Privacy Policy

    Last updated: 27/04/2026

    1. Data Controller

    Comissão de Festas São João de Sobrado 27, with registered office at Tasquinha de São João, Largo do Passal, 4440-337 Sobrado, Valongo, Portugal, reachable at organizacao@saojoaodesobrado.pt.

    For any data protection matter, please use organizacao@saojoaodesobrado.pt and write 'GDPR' in the subject line.

    2. Categories of data processed

    Depending on the user's interaction with the platform, we may process:

    • First and last name
    • Email address
    • Tax ID (optional, for invoicing)
    • Billing address (only if a formal invoice is requested)
    • Technical data: truncated IP address, session identifier, browser type and security logs
    • User-submitted content: photographs, descriptions and associated metadata in the 'Memories' section

    3. Purposes and legal bases (mapped per purpose)

    Each purpose has a specific legal basis under Art. 6 GDPR:

    • Ticket sales and management — legal basis: performance of a contract (Art. 6(1)(b)).
    • Issuing invoices/receipts and tax compliance — legal basis: legal obligation (Art. 6(1)(c)) and Art. 123 of the Portuguese Corporate Tax Code.
    • Operational communications (purchase confirmation, event changes, password recovery) — legal basis: performance of contract.
    • Cultural communications or newsletter — legal basis: consent (Art. 6(1)(a)), revocable at any time.
    • Compliance with legal/tax obligations (invoicing, accounting, requests from public authorities) — legal basis: legal obligation.
    • Platform security, fraud and abuse prevention (rate limiting, anti-bot, logs) — legal basis: legitimate interest (Art. 6(1)(f)), with a balancing test documented internally (LIA).
    • Submission and curation of photographs in the 'Memories' section — legal basis: separate granular consent (historical archive vs. public dissemination), under Art. 6(1)(a) and Art. 7.

    4. Recipients and Processors

    We do not sell or share data with third parties for commercial purposes. Data may be processed, on behalf of Comissão de Festas and under a processor agreement under Art. 28 GDPR, by the following categories of providers:

    • Hosting and database: Lovable Cloud / Supabase (EU infrastructure).
    • Transactional email delivery: Resend (EU infrastructure).
    • Content delivery network and abuse/DDoS protection: Cloudflare.
    • Statutory recipients: tax, judicial or administrative authorities when required by law.

    5. International transfers

    Main processors (hosting, database, transactional email) are located in the European Union. Where a secondary provider (e.g. CDN) entails transfers outside the EEA, those are based on a Commission adequacy decision or the Standard Contractual Clauses (SCC) approved by Implementing Decision (EU) 2021/914, complemented where necessary by supplementary measures (encryption in transit and at rest).

    6. Data subject rights

    Under Arts. 15–22 GDPR you have the right to:

    • Access your personal data
    • Rectify inaccurate data
    • Erasure ('right to be forgotten') where applicable
    • Restrict or object to processing
    • Portability of data you provided, in a structured format
    • Withdraw consent, without affecting the lawfulness of past processing
    • Lodge a complaint with the Portuguese Data Protection Authority (CNPD), www.cnpd.pt

    To exercise these rights, please contact us at organizacao@saojoaodesobrado.pt.

    7. Data retention

    Retention follows the storage limitation principle (Art. 5(1)(e) GDPR) and applicable legal obligations. Specifically:

    • Invoicing and accounting data: 10 years (Art. 123 of the Portuguese Corporate Tax Code).
    • User account data: while the account is active, plus 12 months of inactivity, after which it is deleted or anonymised.
    • Technical and security logs: 6 to 12 months, unless longer retention is required to handle a security incident.
    • Approved 'Memories' content: until the data subject withdraws consent or until the cultural interest ceases; rejected submissions are kept for 30 days.
    • Email unsubscribe list: indefinitely, to prevent re-sending (legitimate interest).

    8. Security

    Appropriate technical and organisational measures are applied: mandatory HTTPS (HSTS), encryption in transit and at rest, multi-factor authentication in the back-office where applicable, role-based access control (RBAC) with database-level Row-Level Security, audit logging, rate limiting and anti-bot protection.

    9. Cookies and local storage

    Please see our Cookie Policy for details about local storage used and the related consent model.

    11. Limits to verification of user-submitted content

    We do not verify the authorship, dating or accuracy of content submitted by third parties. The user is solely responsible for what they submit.

    • We do not verify authorship or dating of content.
    • We do not validate the identity of people depicted.
    • We do not confirm intellectual property rights over submitted material.
    • We reserve the right to remove content that breaches the law or these policies.

    12. Rights of people depicted in photographs

    Identifiable people in photographs submitted by third parties have the right to:

    • Request removal of the image in which they appear.
    • Request anonymisation (blurring) of their image.
    • Object to its use for public dissemination purposes.

    13. Limitation of liability for third-party content

    We act as a technical host of user-submitted content ('Memories'), under the liability regime of information society service providers (Decree-Law 7/2004). We remove unlawful content as soon as we obtain actual knowledge of it.

    14. Minors

    In Portugal, direct consent to information society services is valid only from the age of 13 (Art. 16 of Law 58/2019). Below that age, authorisation from those holding parental responsibility is required. If we become aware of processing data of a child under 13 without authorisation, the data will be deleted.

    15. Automated decisions

    We do not take automated individual decisions, including profiling, with legal or similarly significant effects (Art. 22 GDPR).

    16. Changes to this policy

    This policy may be updated. The version and date in force are shown at the top. Material changes will be notified through the site and, where applicable, by email.

    17. Contact and complaints

    For any data protection request, or to file an internal complaint before contacting the supervisory authority, please reach us at organizacao@saojoaodesobrado.pt.