Let's talk
Back to Casa Ideal®

Casa Ideal® · DATA PROTECTION

Privacy Policy

Updated on 17 January 2021

Contents
  1. Introduction
  2. Data Protection Principles
  3. Lawfulness and Fairness of Processing
  4. Processing Only for Specific Purposes
  5. Adequate, Relevant and Limited Processing
  6. Accuracy of Personal Data
  7. Retention of Personal Data
  8. Data Subject Rights
  9. Security of Retained Data
  10. Disclosure of Data
  11. International Transfers of Personal Data
  12. Log Information, Cookies and Web Beacons
  13. Information about Professionals

Introduction

This Privacy Policy was developed to support Green Proposal, Lda. (hereinafter Casa Ideal®), tax number 513 565 892, in adapting its activities to the General Data Protection Regulation, approved by Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (“GDPR”).

This policy is complemented by other security policies relevant to the company's business. Together they describe Casa Ideal®'s approach to information security and privacy.

This policy applies to all Casa Ideal® Professionals and Partners and, where identified, to third parties accessing company assets.

The terms ‘Privacy’, ‘Data Privacy’ and ‘Data Protection’ may be used interchangeably, as they relate to a complex set of legal requirements applicable to Personal Data that extend beyond data security and confidentiality. For example, they include requirements concerning transparency in data use and retention.

Compliance with this policy is mandatory. All Professionals and Partners therefore have individual responsibility for ensuring compliance and, where necessary, must seek clarification from their respective team leaders.

Casa Ideal® is responsible for defining appropriate mechanisms to achieve compliance with this policy. Teams are responsible for operational implementation, with support from the Privacy Officer.

Compliance with this policy may be monitored through inspections, audits and/or requests for written confirmation of compliance. All areas are responsible for regularly assessing compliance within their area of responsibility.

Accordingly, any employee who breaches this policy is subject to disciplinary action.

This policy is based on the principles established in the GDPR. However, national differences apply to Casa Ideal®'s data protection and privacy obligations when processing personal data outside the EU, receiving personal data from outside the EU or processing personal data of non-EU citizens.

If in doubt, contact the Privacy Officer (info@casa-ideal.pt).

Data Protection Principles

In the course of our activities, we process Personal Data received through business opportunities, client engagements, marketing activities and a range of other related and supporting activities.

Data may be received directly from a Data Subject (for example, in person, by post, email, telephone or from other sources), including from our clients, partners, processors, joint controllers, support service providers and credit reference agencies.

All professionals and partners must only request Personal Data from a Data Subject that is relevant and necessary for a specific business purpose and task.

Casa Ideal® undertakes to comply with the personal data protection principles defined by the GDPR, namely:

  • Lawfulness, fairness and transparency: we must have a legitimate reason for processing Personal Data, such as the Data Subject's consent or compliance with a legal obligation. We must also clearly inform the Data Subject about the processing;
  • Purpose limitation: we must only request Personal Data for specified, explicit and legitimate purposes and must not process it beyond the purpose for which it was requested;
  • Data minimisation: Personal Data processed must be adequate, relevant and limited to what is necessary;
  • Accuracy: we must ensure that Personal Data is accurate and update it whenever necessary;
  • Storage limitation: we must not retain Personal Data longer than necessary for the purposes for which it is processed, although some data may be retained for historical and statistical purposes;
  • Integrity and confidentiality: appropriate security controls must protect data against unauthorised and unlawful processing, loss, destruction or damage, including technical and organisational measures such as defined processes, training and awareness;
  • Lawful transfers outside the European Economic Area: we only transfer Personal Data outside the EEA where appropriate safeguards exist, such as a contractual basis;
  • Data Subject rights: Data Subjects have various rights that we must respect, including access to a copy of the data we hold and withdrawal of consent for direct marketing.

Lawfulness and Fairness of Processing

Whenever Personal Data is collected, a legal basis for processing is required. Under the GDPR, we must identify at least one of the following grounds:

  • Consent: the Data Subject has consented to processing for one or more specific purposes;
  • Contract: processing is necessary to perform a contract to which the Data Subject is a party or to take pre-contractual steps;
  • Legal obligation: processing is necessary to comply with a legal obligation to which the Controller is subject;
  • Vital interests: processing is necessary to protect the Data Subject's vital interests;
  • Public interest: processing is necessary to perform a task carried out in the public interest;
  • Legitimate interests: processing is necessary for the Controller's legitimate interests, except where overridden by the Data Subject's interests or fundamental rights and freedoms.

When acting as Controller, we must ensure that we have a legitimate basis to collect and process Personal Data.

In some situations, we may act as Processor on behalf of our client. The client is then responsible for ensuring an appropriate ground for processing Personal Data and sharing it with us. However, we must ensure that our contract clearly sets out our responsibilities and that, when collecting Personal Data directly from Data Subjects on the client's behalf, we have a basis to do so lawfully.

Additional conditions must be met when processing Special Categories of Data. Please contact the Privacy Officer for further guidance.

The GDPR requires Data Subjects to receive information about processing to ensure fairness and transparency. Whenever we collect Personal Data, we must appropriately explain why we need the information and how it will be processed. When information is collected through our website, this information is provided in a ‘Privacy Notice’.

Any other information to be provided when collecting personal data must also be available online. Please consult the ‘Privacy Policy’ and ‘Cookies Policy’ for further information.

Processing Only for Specific Purposes

Whenever we collect and process Personal Data, we must ensure that it is used only for the specific purposes communicated to the Data Subject.

Casa Ideal® must never process Personal Data for additional purposes that have not been communicated to the Data Subject. We must be clear about the purpose of processing and understand the purposes for which our clients may have collected Personal Data, or contact the Privacy Officer.

Adequate, Relevant and Limited Processing

When collecting and processing Personal Data, we must follow the principle of data minimisation. This means collecting only the minimum Personal Data necessary to carry out a specific task.

We must also ensure that we have an adequate amount of Personal Data to perform a specific task properly, for example collecting only the data needed to identify a person.

This also applies to sharing and other processing activities. It is important to minimise the data held and processed. When sharing data internally or externally, or using it for activities such as testing, only the minimum amount must be used or shared in each case.

Accuracy of Personal Data

We must ensure that Personal Data is accurate and up to date. Appropriate processes must maintain accuracy whenever necessary, for example for professionals or current and prospective clients whose data is held by the relevant areas.

When acting as Controller in relation to a client, we will not be required to implement mechanisms to keep that data up to date; this is the responsibility of the Controller, namely our client.

Retention of Personal Data

Personal Data must not be kept longer than necessary. We must define and apply maximum retention periods for the Personal Data we process and implement processes to delete it when those periods expire. The following retention periods may therefore apply:

(i) as long as necessary for the relevant activity or services;

(ii) any retention period required by law;

(iii) until the end of the period during which disputes or investigations may arise in relation to the services; or

(iv) for the minimum period specified in the contract.

Data Subject Rights

The GDPR requires us to inform people about the Personal Data we collect and the purposes and means of processing. This information is provided in a ‘Privacy Notice’.

a) Right of access

  • The Data Subject has the right to request access to the Personal Data we hold about them, the purpose of processing and the categories of data concerned.
  • We must notify the Data Subject of recipients with whom we will share their data, particularly if a recipient is in another country or is an international organisation.
  • Wherever possible, we will define the retention period needed to meet business objectives.
  • We must inform the Data Subject of their right to object to processing and their rights to rectification and erasure.
  • We must inform the Data Subject of their right to complain to a supervisory authority.
  • When data is collected from someone other than the Data Subject, we must inform the Data Subject of its source.
  • We must have processes to identify and respond to Data Subject access requests without undue delay and within a maximum of one month.

b) Right to rectification

  • Data Subjects have the right to have inaccurate data corrected. Casa Ideal® must make every effort to do so immediately.

c) Right to erasure

  • The Data Subject has the right to obtain erasure of their data from the Controller (‘right to be forgotten’). Casa Ideal® must make every effort to delete held data immediately, except where retention is legally required. If you receive a Data Subject request, contact the Privacy Officer before deleting any data.

d) Children's rights

  • All individuals, including children, are protected by the GDPR. For children under 13, we must not process Personal Data based on their consent unless authorised by the holders of parental responsibility.

e) Marketing

  • We may sometimes send marketing material to clients and partners to inform them about services, upcoming events or other activities of interest. We must indicate their right to withdraw consent at any time if they no longer wish to be contacted in this way.
  • We must also have processes ensuring that all participation preferences are recorded and respected.

Security of Retained Data

Casa Ideal® will maintain data security by protecting the confidentiality, integrity and availability of Personal Data:

  • Confidentiality means that only authorised people can access data;
  • Integrity means that Personal Data must be accurate and appropriate for the purposes of processing;
  • Availability means that authorised users must be able to access data when needed for authorised purposes.

Disclosure of Data

All professionals and partners must avoid inappropriate disclosure of Personal Data and comply with our general confidentiality obligations.

It is permitted to:

a) Disclose Personal Data to third parties only under instructions or where we have a legitimate basis to do so and no restrictions apply.

b) Disclose Personal Data to third parties if we sell or buy any business or assets, or act as joint Controller as part of a joint venture.

c) Share Personal Data with a third party processing it on our behalf, which may include transfer to a third country.

Personal Data may generally be disclosed:

a) To Professionals or agents so that they can perform their duties.

b) Where non-disclosure could prejudice the prevention or detection of crime, prosecution of offenders, or assessment or collection of any tax or duty. Casa Ideal® must have appropriate grounds for disclosure in this category to avoid criminal proceedings. All disclosures must be justified and documented.

For legal purposes, data may be disclosed:

a) If required by law, statute or court order.

b) For the purpose of obtaining legal advice;

c) In connection with or for the purposes of legal proceedings, or where necessary to defend a legal right.

d) To safeguard national security.

International Transfers of Personal Data

Casa Ideal® may transfer Personal Data to a third country or international organisation. Personal Data we hold may also be processed by staff operating in a third country or for one of our suppliers.

We must ensure that at least one of the following conditions applies:

a) The country receiving Personal Data ensures an adequate level of protection for Data Subjects' rights and freedoms, as decided by the European Commission.

b) Appropriate safeguards are provided, for example standard data protection clauses.

c) The Data Subject has explicitly consented to the transfer after being informed of the possible risks.

d) The transfer is necessary for a reason established in the GDPR, including performance of a contract between Casa Ideal® and the Data Subject, or protection of the Data Subject's vital interests.

e) The transfer is legally required for important public interest reasons or to establish or defend legal claims.

Log Information, Cookies and Web Beacons

Casa Ideal®'s website uses cookies to distinguish users. Casa Ideal® collects standard internet log information, including users' IP addresses, browser type and language, access times and referring website addresses.

To ensure that our website is well managed and to facilitate navigation, Casa Ideal® or its service providers may also use cookies (small text files stored in the user's browser) or web beacons (electronic images allowing our website to count visitors accessing a website and certain cookies) to collect aggregate data.

Information about Professionals

Collection and retention

  • As an employer, Casa Ideal® collects, processes and retains personal data concerning employees, contractors, consultants and applicants. Human Resources and other departments processing Professionals' Personal Data must verify and document the legal basis for processing. Such data must only be processed for a valid and legitimate purpose.
  • Personal data about our employees is collected through various channels and formats, such as application forms; electronic web forms, for example during recruitment; data records; CCTV images; team photographs, including identification cards; data from other sources, for example previous employers; credit checks and security checks; etc.
  • Personal data about our Professionals is created and stored through various channels and formats, such as payslips; appraisal records; employment contracts; emails; sickness records; etc.

Training and awareness

  • We are committed to providing appropriate personal data protection training to all Professionals. Where necessary, we will provide tailored training and awareness according to their roles.

Process design and change

  • For all proposed new business systems and procedures involving Personal Data, consideration must be given to whether a privacy and information security impact assessment is necessary to identify risks and controls.