Privacy Policy
Version 2026-10-v1 · Last updated: 2 October 2026
This policy explains what personal data we process when you use humidade.pt, why, on what legal basis, for how long, who we share it with and how you can exercise your rights, under Articles 13 and 14 of the General Data Protection Regulation (GDPR) and Portuguese Law No. 58/2019.
In short
- You can do the diagnosis without giving your name, email or phone number. We keep your answers, measurements, any photos you choose to send (with no GPS location) and only the first 4 digits of your postcode.
- We only ask for contact details if you want quotes. With your explicit consent, we send them to no more than 2 companies, named in the confirmation email.
- We do not sell data. Companies may only use it to respond to your request and are forbidden to resell it.
- Contact details are encrypted in a database hosted in the European Union.
- Advertising cookies only with your permission. Site statistics use no cookies.
- You can ask for access, correction or erasure, or withdraw your consent, at privacidade@humidade.pt. We reply within one month.
This summary helps you read the document but does not replace it.
In this document15 sections
01Who is the controller#
The controller of the data collected on humidade.pt is:
- Aljubarrota — Comércio & Serviços, Lda.
- Company number (NIPC): [to be completed]
- Registered office: [to be completed]
- Registered at the Commercial Registry Office of [to be completed]
- Data protection: privacidade@humidade.pt
- General contact: geral@humidade.pt or the contact page
Further company details are on the legal notice page.
02Data protection officer#
We have not appointed a data protection officer (DPO). The GDPR (Article 37) only requires one for public authorities and for organisations whose core activities consist of regular and systematic monitoring of people on a large scale or large-scale processing of special categories of data (for example, health data). That is not our case: we do not track people’s behaviour, we do not process health data and the volume of data is small. (to be validated)
Privacy matters are handled directly by the company’s management at privacidade@humidade.pt. We will review this decision if the service grows or changes.
03What data we process and where it comes from#
Most of the data is given to us by you. Some is generated automatically when you use the site, and some comes from the partner companies that received your request (Article 14 GDPR).
Diagnosis (no contact details)
- Answers to the questionnaire: affected rooms, type and age of the home, signs observed, ventilation and heating habits, size and duration of the stains, whether you own or rent.
- Optional measurements: relative humidity, air and wall temperature.
- The first 4 digits of your postcode, to show your region and, if you ask, to find companies in your area. We do not ask for your address.
- Optional photos. We reduce their size and remove EXIF metadata — including GPS location and phone model — as soon as we receive them.
- Where the visit came from: campaign parameters (UTM), landing page and the site you came from (referrer).
- The diagnosis is linked to a random link that cannot be guessed. Anyone with the link can see the report — only share it with people you choose.
- While you answer, the draft is saved on our server and also in your browser (localStorage
humidade_quiz_v1), so you can carry on later.
Quote request (only if you ask for it)
- Name, Portuguese mobile number and, optionally, email.
- Desired timeframe (urgent, 1 to 3 months or ‘just looking’) and type of service.
- SMS verification code, if you choose to confirm your number.
- Consent record: date and time, version of the text accepted and IP address.
Emails you ask for, and reviews
- Email address to receive the link to your report or the reminder to measure again in 2 weeks.
- A rating from 1 to 5 and an optional comment about the company that contacted you.
Data we receive from partner companies
- The status of your request (contacted, visit, quote, contract or lost), the diagnosis confirmed on site and, if the company enters it, the contract value. We use this to monitor quality and calibrate the model.
Partner companies (business customers)
- Company name, tax number (NIF), address, website, municipalities and types of work, name, email and phone of the contact person.
- Dashboard credentials (the password is stored only as an irreversible hash).
- Date, time and version of the contract and data-sharing agreement accepted, balance, transactions, invoices and disputes.
What we do not ask for
We ask no questions about health and do not intend to process special categories of data (Article 9 GDPR). Please do not write health information or send photos showing people or documents.
Providing data is always optional. Without answers we cannot calculate the diagnosis; without a name and mobile number we cannot send your request to companies.
04What we use the data for, on what legal basis and for how long#
| Purpose | Data | Legal basis (GDPR, Art. 6(1)) | Retention |
|---|---|---|---|
| Calculate the diagnosis and keep the report | Answers, measurements, postcode prefix, language and result | Providing the service you ask for under the Terms and Conditions — point (b) | 24 months after last use; then anonymised (to be validated) |
| Keep the photos you send | Resized photos, with no EXIF or GPS | Providing the service — point (b) | 12 months after upload, or sooner if you ask for erasure (to be validated) |
| Keep the draft so you can carry on later | Answers in progress (server and browser localStorage) | Providing the service — point (b) | Unfinished drafts: 90 days (to be validated). In the browser: until you finish the diagnosis or clear your data |
| Learn which pages and campaigns bring people to the diagnosis | UTM parameters, landing page, referrer | Legitimate interest in assessing our outreach channels — point (f) | With the diagnosis (24 months) (to be validated) |
| Improve and calibrate the model; statistics | Answers, result and diagnosis confirmed on site, without contact details | Legitimate interest in improving the accuracy of the service — point (f) | 24 months; then only anonymised data, which is no longer personal data |
| Send your request to partner companies (2 at most) | Name, mobile, email, timeframe, type of service, owner or tenant, report, photos, postcode prefix | Explicit, separate consent — point (a) | 24 months after the request, or until you withdraw consent or ask for erasure (to be validated) |
| Demonstrate that you gave consent | Date and time, version of the text accepted, IP address | Legal obligation to be able to demonstrate consent (Art. 7(1)) — point (c) | While the request exists and for 3 years after (to be validated) |
| Verify your mobile by SMS (optional) | Mobile (hashed), code (hashed), IP address, attempts | Legitimate interest in preventing fake requests and abuse — point (f) | The code expires after 10 minutes; the record is deleted after 30 days (to be validated) |
| Classify and route the request | Diagnosis result, timeframe, owner or tenant, verified mobile, postcode prefix | Necessary to act on the request you made — point (b). See automated decisions | With the request |
| Confirmation email naming the companies | Email, first name, request code | Acting on your request — point (b) | Record of the email: 24 months (to be validated) |
| Ask for your review after 30 days and rank companies | Email, request code, rating from 1 to 5, optional comment | Legitimate interest in ensuring the quality of companies — point (f). You can object at any time | While the company is a partner and for 24 months after (to be validated) |
| ‘Measure again’ reminder and report link email | Email, reminder date | Consent, given when you ask for the reminder — point (a); the one-off link email is acting on your request — point (b) | Up to 30 days after the reminder is sent (to be validated) |
| Reply to your messages | The data you send us | Legitimate interest in replying — point (f), or steps at your request — point (b) | 2 years after the last contact (to be validated) |
| Handle requests to exercise your rights | Details of the request and our reply | Legal obligation — point (c) | 5 years (to be validated) |
| Manage partner company accounts | Company and contact person details, credentials, acceptance of the contract and data agreement | Performance of the contract — point (b); contact person: legitimate interest — point (f) | Term of the contract plus 24 months (to be validated) |
| Partner invoicing, balance and disputes | Transactions, invoices, disputes | Tax legal obligation — point (c) and contract — point (b) | 10 years (Article 123 of the Portuguese Corporate Income Tax Code) (to be validated) |
| Security and abuse prevention | IP address, date and time, browser, server logs | Legitimate interest in protecting the service — point (f) | Up to 90 days (to be validated) |
| Shop purchases (order, payment, delivery, after-sales support) | Name, email, phone, delivery address, NIF (optional), items, amounts, payment status | Performance of the sales contract — point (b) | While the order and warranties are ongoing (3-year legal guarantee) |
| Shop invoicing and accounting/tax obligations | Name, NIF, address, items and amounts invoiced | Compliance with a legal obligation — point (c) | 10 years (accounting and tax obligation) |
| Visit statistics (Plausible) | Aggregated counts, with no cookies or identifiers | No identifiable personal data is processed; legitimate interest — point (f) | Aggregated data only |
| Measure advertising (Google Ads and Google Analytics 4) | Cookie identifiers, pages visited, conversions | Consent given in the cookie notice — point (a) | See the Cookie Policy; until you withdraw consent |
Calculate the diagnosis and keep the report
- Data
- Answers, measurements, postcode prefix, language and result
- Legal basis (GDPR, Art. 6(1))
- Providing the service you ask for under the Terms and Conditions — point (b)
- Retention
- 24 months after last use; then anonymised (to be validated)
Keep the photos you send
- Data
- Resized photos, with no EXIF or GPS
- Legal basis (GDPR, Art. 6(1))
- Providing the service — point (b)
- Retention
- 12 months after upload, or sooner if you ask for erasure (to be validated)
Keep the draft so you can carry on later
- Data
- Answers in progress (server and browser localStorage)
- Legal basis (GDPR, Art. 6(1))
- Providing the service — point (b)
- Retention
- Unfinished drafts: 90 days (to be validated). In the browser: until you finish the diagnosis or clear your data
Learn which pages and campaigns bring people to the diagnosis
- Data
- UTM parameters, landing page, referrer
- Legal basis (GDPR, Art. 6(1))
- Legitimate interest in assessing our outreach channels — point (f)
- Retention
- With the diagnosis (24 months) (to be validated)
Improve and calibrate the model; statistics
- Data
- Answers, result and diagnosis confirmed on site, without contact details
- Legal basis (GDPR, Art. 6(1))
- Legitimate interest in improving the accuracy of the service — point (f)
- Retention
- 24 months; then only anonymised data, which is no longer personal data
Send your request to partner companies (2 at most)
- Data
- Name, mobile, email, timeframe, type of service, owner or tenant, report, photos, postcode prefix
- Legal basis (GDPR, Art. 6(1))
- Explicit, separate consent — point (a)
- Retention
- 24 months after the request, or until you withdraw consent or ask for erasure (to be validated)
Demonstrate that you gave consent
- Data
- Date and time, version of the text accepted, IP address
- Legal basis (GDPR, Art. 6(1))
- Legal obligation to be able to demonstrate consent (Art. 7(1)) — point (c)
- Retention
- While the request exists and for 3 years after (to be validated)
Verify your mobile by SMS (optional)
- Data
- Mobile (hashed), code (hashed), IP address, attempts
- Legal basis (GDPR, Art. 6(1))
- Legitimate interest in preventing fake requests and abuse — point (f)
- Retention
- The code expires after 10 minutes; the record is deleted after 30 days (to be validated)
Classify and route the request
- Data
- Diagnosis result, timeframe, owner or tenant, verified mobile, postcode prefix
- Legal basis (GDPR, Art. 6(1))
- Necessary to act on the request you made — point (b). See automated decisions
- Retention
- With the request
Confirmation email naming the companies
- Data
- Email, first name, request code
- Legal basis (GDPR, Art. 6(1))
- Acting on your request — point (b)
- Retention
- Record of the email: 24 months (to be validated)
Ask for your review after 30 days and rank companies
- Data
- Email, request code, rating from 1 to 5, optional comment
- Legal basis (GDPR, Art. 6(1))
- Legitimate interest in ensuring the quality of companies — point (f). You can object at any time
- Retention
- While the company is a partner and for 24 months after (to be validated)
‘Measure again’ reminder and report link email
- Data
- Email, reminder date
- Legal basis (GDPR, Art. 6(1))
- Consent, given when you ask for the reminder — point (a); the one-off link email is acting on your request — point (b)
- Retention
- Up to 30 days after the reminder is sent (to be validated)
Reply to your messages
- Data
- The data you send us
- Legal basis (GDPR, Art. 6(1))
- Legitimate interest in replying — point (f), or steps at your request — point (b)
- Retention
- 2 years after the last contact (to be validated)
Handle requests to exercise your rights
- Data
- Details of the request and our reply
- Legal basis (GDPR, Art. 6(1))
- Legal obligation — point (c)
- Retention
- 5 years (to be validated)
Manage partner company accounts
- Data
- Company and contact person details, credentials, acceptance of the contract and data agreement
- Legal basis (GDPR, Art. 6(1))
- Performance of the contract — point (b); contact person: legitimate interest — point (f)
- Retention
- Term of the contract plus 24 months (to be validated)
Partner invoicing, balance and disputes
- Data
- Transactions, invoices, disputes
- Legal basis (GDPR, Art. 6(1))
- Tax legal obligation — point (c) and contract — point (b)
- Retention
- 10 years (Article 123 of the Portuguese Corporate Income Tax Code) (to be validated)
Security and abuse prevention
- Data
- IP address, date and time, browser, server logs
- Legal basis (GDPR, Art. 6(1))
- Legitimate interest in protecting the service — point (f)
- Retention
- Up to 90 days (to be validated)
Shop purchases (order, payment, delivery, after-sales support)
- Data
- Name, email, phone, delivery address, NIF (optional), items, amounts, payment status
- Legal basis (GDPR, Art. 6(1))
- Performance of the sales contract — point (b)
- Retention
- While the order and warranties are ongoing (3-year legal guarantee)
Shop invoicing and accounting/tax obligations
- Data
- Name, NIF, address, items and amounts invoiced
- Legal basis (GDPR, Art. 6(1))
- Compliance with a legal obligation — point (c)
- Retention
- 10 years (accounting and tax obligation)
Visit statistics (Plausible)
- Data
- Aggregated counts, with no cookies or identifiers
- Legal basis (GDPR, Art. 6(1))
- No identifiable personal data is processed; legitimate interest — point (f)
- Retention
- Aggregated data only
Measure advertising (Google Ads and Google Analytics 4)
- Data
- Cookie identifiers, pages visited, conversions
- Legal basis (GDPR, Art. 6(1))
- Consent given in the cookie notice — point (a)
- Retention
- See the Cookie Policy; until you withdraw consent
Where we rely on legitimate interest, we have balanced that interest against your rights and expectations and limited the data to what is necessary. You can ask us for that assessment and object to the processing (see your rights).
At the end of these periods, data is deleted or irreversibly anonymised. We may keep it longer only where the law requires it or to defend ongoing legal proceedings.
05Sharing with partner companies#
We only send your data to companies if you ask us to and tick the consent box, which is never pre-ticked and is not a condition for seeing the diagnosis. Without that consent, the request is not sent.
- Each request goes to no more than 2 companies (or just 1 if the request is exclusive). Companies are chosen by an algorithm, with no paid placements — see automated decisions.
- We name the companies in the confirmation email. If you did not give an email, you can ask us at any time at privacidade@humidade.pt.
- Companies receive your name, mobile, email (if given), the diagnosis report, photos, postcode prefix, timeframe and type of service.
- If you choose ‘just looking’, we keep the request but do not send it to any company.
Companies as independent controllers
Once they receive your data, the companies become independent controllers of the processing they carry out to contact you and give you a quote. Each company has signed a data-sharing agreement with us (see the Partner Terms) that requires it to:
- use the data only to contact you about the work you asked for;
- not resell or pass it on, or use it for advertising without your own separate consent;
- delete it after 24 months or when you ask, unless you have entered into a contract with it or the law requires it to keep the data;
- protect it with appropriate security measures and notify us of any data breach within 72 hours.
You can exercise your rights directly with the company or through us; in that case, we pass your request on to the company.
Withdrawing consent
You can withdraw your consent at any time by replying to the confirmation email or writing to privacidade@humidade.pt. We stop sending the request to new companies and ask the companies that already received it to stop using it and delete your data — unless you have already asked for or accepted a quote from that company, in which case the relationship is between you and that company only. Withdrawal does not affect the lawfulness of processing carried out before it.
06Processors and other recipients#
We use service providers that process data only on our behalf and on our instructions, under contracts in accordance with Article 28 GDPR:
| Provider | Service | Data location | Safeguards |
|---|---|---|---|
| Hetzner Online GmbH | Hosting of servers, database and backups | Germany (EU) | Data processing agreement (Art. 28) |
| Brevo (Sendinblue SAS) or Postmark (ActiveCampaign, LLC) [to be confirmed] | Sending emails (confirmations, reminders, review requests, dashboard access) | EU (Brevo) or USA (Postmark) [to be confirmed] | Art. 28; if in the USA, see transfers |
| [to be confirmed] | Sending the verification SMS | [to be confirmed] | Art. 28 |
| Cloudflare, Inc. | Content delivery network, attack protection and anti-spam check (Turnstile) | Worldwide network, including the USA | EU-US Data Privacy Framework and standard contractual clauses (to be validated) |
| Plausible Insights OÜ | Cookieless visit statistics | EU | Receives no identifiable personal data |
| Stripe Payments Europe, Ltd. | Processing shop payments (card, Multibanco, MB WAY). We never receive or store card data | Ireland (EU); possible transfer to the USA | Independent controller for payment data; EU-US Data Privacy Framework and standard contractual clauses |
| [to be confirmed — e.g. CTT Expresso] | Delivering shop orders (name, address, phone) | Portugal (EU) | Art. 28 or independent controller, depending on the contract (to be validated) |
| Google Ireland Limited | Google Ads and Google Analytics 4 — only with your consent | Ireland and USA | EU-US Data Privacy Framework and standard contractual clauses |
| [to be confirmed] | Certified invoicing software (invoices to partner companies) | [to be confirmed] | Art. 28 |
Hetzner Online GmbH
- Service
- Hosting of servers, database and backups
- Data location
- Germany (EU)
- Safeguards
- Data processing agreement (Art. 28)
Brevo (Sendinblue SAS) or Postmark (ActiveCampaign, LLC) [to be confirmed]
- Service
- Sending emails (confirmations, reminders, review requests, dashboard access)
- Data location
- EU (Brevo) or USA (Postmark) [to be confirmed]
- Safeguards
- Art. 28; if in the USA, see transfers
[to be confirmed]
- Service
- Sending the verification SMS
- Data location
- [to be confirmed]
- Safeguards
- Art. 28
Cloudflare, Inc.
- Service
- Content delivery network, attack protection and anti-spam check (Turnstile)
- Data location
- Worldwide network, including the USA
- Safeguards
- EU-US Data Privacy Framework and standard contractual clauses (to be validated)
Plausible Insights OÜ
- Service
- Cookieless visit statistics
- Data location
- EU
- Safeguards
- Receives no identifiable personal data
Stripe Payments Europe, Ltd.
- Service
- Processing shop payments (card, Multibanco, MB WAY). We never receive or store card data
- Data location
- Ireland (EU); possible transfer to the USA
- Safeguards
- Independent controller for payment data; EU-US Data Privacy Framework and standard contractual clauses
[to be confirmed — e.g. CTT Expresso]
- Service
- Delivering shop orders (name, address, phone)
- Data location
- Portugal (EU)
- Safeguards
- Art. 28 or independent controller, depending on the contract (to be validated)
Google Ireland Limited
- Service
- Google Ads and Google Analytics 4 — only with your consent
- Data location
- Ireland and USA
- Safeguards
- EU-US Data Privacy Framework and standard contractual clauses
[to be confirmed]
- Service
- Certified invoicing software (invoices to partner companies)
- Data location
- [to be confirmed]
- Safeguards
- Art. 28
Other recipients:
- the partner companies that received your request, as independent controllers (see above);
- our certified accountant, for partner companies’ invoicing data [to be confirmed];
- public authorities and courts, where the law requires it — for example, the Tax Authority or the CNPD;
- a potential buyer or successor of the business, in the event of a transfer, with the safeguards of this policy maintained.
We do not sell personal data or pass it on for third-party advertising.
07Transfers outside the European Economic Area#
Diagnoses, requests and accounts are hosted in the European Union. Some providers — Cloudflare, Google (only if you accept marketing cookies) and, if chosen, the Postmark email service — may process data in the United States.
In those cases, the transfer is based on the European Commission’s adequacy decision on the EU-US Data Privacy Framework (of 10 July 2023), for certified companies, and, where applicable, on standard contractual clauses approved by the Commission (Article 46 GDPR). You can ask us for information about the applicable safeguards at privacidade@humidade.pt. (to be validated)
08Automated decision-making and profiling#
We use two automated processes. Here we explain how they work and why, in our view, they do not produce legal effects or similarly significantly affect you (Article 22 GDPR). (to be validated)
1. The diagnosis
The result is calculated by a scoring model: each answer and measurement adds points to the three possible causes (condensation, rising damp and water ingress), which are converted into probabilities. The weights are published in the methodology. It is an indicative estimate: it decides nothing on its own, and you can ignore it, repeat it or ask for a technical visit.
2. Classification and routing of the request
When you ask for quotes, the request is classified automatically to set the price the company pays us:
- Class A — probable cause rising damp or water ingress, owner-occupier, urgent or 1 to 3 months, and mobile verified by SMS;
- Class B — other requests with a defined timeframe;
- Class C — ‘just looking’: not sent to companies.
The system then picks up to 2 active companies that cover your postcode and the type of work needed, ranked by customers’ average rating, response time and rotation between companies. Companies that are paused, have no balance or have reached their weekly limit are excluded. No company pays to appear first.
The classification does not change the diagnosis you see or the price you are quoted, nor does it commit you to anything: the service is free for you and you alone decide whether to accept a quote. If you disagree with the routing, or if no company is available, you can ask for a review by a person at privacidade@humidade.pt.
09Your rights#
Under Articles 15 to 22 GDPR, you have the right to:
- Access — know whether we process data about you and get a copy.
- Rectification — correct inaccurate or incomplete data.
- Erasure — ask us to delete your data, unless we must keep it by law or to defend legal proceedings.
- Restriction — ask us to suspend processing, for example while we check the accuracy of the data.
- Portability — receive the data you gave us in a structured, machine-readable format, or ask us to send it to another organisation.
- Objection — object to processing based on legitimate interest, including the review request.
- Withdraw consent at any time, without affecting processing carried out before.
- Not be subject to solely automated decisions with significant effects, and ask for human intervention.
How to exercise them
- Write to privacidade@humidade.pt or by post to our registered office [to be completed].
- If you have them, include the report link or the request code (for example, HM-0123) and the mobile or email you used.
- To protect your data, we may ask you to confirm your identity — for example, by replying from the email you used or with a code sent to your mobile. We do not ask for copies of identity documents unless genuinely necessary.
- Exercising your rights is free. We reply within one month, which may be extended by two further months for complex or numerous requests; if so, we tell you within the first month and explain why.
If you asked for quotes, you can also exercise your rights directly with the companies that received the request.
10Complaints to the CNPD#
If you believe the processing of your data breaks the law, you have the right to lodge a complaint with the supervisory authority: Comissão Nacional de Proteção de Dados (CNPD), Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, Portugal, telephone +351 213 928 400, www.cnpd.pt. If you live in another EU country, you can complain to the authority in that country.
We would appreciate it if you contacted us first so we can try to resolve the matter — but you are not obliged to.
11Children#
humidade.pt is intended for adults. Quote requests and reminders require you to be at least 18. We do not knowingly collect data from children under 16. If you become aware that a child has sent us data, please contact us so we can delete it.
12How we protect data#
We apply technical and organisational measures appropriate to the risk (Article 32 GDPR), including:
- connections always encrypted (HTTPS/TLS);
- name, mobile and email in requests, and reminder emails, encrypted in the database, with the key stored separately;
- passwords, SMS codes and the numbers used to detect duplicates stored only as hashes;
- removal of EXIF metadata (including GPS) from photos;
- random report links that cannot be guessed;
- each company only sees the requests assigned to it; internal access limited to those who need it, and exports containing contact details require a specific permission;
- rate limits and anti-spam protection on forms;
- servers and daily backups in the European Union.
No system is infallible, but we review these measures regularly.
13Data breaches#
If a personal data breach occurs (for example, unauthorised access), we immediately assess the risk, take steps to contain it and record it internally (Article 33(5)).
- If there is a risk to your rights, we notify the CNPD within 72 hours of becoming aware of it.
- If the risk is high, we inform you directly and without undue delay, explaining what happened and what you can do (Article 34).
- Partner companies must notify us of breaches involving data received through us within 72 hours.
14Cookies#
We only use essential cookies and, with your consent, Google marketing cookies. Statistics (Plausible) use no cookies. The details are in the Cookie Policy.
15Changes to this policy#
We may update this policy when the service changes or the law requires it. The current version (2026-10-v1) and the date of the last update are at the top of the page. If the changes are significant — for example, new purposes or new recipients — we will announce them on the site and, where we have your contact details and the law requires it, by email. For new purposes based on consent, we will ask for it again.
This is a translation. If there is any discrepancy between this version and the Portuguese version, the Portuguese version prevails. (to be validated)