DRAFT · This text must still be reviewed by a lawyer before publication.
Privacy policy
Draft · version of 4 October 2026 (form update)
1. Scope
This policy explains what personal data we process, why, for how long and what rights you have. It applies to visitors to this website, people who contact us, representatives of our customer companies and people whose business contact details appear in the prospecting we carry out.
We work exclusively business to business. We only process data about people in their capacity as professionals representing a company, never in their personal or family life.
2. Who we are and how to contact us
The Abreportas brand is operated by Alvo Desvelado - Unipessoal, Lda., a company incorporated in Portugal with Portuguese tax number (NIF) 518473201 ("Abreportas", "we", "us").
For any privacy question or to exercise your rights: comercial@abreportas.com · +351 932 113 544.
Given the nature and size of our business, we have not appointed a data protection officer (DPO). The contact above is the single point for all privacy requests.
3. Our two roles
We are the controller when we decide what the data is used for: running this website, handling your enquiries, managing our customer relationships and prospecting companies to promote our own services.
We are a processor when we carry out sales prospecting on behalf of a customer company. In that case the customer is the controller: it defines the market, the profile of companies to contact and the messages, and the outreach is made in its name. We act only on its documented instructions under a data processing agreement (Article 28 GDPR). Every message identifies the company on whose behalf it is sent.
If you receive a message sent on behalf of one of our customers and want to exercise your rights, you can contact that company or us. If you contact us, we pass the request to the customer and help it respond; an objection is applied immediately.
4. What data we process and where it comes from
| Who | Data | Source |
|---|---|---|
| Website visitors | Technical request data: IP address, browser and device type, page requested, date and time. | Collected automatically by our hosting provider when serving pages. |
| People who fill in the diagnostic form | Name, company, industry, market, mobile, email, consent, visit origin (UTM) and approximate country. | You and, for the country, our hosting provider (see section 5). |
| People who contact us | Name, company, role, contact details and the content of the conversation (WhatsApp, phone or email). | You. |
| Customers and their representatives | Name, role, business contact details, billing data, instructions and communications about the service. | You or the customer company. |
| Business contacts in prospecting | Company name and sector, business location, the company's website and public profiles, business email and phone published by the company and, where published, the name and role of the decision-maker. Also the contact history, replies received and, where applicable, a request not to be contacted again. | Public sources: the companies' own websites, online maps, industry directories, public registers and public professional profiles. Also: the exclusion list provided by the customer and the person's own replies. |
We do not seek or process sensitive data (such as health, political opinions or religion), nor personal contact details such as home addresses or personal email addresses. WhatsApp is only used for mobile numbers that the company itself publishes as a business contact. We never buy contact lists.
5. Diagnostic request form
On our diagnostic request pages (for example, those we share on Instagram) you can leave your details so we can contact you. This form is separate from prospecting: here, you are the one asking us to get in touch.
| Topic | How it works |
|---|---|
| Data collected | Name, company, industry, target market, mobile number and email; a record of your consent (answer, wording accepted, date and time); where the visit came from (UTM parameters and ad click identifier in the link, the form page and the referring page); and your approximate country, derived from your IP address by our hosting provider. We do not store your IP address with the request. |
| Purposes | Answering your request, booking the diagnostic and, where relevant, preparing and sending a service proposal. Visit origin and country also tell us, as internal statistics, which channels and campaigns generate requests. |
| Legal basis | Steps taken at your request before a contract (Article 6(1)(b) GDPR) and your consent (Article 6(1)(a)), given by ticking the box on the form, which you can withdraw at any time without affecting processing already carried out. Measuring where requests come from is based on our legitimate interest (Article 6(1)(f)). |
| Required fields | All fields are needed for us to reply. If you would rather not fill them in, you can contact us by WhatsApp or phone. |
| What we don't do | We do not add anyone to newsletters or prospecting lists, and we send no automated messages: a person replies. |
| Retention | If the request does not lead to a contract, up to 24 months after the last contact. If you become a customer, the customer data periods apply (section 12). The consent record is kept for the same period, as evidence. If you withdraw consent or ask for erasure, we delete the data, except the minimum needed to show we honoured your request. |
| Processors | Website hosting and serverless functions (they receive and validate the form and derive the country); the automation tool or CRM the request is sent to (webhook) and stored in; and a transactional email service that sends us an internal alert for each new request. If any of these providers processes data outside the EEA, the safeguards in section 11 apply. |
6. Purposes and legal bases
| Purpose | Legal basis (Article 6(1) GDPR) |
|---|---|
| Running the website and protecting it from abuse and attacks | Legitimate interest (point f) |
| Answering your enquiries and preparing the diagnostic or a proposal | Steps taken at your request before a contract (point b) and legitimate interest (point f) |
| Handling requests made through the diagnostic form | Pre-contractual steps (point b) and consent (point a); request origin: legitimate interest (point f). See section 5 |
| Providing the service to customers and managing the contract | Performance of a contract (point b) |
| Invoicing, accounting and other legal obligations | Legal obligation (point c) |
| Promoting our services to other companies (our own prospecting) | Legitimate interest (point f), see section 7 |
| Prospecting on behalf of customers | Determined by the customer as controller; as a rule, its legitimate interest (point f). We only process the data on its instructions. |
| Recording objections so you are not contacted again | Legal obligation (point c) and legitimate interest (point f) |
| Defending legal claims | Legitimate interest (point f) |
We do not use one customer's data to serve another customer, or for any purpose of our own other than those described here.
7. Legitimate interest in B2B prospecting
Business-to-business prospecting relies on legitimate interest, which requires balancing that interest against the rights of the person contacted. Before each campaign we carry out (or, for campaigns on behalf of customers, help the customer carry out) a written assessment. The factors that keep it balanced are:
- outreach is aimed at companies and at people in their professional role, on topics related to their business;
- we only use data the companies have made public in order to be contacted;
- volumes are low, messages are personalised and the sequence stops as soon as there is a reply;
- every message identifies the sender and explains how to stop receiving messages;
- objecting is simple, free and honoured across all channels.
You can request a summary of this assessment at comercial@abreportas.com. For electronic communications we also follow national rules on unsolicited commercial communications.
8. How to stop being contacted
You can object at any time, without giving a reason, to being contacted for sales purposes. Simply reply saying you do not want to be contacted (on any channel), or write to comercial@abreportas.com.
The sequence stops immediately on every channel. We keep only the minimum needed (for example, the email or phone number and the date of the request) on a suppression list, to make sure you are not contacted again by the same campaign or by future campaigns for the same customer.
9. Artificial intelligence and automated decisions
We use artificial intelligence tools to research and organise public information about companies, suggest which companies to contact and draft personalised messages. A person approves the message templates before anything is sent, and replies and negotiations are always reviewed and approved by a person.
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR). The AI providers we use act as our processors and are not permitted to use the data to train their own models.
10. Who we share data with
We share data only as far as necessary and we never sell it. Recipients are:
- Service providers (processors): hosting and IT infrastructure (including serverless functions), email and messaging (including transactional email), automation tools (webhooks), work and CRM tools, artificial intelligence services and accounting. All are contractually bound to process data only on our instructions, with confidentiality and appropriate security. An up-to-date list is available on request.
- Our customers: data from prospecting carried out for a customer belongs to that customer and stays with it, including when the service ends.
- Third-party communication services: when you contact us via WhatsApp, or are contacted through it, the service is provided by its operator under its own privacy policy.
- Authorities, courts and professional advisers (legal, tax), where required by law or to defend our rights.
- Potential buyers or investors, in the event of a restructuring, merger or sale of the business, subject to confidentiality.
11. Transfers outside the EEA
We prefer providers that store data in the European Economic Area. If a provider processes data outside the EEA, the transfer only takes place with appropriate safeguards: a European Commission adequacy decision (for example, the EU-US Data Privacy Framework, for certified companies) or Commission-approved standard contractual clauses, together with an assessment of the level of protection in the destination country. You can ask about the safeguards that apply at comercial@abreportas.com.
12. How long we keep data
| Data | Period |
|---|---|
| Website technical logs | A short period set by the hosting provider, as a rule no longer than 30 days |
| Diagnostic form requests (including the consent record) | Up to 24 months after the last contact, if they do not lead to a contract |
| Enquiries that do not lead to a contract | Up to 24 months after the last contact |
| Customer data | For the duration of the contract and then for the applicable limitation period; invoicing and accounting records: 10 years |
| Our own prospecting | Up to 12 months after a sequence ends with no reply; if there is a conversation, up to 24 months after the last contact |
| Prospecting on behalf of customers | For the duration of the customer contract; at the end, the data is handed over to the customer and deleted from our systems within 30 days, unless the customer instructs otherwise |
| Suppression list (objections) | For as long as needed to make sure you are not contacted again, with minimal data only |
| Rights requests | 3 years after our reply, as evidence; identity documents deleted right after verification |
We delete or correct data sooner if we learn it is wrong, if the purpose no longer applies or if you ask us to erase it.
13. Security
We apply technical and organisational measures appropriate to the risk, including: access limited to those who need it, strong authentication on work accounts, encrypted communications, data minimisation, logging of sends and daily outreach limits. No system is completely immune; if a personal data breach occurs, we notify the supervisory authority within 72 hours where the law requires, inform affected people if there is a high risk and, as a processor, alert the customer without delay.
14. Your rights
Under the GDPR you have the right to:
- Access: know whether we process your data and get a copy;
- Rectification: correct inaccurate or incomplete data;
- Erasure: ask for your data to be deleted, where the legal conditions are met;
- Restriction: ask us to pause processing, for example while we check a correction;
- Portability: receive the data you gave us in a structured, commonly used format, where processing is based on consent or contract;
- Object: object to processing based on legitimate interest and, unconditionally, to direct marketing;
- Withdraw consent, where processing is based on it, without affecting what was done before;
- Not be subject to decisions based solely on automated processing with significant effects.
To exercise any right, write to comercial@abreportas.com. It is free. We reply within one month, extendable by two further months for complex requests (we will let you know). We may ask for information to confirm your identity, solely to avoid disclosing data to someone not entitled to it.
15. Cookies
This website does not use cookies, third-party analytics, advertising or tracking pixels, and fonts are served from the site itself with no third-party requests. On the diagnostic request pages, the campaign parameters (UTM) from the link you clicked are stored temporarily in your browser's session storage (sessionStorage) so they can travel with the form; they do not identify you, are not shared with third parties and are deleted when you close the tab. That is why we do not ask for cookie consent. The WhatsApp and phone buttons take you to third-party services with their own rules. If we ever use non-essential cookies, we will ask for your consent first.
16. Children
Our services are for businesses and professionals. We do not intend to process children's data; if you believe this has happened, contact us and we will delete it.
17. Complaints
If you believe your rights have not been respected, you can complain to the Portuguese data protection authority, CNPD (www.cnpd.pt), to the Spanish authority, AEPD (www.aepd.es), or to the authority in the country where you live or work. We would appreciate the chance to resolve the matter first.
18. Changes to this policy
We may update this policy when our practices or the law change. The current version is always on this page, with its date. If a change is significant, we will give customers reasonable advance notice.