Privacy Policy
Version 2026-09-22.3
Effective date: Pending verified information
1. Who is responsible for your data
Pending verified information, a self-employed professional established in Portugal and trading as bless.team, is responsible for the personal data described in this policy.
- Portuguese tax identification number (NIF): Pending verified information
- Postal address: Pending verified information
- Privacy contact: Pending verified information
You can use the email or postal address above for questions about your data and to exercise your rights.
This policy covers visits to bless.team, enquiries about the Frontend Risk Audit and the related proposal correspondence. Personal data means information relating to an identified or identifiable person, including a name, an individual work email address or an online identifier.
We process personal data in accordance with the General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 — and Portuguese Law No. 58/2019 of 8 August, which implements the GDPR in Portugal, together with other applicable data protection legislation.
If we enter into an engagement, we provide any additional information needed for that work. This website policy does not authorise access to client systems or the processing of client datasets for an audit.
2. Information we process
Enquiries. The contact form asks for your name, email address and message; company is optional. We receive the information you submit and subsequent correspondence, including messages you send directly by email. We also keep the submission time, language, notice version and a record of your consent and acknowledgement of this policy. The acknowledgement confirms that you have read the policy; it is not a separate permission for other uses.
Please do not send source code, passwords, access credentials, sensitive personal data or confidential technical material through the initial form. We ask for scope details later if you request a proposal; technical access follows the separate contractual process.
Website delivery and protection. Cloudflare processes technical information needed to deliver and protect the site, such as IP address, browser and device information, request details and security signals. Turnstile assesses browser and connection signals to help distinguish people from automated abuse. We do not include your form message in the data we send to the Turnstile widget.
Preferences and optional analytics. We store your selected theme and privacy choice in your browser. If you allow analytics, PostHog measures visits, selected interactions, form outcomes, browser errors and page performance, using a persistent browser identifier, a pseudonymous profile and approximate country. With your permission, it also records interactions with our website for session replay. Section 4 explains this choice.
3. Why we use information and our legal bases
| Purpose | Information involved | Legal basis |
|---|---|---|
| Answer your initial form enquiry | Name, email, message, optional company and the related submission record | Consent for this purpose, Article 6(1)(a) GDPR |
| Respond to a business enquiry you send directly by email | Sender and contact details, message and relevant correspondence | Legitimate interests in responding to correspondence addressed to the practice, Article 6(1)(f) |
| Prepare a proposal you request on behalf of a business | Necessary contact, company and scope correspondence | Legitimate interests in assessing and responding to a requested business opportunity, Article 6(1)(f) |
| Take steps you request towards a contract to which you are personally a party | Necessary identification and proposal details | Pre-contractual steps at your request, Article 6(1)(b) |
| Deliver and protect the website and form, diagnose faults and monitor their technical operation | Request, connection, error and security information | Legitimate interests in operating a reliable website and preventing abuse, Article 6(1)(f) |
| Remember your requested theme and apply your privacy choice | Preference values, and the date and version of the privacy choice | Legitimate interests in providing the preferences you request and respecting your choice, Article 6(1)(f) |
| Measure visits, interactions, form outcomes, errors, performance and approximate country through optional browser analytics | The pseudonymous measurements described in section 4 | Consent, Article 6(1)(a), before activation |
| Diagnose usability problems and verify interface fixes through optional session replay | Masked page state, clicks, scrolling, pointer movements, navigation and timing described in section 4 | Consent, Article 6(1)(a), before recording starts |
| Handle data-rights requests and keep records required by law | Necessary request, identity-verification and compliance records; applicable accounting records if an engagement follows | Compliance with a legal obligation, Article 6(1)(c) |
| Establish, exercise or defend a specific legal claim | Only records relevant to that claim | Legitimate interests in protecting legal rights, Article 6(1)(f) |
The separate email and proposal purposes do not let us substitute a new basis to continue answering your initial enquiry after you withdraw consent. We do not use enquiry details for newsletters or advertising, sell personal data, or combine form submissions with browser analytics to identify visitors. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
Providing data through the form is voluntary. Name, email and a message are needed to handle that enquiry; without consent to use them for the reply, the form cannot be submitted. The company field and permission for analytics are optional. Sending the form does not create a service contract.
4. Your analytics choice
PostHog browser analytics and session replay are off until you select Allow analytics & replay. Before permission, and on later visits while a refusal applies, we do not load the analytics or recording software, collect recordings or send browser analytics events. You can read the website and send an enquiry without allowing analytics.
When allowed, PostHog receives selected page views and actions, the start and outcome of form attempts, browser errors and page-performance measurements. These events include a random browser identifier, session information, timestamps, page and language, limited browser/device information, and the referring website domain. We do not send the contents of form fields, your name, email address, message, access credentials or full URL query strings to analytics. A recorded successful form result means that the browser received confirmation of acceptance by the mail service; it is not proof of delivery to our inbox.
The random identifier is stored in localStorage on this site and can recognise repeat visits in the same browser while permission remains valid. PostHog maintains a pseudonymous profile for that identifier to group visits, events and recordings and support deletion. This is personal data in pseudonymous form, not fully anonymous data. We do not add your name, email or enquiry contents to this profile, link it to contact-form submissions, connect different devices, restore deleted identifiers through fingerprinting or enable advertising tracking.
Session replay. With your permission, we record the state of our website pages and interactions such as clicks, scrolling, pointer movements, navigation and timing. PostHog reconstructs these as a replay so we can understand confusing steps, diagnose interface faults and check whether fixes work. It does not record your desktop, other applications, camera or microphone. Form fields and potentially personal text are masked before transmission, and contact-form contents are excluded. We do not capture network request or response bodies, credentials or console logs in replay. The recordings are linked to the pseudonymous browser profile and are accessible only to the operator and authorised service providers for these purposes. We do not sell personal data, analytics profiles or session recordings, or disclose them for third parties’ own marketing.
Cloudflare estimates the country from the network connection; our site passes only the country code to PostHog. PostHog geographic enrichment is disabled and the original IP is excluded from stored analytics events. We do not retain city, region or coordinates in these events and do not request device geolocation. The estimate may be inaccurate, including when a VPN is used. IP addresses still undergo network processing; Cloudflare delivery and security processing are separate.
You can allow or refuse analytics in the first-visit privacy window or in the expanded choices above this policy. The footer link Privacy & choices returns to those controls. Do not allow withdraws permission. Dismissing the popup using its close button, Escape or the backdrop also records refusal, even after a previous permission. Following its policy link, opening this page, or leaving this page does not change your choice.
We apply an allowed or refused choice for 180 days, unless you change it, clear site data or a material change requires a new choice. Expiry stops analytics until you allow it again. On withdrawal or loss of valid permission, we stop further collection and sending and clear the local analytics identifier and state. A fresh permission creates a new identifier; we do not reconnect it to the removed one.
To delete PostHog analytics linked to this browser, select Request deletion of analytics data in Privacy & choices. The request covers the associated profile, events and session recordings. Once accepted, we reset the saved choice and return you to the homepage, where analytics stays off until you make a new choice. PostHog processes deletion under its documented data-deletion procedures; event deletion is asynchronous. For other personal data, or if the browser reference is unavailable, contact us as described in section 7. Enquiries and email correspondence follow the separate process described in sections 6 and 7.
Cloudflare continues to deliver and protect the website and process enquiries. Its operational measurements concern requests, function execution, errors and the result of mail handling. We limit application logs to technical outcomes and do not intentionally log form contents or send these operational logs to PostHog. Their retention is described in section 6.
We also review aggregate Google Search Console reports about our pages’ search visibility and import selected date/page totals into PostHog. This does not add a Google Analytics tag to your browser or link a search query to an individual analytics identifier.
Your analytics choice is separate from consent to answer a contact-form enquiry. Reading this policy, continuing to browse or acknowledging the policy in the form does not give consent to analytics.
5. Who receives information and where it is processed
The person operating bless.team has access to enquiries to handle them. We use the following providers:
| Provider | Role and purpose |
|---|---|
| Cloudflare, Inc. and the entities identified in its applicable terms | Website hosting, delivery, security, contact-form processing, email delivery and operational technical measurements |
| PostHog, Inc. | Optional browser analytics and session replay after consent; processing and presentation of the measurements in section 4 and selected aggregate search reports, using PostHog Cloud EU |
| Pending verified information | Receiving, storing and sending enquiry correspondence; see its privacy information |
Cloudflare’s Customer Data Processing Addendum describes its processing on behalf of customers. For Turnstile, Cloudflare also acts as a controller for certain processing to improve bot detection, as explained in its Turnstile Privacy Addendum.
Our chosen PostHog region is EU (Frankfurt). Its Data Processing Agreement describes processing on customers’ behalf; see also PostHog’s Privacy Policy. Choosing the EU region does not mean that all support access, subprocessors or international transfers are excluded.
We may disclose limited relevant information to professional advisers where necessary for a specific legal or accounting matter, or to competent authorities when the law requires it.
These services can involve processing outside the European Economic Area. The applicable destinations and transfer arrangements are Pending verified information. Where a transfer requires safeguards, we use the applicable adequacy decision or appropriate safeguards, such as the European Commission’s Standard Contractual Clauses. Contact us using section 1 to ask for details or a copy of the relevant safeguards, subject to necessary redactions.
6. How long we keep information
| Category | Retention |
|---|---|
| Initial enquiry and its consent record | While we handle the enquiry and exchange relevant messages. If we send a reply and receive no response, we delete the enquiry and its consent record 30 days after our last outgoing reply. A new incoming response reopens the dialogue |
| Enquiry sent directly by email | The same active-dialogue and 30-day no-response periods apply; if you close the enquiry, we delete it without undue delay subject to a separately justified legal obligation or claim |
| Requested proposal correspondence | While preparing the requested proposal or actively discussing it. If our last proposal or scope message receives no response, the same 30-day period applies |
| Closed enquiry or withdrawn consent | We stop the consent-based purpose and delete the relevant information without undue delay, except for a limited record that another stated lawful purpose requires us to keep |
| Contract and tax records if an engagement follows | Only necessary records enter the separate client or accounting file. Invoice and tax documents follow the applicable statutory retention period, generally 10 years; this does not apply automatically to all emails, code or audit materials |
| Records needed for a specific legal claim | For the period needed to address that claim, taking account of applicable limitation periods; access is restricted and we review the need to keep them |
| Data-rights and compliance records | Pending verified information |
| Cloudflare technical and security records | Pending verified information |
| PostHog browser events and analytics reports | Pending verified information We use these measurements to compare website changes and seasonal trends. A separate deletion request is available as described in section 4 |
| Pseudonymous PostHog profiles | Pending verified information These profiles group repeat visits and enable deletion of associated data; they do not contain enquiry contact details |
| PostHog session recordings | Pending verified information We use this shorter period to investigate recent usability problems and verify interface fixes. You can separately request deletion as described in section 4 |
| Imported aggregate search reports | Pending verified information |
| Temporary working analytics exports | 30 days after export, then deletion from our working copies |
| Deleted email and provider backup copies | Pending verified information |
| Browser preferences | The periods listed in the Cookie Policy |
We do not create a separate application database of form enquiries. Email storage and providers’ technical records remain subject to the periods above. Deletion from our working mailbox does not necessarily remove a provider’s recovery or backup copies immediately.
7. Your rights and withdrawing consent
To withdraw consent for an enquiry, reply to our correspondence or write to Pending verified information. You do not need to give a reason. Withdrawal does not affect the lawfulness of processing before withdrawal. You can withdraw permission for browser analytics through Privacy & choices, as described in section 4.
Under the GDPR, you may request access to your personal data, correction, erasure or restriction of processing. Where processing is automated and based on consent or a contract, the right to data portability may also apply.
You have the right to object, on grounds relating to your particular situation, to processing based on legitimate interests. We will stop that processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or need the information for legal claims.
We normally respond within one month. If a request is complex or we receive several requests, the GDPR allows an extension of up to two further months; we tell you why within the first month. Requests are normally free of charge. We may ask for proportionate information if we need to confirm your identity.
You may complain to the Portuguese Data Protection Authority (CNPD), or to another competent supervisory authority, including in the EU country where you habitually live or work or where you believe an infringement occurred.
8. Security and confidentiality
We apply technical and organisational safeguards appropriate to the personal data we handle and the risks involved. These measures are intended to protect against unauthorised access or disclosure, misuse, alteration, and accidental loss or destruction. Access is limited to what is necessary for the purposes described in this policy.
We treat your personal data as confidential. We do not sell it or disclose it to third parties for their own marketing purposes. Any disclosure is limited to the purposes and recipients described in this policy.
No system can guarantee absolute security. If a personal data breach occurs, we assess and document it, take appropriate action and notify the competent authority and affected people where the GDPR requires it. You can report a concern using the contact details in section 1.
9. Cookies and similar technologies
The Cookie Policy explains browser storage, security technologies and the optional analytics service. The site does not use advertising pixels or newsletter tracking.
10. Changes to this policy
We update this policy when our processing or applicable requirements change and show the new version and effective date. Before material changes affecting the processing of your personal data take effect, we notify you by email where we already hold your email address for an enquiry or engagement. The revised policy is also published on this page. If we need consent for a new purpose, we ask before starting that processing. An update to this policy does not itself give us new consent.