Skip to content

Last updated: August 11, 2026 Privacy Policy

This Privacy Policy explains how the personal data of users who visit this website or get in touch through its forms, email, phone, or other means indicated on the site is collected, used, and protected.

This website respects the privacy of its users and seeks to comply with the General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679 — and the applicable legislation in Portugal. The National Data Protection Commission (CNPD) is the national supervisory authority for personal data protection.

1. Data Controller

The data controller for personal data is:

Name: Sérgio Ferraz
Trade name: SF Web Solutions
Email: info@sergioferraz.com
Location: Portugal

2. Personal data collected

This website may collect the following personal data when the user fills out a contact form, sends an email, or gets in touch by other means:

– Name
– Email address
– Phone number, if provided
– Company or business name, if provided
– Information about the desired project or service
– IP address (automatically recorded by server logs)
– Any other information voluntarily sent in the message

Technical data collected automatically:
– Device and browser type
– Pages visited and time spent on page
– Visit source (referring URL)
– Date and time of access

3. Purposes of processing

The collected data is used to:

– Respond to contact or quote requests
– Analyze needs related to website creation or digital services
– Prepare commercial proposals
– Provide contracted services
– Communicate with the client during the project
– Comply with legal, tax, or administrative obligations
– Improve the website’s functioning and security
– Analyze usage statistics (in an anonymized manner)
– Prevent fraud and abuse

4. Legal basis for processing

The processing of personal data may be based on:

Pre-contractual request (Article 6(1)(b) of the GDPR): when the user requests information or a quote
Contract performance (Article 6(1)(b)): when services are provided
Compliance with legal obligations (Article 6(1)(c)): when applicable
Legitimate interest (Article 6(1)(f)): for website security, contact organization, service improvement, and statistical analysis
Consent (Article 6(1)(a)): when necessary, for example for non-essential cookies or commercial communications

5. Data retention

Personal data will be kept only for the period necessary to fulfill the purposes for which it was collected:

Contact/quote data: 2 years after the last contact, unless they become a client
Client data: for the duration of the contract and 10 years thereafter (tax obligations)
Browsing data (analytics): 26 months (Google Analytics)
Server logs: 90 days

After these periods, the data is deleted or anonymized.

6. Sharing and international transfers

Personal data is not sold to third parties. It may be shared with service providers acting on our behalf:

Services used:
Google Analytics (Google LLC, USA): web traffic analysis
– Transfer protected by EU-approved Standard Contractual Clauses
– Data anonymized whenever possible
Complianz (WordPress plugin): cookie consent management
Hosting provider: website data storage
Email services: sending communications

All subcontractors comply with the GDPR or are protected by adequate transfer mechanisms.

7. Cookies and similar technologies

This website uses cookies to:

Essential cookies (do not require consent):
– Basic site functioning
– Session management
– Language preferences
– Security (attack prevention)

Analytical cookies (require consent):
Google Analytics: usage statistics (visits, pages viewed, source)
Google Tag Manager: tag management

How to manage cookies:

– Through the consent banner upon entering the site
– Through the “Manage consent” link in the site footer
– In your browser settings

For more details, please consult the Cookie Policy (link in the footer).

8. Data subject rights

Under the GDPR, the user can exercise the following rights:

Right of access: to know what data is processed and how
Right to rectification: to correct incorrect or incomplete data
Right to erasure (“right to be forgotten”): to request the deletion of data
Right to restriction of processing: to suspend processing in certain situations
Right to object: to object to processing for specific purposes
Right to data portability: to receive data in a structured format
Right to withdraw consent: when processing depends on consent
Right not to be subject to automated decisions: including profiling

9. How to exercise your rights

To exercise any of the above rights:

1. Send an email to: info@sergioferraz.com
2. Subject: “Exercise of GDPR rights”
3. Include: your name, contact email, and which right you wish to exercise
4. Response: you will receive confirmation within a maximum of 30 days

Note: We may request additional documentation to verify your identity (for example, a copy of your ID card with sensitive data redacted).

If you are not satisfied with the response, you can lodge a complaint with the CNPD (National Data Protection Commission):
– Website: www.cnpd.pt
– Email: geral@cnpd.pt

10. Data security

We implement technical and organizational measures to protect personal data:

SSL/TLS encryption on all communications
Restricted data access (only the controller)
Regular website backups
Active security plugins (firewall, attack protection)
Regular updates of WordPress and plugins
Strong authentication in administrative areas

11. Changes to this Policy

This Privacy Policy may be updated periodically. Any changes will be published on this page with the update date. We recommend that you check this page regularly to stay informed.

12. Contact

For any questions related to this Privacy Policy or the processing of personal data:

Email: info@sergioferraz.com
Controller: Sérgio Ferraz
Trade name: SF Web Solutions
Location: Portugal

Your privacy is important to us. Thank you for trusting SF Web Solutions.