WHO ARE WE?

Navia Digital is committed to protecting the personal data of Customers/Users of Navia Digital products and services, as well as personal data in all situations where personal data processing takes place. In this context, it has drawn up this Policy, which underpins its commitment to respecting the rules on the protection of personal data.

WHY THIS PERSONAL DATA PROTECTION POLICY?

This Policy is intended to inform Customers/Users of the general rules for processing personal data, which are collected and processed in strict compliance with the provisions of the personal data protection legislation in force at any given time, namely Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (‘GDPR’).

Navia Digital respects best practices in the field of security and protection of personal data, and to this end has taken the necessary technical and organisational measures to comply with the GDPR and ensure that the processing of personal data is lawful, fair, transparent and limited to the authorised purposes.

Navia Digital is committed to the protection and confidentiality of personal data and has adopted the measures it deems appropriate to ensure the accuracy, integrity and confidentiality of personal data, as well as all other rights of the respective data subjects.

WHAT DOES THIS DATA PROTECTION POLICY COVER?

This Data Protection Policy applies exclusively to the collection and processing of personal data for which Navia Digital is responsible, within the scope of the services and products made available to its Customers/Users and in all situations where personal data is processed by Navia Digital.

WHAT IS PERSONAL DATA?

Personal data is any information of any nature and regardless of its medium, including sound and image, relating to an identified or identifiable natural person.

An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to a name, an identification number, location data, an electronic identifier or to one or more factors specific to his or her physical, physiological, genetic, mental, economic, cultural or social identity.

Personal data is any information of any nature and regardless of its medium, including sound and image, relating to an identified or identifiable natural person.

An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to a name, an identification number, location data, an electronic identifier or to one or more factors specific to his or her physical, physiological, genetic, mental, economic, cultural or social identity.

WHAT IS THE PROCESSING OF PERSONAL DATA?

The processing of personal data consists of an operation or set of operations carried out on personal data or sets of personal data, whether or not by automated means, namely collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, comparison, interconnection, restriction, erasure or destruction.

WHO IS RESPONSIBLE FOR DATA PROCESSING?

The entity responsible for processing personal data is Navia Digital itself, which determines the purposes and means of processing such data.

To this end, if the owner of the personal data needs to contact the data controller, they can do so through the means and contacts listed below:

Through the Navia Digital website – using the contact form or the alternative contact methods shown in the footer of the website.

WHO IS THE DATA PROTECTION ADMINISTRATOR?

The Data Protection Administrator plays an important role in the processing of personal data, ensuring, among other things, that data processing complies with the legislation in force, verifying compliance with this Data Protection Policy and defining clear rules for the processing of personal data, ensuring that all those who entrust it with the processing of their personal data are aware of how Navia Digital processes them and what rights they have in this regard.

Therefore, if the owners of personal data so wish, they can address a communication to the Data Protection Administrator on matters relating to the processing of personal data, using the contact details on the ‘Contacts’ page.

WHAT TYPES OF PERSONAL DATA ARE PROCESSED?

Within the scope of its activities, Navia Digital processes the personal data necessary to provide services and/or supply products, as well as social intervention, processing data such as name, address, telephone number and email address, in accordance with the more detailed information provided to the holders of personal data.

Without prejudice to compliance with the legal rules on the retention and transmission of data for the purposes of investigation, detection and prosecution of serious crimes, as well as other processing to which it is legally obliged, the traffic, geographical location, profile and/or consumption data of the Client/Users will be processed by Navia Digital to the extent that it is necessary for the provision of the services. In this way, based on location, profile and/or consumption, the Customer/User will have access, in particular, to specific features of the services, content suggestions and proximity information services.

Location information may also be recorded and transmitted to organisations with legal authority to receive emergency calls, for the purpose of responding to incoming calls.

Personal, traffic, geographic location, profile and/or consumption data is also processed for the purposes of marketing or disseminating offers of goods or services from Navia Digital, if the data subject has authorised this.

Personal data will also be processed, if the respective data subject has authorised it, for the purposes of disseminating information services and lists within the scope of the universal service, including transmission to third parties for publication of said lists and provision of information services.

If the Customer/User has given his/her prior consent, this may be withdrawn at any time, without, however, jeopardising the lawfulness of the processing carried out on the basis of the consent previously given.

WHEN AND HOW DO WE COLLECT YOUR PERSONAL DATA?

Navia Digital collects your personal data, namely by telephone, in writing and via the website, guaranteeing, whenever necessary, the prior consent of the holder of the personal data.

Some personal data is essential for the performance of the contract and, if it is missing or insufficient, Navia Digital will not be able to provide the product or service in question.

If the holder of the personal data is not a Navia Digital Customer/User, their personal data will only be processed when it is made available, namely by subscribing to newsletters, in which case the rules of this Data Protection Policy will apply.

The personal data collected may be processed by computer and in an automated or non-automated manner, in all cases guaranteeing strict compliance with personal data protection legislation, being stored in specific databases created for this purpose and, under no circumstances, will the data collected be used for any purpose other than that for which it was collected or consent was given by the data subject.

WHO ARE THE RECIPIENTS OF PERSONAL DATA?

Without prejudice to the recipients indicated throughout this Data Protection Policy, Navia Digital may communicate the personal data of the Customer/User for the purpose of complying with legal obligations, namely to police, judicial, tax and regulatory bodies.

WHAT ARE THE PURPOSES OF PROCESSING PERSONAL DATA?

In general, the personal data collected is based on and intended for the management of the contractual relationship, the provision of the contracted services and the adaptation of the services to the needs and interests of the Client/User. Navia Digital may also, where legally permissible, use the personal data provided by the data subject for other purposes, such as sending suggestions, disseminating institutional brand information, publicising campaigns, promotions, advertising and news about Navia Digital’s products and/or services, as well as carrying out market research or evaluation surveys.

HOW LONG DO WE KEEP YOUR PERSONAL DATA?

The length of time for which personal data is stored and retained varies according to the purpose for which the information is processed.

In fact, there are legal requirements that oblige us to keep data for a minimum period of time. Therefore, whenever there is no specific legal requirement, the data will only be stored and kept for the minimum period necessary to fulfil the purposes for which it was collected or subsequently processed, under the terms defined by law.

WHAT ARE YOUR RIGHTS AS A DATA SUBJECT?

As holders of personal data, Customers/Users are guaranteed, at any time, the right to access, rectify, update, limit and erase their personal data (except for data that is indispensable for the provision of services by Navia Digital duly identified in the Form as being mandatory or for the fulfilment of legal obligations to which the controller is subject), the right to object to its use for commercial purposes by Navia Digital and to withdraw consent, without this compromising the lawfulness of the processing carried out under that consent, as well as the right to data portability.

HOW CAN YOU ACCESS, RECTIFY, UPDATE, LIMIT, ERASE, OPPOSE THE PROCESSING OF YOUR PERSONAL DATA, OR WITHDRAW CONSENT?

Without prejudice to the provisions of the GDPR, the holder of personal data may do so directly or by written request addressed to the respective Data Controller, through the contacts provided for this purpose in this document, as well as other contacts provided by Navia Digital.

HOW CAN YOU OBJECT TO RECEIVING CONTACTS FOR MARKETING PURPOSES?

Navia Digital may publicise new products or services to its Customers/Users, in particular by telephone, e-mail, SMS, MMS or any other electronic communications service, if the holder of the personal data has given their consent.

If the data subject does not wish to continue receiving these communications, they may withdraw their consent to the use of their data for marketing purposes at any time.

HOW CAN YOU COMPLAIN?

Without prejudice to being able to submit complaints directly to Navia Digital, through the contacts provided for this purpose, the Customer/User can complain directly to the Supervisory Authority, which is the National Data Protection Commission (CNPD), using the contacts provided by this entity for this purpose.

WHAT MEASURES HAS Navia Digital ADOPTED TO ENSURE THE SECURITY OF YOUR PERSONAL DATA?

Navia Digital is committed to guaranteeing the protection of the security of the personal data made available to it, and has approved and implemented strict rules in this regard. Compliance with these rules is an obligation of all those who legally access them.

Bearing in mind Navia Digital’s concern and commitment to protecting personal data, a number of technical and organisational security measures have been adopted to protect the personal data made available to it against unauthorised disclosure, loss, misuse, alteration, processing or access, as well as against any other form of unlawful processing.

In addition, third parties who, in the context of the provision of services, process the personal data of the Client/User in the name and on behalf of Navia Digital, are obliged, in writing, to implement appropriate technical and security measures which, at all times, meet the requirements of the legislation in force and ensure the defence of the rights of the data subject (in particular, the protection of the privacy and personal data of Clients/Users).

To this end, on the Navia Digital website, personal data collection forms require encrypted browser sessions and all personal data provided is stored securely on Navia Digital’s systems which, in turn, are on Navia Digital’s server, covered by all the physical and logical security measures that Navia Digital has deemed indispensable for the protection of personal data.

UNDER WHAT CIRCUMSTANCES IS DATA COMMUNICATED TO OTHER ENTITIES (THIRD PARTIES AND SUBCONTRACTORS)?

In the course of its business, Navia Digital may use third parties to provide certain services. Sometimes, the provision of these services implies access by these entities to the personal data of Customers/Users. When this happens, Navia Digital takes appropriate measures to ensure that the entities that have access to the data are reputable and offer the highest guarantees at this level, which is duly enshrined and contractually safeguarded between Navia Digital and the third party(ies).

Accordingly, any entity subcontracted by Navia Digital shall process the personal data of our Customers/Users in the name and on behalf of Navia Digital and shall adopt the necessary technical and organisational measures to protect personal data against accidental or unlawful destruction, accidental loss, alteration, dissemination or unauthorised access and against any other form of unlawful processing.

In any case, Navia Digital remains responsible for the personal data made available to it.

UNDER WHAT CIRCUMSTANCES DO WE TRANSFER YOUR PERSONAL DATA?

The provision of certain services by Navia Digital may involve the transfer of your data outside Portugal, including outside the European Union or to International Organisations.

In such cases, Navia Digital will strictly comply with the applicable legal provisions, in particular as regards determining the suitability of the destination country(ies) with regard to the protection of personal data and the requirements applicable to such transfers, including, where applicable, the conclusion of appropriate contractual instruments that guarantee and respect the legal requirements in force.

HOW CAN YOU FIND OUT ABOUT ANY CHANGES TO NAVIA DIGITAL’S PERSONAL DATA PROTECTION POLICY?

Navia Digital reserves the right to make adjustments or changes to this Personal Data Protection Policy at any time, and such changes will be duly publicised on Navia Digital’s various communication channels.