This policy describes how Seamless Doubt — Sociedade Unipessoal Limitada ("Seamless Doubt", "we") collects, uses and protects your personal data when you visit seamlessdoubt.com or contact us, in compliance with Regulation (EU) 2016/679 ("GDPR") and Portuguese Law 58/2019.
1. Data controller
Seamless Doubt — Sociedade Unipessoal LimitadaPortuguese VAT 519 387 473
Rua Santo Amaro, 24, Gandra, 4585-089 Gandra, Paredes, Portugal
Contact: privacidade@seamlessdoubt.com
2. Data we collect
- Contact form: name, email address and the content of the message you send us.
- Security documentation requests: name, company, email, role, requested documents and message, submitted through the security section form.
- Technical data: IP address, browser type, operating system and pages visited, logged by our hosting provider for the time strictly required to keep the service running and secure.
- Anti-abuse verification on authentication forms: the sign-in and password-reset pages (
/adminand/portal) run Cloudflare Turnstile, an invisible check that tells humans from bots. Cloudflare receives your IP address, request headers and browser signals and returns only a validity token — we receive no profile of you, and Turnstile is never used for advertising or cross-site tracking. - Security records: when a check fails or a rate limit is hit, we store the event, the endpoint and an irreversible hash of the identifier (email or IP) — never the email or IP in the clear.
- Usage preferences: your light/dark theme choice, stored in a technical cookie on your device.
- Analytics (consent only): anonymised usage statistics, collected only after you accept in the cookie banner.
3. Purposes and legal basis
- Respond to enquiries — pre-contractual measures (Art. 6(1)(b) GDPR).
- Keep the site secure and operational — legitimate interest (Art. 6(1)(f) GDPR).
- Prevent automated access and account abuse (Cloudflare Turnstile on authentication forms, per-account and per-IP rate limits, and the security events they generate) — legitimate interest in protecting client accounts and data against automated attacks (Art. 6(1)(f) GDPR), and a technical measure required by Art. 32 GDPR. It serves no other purpose and produces no automated decision with legal effect on you: a failed check simply asks you to try again.
- Send requested security documentation (security policy, DPA, sub-processor list) — pre-contractual measures (Art. 6(1)(b) GDPR).
- Comply with legal obligations (invoicing, accounting) — Art. 6(1)(c) GDPR.
- Analytics and service improvement — consent (Art. 6(1)(a) GDPR), revocable at any time.
4. Retention periods
We keep your data only for as long as necessary for the purposes for which it was collected, or for the legally required period:
- Contact form messages: up to 24 months after the last interaction, unless they lead to a contractual relationship.
- Contractual and invoicing data: 10 years from the end of the fiscal year concerned (Art. 123 Portuguese Corporate Income Tax Code and Art. 40 VAT Code).
- Correspondence relating to legal obligations or defence of rights in proceedings: until the applicable statute of limitations expires.
- Security documentation requests: up to 24 months, deleted automatically.
- Applications (including spontaneous ones) and CVs: 12 months after the process ends, deleted automatically.
- Server and security technical logs: 30 days.
- Security events (captcha failures, rate-limit hits): 90 days, with hashed identifiers; alerts derived from them, 180 days.
- Rate-limit counters: deleted within the hour after the window closes.
- Technical cookies (sd-theme, sd-consent): 12 months on your device.
- Analytics data with consent: up to 14 months or until you withdraw consent, whichever comes first.
Once these periods elapse, data is securely deleted or irreversibly anonymised.
5. Recipients and processors
Your data may be processed by the following sub-processors. Supabase and Cloudflare provide DPAs with EU Standard Contractual Clauses incorporated (verified). The remaining providers are undergoing documentary verification.
- Supabase — database, authentication and storage (data in Ireland, EU). DPA with SCCs verified.
- Cloudflare — CDN, TLS and bot protection, including Turnstile on the sign-in and password-reset forms (receives IP and browser signals to issue the verification token). DPA with SCCs verified (v6.4, 3 April 2026).
- Lovable — application hosting and runtime. Documentary verification in progress.
- Transactional email provider for replying to enquiries. Documentary verification in progress.
6. International transfers
Where sub-processors operate outside the European Economic Area, we ensure transfers are covered by Standard Contractual Clauses approved by the European Commission or other mechanisms set out in Chapter V GDPR.
7. Your rights
As a data subject, and under Articles 15 to 22 of the GDPR, you have the following rights, which you can exercise free of charge:
- Right of access (Art. 15): obtain confirmation of which of your data we process and receive a copy.
- Right to rectification (Art. 16): correct inaccurate data or complete incomplete data.
- Right to erasure / "right to be forgotten" (Art. 17): request deletion of your data when it is no longer needed, when you withdraw consent, or when you object to processing — unless a legal retention obligation applies.
- Right to restriction of processing (Art. 18): request suspension of processing in specific cases (contested accuracy, pending objection, etc.).
- Right to data portability (Art. 20): receive your data in a structured, commonly used format, or request its direct transmission to another controller, where technically feasible.
- Right to object (Art. 21): object at any time to processing based on our legitimate interest.
- Right to withdraw consent (Art. 7(3)): at any time, without affecting the lawfulness of prior processing. For analytics cookies, simply click "Cookie settings" in the footer and choose "Reject".
- Right not to be subject to automated decisions (Art. 22): we do not carry out processing with legal effects based solely on automated decision-making or profiling.
- Right to lodge a complaint: with the Portuguese Data Protection Authority (CNPD) — Av. D. Carlos I, 134, 1.º, 1200-651 Lisbon, geral@cnpd.pt.
How to exercise your rights
- Send a request to privacidade@seamlessdoubt.com with the subject "GDPR rights request".
- Clearly state which right you wish to exercise and, where applicable, the data or processing concerned.
- To confirm the request comes from the data subject, we may ask for an additional verification element (e.g. reply from the email address used in previous contacts). We will not ask for a copy of your ID document unless strictly necessary and proportionate.
- We respond within a maximum of 1 month from receipt (extendable by 2 further months for complex requests, with prior reasoned notice), under Art. 12(3) GDPR.
- If you believe processing infringes the GDPR, you may at any time lodge a complaint with the CNPD without needing to contact us first.
8. Marketing communications
The contact form includes a checkbox, unticked by default, through which you can authorise Seamless Doubt to send you news, content and information about our services by email. This authorisation is based on your free, specific, informed and unambiguous consent (Art. 6(1)(a) and Art. 7 GDPR; Art. 13-A of Portuguese Law 41/2004).
- What we send: occasional communications about new services, articles and materials relevant to SMBs and business groups. We do not share data with third parties for marketing purposes.
- Typical frequency: no more than one message per month.
- Who processes it: Seamless Doubt — Sociedade Unipessoal Limitada, using a transactional email provider under a GDPR data-processing agreement.
- Consent record retention: we keep a record of your authorisation (timestamp and version of the consent text) for the duration of the relationship and up to 3 years afterwards, as evidence under Art. 7(1) GDPR.
How to withdraw consent
You can withdraw consent at any time, free of charge and as easily as it was given:
- Unsubscribe link in the footer of every marketing email — one click is enough.
- Email to privacidade@seamlessdoubt.com with the subject "Unsubscribe from marketing".
Withdrawal takes effect within a maximum of 10 working days and does not affect the lawfulness of communications sent beforehand. We will still contact you to reply to requests you send us or to fulfil contractual and legal obligations — these service communications do not depend on marketing consent.
9. Recruitment and job applications
When you apply for an open role or send a spontaneous application through this site, we process the data you provide in order to assess your fit for the role.
- Data collected: full name, email, phone (optional), LinkedIn profile (optional), your message, and the CV you attach (PDF, DOC or DOCX) including whatever personal information you choose to put in it, plus the role you applied to.
- Purpose: managing the recruitment process — screening, contact, interviews and decision.
- Legal basis: pre-contractual steps taken at your request (Art. 6(1)(b) GDPR). Keeping your application on file for future openings relies on our legitimate interest (Art. 6(1)(f) GDPR), which you may object to at any time.
- Sensitive data: we do not ask for special categories of data (Art. 9 GDPR) — health, ethnic origin, beliefs, etc. Please do not include them in your CV or message; if sent on your own initiative, they are deleted.
- Retention: 12 months after the recruitment process ends. After that, the application and CV are securely deleted or anonymised. If you are hired, the data becomes part of your employee file, with its own retention periods set by employment law.
- Recipients: only the founders and Seamless Doubt staff involved in the decision. Files are stored with our database and storage provider (Supabase, EU) in a private, access-restricted bucket. We never share applications with third parties or use them for marketing.
- Automated decisions: we do not use automated screening or profiling. Every decision is made by a person.
You can exercise the rights described in section 7 — including access to your file, rectification and immediate deletion of your application — by writing to privacidade@seamlessdoubt.com with the subject "Job application — GDPR".
10. Security
We apply appropriate technical and organisational measures to protect your data, including encryption in transit (HTTPS/TLS), least-privilege access controls, and periodic reviews of our security practices.
11. Shared links
When we share a document, proposal or report through a link, the rule is simple: we only count opens in aggregate. That means one counter per link — no per-recipient token, no IP address stored, no user-agent stored. We cannot, and do not want to, know who opened it, when, or how many times any individual opened it.
If we ever start tying opens to an identified person (for example a unique link per recipient linked to a sales contact), that stops being a technical count and becomes personal data processing with its own purpose. In that case we commit to: creating a dedicated entry in our record of processing activities (ROPA), with a written purpose, a legitimate-interest basis and a documented balancing test; setting its own retention period; and updating this policy before the feature goes live. You will always have the right to object (Art. 21 GDPR) to that processing, without losing access to the shared content: you keep receiving and opening the link.
12. Changes
This policy may be updated. The "Last updated" date at the top reflects the version in force. Material changes will be communicated with appropriate prominence.
Questions? Email geral@seamlessdoubt.com
