If the enquiry leads to a contract, statutory accounting and tax retention periods apply instead, currently [[CONFIRMAR: prazo fiscal, indicação corrente de 10 anos]]. The data used for the rate limit does not survive the ten-minute window or the process that held it. Hosting logs follow the provider periods.
12. Cookies. This site uses no cookies and therefore has no cookie banner and asks for no consent to set them. The only information stored in your browser is your preference between light and dark mode, saved locally when you press the toggle yourself. That preference is sent nowhere, identifies nobody, and is not read by the server. It falls within the exemption for storage strictly necessary to provide a service the user has expressly requested, set out in article 5(3) of Directive 2002/58/EC and transposed in Portugal by Lei n.º 41/2004. You can remove it by clearing site data in your browser.
13. Usage statistics. In this version the site carries no audience measurement tool of any kind. If one is installed, this policy will be updated before measurement begins.
14. Automated decisions and profiling. No automated decisions with legal or similarly significant effects are taken, and no profiling is carried out. Messages are read and answered by a person.
15. Minors. This site addresses companies and professionals, not minors. No data relating to minors is knowingly collected. If we become aware that a message was sent by a minor, the data is deleted.
16. Your rights. You may request access to the data concerning you, its rectification, its erasure, restriction of processing and portability, and you may object to processing based on legitimate interest. Where processing rests on your consent, you may withdraw it at any time, without affecting what was done before. Requests are made by email to hello@quironlabs.pt and are answered within one month, extendable by a further two months where the request is complex, in which case you will be told within the first month. Additional information may be requested in order to confirm the identity of the person asking.
17. Complaints. If you consider that the processing of your data breaches the law, you may complain to the Comissão Nacional de Proteção de Dados, the Portuguese data protection authority: Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, geral@cnpd.pt, www.cnpd.pt. A complaint to the CNPD does not depend on contacting us first, but we would welcome the chance to settle the matter directly.
18. Changes to this policy. This policy may change when the site changes or when the way data is handled changes. The version in force is always the one published on this page, with the date shown beside it. Changes affecting what has already been submitted are notified by email to anyone with an open enquiry.
- Legal name
- Rabbit Would Do, Lda
- NIPC
- 519 465 822
- Address
- Campo Grande, 12, 1.º, Escritório 2, 1700-092 Lisboa
- Share capital
- 1.000,00 €
- hello@quironlabs.pt