DataRoad Privacy Policy

Finance Consulting 3

Privacy Policy

DataRoad — IT Services and Consulting Last updated: May 2026


1. Introduction and Commitment

DataRoad is a Portuguese managed service provider (MSP) that serves national and international organisations with high standards of quality, security and operational continuity.

For DataRoad, the protection of personal data It is a fundamental principle and an integral part of our value proposition. As a specialist provider in cybersecurity and critical infrastructure, we are committed to processing the personal data entrusted to us with the highest level of rigor, transparency and security.

This Privacy Policy (hereinafter “Policy”) describes, in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation — GDPR) and with the Law No. 58/2019, of 8 August, how DataRoad collects, uses, retains and protects the personal data of the data subjects with whom it interacts.


2. Identification of the Data Controller

Company name: DATAROAD IT SERVICES AND CONSULTING LDA  Trading name: DataRoad Head office Avenida dos Moinhos n.º 12 B, 2610-119 Alfragide (Quinta Grande), Portugal NIPC 513368078  Registered at the Lisbon Commercial Registry Office under number: 513368078

Telephone: +351 211 459 950
General email: sales@dataroad.pt
Data Protection Officer (DPO) email: [DPO@DATAROAD.PT]

DataRoad acts as Data Controller (“Controller“) regarding the personal data it collects directly — namely through the Website, contact forms, commercial processes and human resources management.

When providing services to clients that involve the processing of personal data held by them (for example, under IT support, monitoring or infrastructure management contracts), DataRoad acts as Subcontractor (“Processor“), under the terms of Article 28 of the GDPR, with this relationship being governed by a specific data processing agreement (DPA — Data Processing Agreement).


3. Relevant Definitions

For the purposes of this Policy, the following definitions shall apply:

  • Personal details: any information relating to an identified or identifiable natural person (data subject);
  • Treatment: any operation performed on personal data (collection, recording, organisation, storage, use, disclosure, erasure, etc.);
  • Data controller: controller;
  • Subcontractor: processor acting on behalf of the data controller;
  • Data subject: natural person to whom the personal data relate.

4. Principles that Guide Our Treatment

The processing of personal data by DataRoad is governed by the following principles, set out in Article 5 of the GDPR:

  • Lawfulness, fairness and transparency: we process data lawfully, fairly and transparently in relation to the data subject;
  • Purpose limitation: we collect data for specified, explicit and legitimate purposes;
  • Data minimisation: we process only the data strictly necessary for each purpose;
  • Accuracy: we keep the data accurate and up to date;
  • Conservation limitation: we retain the data only for the period necessary for the purposes in question;
  • Integrity and confidentiality: we protect the data through appropriate technical and organisational measures;
  • Responsibility: We are responsible for compliance with these principles and we demonstrate this in a documented manner.

5. Categories of Personal Data Processed

Depending on the type of relationship established with the data subject, DataRoad may process the following categories of personal data:

5.1. Website Visitors

  • Technical identification data: IP address, browser type, operating system, language, screen resolution;
  • Browsing data: pages visited, time spent, traffic source (referrer);
  • Cookies and similar identifiers (see Cookie Policy).

5.2. Requests for information or commercial quotation

  • First name and surname;
  • Represented company/organisation and job title (where applicable);
  • Contact email and telephone;
  • Message content or description of the requirement;
  • Any other data that the user voluntarily includes in their communication.

5.3. Customers

  • Identification data of the company and its legal representatives;
  • Commercial and technical contact details (name, job title, email, telephone number);
  • Billing data (VAT number, registered address, commercial terms);
  • History of communications, proposals, contracts and invoices;
  • Technical user and system data in the context of the provision of services (see section 5.6);
  • Support ticket history, technical interventions and reports.

5.4. Suppliers and partners

  • Identification data of the entity and its representatives;
  • Business contact details;
  • Billing details;
  • Transaction and communication history.

5.5. Job applicants

  • Data contained in CV and cover letter;
  • Professional and academic history, and references;
  • Contact details;
  • Other data voluntarily shared by the candidate.

5.6. Client end-users (in the context of IT service provision)

When DataRoad provides IT management services to its clients, it may access personal data of end users (employees or users of those clients), namely:

  • Account identifiers (user, corporate email, username);
  • Authentication data (tokens, certificates — not clear-text passwords);
  • Technical logs for equipment, networks, and applications;
  • Configuration data for managed personal and professional equipment;
  • IP addresses, technical geolocation data and monitoring data.

In these situations, the DataRoad acts exclusively as a Subcontractor, processing the data on behalf of and in accordance with the customer's documented instructions, under a specific data processing agreement (DPA), pursuant to Article 28 of the GDPR.


6. Purposes and Legal Bases for Processing

PurposeData CategoriesLegal basis
Statistical analysis and website optimisationBrowsing data, cookiesConsent (Article 6(1)(a))
Response to contact requests and commercial proposalsIdentification and contact detailsPre-contractual enquiries (Article 6(1)(b))
Management of business relationships with customersCustomer data and their communicationsPerformance of a contract (Article 6(1)(b))
Invoicing and compliance with tax obligationsBilling detailsLegal obligation (Article 6(1)(c))
Provision of managed IT servicesTechnical and end-user dataPerformance of the contract + DPA (Article 28)
Supplier and partner managementIdentification and contact detailsPerformance of a contract (Article 6(1)(b))
Recruitment and selectionCandidate detailsPre-contractual enquiries (Article 6(1)(b))
Sending marketing communicationsEmail, nameConsent (Article 6(1)(a))
Compliance with legal and regulatory obligationsAs required by lawLegal obligation (Article 6(1)(c))
Defence of rights in legal or administrative proceedingsAs requiredLegitimate interest (Article 6(1)(f))
Information security and fraud preventionLogs, technical dataLegitimate interest (Article 6(1)(f))

7. Source of the Data

Most of the data processed is provided directly by the data subjects (via the Website, commercial communications, or in the course of performing contracts).

Additionally, DataRoad may obtain personal data from:

  • Public sources: commercial registers, corporate websites, professional social networks (namely LinkedIn) — for the purposes of B2B commercial prospecting;
  • Clients: when these entrust us with personal data of end users for the purpose of providing services;
  • Technology partners and manufacturers: as part of certification schemes, partnerships and distribution channels.

8. Recipients and Subcontractors

DataRoad may transfer personal data to the following categories of recipients, exclusively to the extent necessary for the purposes described:

8.1. Internal recipients

  • DataRoad employees, upon the need for access (principle of need-to-know) and are subject to confidentiality obligations.

8.2. Subcontractors

DataRoad uses qualified service providers to support its business, specifically in the following areas:

  • Communication and productivity platforms (Microsoft 365, Google Workspace);
  • Ticket and helpdesk management platforms (notably the portal helpdesk.dataroad.pt);
  • Remote Monitoring & Management (RMM) tools for IT infrastructure management;
  • 24/7 monitoring and alarm platforms;
  • Cloud storage and backup solutions;
  • Cloud infrastructure and hosting services;
  • Web analytics and digital marketing platforms (such as Google Analytics);
  • Accountancy, invoicing and legal consultancy services;
  • Telecommunications and postal service providers.

All subcontractors are selected based on criteria of quality, safety and GDPR compliance, and are bound by written contract to duties of confidentiality and data protection, pursuant to Article 28 of the GDPR.

8.3. Other recipients

  • Public and judicial authorities, where required by law or by a court order;
  • External auditors and consultants, whilst strictly carrying out their duties;
  • Insurance companies, where applicable to claims or professional liability.

A DataRoad does not sell, let or transfer personal data to third parties for commercial purposes.


9. International Data Transfers

9.1. Wherever possible, DataRoad gives priority to processing personal data on servers located in the European Economic Area (EEA).

9.2. Some of the technological tools used (namely services provided by Microsoft, Google or other global providers) may involve data transfers to countries outside the EEA, namely to the United States of America.

9.3. In such situations, DataRoad ensures that transfers are carried out on the basis of adequate safeguards as set out in Article 46 of the GDPR, namely:

  • Conformity decisions by the European Commission (namely the EU-US Data Privacy Framework);
  • Standard Contractual Clauses (SCCs) approved by the European Commission;
  • Binding Corporate Rules (BCR), where applicable.

9.4. Data subjects may request detailed information about the transfers applicable to their situation by contacting the DPO.


10. Retention periods

DataRoad retains personal data only for as long as is necessary to fulfil the purposes for which it was collected, in accordance with the following criteria:

Data CategoryRetention Period
Website visitor data (logs, analytics)Up to 26 months (Google Analytics 4 — default setting)
Enquiries without a commercial follow-up12 months
Commercial proposal data5 years after the proposal was issued
Customer data (active relationship)Throughout the term of the agreement
Contract details and billing10 years (tax obligations — Article 123 of the Corporate Income Tax Code)
Support tickets and technical reports5 years after closure
Data of unselected candidates12 months (with consent), barring withdrawal
Marketing data (newsletter)Until consent is withdrawn
Electronic communications (emails)5 years
Security and access logs12 months (as a rule) or as required by law

Once the relevant time limits have expired, the data is deleted or anonymised securely and irreversibly, except where retention is necessary for legal reasons or for the defence of rights in judicial proceedings.


11. Security Measures

As a cybersecurity-focused MSP, DataRoad adopts robust technical and organisational measures to protect personal data against unauthorised access, loss, accidental destruction or disclosure, namely:

Technical measures

  • Encryption of data in transit (TLS 1.3) and at rest (AES-256);
  • Multi-factor authentication (MFA) across all critical systems;
  • Access control based on the principle of least privilege;
  • Network segmentation e firewalls next-generation;
  • Backups redundant and regularly tested;
  • 24/7 continuous monitoring of security events (SIEM/SOC);
  • Updates and patching systematic of systems and applications;
  • Vulnerability management with periodic audits;
  • Anti-malware and EDR across all endpoints.

Organisational measures

  • Internal Data Protection Policy documented and reviewed periodically;
  • Continuous professional development of data protection and cybersecurity collaborators;
  • Non-disclosure agreements (NDA) with employees and service providers;
  • Incident response plan and the procedure for notification to the CNPD within 72h;
  • Data Protection Impact Assessments (DPIAs) where applicable;
  • Record of Processing Activities (RAT) updated;
  • Internal and external audits Periodic.

12. Data Subjects' Rights

As the data subject, you have the following rights, guaranteed by the GDPR:

LawDescription
AccessObtain confirmation of which of your data we process and access it
RectificationRequest correction of inaccurate or outdated data
Deletion right to be forgottenRequest the deletion of your data, in the cases provided for under the GDPR
LimitationRequest the temporary suspension of the processing of your data
OppositionObject to the processing of your data, particularly for marketing
PortabilityTo receive your data in a structured and readable format, or to request transfer to another controller
Withdraw consentAt any time, without affecting the lawfulness of processing based on consent before its withdrawal
Not to be subject to automated decisionsIncluding profile definition, except where legally required
ComplaintLodge a complaint with the competent supervisory authority

12.1. How to exercise your rights

You can exercise your rights by contacting us via:

  • Email [DPO@DATAROAD.PT]
  • Post office Avenida dos Moinhos n.º 12 B, 2610-119 Alfragide, Portugal

To ensure security and prevent unauthorised data disclosure, we may request additional information to confirm your identity.

DataRoad will respond to your request within 30 days, extendable by a further two months in the event of complexity or volume of requests, with notification being given in that eventuality.

12.2. Complaint to the supervisory authority

Without prejudice to any other administrative or judicial remedy, the data subject has the right to lodge a complaint with National Data Protection Commission:


13. Automated Decisions and Profiling

A DataRoad does not make decisions with legal or significant effects based exclusively on automated processing of personal data, including profiling.

The automated systems used (namely technical monitoring tools, firewalls and intrusion detection systems) operate based on technical parameters and not on personal profiles.


14. Biscuits

The use of cookies on the Site is governed by our Cookie Policy, available at [LINK TO COOKIE POLICY], which forms an integral part of this Privacy Policy.


15. Processing of Children's Data

15.1. The DataRoad Website and services are not intended for persons under 18 years of age. We do not knowingly collect personal data from minors.

15.2. Should we become aware that a minor's data has been collected without the consent of the holders of parental responsibility, we shall proceed with its immediate deletion.


16. Personal Data Breaches

16.1. In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects, DataRoad shall notify the CNPD within 72 hours upon becoming aware of it, pursuant to Article 33 of the GDPR.

16.2. When the breach is likely to entail high risk, DataRoad will likewise notify the affected data subjects without undue delay, in accordance with Article 34 of the GDPR.


Data Protection Officer (DPO)

DataRoad has appointed a Data Protection Officer (DPO), responsible for monitoring GDPR compliance and serving as a point of contact for data subjects and the CNPD.

DPO contacts:

  • Epost: [DPO@DATAROAD.PT]
  • Mail: Data Protection Officer, Avenida dos Moinhos n.º 12 B, 2610-119 Alfragide, Portugal

18. Changes to the Privacy Policy

18.1. DataRoad reserves the right to update this Policy whenever necessary, specifically due to legislative, jurisprudential, regulatory or sector best practice changes.

18.2. The updated version will be published on the Website, indicating the date of the last revision.

18.3. In the event of substantial changes, DataRoad will actively inform the data subjects by appropriate means, specifically by email or a prominent notice on the Website.


19. Applicable Law

This Policy is governed, in particular, by the following legislation:

  • Regulation (EU) 2016/679, of the European Parliament and of the Council, of 27 April 2016 (GDPR);
  • Law No. 58/2019, of 8 August, which ensures the enforcement of the GDPR in the Portuguese legal order;
  • Law No. 41/2004, of 18 August (Privacy in Electronic Communications);
  • Decree-Law No. 7/2004, of 7 January (E-commerce);
  • Law No. 46/2018, dated 13 August (Cybersecurity);
  • Law No 48/2024, of 21 November (Transposition of the NIS2 Directive);
  • CNPD guidelines and do European Data Protection Board (EDPB).

20. Contacts

For any queries relating to this Privacy Policy or the processing of your personal data:

DataRoad — IT Services and Consulting
Avenida dos Moinhos n.º 12 B 2610-119 Alfragide (Quinta Grande), Portugal
Telephone: +351 211 459 950
General email: sales@dataroad.pt
Email DPO: [DPO@DATAROAD.PT]


© 2026 DataRoad IT Services and Consulting. All rights reserved.

Protecting personal data is not just a legal obligation: it's a matter of trust.We help your company comply with the GDPR in practice — controlled access, encrypted backups and audit-proof logs.Talk to us about the security of your data

(Call to a national landline)

sales@dataroad.pt
Contact us now

Contact Form

Request a quote from DataRoad. We’ll take care of the rest with a prompt and clear response to support your business’s needs.

Tell us what you need. IT support, network installation, cyber security, an office move or simply a second opinion on your IT infrastructure — we’re here to help.

Please fill in the form and a specialist technician will contact you on the same day.

    A reply on the same working day. No obligation.

    Some of the companies that entrust their infrastructure to DataRoad, sectors where downtime costs much more than IT support

    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client
    DataRoad client

    Proven excellence in numbersThe confidence of those who cannot stopResults that guarantee your peace of mindThe strength of a leading IT partner

    0+Years of experience
    0+Companies
    0+IT Projects
    0+IT Certifications
    0+Countries
    0+Hotels
    0+Embassies
    0%Guaranteed uptime
    DataRoad — IT services for businesses
    Privacy Overview

    This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.