Data controller
Cyberprotech Unipessoal, Lda., Portuguese company registration and tax number 518 608 565, with registered office at R. Padre António Vieira 46, Centro Comercial Charlot, Shop 43, 8100-611 Loulé, Portugal, is the controller for the personal data processing described in this policy. For privacy questions or to exercise your rights, contact info@cyberprotech.pt and identify the purpose or request concerned without sending unnecessary data.
Data we may process
- Name, email address, organization, telephone number, subject and message provided in the contact form or other communication requests.
- For CSIRT support requests: notifier type, name, email address, telephone number, organization, incident status, type, impact and description, as well as the request reference, status and operational history.
- Name, email address, organization, role, telephone number and assessment answers when required by the access level of a resource.
- For validation of the RJCS path: name, organization and professional email address; optionally telephone number, role and context; and the guidance answers that the user chooses to associate with the request.
- Name and email address when a visitor chooses to subscribe to alerts and news, together with the technical evidence required to record consent.
- Optional communications consent and its timestamp.
- Records of delivery, visits to a resource page and use of its download button.
- Requested URL, referrer and minimised technical data in the URL Observatory; this module does not retain the IP address, create a fingerprint or identify visitors.
- Technical security and session records strictly required to operate and protect the service.
- Technical usage signals analyzed by Google reCAPTCHA v3 to prevent automated submissions through contact and incident-support forms.
Data by Resource access level
The information requested is proportionate to the level assigned to each resource. Before submission, the form displays the applicable fields and processing purpose.
At Level 0, access may be anonymous. Email is shown only when the visitor chooses to receive communications. At subsequent levels, professional identification, contact details, organization characteristics and assessment answers required for delivery and follow-up may progressively be requested.
Acceptance of the access conditions is required to obtain the resource. Consent to communications is optional, independent of the download and may be withdrawn at any time.
Initial guidance and RJCS support
Initial guidance may be completed without identification. Until support is requested, the answers remain in the browser and are not transmitted to Cyberprotech.
When the user requests human validation, we first show the elements that will be associated with the case: answers provided, preliminary result, name, organization, professional email address, optional fields completed, reference, date and version of the rules used.
The request is intended to answer, clarify and support an action requested by the user. We do not use an IP address, cookies or fingerprint as the identity of the case. The guidance does not constitute an official qualification and does not replace self-identification or the decision of the competent authority.
The option to receive alerts and news is shown separately, is optional and does not affect creation or support of the request.
Purposes and legal bases
- Responding to requests and taking pre-contractual steps.
- Organising RJCS guidance answers and supporting validation expressly requested by the user, based on pre-contractual steps or the legitimate interest in responding to and documenting the request, depending on context.
- Receiving, prioritizing and following up incident-support requests, coordinating the response and, where applicable and authorized, supporting preparation of the official notification.
- Delivering requested resources and managing their versions and access.
- Performing contracts and complying with legal obligations.
- Protecting the digital ecosystem and public forms, preventing abuse, managing sessions and retaining security evidence, based on legitimate interests and, where applicable, compliance with legal obligations.
- Measuring website use and improving content through Google Analytics 4 only after consent. We do not use this measurement for behavioral advertising or solely automated decisions with legal or similarly significant effects.
- Sending important alerts and news only with specific, freely given consent that is independent of a contact request or download. The subscription may be canceled at any time.
Recipients and service providers
Data is accessible only to authorized persons and providers strictly necessary for hosting, email, security, maintenance and support, subject to instructions, confidentiality and appropriate safeguards. We do not sell personal data. Data may be disclosed to authorities where required by law or a valid request.
The contact and incident-support forms use Google reCAPTCHA v3 as an anti-abuse measure; Google Analytics 4 is activated only after consent. These services may involve access to or international transfer of technical data under the provider's terms and applicable legal mechanisms.
Links to external services lead to independent controllers with their own policies.
Retention
We retain data only for as long as necessary for its purpose, requested follow-up, the duration of the relationship and applicable legal periods. Tokens and access codes have limited validity; technical events and audit records are retained in proportion to security and accountability needs.
Specific criteria and periods are defined by purpose and reviewed when new modules are activated. When the need ends, data is deleted or anonymised unless retention is required by law or necessary to establish, exercise or defend legal claims.
RJCS support requests are retained while the case is active and, after closure, only for the period necessary for requested continuity, accountability, legal claims and applicable obligations. Data is then deleted or anonymised when identifiable retention is no longer necessary.
Data subject rights
Where applicable, you may request access, rectification, erasure, restriction, objection and portability, and withdraw consent without affecting the lawfulness of earlier processing. Send your request to info@cyberprotech.pt; we may request only the information needed to confirm your identity and respond securely. You may also lodge a complaint with the Portuguese Data Protection Authority (CNPD).
Security
We apply proportionate technical and organizational measures, including minimization, separation between public and private data, access control, token protection, auditing and encrypted communications where supported. Sensitive incident-support content is encrypted at rest and operational access is restricted. No system eliminates risk entirely; incidents are handled under the applicable procedures.
End of the Privacy PolicyYou may now complete the reading and return to the form.