Skip to content

Legal

Privacy and data protection

Written in plain English, with no paragraphs copied from a template. If anything here isn't clear, ask.

Last updated: August 2026.

Who the data controller is

Limite Arrojado Unipessoal Lda., Portuguese company registration number 515 289 108, registered office at Rua da Fonte, n.º 444, Valongo — Antanhol, 3040-589 Coimbra, Portugal. “Limite Arrojado” is the trading name the company operates under.

For anything relating to personal data, write to privacidade@limitearrojado.pt.

Why GDPR applies to you even outside the EU

We are established in Portugal, so the General Data Protection Regulation governs everything we do with personal data — regardless of where you are. In practice that means you get the same protections a European client gets: a stated purpose for every piece of data, a defined retention period, and the right to demand it all back or have it erased.

If we process personal data on your behalf as part of a project, we sign a data processing agreement before that work begins.

What we collect

Through the forms on this site: name, email, phone (if you give it), company name, website address and whatever you write in the message.

If you allow audience measurement: the pages you look at, how long you stay on each one, the site or search that brought you here, and approximate device and region information. Never your name. Google Analytics 4 uses your IP address to estimate the region and then discards it — it is not stored.

If you allow advertising: the pages you look at and the forms you submit are reported to Meta, so we can tell which of our Facebook and Instagram ads bring people here. In that case — and only in that case — the email address you type into the form is sent to Meta hashed with SHA-256, an irreversible digest the address cannot be reconstructed from, so that Meta can match the request to the ad that produced it. Without that permission, none of this happens.

If you arrived through an ad or a campaign, the origin parameters in the address (utm_source, utm_medium, utm_campaign, utm_content) travel in the internal email for your request, so we know where it came from. That is data about the campaign, not about you, and it depends on no cookie and no permission.

We don't sell data and we don't build behavioral profiles to hand to anyone.

When you choose what to allow in the cookie box, we keep a receipt of that choice: a random identifier — which does not identify you and exists only to tie this proof to your browser —, the purposes you accepted, the version of the request, the date, the language, the path of the page you decided on, your truncated IP address and your browser identifier. It is the proof Article 7(1) GDPR requires us to be able to produce, and it exists for those who refuse as much as for those who accept.

For security reasons, and for a short period, our servers log IP addresses and technical access information.

Cookies, analytics and advertising

This site sets no cookie at all before you allow it. The Google Tag Manager container — which is what loads Google Analytics and the Meta Pixel — only reaches the page after you choose. It isn't loaded and then held back: it simply does not exist until there is permission.

There are two separate, independent permissions. You can say yes to audience measurement and no to advertising, or the other way round, or no to both. Each one loads only what belongs to it.

Audience measurement, if you allow it: the «_ga» and «_ga_<identifier>» cookies from Google Analytics, for a maximum of two years, to tell a first visit apart from a return.

Advertising, if you allow it: the «_fbp» and «_fbc» cookies from Meta, for 90 days. The first identifies the browser between visits; the second records the ad click that brought you here. This is what lets Meta tie the visit to your account, and it is why we ask for it separately.

If you decline, nothing is installed and the site works exactly the same — the ads even keep running, we just don't get to know whether they worked. Your choice is kept in the browser's local storage — it is not a cookie, and it exists so we don't ask again on every page. A refusal is honored for six months; an acceptance, for a year.

That choice also produces a receipt sent to our server, whether you accept or refuse. It is what lets us demonstrate what you allowed, which the GDPR requires of us rather than being a choice of ours — a record kept only in your browser would prove nothing, because it sits under your control. The receipt carries no name and nothing that identifies you: it carries a random number tying it to this browser.

Until you choose, every Consent Mode signal sits at «denied», which is the state the page boots in. And when the purposes change — as they did when campaigns started — we ask again rather than reuse a permission given for something else.

You can change your mind at any time, right here or in the footer of any page. Withdrawing permission is as quick as giving it — which is what Article 7 GDPR requires.

On what legal basis

To answer your request and prepare a possible proposal — steps taken at your request prior to entering into a contract (Article 6(1)(b) GDPR).

To contact companies at a professional email address as part of business-to-business outreach — legitimate interest (Article 6(1)(f) GDPR). We always identify ourselves, we say where we got the contact, and we give an immediate way to refuse further contact. Before each campaign we check the register of legal persons who do not wish to receive such communications, maintained by the Portuguese Directorate-General for Consumer Affairs under Article 13-A of Law 41/2004.

To meet legal obligations, in particular tax and accounting ones, where a contract exists.

To keep the receipt of your cookie choice — meeting the obligation to demonstrate consent (Article 7(1), read with Article 5(2) GDPR). It is the only processing on this list that happens even when you refuse everything, and it happens precisely so that we can prove you refused.

To understand which pages get read and what brings people here, so we can improve the site — on the basis of your consent (Article 6(1)(a) GDPR), which you can withdraw whenever you like.

To find out which of our ads work, and to measure the conversions that come from them — also on the basis of your consent (Article 6(1)(a) GDPR), asked separately from the one above and just as reversible. We do not claim legitimate interest for advertising cookies, because it would not be defensible.

How long we keep it

Contacts that don't result in a commercial relationship: up to 12 months, after which they're deleted.

Clients: for the duration of the contract and for the legally required retention periods that follow (ten years for tax records).

Suppression list (anyone who asked not to be contacted): kept indefinitely, precisely so that we never contact them again. It holds the bare minimum — an email address and the date of the request.

Audience measurement data: 14 months in Google Analytics, after which it is deleted automatically.

Advertising data: the Meta cookies last 90 days in your browser. The conversion events reported to Meta follow that platform's own retention periods, which we do not control.

Consent receipts: 24 months, deleted automatically by the database itself when the period is up. That is twice the maximum life of a permission, leaving room if someone complains about a choice that has already expired.

Who we share it with

Service providers necessary to run the business: website hosting (Vercel), email delivery (Resend) and the database holding the consent receipts (Google Firebase, on servers in the European Union). All bound by a data processing agreement under Article 28 GDPR: they process the data on our behalf and on our instructions, and cannot use it for anything of their own.

If you allow audience measurement, that data is processed by Google Ireland Limited and may be transferred to the United States under the EU-US Data Privacy Framework, which Google has joined. Without that permission, no measurement data reaches Google.

With Meta the relationship is a different one, and it is worth saying so plainly: for the collection of advertising data on this site and its transmission to Meta, we and Meta Platforms Ireland Limited are JOINT CONTROLLERS under Article 26 GDPR. Each answers for its own part — we for asking your permission on valid terms and for sending only what you allowed; Meta for what it does with that data from then on, which is its own processing and outside our control. The terms that divide these responsibilities are Meta's Business Tools Controller Addendum, published on its site.

In practice, so you are not left guessing: if you allow advertising, Meta can tie this visit to your Facebook or Instagram account and use it for its own purposes. You may exercise your rights with either of us — but as to what Meta does afterwards, you have to go to Meta, because Meta is the one deciding. The data may be transferred to the United States under the EU-US Data Privacy Framework, which Meta has joined. Without that permission, nothing reaches Meta at all — not from your browser, and not from our server.

We do not sell, rent or hand over data to third parties for marketing. Ever.

Your rights

You have the right to access, rectify, erase, restrict and port your data, and to object to processing based on legitimate interest.

Write to privacidade@limitearrojado.pt. We respond within 30 days at the latest, at no cost.

If you believe your rights haven't been respected, you can complain to the Portuguese data protection authority, the CNPD (cnpd.pt).

How to stop hearing from us

Reply to any email from us with the word «remove». You go on the suppression list immediately and we don't write again. You don't need to justify it and you don't need to click anything.