Privacy Policy

Version 2026-09-14 · Last updated 2026-09-14

This policy explains what personal data this site processes, on what basis and for how long. The Portuguese version is the reference text.

1. Data controller

The controller is the entity identified at the end of this page. Any request concerning personal data should be sent to the email address shown there.

2. What data is processed

Account: email address, password stored only as a cryptographic hash (never in plain text), preferred language, and the dates of creation, address verification and password change.

Document content: everything you enter in the form is stored as a draft, including names, marital status, identification document number and expiry, tax number, address and property details — of both landlord and tenant. You enter this data; where it concerns third parties, it is you who must have a basis for processing it.

Payments: payment is processed by Paddle. Card details never pass through this site and are not stored here. On this side only the transaction identifier, amount, currency, date and the accepted version of the Terms are kept.

Technical logs: the server may record the IP address, date and request made, for diagnostics and to detect abuse.

3. Purposes and lawful basis

Providing the contracted service — creating the account, storing the draft, generating and delivering the document: performance of a contract, Article 6(1)(b) GDPR.

Security, fraud prevention and technical diagnostics: legitimate interest, Article 6(1)(f).

Keeping invoicing records: legal obligation, Article 6(1)(c).

No automated decision-making producing legal effects is carried out, and no profiling for advertising.

4. Retention periods

Account data and documents are kept for as long as the account exists. When the account is deleted, the associated drafts and documents are deleted with it.

Invoices are issued and kept by Paddle, as Merchant of Record, for the period required by the applicable tax law. Those records sit on Paddle's side and are not removed by deleting your account on this site.

5. Who has access

Data is not sold or shared for advertising. It is accessed by processors strictly necessary to run the service: the server hosting provider, the email sending provider, and Paddle as payment processor and Merchant of Record.

Where any such processor handles data outside the European Economic Area, the transfer relies on the standard contractual clauses approved by the European Commission.

On this site's administration side, the panel shows only counts — how many accounts, drafts and paid documents. It contains no screen that allows reading a user's document content: names, document numbers, tax numbers and addresses are not accessible that way.

6. Your rights

You may request access, rectification, erasure, restriction of processing, data portability, and object to processing based on legitimate interest. Requests go to the address shown at the end of this page.

You also have the right to lodge a complaint with the Comissão Nacional de Proteção de Dados (CNPD), the Portuguese supervisory authority.

7. Cookies

This site uses a single cookie: the session cookie, which keeps you signed in and stores the language you chose. It is strictly necessary to provide the service you requested and is therefore exempt from consent under article 5(3) of Law 41/2004. That is why there is no cookie consent banner here.

There are no advertising, analytics or social-network cookies. Loading a page makes no request to any third-party server: fonts, stylesheets and scripts are served from this site, so the visitor's IP address is not transmitted to anyone else.

The only exception is payment: when you click the purchase button, and only then, Paddle's script is loaded from cdn.paddle.com. From that point the services Paddle itself uses in its checkout are also contacted — for error reporting, interface translation and fonts — and cookies may be set for fraud prevention. Anyone who does not start a purchase never contacts any of these services.

8. Changes

This policy may change. The date of the last update is shown at the top of this page.

Contact

Contact details have not been configured yet. Fill them in under Admin → Site → Entity and contact details.