Privacy Policy
We explain transparently which personal data we process on mssolution.pt, why we process it, how long we retain it and how you can exercise your rights.
1. Controller and contact
MS Solution Tecnologia, operating in Portugal with a presence in the Lisbon — Torres Vedras — Silveira area, is the controller of personal data collected through this website.
Privacy enquiries and requests relating to personal data may be sent to geral@mssolution.pt.
2. Data processed and its source
We process the information you voluntarily provide in forms: name, email address, telephone, company, location, relationship with MS Solution, request type and message. Do not send health data, identity documents, passwords or other sensitive information through these fields.
For security and compliance evidence, we may process the date and time, an IP address that is reduced and transformed using HMAC without retaining the raw address, request source, pseudonymous visitor identifier, language and general device information.
If you authorise optional categories, the providers named in the Cookie Policy may process online identifiers, pages viewed, visit source, events, performance and technical browser or device information.
3. Purposes and lawful bases
We respond to enquiries, prepare assessments and proposals and take pre-contractual steps requested by the data subject. We maintain security, abuse prevention and technical records on the basis of our legitimate interest in protecting the service and, where relevant, compliance with legal obligations.
Optional preferences, statistics and marketing rely on consent that is freely given, specific, informed and unambiguous. Refusing or withdrawing consent does not prevent access to content and does not affect processing lawfully carried out beforehand.
4. Recipients and processors
Internal access is limited to people who need the data to respond, secure the website or fulfil obligations. We use Supabase for secure processing and storage, n8n for private routing and Cloudflare Turnstile to protect forms.
With consent and only when configured, we may use Google Analytics, Microsoft Clarity, Google Ads, Meta Pixel and LinkedIn Insight Tag. We do not sell personal data.
5. International transfers
Some providers may process data outside the European Economic Area. In those cases, we use mechanisms recognised by the GDPR, such as adequacy decisions, Standard Contractual Clauses and supplementary measures appropriate to the risk.
6. Retention
Commercial enquiries are generally retained for up to 24 months after the last relevant interaction unless needed for longer because of a contract, legal obligation or legal claim. Security records are kept only as long as necessary, normally up to 90 days unless an incident occurs.
Consent history is retained while the choice is valid and for up to 24 months after expiry or withdrawal. Data-rights requests may be kept for up to 3 years after submission. Statutory periods for contracts, invoicing and accounting take precedence where relevant.
7. Security and data minimisation
We apply access control, server-side validation, rate limiting, anti-automation protection, audit records and encrypted transmission. Form fields are masked from measurement tools and private keys remain on the server.
No system is completely invulnerable. We review technical and organisational measures in proportion to risk and respond to incidents in accordance with the law.
8. Your rights
You may request information, access, rectification, erasure, restriction, portability and objection, and you may withdraw consent. Some rights depend on the conditions and exceptions in the GDPR and other applicable law.
A dedicated page allows you to exercise these rights electronically. To protect data, we may request additional information that is strictly necessary to confirm identity.
9. Automated decisions and children
The website does not make solely automated decisions that have legal or similarly significant effects on visitors. Our services are intended for businesses and are not directed at children.
10. Complaints and updates
We aim to respond without undue delay and, in principle, within one month. If you believe processing breaches the GDPR, you may complain to the Portuguese data protection authority at cnpd.pt or to the authority where you live, without prejudice to other remedies.
We may update this policy to reflect legal, technical or operational changes. Material changes affecting optional consent will trigger a new choice.