Abreportas Free diagnostic

DRAFT · This text must still be reviewed by a lawyer before publication.

Privacy policy

Draft · version of 4 October 2026 (form update)

1. Scope

This policy explains what personal data we process, why, for how long and what rights you have. It applies to visitors to this website, people who contact us, representatives of our customer companies and people whose business contact details appear in the prospecting we carry out.

We work exclusively business to business. We only process data about people in their capacity as professionals representing a company, never in their personal or family life.

2. Who we are and how to contact us

The Abreportas brand is operated by Alvo Desvelado - Unipessoal, Lda., a company incorporated in Portugal with Portuguese tax number (NIF) 518473201 ("Abreportas", "we", "us").

For any privacy question or to exercise your rights: comercial@abreportas.com · +351 932 113 544.

Given the nature and size of our business, we have not appointed a data protection officer (DPO). The contact above is the single point for all privacy requests.

3. Our two roles

We are the controller when we decide what the data is used for: running this website, handling your enquiries, managing our customer relationships and prospecting companies to promote our own services.

We are a processor when we carry out sales prospecting on behalf of a customer company. In that case the customer is the controller: it defines the market, the profile of companies to contact and the messages, and the outreach is made in its name. We act only on its documented instructions under a data processing agreement (Article 28 GDPR). Every message identifies the company on whose behalf it is sent.

If you receive a message sent on behalf of one of our customers and want to exercise your rights, you can contact that company or us. If you contact us, we pass the request to the customer and help it respond; an objection is applied immediately.

4. What data we process and where it comes from

WhoDataSource
Website visitorsTechnical request data: IP address, browser and device type, page requested, date and time.Collected automatically by our hosting provider when serving pages.
People who fill in the diagnostic formName, company, industry, market, mobile, email, consent, visit origin (UTM) and approximate country.You and, for the country, our hosting provider (see section 5).
People who contact usName, company, role, contact details and the content of the conversation (WhatsApp, phone or email).You.
Customers and their representativesName, role, business contact details, billing data, instructions and communications about the service.You or the customer company.
Business contacts in prospectingCompany name and sector, business location, the company's website and public profiles, business email and phone published by the company and, where published, the name and role of the decision-maker. Also the contact history, replies received and, where applicable, a request not to be contacted again.Public sources: the companies' own websites, online maps, industry directories, public registers and public professional profiles. Also: the exclusion list provided by the customer and the person's own replies.

We do not seek or process sensitive data (such as health, political opinions or religion), nor personal contact details such as home addresses or personal email addresses. WhatsApp is only used for mobile numbers that the company itself publishes as a business contact. We never buy contact lists.

5. Diagnostic request form

On our diagnostic request pages (for example, those we share on Instagram) you can leave your details so we can contact you. This form is separate from prospecting: here, you are the one asking us to get in touch.

TopicHow it works
Data collectedName, company, industry, target market, mobile number and email; a record of your consent (answer, wording accepted, date and time); where the visit came from (UTM parameters and ad click identifier in the link, the form page and the referring page); and your approximate country, derived from your IP address by our hosting provider. We do not store your IP address with the request.
PurposesAnswering your request, booking the diagnostic and, where relevant, preparing and sending a service proposal. Visit origin and country also tell us, as internal statistics, which channels and campaigns generate requests.
Legal basisSteps taken at your request before a contract (Article 6(1)(b) GDPR) and your consent (Article 6(1)(a)), given by ticking the box on the form, which you can withdraw at any time without affecting processing already carried out. Measuring where requests come from is based on our legitimate interest (Article 6(1)(f)).
Required fieldsAll fields are needed for us to reply. If you would rather not fill them in, you can contact us by WhatsApp or phone.
What we don't doWe do not add anyone to newsletters or prospecting lists, and we send no automated messages: a person replies.
RetentionIf the request does not lead to a contract, up to 24 months after the last contact. If you become a customer, the customer data periods apply (section 12). The consent record is kept for the same period, as evidence. If you withdraw consent or ask for erasure, we delete the data, except the minimum needed to show we honoured your request.
ProcessorsWebsite hosting and serverless functions (they receive and validate the form and derive the country); the automation tool or CRM the request is sent to (webhook) and stored in; and a transactional email service that sends us an internal alert for each new request. If any of these providers processes data outside the EEA, the safeguards in section 11 apply.

6. Purposes and legal bases

PurposeLegal basis (Article 6(1) GDPR)
Running the website and protecting it from abuse and attacksLegitimate interest (point f)
Answering your enquiries and preparing the diagnostic or a proposalSteps taken at your request before a contract (point b) and legitimate interest (point f)
Handling requests made through the diagnostic formPre-contractual steps (point b) and consent (point a); request origin: legitimate interest (point f). See section 5
Providing the service to customers and managing the contractPerformance of a contract (point b)
Invoicing, accounting and other legal obligationsLegal obligation (point c)
Promoting our services to other companies (our own prospecting)Legitimate interest (point f), see section 7
Prospecting on behalf of customersDetermined by the customer as controller; as a rule, its legitimate interest (point f). We only process the data on its instructions.
Recording objections so you are not contacted againLegal obligation (point c) and legitimate interest (point f)
Defending legal claimsLegitimate interest (point f)

We do not use one customer's data to serve another customer, or for any purpose of our own other than those described here.

7. Legitimate interest in B2B prospecting

Business-to-business prospecting relies on legitimate interest, which requires balancing that interest against the rights of the person contacted. Before each campaign we carry out (or, for campaigns on behalf of customers, help the customer carry out) a written assessment. The factors that keep it balanced are:

You can request a summary of this assessment at comercial@abreportas.com. For electronic communications we also follow national rules on unsolicited commercial communications.

8. How to stop being contacted

You can object at any time, without giving a reason, to being contacted for sales purposes. Simply reply saying you do not want to be contacted (on any channel), or write to comercial@abreportas.com.

The sequence stops immediately on every channel. We keep only the minimum needed (for example, the email or phone number and the date of the request) on a suppression list, to make sure you are not contacted again by the same campaign or by future campaigns for the same customer.

9. Artificial intelligence and automated decisions

We use artificial intelligence tools to research and organise public information about companies, suggest which companies to contact and draft personalised messages. A person approves the message templates before anything is sent, and replies and negotiations are always reviewed and approved by a person.

We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR). The AI providers we use act as our processors and are not permitted to use the data to train their own models.

10. Who we share data with

We share data only as far as necessary and we never sell it. Recipients are:

11. Transfers outside the EEA

We prefer providers that store data in the European Economic Area. If a provider processes data outside the EEA, the transfer only takes place with appropriate safeguards: a European Commission adequacy decision (for example, the EU-US Data Privacy Framework, for certified companies) or Commission-approved standard contractual clauses, together with an assessment of the level of protection in the destination country. You can ask about the safeguards that apply at comercial@abreportas.com.

12. How long we keep data

DataPeriod
Website technical logsA short period set by the hosting provider, as a rule no longer than 30 days
Diagnostic form requests (including the consent record)Up to 24 months after the last contact, if they do not lead to a contract
Enquiries that do not lead to a contractUp to 24 months after the last contact
Customer dataFor the duration of the contract and then for the applicable limitation period; invoicing and accounting records: 10 years
Our own prospectingUp to 12 months after a sequence ends with no reply; if there is a conversation, up to 24 months after the last contact
Prospecting on behalf of customersFor the duration of the customer contract; at the end, the data is handed over to the customer and deleted from our systems within 30 days, unless the customer instructs otherwise
Suppression list (objections)For as long as needed to make sure you are not contacted again, with minimal data only
Rights requests3 years after our reply, as evidence; identity documents deleted right after verification

We delete or correct data sooner if we learn it is wrong, if the purpose no longer applies or if you ask us to erase it.

13. Security

We apply technical and organisational measures appropriate to the risk, including: access limited to those who need it, strong authentication on work accounts, encrypted communications, data minimisation, logging of sends and daily outreach limits. No system is completely immune; if a personal data breach occurs, we notify the supervisory authority within 72 hours where the law requires, inform affected people if there is a high risk and, as a processor, alert the customer without delay.

14. Your rights

Under the GDPR you have the right to:

To exercise any right, write to comercial@abreportas.com. It is free. We reply within one month, extendable by two further months for complex requests (we will let you know). We may ask for information to confirm your identity, solely to avoid disclosing data to someone not entitled to it.

15. Cookies

This website does not use cookies, third-party analytics, advertising or tracking pixels, and fonts are served from the site itself with no third-party requests. On the diagnostic request pages, the campaign parameters (UTM) from the link you clicked are stored temporarily in your browser's session storage (sessionStorage) so they can travel with the form; they do not identify you, are not shared with third parties and are deleted when you close the tab. That is why we do not ask for cookie consent. The WhatsApp and phone buttons take you to third-party services with their own rules. If we ever use non-essential cookies, we will ask for your consent first.

16. Children

Our services are for businesses and professionals. We do not intend to process children's data; if you believe this has happened, contact us and we will delete it.

17. Complaints

If you believe your rights have not been respected, you can complain to the Portuguese data protection authority, CNPD (www.cnpd.pt), to the Spanish authority, AEPD (www.aepd.es), or to the authority in the country where you live or work. We would appreciate the chance to resolve the matter first.

18. Changes to this policy

We may update this policy when our practices or the law change. The current version is always on this page, with its date. If a change is significant, we will give customers reasonable advance notice.

← Back to home