DataRoad Privacy Policy
Privacy Policy
DataRoad — IT Services and Consulting Last updated: May 2026
1. Introduction and Commitment
DataRoad is a Portuguese managed service provider (MSP) that serves national and international organisations with high standards of quality, security and operational continuity.
For DataRoad, the protection of personal data It is a fundamental principle and an integral part of our value proposition. As a specialist provider in cybersecurity and critical infrastructure, we are committed to processing the personal data entrusted to us with the highest level of rigor, transparency and security.
This Privacy Policy (hereinafter “Policy”) describes, in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation — GDPR) and with the Law No. 58/2019, of 8 August, how DataRoad collects, uses, retains and protects the personal data of the data subjects with whom it interacts.
2. Identification of the Data Controller
Company name: DATAROAD IT SERVICES AND CONSULTING LDA Trading name: DataRoad Head office Avenida dos Moinhos n.º 12 B, 2610-119 Alfragide (Quinta Grande), Portugal NIPC 513368078 Registered at the Lisbon Commercial Registry Office under number: 513368078
Telephone: +351 211 459 950
General email: sales@dataroad.pt
Data Protection Officer (DPO) email: [DPO@DATAROAD.PT]
DataRoad acts as Data Controller (“Controller“) regarding the personal data it collects directly — namely through the Website, contact forms, commercial processes and human resources management.
When providing services to clients that involve the processing of personal data held by them (for example, under IT support, monitoring or infrastructure management contracts), DataRoad acts as Subcontractor (“Processor“), under the terms of Article 28 of the GDPR, with this relationship being governed by a specific data processing agreement (DPA — Data Processing Agreement).
3. Relevant Definitions
For the purposes of this Policy, the following definitions shall apply:
- Personal details: any information relating to an identified or identifiable natural person (data subject);
- Treatment: any operation performed on personal data (collection, recording, organisation, storage, use, disclosure, erasure, etc.);
- Data controller: controller;
- Subcontractor: processor acting on behalf of the data controller;
- Data subject: natural person to whom the personal data relate.
4. Principles that Guide Our Treatment
The processing of personal data by DataRoad is governed by the following principles, set out in Article 5 of the GDPR:
- Lawfulness, fairness and transparency: we process data lawfully, fairly and transparently in relation to the data subject;
- Purpose limitation: we collect data for specified, explicit and legitimate purposes;
- Data minimisation: we process only the data strictly necessary for each purpose;
- Accuracy: we keep the data accurate and up to date;
- Conservation limitation: we retain the data only for the period necessary for the purposes in question;
- Integrity and confidentiality: we protect the data through appropriate technical and organisational measures;
- Responsibility: We are responsible for compliance with these principles and we demonstrate this in a documented manner.
5. Categories of Personal Data Processed
Depending on the type of relationship established with the data subject, DataRoad may process the following categories of personal data:
5.1. Website Visitors
- Technical identification data: IP address, browser type, operating system, language, screen resolution;
- Browsing data: pages visited, time spent, traffic source (referrer);
- Cookies and similar identifiers (see Cookie Policy).
5.2. Requests for information or commercial quotation
- First name and surname;
- Represented company/organisation and job title (where applicable);
- Contact email and telephone;
- Message content or description of the requirement;
- Any other data that the user voluntarily includes in their communication.
5.3. Customers
- Identification data of the company and its legal representatives;
- Commercial and technical contact details (name, job title, email, telephone number);
- Billing data (VAT number, registered address, commercial terms);
- History of communications, proposals, contracts and invoices;
- Technical user and system data in the context of the provision of services (see section 5.6);
- Support ticket history, technical interventions and reports.
5.4. Suppliers and partners
- Identification data of the entity and its representatives;
- Business contact details;
- Billing details;
- Transaction and communication history.
5.5. Job applicants
- Data contained in CV and cover letter;
- Professional and academic history, and references;
- Contact details;
- Other data voluntarily shared by the candidate.
5.6. Client end-users (in the context of IT service provision)
When DataRoad provides IT management services to its clients, it may access personal data of end users (employees or users of those clients), namely:
- Account identifiers (user, corporate email, username);
- Authentication data (tokens, certificates — not clear-text passwords);
- Technical logs for equipment, networks, and applications;
- Configuration data for managed personal and professional equipment;
- IP addresses, technical geolocation data and monitoring data.
In these situations, the DataRoad acts exclusively as a Subcontractor, processing the data on behalf of and in accordance with the customer's documented instructions, under a specific data processing agreement (DPA), pursuant to Article 28 of the GDPR.
6. Purposes and Legal Bases for Processing
| Purpose | Data Categories | Legal basis |
|---|---|---|
| Statistical analysis and website optimisation | Browsing data, cookies | Consent (Article 6(1)(a)) |
| Response to contact requests and commercial proposals | Identification and contact details | Pre-contractual enquiries (Article 6(1)(b)) |
| Management of business relationships with customers | Customer data and their communications | Performance of a contract (Article 6(1)(b)) |
| Invoicing and compliance with tax obligations | Billing details | Legal obligation (Article 6(1)(c)) |
| Provision of managed IT services | Technical and end-user data | Performance of the contract + DPA (Article 28) |
| Supplier and partner management | Identification and contact details | Performance of a contract (Article 6(1)(b)) |
| Recruitment and selection | Candidate details | Pre-contractual enquiries (Article 6(1)(b)) |
| Sending marketing communications | Email, name | Consent (Article 6(1)(a)) |
| Compliance with legal and regulatory obligations | As required by law | Legal obligation (Article 6(1)(c)) |
| Defence of rights in legal or administrative proceedings | As required | Legitimate interest (Article 6(1)(f)) |
| Information security and fraud prevention | Logs, technical data | Legitimate interest (Article 6(1)(f)) |
7. Source of the Data
Most of the data processed is provided directly by the data subjects (via the Website, commercial communications, or in the course of performing contracts).
Additionally, DataRoad may obtain personal data from:
- Public sources: commercial registers, corporate websites, professional social networks (namely LinkedIn) — for the purposes of B2B commercial prospecting;
- Clients: when these entrust us with personal data of end users for the purpose of providing services;
- Technology partners and manufacturers: as part of certification schemes, partnerships and distribution channels.
8. Recipients and Subcontractors
DataRoad may transfer personal data to the following categories of recipients, exclusively to the extent necessary for the purposes described:
8.1. Internal recipients
- DataRoad employees, upon the need for access (principle of need-to-know) and are subject to confidentiality obligations.
8.2. Subcontractors
DataRoad uses qualified service providers to support its business, specifically in the following areas:
- Communication and productivity platforms (Microsoft 365, Google Workspace);
- Ticket and helpdesk management platforms (notably the portal
helpdesk.dataroad.pt); - Remote Monitoring & Management (RMM) tools for IT infrastructure management;
- 24/7 monitoring and alarm platforms;
- Cloud storage and backup solutions;
- Cloud infrastructure and hosting services;
- Web analytics and digital marketing platforms (such as Google Analytics);
- Accountancy, invoicing and legal consultancy services;
- Telecommunications and postal service providers.
All subcontractors are selected based on criteria of quality, safety and GDPR compliance, and are bound by written contract to duties of confidentiality and data protection, pursuant to Article 28 of the GDPR.
8.3. Other recipients
- Public and judicial authorities, where required by law or by a court order;
- External auditors and consultants, whilst strictly carrying out their duties;
- Insurance companies, where applicable to claims or professional liability.
A DataRoad does not sell, let or transfer personal data to third parties for commercial purposes.
9. International Data Transfers
9.1. Wherever possible, DataRoad gives priority to processing personal data on servers located in the European Economic Area (EEA).
9.2. Some of the technological tools used (namely services provided by Microsoft, Google or other global providers) may involve data transfers to countries outside the EEA, namely to the United States of America.
9.3. In such situations, DataRoad ensures that transfers are carried out on the basis of adequate safeguards as set out in Article 46 of the GDPR, namely:
- Conformity decisions by the European Commission (namely the EU-US Data Privacy Framework);
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Binding Corporate Rules (BCR), where applicable.
9.4. Data subjects may request detailed information about the transfers applicable to their situation by contacting the DPO.
10. Retention periods
DataRoad retains personal data only for as long as is necessary to fulfil the purposes for which it was collected, in accordance with the following criteria:
| Data Category | Retention Period |
|---|---|
| Website visitor data (logs, analytics) | Up to 26 months (Google Analytics 4 — default setting) |
| Enquiries without a commercial follow-up | 12 months |
| Commercial proposal data | 5 years after the proposal was issued |
| Customer data (active relationship) | Throughout the term of the agreement |
| Contract details and billing | 10 years (tax obligations — Article 123 of the Corporate Income Tax Code) |
| Support tickets and technical reports | 5 years after closure |
| Data of unselected candidates | 12 months (with consent), barring withdrawal |
| Marketing data (newsletter) | Until consent is withdrawn |
| Electronic communications (emails) | 5 years |
| Security and access logs | 12 months (as a rule) or as required by law |
Once the relevant time limits have expired, the data is deleted or anonymised securely and irreversibly, except where retention is necessary for legal reasons or for the defence of rights in judicial proceedings.
11. Security Measures
As a cybersecurity-focused MSP, DataRoad adopts robust technical and organisational measures to protect personal data against unauthorised access, loss, accidental destruction or disclosure, namely:
Technical measures
- Encryption of data in transit (TLS 1.3) and at rest (AES-256);
- Multi-factor authentication (MFA) across all critical systems;
- Access control based on the principle of least privilege;
- Network segmentation e firewalls next-generation;
- Backups redundant and regularly tested;
- 24/7 continuous monitoring of security events (SIEM/SOC);
- Updates and patching systematic of systems and applications;
- Vulnerability management with periodic audits;
- Anti-malware and EDR across all endpoints.
Organisational measures
- Internal Data Protection Policy documented and reviewed periodically;
- Continuous professional development of data protection and cybersecurity collaborators;
- Non-disclosure agreements (NDA) with employees and service providers;
- Incident response plan and the procedure for notification to the CNPD within 72h;
- Data Protection Impact Assessments (DPIAs) where applicable;
- Record of Processing Activities (RAT) updated;
- Internal and external audits Periodic.
12. Data Subjects' Rights
As the data subject, you have the following rights, guaranteed by the GDPR:
| Law | Description |
|---|---|
| Access | Obtain confirmation of which of your data we process and access it |
| Rectification | Request correction of inaccurate or outdated data |
| Deletion right to be forgotten | Request the deletion of your data, in the cases provided for under the GDPR |
| Limitation | Request the temporary suspension of the processing of your data |
| Opposition | Object to the processing of your data, particularly for marketing |
| Portability | To receive your data in a structured and readable format, or to request transfer to another controller |
| Withdraw consent | At any time, without affecting the lawfulness of processing based on consent before its withdrawal |
| Not to be subject to automated decisions | Including profile definition, except where legally required |
| Complaint | Lodge a complaint with the competent supervisory authority |
12.1. How to exercise your rights
You can exercise your rights by contacting us via:
- Email [DPO@DATAROAD.PT]
- Post office Avenida dos Moinhos n.º 12 B, 2610-119 Alfragide, Portugal
To ensure security and prevent unauthorised data disclosure, we may request additional information to confirm your identity.
DataRoad will respond to your request within 30 days, extendable by a further two months in the event of complexity or volume of requests, with notification being given in that eventuality.
12.2. Complaint to the supervisory authority
Without prejudice to any other administrative or judicial remedy, the data subject has the right to lodge a complaint with National Data Protection Commission:
- Web https://www.cnpd.pt
- Address: Av. D. Carlos I, 134 — 1.º, 1200-651 Lisbon
- Telephone: +351 213 928 400
- Email geral@cnpd.pt
13. Automated Decisions and Profiling
A DataRoad does not make decisions with legal or significant effects based exclusively on automated processing of personal data, including profiling.
The automated systems used (namely technical monitoring tools, firewalls and intrusion detection systems) operate based on technical parameters and not on personal profiles.
14. Biscuits
The use of cookies on the Site is governed by our Cookie Policy, available at [LINK TO COOKIE POLICY], which forms an integral part of this Privacy Policy.
15. Processing of Children's Data
15.1. The DataRoad Website and services are not intended for persons under 18 years of age. We do not knowingly collect personal data from minors.
15.2. Should we become aware that a minor's data has been collected without the consent of the holders of parental responsibility, we shall proceed with its immediate deletion.
16. Personal Data Breaches
16.1. In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects, DataRoad shall notify the CNPD within 72 hours upon becoming aware of it, pursuant to Article 33 of the GDPR.
16.2. When the breach is likely to entail high risk, DataRoad will likewise notify the affected data subjects without undue delay, in accordance with Article 34 of the GDPR.
Data Protection Officer (DPO)
DataRoad has appointed a Data Protection Officer (DPO), responsible for monitoring GDPR compliance and serving as a point of contact for data subjects and the CNPD.
DPO contacts:
- Epost: [DPO@DATAROAD.PT]
- Mail: Data Protection Officer, Avenida dos Moinhos n.º 12 B, 2610-119 Alfragide, Portugal
18. Changes to the Privacy Policy
18.1. DataRoad reserves the right to update this Policy whenever necessary, specifically due to legislative, jurisprudential, regulatory or sector best practice changes.
18.2. The updated version will be published on the Website, indicating the date of the last revision.
18.3. In the event of substantial changes, DataRoad will actively inform the data subjects by appropriate means, specifically by email or a prominent notice on the Website.
19. Applicable Law
This Policy is governed, in particular, by the following legislation:
- Regulation (EU) 2016/679, of the European Parliament and of the Council, of 27 April 2016 (GDPR);
- Law No. 58/2019, of 8 August, which ensures the enforcement of the GDPR in the Portuguese legal order;
- Law No. 41/2004, of 18 August (Privacy in Electronic Communications);
- Decree-Law No. 7/2004, of 7 January (E-commerce);
- Law No. 46/2018, dated 13 August (Cybersecurity);
- Law No 48/2024, of 21 November (Transposition of the NIS2 Directive);
- CNPD guidelines and do European Data Protection Board (EDPB).
20. Contacts
For any queries relating to this Privacy Policy or the processing of your personal data:
DataRoad — IT Services and Consulting
Avenida dos Moinhos n.º 12 B 2610-119 Alfragide (Quinta Grande), Portugal
Telephone: +351 211 459 950
General email: sales@dataroad.pt
Email DPO: [DPO@DATAROAD.PT]
© 2026 DataRoad IT Services and Consulting. All rights reserved.
Protecting personal data is not just a legal obligation: it's a matter of trust.We help your company comply with the GDPR in practice — controlled access, encrypted backups and audit-proof logs.Talk to us about the security of your data
Contact us now
Contact Form
Request a quote from DataRoad. We’ll take care of the rest with a prompt and clear response to support your business’s needs.
Tell us what you need. IT support, network installation, cyber security, an office move or simply a second opinion on your IT infrastructure — we’re here to help.
Please fill in the form and a specialist technician will contact you on the same day.
Some of the companies that entrust their infrastructure to DataRoad, sectors where downtime costs much more than IT support























































































































































































