Privacy Policy - RaiaWeb
Version 2.2 - Last updated: 18 July 2026
Courtesy translation. This English version is provided for convenience only. In the event of any discrepancy, the Portuguese version prevails.
RaiaWeb values the privacy of its users and complies with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), Law No. 58/2019 and Law No. 41/2004. This policy explains how we collect, use, share and protect your personal data.
1. Data Controller
- Controller: Alex Nabais Gomes, sole trader, operating under the trading name "RaiaWeb"
- NIF: 268386625
- Registered business address: Rua da Fonte Mestre, No. 22, 6320-637 Soito, Portugal
- Contact for privacy matters: privacy@raiaweb.pt
- General contact: support@raiaweb.pt
No Data Protection Officer has been appointed, as this is not legally required; for any privacy matters, please use privacy@raiaweb.pt.
2. Scope of this Policy
This policy applies to personal data processed by RaiaWeb as data controller: data of website visitors, customers and contacts.
It does not apply to content and personal data that our customers host or process through the contracted services (for example, data of visitors and users of hosted websites) - in such cases, RaiaWeb acts as processor, as explained in section 12.
3. Data We Collect
We only collect the data necessary for the purposes described in this policy:
- Identification and contact details: name, email, telephone number, NIF and billing address.
- Contractual and transactional data: contracted services, order history, invoices and payment status. We do not store full payment card numbers - these are processed directly by the payment providers.
- Technical and usage data: IP address, user agent, access and security logs, preferences (for example, language) and cookies (see Cookie Policy).
- Support: content and attachments of tickets and other support contacts.
- Domain registration: domain holder data, transmitted to the relevant registration entities (see section 5). If you provide third-party data for the registration of a domain, you guarantee that you hold the necessary authorisation to do so and that you have informed those persons of this processing.
- Software licence verification (TapNTable): IP address, licence key, software version and date/time of licence checks and update downloads. The TapNTable software does not transmit any other data to RaiaWeb - in particular, it does not transmit the customer's business data or data of their end customers.
- Maintenance Services: identification of the website or application (address, platform and hosting used), the technical contact provided by the customer, and any access credentials supplied to us for the performance of the service, together with technical records of the work carried out, of availability monitoring and of backups. Credentials are kept in a management panel with restricted access and used solely to perform the service.
- Legal Documents Service: business data provided for completing the templates - company name, NIF, contact details, address, business activity and characteristics of the customer's website or service.
- SEO Services: identification of the accounts and properties (for example, Google Search Console, Google Business Profile and web analytics tools) to which the customer grants us access, and the data contained therein, to the extent necessary to provide the service.
Data is collected directly from you. Identification data and the NIF are necessary for entering into the contract and complying with tax obligations - without them, it is not possible to provide the service. The remaining data is optional.
4. Purposes, Legal Bases and Retention Periods
| Purpose | Legal basis (Article 6 GDPR) | Retention |
|---|---|---|
| Account creation and management, provision of the services | Performance of a contract - point (b) | Duration of the contractual relationship + 5 years (limitation periods) |
| Invoicing, accounting and tax obligations, including reporting of invoices to the Tax Authority | Legal obligation - point (c) | 10 years |
| Customer support (tickets) | Performance of a contract - point (b) | Up to 3 years after closure |
| Licence verification and provision of updates for the licensed software (TapNTable) | Performance of a contract - point (b) | Technical verification logs: 12 months |
| Provision of the Maintenance Services, the SEO Services and the Legal Documents Service (Annex C to the Terms) | Performance of a contract - point (b) | Duration of the contractual relationship + 5 years (limitation periods) |
| Security, fraud and abuse prevention, technical logs | Legitimate interest - point (f) | 6 to 12 months, unless incident investigation requires otherwise |
| Marketing communications to customers about services similar to those contracted | Legitimate interest - point (f), pursuant to Article 13-A(2) of Law No. 41/2004 | Until objection or 2 years without interaction |
| Newsletter and marketing to non-customers | Consent - point (a) | Until withdrawal of consent or 2 years without interaction |
| Usage statistics | Legitimate interest - point (f) | Aggregated and non-identifiable data |
You may object at any time to processing based on legitimate interest, including - freely and free of charge - to direct marketing. You may withdraw your consent at any time, without affecting the lawfulness of processing carried out before its withdrawal. Every marketing communication provides a simple and free way to opt out.
5. Who We Share Data With
We do not sell your data. We share it only with recipients strictly necessary for the provision of the services, bound by contract and by RaiaWeb's instructions (Article 28 GDPR), or where required by law:
- Infrastructure and hosting: Innov4web (Portugal) - shared cPanel hosting; OVH and companies within the same group - virtual private servers (VPS), in the datacentre region chosen by the client at the time of ordering (see section 6)
- Domain registration: Innov4web (registrar) and DNS.pt (.pt domains); other registries and ICANN, depending on the extension
- SSL certificates: SSLs.com (Namecheap, Inc., USA) and the respective certificate authorities (namely Sectigo) - see section 6
- Payment providers: ifthenpay
- Certified invoicing: Moloni, with statutory reporting of invoices to the Tax and Customs Authority (e-fatura / SAF-T)
- Public authorities: only when legally required.
The list of sub-processors is set out in Annex III of the Data Processing Agreement (DPA), published on the Website.
6. International Transfers
We favour providers within the European Economic Area. Shared hosting and email are located in Portugal and are not transferred outside the EEA.
For virtual private servers (VPS), the datacentre region is chosen by you during the order process. Alongside regions within the European Union (France, Germany, Poland and Italy), regions in third countries are available: Canada and the United Kingdom, under European Commission adequacy decisions, and Singapore, Australia and India, under Standard Contractual Clauses. If you choose a region outside the European Union, the data you host there is subject to the jurisdiction of that country. To keep your data exclusively within the European Union, choose an EU region. The full, up-to-date list is set out on the Switching Providers and Transparency page.
Transfers outside the EEA also occur in connection with the issuance of SSL certificates (SSLs.com/Namecheap, in the USA, and the respective certificate authorities), carried out with appropriate legal safeguards - a European Commission adequacy decision (EU-US Data Privacy Framework, where the entity is certified) or Standard Contractual Clauses. You may request information or a copy of the safeguards via privacy@raiaweb.pt.
7. Your Rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection - including the right to object, at any time and free of charge, to the use of your data for direct marketing - as well as the right to withdraw any consent given.
To exercise your rights, contact privacy@raiaweb.pt. We respond within one month, extendable by a further two months in cases of particular complexity, in which case you will be informed of the extension and the reasons for it. We may request identity verification where there are reasonable doubts as to the identity of the requester.
You also have the right to lodge a complaint with the supervisory authority: CNPD - the Portuguese supervisory authority (Comissão Nacional de Proteção de Dados), Av. D. Carlos I, 134, 1st floor, 1200-651 Lisbon - www.cnpd.pt.
8. Automated Decisions
RaiaWeb does not make decisions based solely on automated processing that produce legal effects or significantly affect data subjects. Automated security systems (anti-fraud, anti-spam, abuse detection) may flag situations, but decisions affecting your account are subject to human review.
9. Information Security
- Encryption in transit and, where applicable, at rest;
- Access control, hardening, network segmentation and monitoring;
- Principle of least privilege, internal policies and periodic reviews;
- Incident response procedures, with notification to the CNPD and, where applicable, to data subjects, pursuant to Articles 33 and 34 GDPR.
10. Cookies and Similar Technologies
We use exclusively cookies that are strictly necessary for the operation of the website and the Customer Area - we do not use statistics, marketing or third-party cookies, and therefore no consent banner is displayed. See the Cookie Policy for details.
11. Minors
RaiaWeb's services are intended for persons over 18 years of age - entering into a contract requires full legal capacity. We do not knowingly collect personal data from minors; if you become aware that a minor has provided us with data, please contact privacy@raiaweb.pt so that it can be deleted.
12. When RaiaWeb Acts as Processor
When customers use our services to host websites, applications or data containing personal data of third parties (for example, visitors, users or customers of the hosted websites), the customer is the data controller and RaiaWeb acts as processor, processing that data exclusively in accordance with the customer's instructions. The same applies when, in connection with the Maintenance Services or the SEO Services, RaiaWeb accesses content, accounts or properties of the customer containing personal data of third parties, or keeps backups of that content - including where the website is hosted with another provider, in which case copies will also exist on RaiaWeb infrastructure.
In these cases, the Data Processing Agreement (DPA) applies, which forms an integral part of the services contract and includes the list of authorised sub-processors.
If you are the subject of data processed on a website or application hosted by RaiaWeb, you should direct the exercise of your rights to the controller of that website (its respective owner). If you contact us directly, we will forward the request to the controller, where possible.
Following termination of the contract with the customer, hosted data is deleted in accordance with the contractual terms, after a 30-day recovery period for export purposes (clause 23.3 of the Terms and Annex B - Regulation (EU) 2023/2854).
13. Changes to this Policy
We may update this policy to reflect legal, technical or operational changes. The version in force, together with its date, is permanently published on this page; material changes are communicated by email or via the Customer Area.