Data and Privacy

Last updated: April 06, 2026

1. Introduction

This Data Protection and Privacy Policy explains how we handle the personal data of users of our website, in compliance with the General Data Protection Regulation (GDPR – Regulation (EU) 2016/679), Law No. 58/2019 (which ensures the implementation of the GDPR in Portugal), and other applicable legislation.

Our website sells online nutrition consultations provided by a nutrition professional.

Important: The site does not store any user data in its own systems or databases. All information required for scheduling and payment is processed transiently and sent directly to the third-party services listed below. We do not store personal data after the necessary processing is completed.

2. Data Controller

The controller responsible for the processing of personal data is:

Vasco Névoa (service provider established in Portugal)
Contact email: use the contact form.
NIF 197241298

You may contact us for any questions related to data protection through the contact method above.

3. Personal Data Processed and Purposes

We only process data that is strictly necessary and in a transient manner. We do not retain it.

PurposeData processed (examples)Third-party service usedLegal basis for processing
Scheduling consultationsName, email, desired date/timeGoogle CalendarPerformance of a contract (Art. 6(1)(b) GDPR)
Spam protection in formsIP address, form behaviourGoogle reCAPTCHALegitimate interest (security)
Website statistical analysisBrowsing data (anonymised)Google AnalyticsLegitimate interest (service improvement)
Payment processingPayment data (we do not access card data)IfThenPayPerformance of a contract
Website hostingTemporary access dataScalingo (France – EU)Legitimate interest (website operation)
Contact emailsName, emailMailJetPerformance of a contract

Sensitive health data: We do not collect or store any data relating to health or nutrition through the website. Any clinical information is handled only during the online consultation, directly with the nutritionist.

4. Recipients of the Data and International Transfers

The data is shared only with the following independent processors/controllers:

  • Google LLC (reCAPTCHA, Analytics and Calendar) – based in the USA. Transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission and other Google safeguard measures.
  • IfThenPay – Portuguese company (EU).
  • Scalingo – French company (EU), responsible for hosting.
  • MailJet (contact form) – company of the Sinch group, with servers in the EU, but with possible transfers outside the EU protected by Standard Contractual Clauses / SCC.

We do not sell or share data with other entities for commercial purposes.

5. Data Retention Period

We do not retain personal data.
The data is automatically deleted after the necessary processing (e.g., after sending to Google Calendar or completion of payment). There are no copies in our systems.

6. Data Subjects’ Rights

Under the GDPR, you may exercise the following rights (free of charge, except in cases of abuse):

  • Right of access, rectification or erasure of data;
  • Right to restriction of processing;
  • Right to object;
  • Right to data portability (when applicable);
  • Right to withdraw consent (when the processing is based on consent).

To exercise any right, please send an email through the contact form. We will respond within a maximum of 30 days.

You also have the right to lodge a complaint with the National Data Protection Commission (CNPD):
• Website: www.cnpd.pt
• Email: geral@cnpd.pt

7. Security Measures

We apply appropriate technical and organisational measures (encryption in communications, restricted access, etc.) to protect the data during transient processing.

8. Consumer Dispute Resolution and Arbitration

Under Law No. 144/2015 of 8 September, we inform consumers that:

  • We are not bound to any specific Alternative Dispute Resolution (ADR) entity by voluntary adhesion.
  • In the event of a dispute relating to online purchases or services, the consumer may resort to the ADR entities listed on the Consumer Portal (www.consumidor.gov.pt) or use the national online dispute resolution platform available in Portugal.
  • You may also try to resolve the dispute directly with us through the contact form before resorting to any entity.

For more information on competent ADR entities:
→ https://www.consumidor.gov.pt/parceiros/sistema-de-defesa-do-consumidor/entidades-de-resolucao-alternativa-de-litigios-de-consumo

9. Cookies and Similar Technologies

This website uses cookies as described below. You can consult the full details below.

What are cookies?
Cookies are small text files that a website stores in your browser when you visit it. They serve to remember information about your browsing, preferences, and to enable certain functionalities.

This website uses strictly necessary first-party cookies and third-party cookies.
Our site does not store personal data on its own servers. All processing is transient.

Cookies used on this website

CategoryDescriptionExamples of cookiesApproximate durationPurposeLegal basis / Note
Strictly necessaryEssential for the basic functioning of the siteTechnical session cookies, Scalingo hosting cookiesSession or a few hoursAllow navigation and correct page loadingService provision / Legitimate interest
Functionality and SecurityProtection against spam and bots in forms_GRECAPTCHA and related cookies (Google reCAPTCHA)Up to 6 monthsProtect contact and scheduling forms from automated spamLegitimate interest (security) – see note below
Statistics / AnalysisAnalysis of traffic and user behaviourga, _ga (Google Analytics 4)Up to 2 yearsUnderstand how users use the site and improve the experienceLegitimate interest (service improvement) – see note below
PaymentPayment processing when redirectedIfThenPay cookiesSession or a few hoursComplete payment for the nutrition consultationPerformance of a contract

Important notes:

  • The integration with Mailjet (sending confirmation emails) is done via API and does not install cookies in your browser.
  • Google reCAPTCHA and Google Analytics are third-party services that may set cookies on your device. These cookies are not strictly necessary for basic site navigation.
  • We do not use marketing, advertising or cross-site behavioural tracking cookies.

Cookie management
Currently, this website does not have a cookie management banner that allows the user to accept or reject specific categories before they are loaded.

However, you can manage or block cookies at any time through your browser settings:

  • Google Chrome: Settings → Privacy and security → Cookies and other site data
  • Mozilla Firefox: Options → Privacy & Security → Cookies and Site Data
  • Safari: Preferences → Privacy
  • Microsoft Edge: Settings → Cookies and site permissions

Blocking non-essential cookies may affect the functioning of some forms (due to reCAPTCHA) or the collection of anonymous statistics.

10. Changes to this Policy

We may update this policy occasionally. The updated version will be published on the website with the new update date. We recommend that you check it periodically.

11. Contact

Any questions about this Policy should be directed to the contact form.