Legal
Privacy and data protection
Written in plain English, with no paragraphs copied from a template. If anything here isn't clear, ask.
Last updated: August 2026.
Who the data controller is
Limite Arrojado Unipessoal Lda., Portuguese company registration number 515 289 108, registered office at Rua da Fonte, n.º 444, Valongo — Antanhol, 3040-589 Coimbra, Portugal. “Limite Arrojado” is the trading name the company operates under.
For anything relating to personal data, write to privacidade@limitearrojado.pt.
Why GDPR applies to you even outside the EU
We are established in Portugal, so the General Data Protection Regulation governs everything we do with personal data — regardless of where you are. In practice that means you get the same protections a European client gets: a stated purpose for every piece of data, a defined retention period, and the right to demand it all back or have it erased.
If we process personal data on your behalf as part of a project, we sign a data processing agreement before that work begins.
What we collect
Through the forms on this site: name, email, phone (if you give it), company name, website address and whatever you write in the message.
If you allow audience measurement: the pages you look at, how long you stay on each one, the site or search that brought you here, and approximate device and region information. Never your name. Google Analytics 4 uses your IP address to estimate the region and then discards it — it is not stored.
If you allow advertising: the pages you look at and the forms you submit are reported to Meta, so we can tell which of our Facebook and Instagram ads bring people here. In that case — and only in that case — the email address you type into the form is sent to Meta hashed with SHA-256, an irreversible digest the address cannot be reconstructed from, so that Meta can match the request to the ad that produced it. Without that permission, none of this happens.
If you arrived through an ad or a campaign, the origin parameters in the address (utm_source, utm_medium, utm_campaign, utm_content) travel in the internal email for your request, so we know where it came from. That is data about the campaign, not about you, and it depends on no cookie and no permission.
We don't sell data and we don't build behavioral profiles to hand to anyone.
When you choose what to allow in the cookie box, we keep a receipt of that choice: a random identifier — which does not identify you and exists only to tie this proof to your browser —, the purposes you accepted, the version of the request, the date, the language, the path of the page you decided on, your truncated IP address and your browser identifier. It is the proof Article 7(1) GDPR requires us to be able to produce, and it exists for those who refuse as much as for those who accept.
For security reasons, and for a short period, our servers log IP addresses and technical access information.
On what legal basis
To answer your request and prepare a possible proposal — steps taken at your request prior to entering into a contract (Article 6(1)(b) GDPR).
To contact companies at a professional email address as part of business-to-business outreach — legitimate interest (Article 6(1)(f) GDPR). We always identify ourselves, we say where we got the contact, and we give an immediate way to refuse further contact. Before each campaign we check the register of legal persons who do not wish to receive such communications, maintained by the Portuguese Directorate-General for Consumer Affairs under Article 13-A of Law 41/2004.
To meet legal obligations, in particular tax and accounting ones, where a contract exists.
To keep the receipt of your cookie choice — meeting the obligation to demonstrate consent (Article 7(1), read with Article 5(2) GDPR). It is the only processing on this list that happens even when you refuse everything, and it happens precisely so that we can prove you refused.
To understand which pages get read and what brings people here, so we can improve the site — on the basis of your consent (Article 6(1)(a) GDPR), which you can withdraw whenever you like.
To find out which of our ads work, and to measure the conversions that come from them — also on the basis of your consent (Article 6(1)(a) GDPR), asked separately from the one above and just as reversible. We do not claim legitimate interest for advertising cookies, because it would not be defensible.
How long we keep it
Contacts that don't result in a commercial relationship: up to 12 months, after which they're deleted.
Clients: for the duration of the contract and for the legally required retention periods that follow (ten years for tax records).
Suppression list (anyone who asked not to be contacted): kept indefinitely, precisely so that we never contact them again. It holds the bare minimum — an email address and the date of the request.
Audience measurement data: 14 months in Google Analytics, after which it is deleted automatically.
Advertising data: the Meta cookies last 90 days in your browser. The conversion events reported to Meta follow that platform's own retention periods, which we do not control.
Consent receipts: 24 months, deleted automatically by the database itself when the period is up. That is twice the maximum life of a permission, leaving room if someone complains about a choice that has already expired.
Who we share it with
Service providers necessary to run the business: website hosting (Vercel), email delivery (Resend) and the database holding the consent receipts (Google Firebase, on servers in the European Union). All bound by a data processing agreement under Article 28 GDPR: they process the data on our behalf and on our instructions, and cannot use it for anything of their own.
If you allow audience measurement, that data is processed by Google Ireland Limited and may be transferred to the United States under the EU-US Data Privacy Framework, which Google has joined. Without that permission, no measurement data reaches Google.
With Meta the relationship is a different one, and it is worth saying so plainly: for the collection of advertising data on this site and its transmission to Meta, we and Meta Platforms Ireland Limited are JOINT CONTROLLERS under Article 26 GDPR. Each answers for its own part — we for asking your permission on valid terms and for sending only what you allowed; Meta for what it does with that data from then on, which is its own processing and outside our control. The terms that divide these responsibilities are Meta's Business Tools Controller Addendum, published on its site.
In practice, so you are not left guessing: if you allow advertising, Meta can tie this visit to your Facebook or Instagram account and use it for its own purposes. You may exercise your rights with either of us — but as to what Meta does afterwards, you have to go to Meta, because Meta is the one deciding. The data may be transferred to the United States under the EU-US Data Privacy Framework, which Meta has joined. Without that permission, nothing reaches Meta at all — not from your browser, and not from our server.
We do not sell, rent or hand over data to third parties for marketing. Ever.
Your rights
You have the right to access, rectify, erase, restrict and port your data, and to object to processing based on legitimate interest.
Write to privacidade@limitearrojado.pt. We respond within 30 days at the latest, at no cost.
If you believe your rights haven't been respected, you can complain to the Portuguese data protection authority, the CNPD (cnpd.pt).
How to stop hearing from us
Reply to any email from us with the word «remove». You go on the suppression list immediately and we don't write again. You don't need to justify it and you don't need to click anything.