Privacy Policy
Privacy and Personal Data Protection Policy
This Policy describes how TradeWinds, Unipessoal LDA collects, uses, retains, discloses and protects personal data in the context of the website and B2B commercial relationships.
Bilingual document: Portuguese and English. In the event of inconsistency, the Portuguese version shall prevail to the extent permitted by law.
1. Purpose and scope
This Privacy and Personal Data Protection Policy describes how TradeWinds, Unipessoal LDA, referred to as “TradeWinds”, the “Company” or the “Controller”, collects, uses, retains, discloses and protects personal data.
This Policy applies to personal data processing connected with:
- use of the Company’s website;
- enquiries, commercial proposals and negotiations;
- relationships with customers, prospective customers, suppliers, service providers, agents, carriers, banks and business partners;
- performance of contracts and international trade transactions;
- invoicing, accounting, logistics, trade control and compliance activities;
- commercial communications and participation in events;
- recruitment processes, where applicable.
The processing of employee data may additionally be governed by separate internal policies and privacy notices.
2. Data Controller
The Controller responsible for processing personal data is TradeWinds, Unipessoal LDA, NIPC 518952690, with registered address at Rua da Alfândega n.º 10, 4A, 9000-059 Funchal, Madeira Free Trade Zone, Portugal.
Requests relating to personal data protection should be sent to Fedor Diasamidze at hq@tradewindslda.eu.
3. Applicable legislation and legal compliance
This Policy has been prepared and is applied in accordance with the applicable Portuguese and European Union legislation governing privacy and the processing of personal data, as amended and in force from time to time, including, in particular:
- Article 35 of the Constitution of the Portuguese Republic, concerning the use of information technology and the protection of personal data;
- Articles 7 and 8 of the Charter of Fundamental Rights of the European Union, concerning respect for private and family life and the protection of personal data;
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data - the General Data Protection Regulation or “GDPR”;
- Portuguese Law No. 58/2019 of 8 August, implementing the GDPR within the Portuguese legal system;
- Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002, concerning privacy and electronic communications, as amended, in particular, by Directive 2009/136/EC;
- Directive 2009/136/EC, amending Directive 2002/58/EC in respect of privacy in electronic communications;
- Portuguese Law No. 41/2004 of 18 August, as amended, concerning the processing of personal data and the protection of privacy in the electronic communications sector, including cookies, similar technologies and direct marketing communications;
- Directive 2000/31/EC of the European Parliament and of the Council of 8 June 2000, concerning certain legal aspects of information society services and electronic commerce;
- Portuguese Decree-Law No. 7/2004 of 7 January, as amended, concerning information society services, electronic commerce and commercial communications;
- Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022, on a Single Market for Digital Services and amending Directive 2000/31/EC - the Digital Services Act (“DSA”), to the extent that the Company’s activities or digital services fall within its scope of application;
- Commission Implementing Decision (EU) 2021/914 of 4 June 2021, concerning standard contractual clauses applicable to transfers of personal data to third countries;
- Portuguese Decree-Law No. 28/2019 of 15 February, as amended, and other applicable Portuguese tax, accounting, commercial and customs legislation governing the retention of invoices, records and supporting documents.
References in this Policy to any legal provision shall be understood as references to the version of that provision in force from time to time.
Reference to the Digital Services Act does not necessarily mean that the Company qualifies as a provider of intermediary services or as an online platform. The relevant obligations shall apply only to the extent that the services actually provided by the Company fall within the scope of Regulation (EU) 2022/2065.
Where any provision of this Policy conflicts with a mandatory provision of applicable law, the mandatory legal provision shall prevail.
4. Categories of data subjects
The Company may process personal data relating to:
- customers and prospective customers who are natural persons;
- representatives, directors, employees, authorised signatories, beneficial owners and contact persons of customer entities;
- suppliers, service providers and their representatives;
- commercial agents, consultants, carriers, freight forwarders and logistics partners;
- representatives of banks, financial institutions, insurers and payment providers;
- website visitors and users;
- job applicants;
- persons contacting the Company or attending Company events.
5. Categories of personal data processed
Depending on the relationship with the data subject, the Company may process the following categories of data.
5.1. Identification data
- full name;
- professional title and functions;
- signature;
- nationality;
- date of birth;
- identification document information, where legally required;
- information concerning corporate representation, ownership or control.
5.2. Contact data
- business or postal address;
- e-mail address;
- telephone number;
- contact details used in professional communication applications.
5.3. Professional and commercial data
- employer or represented organisation;
- position, department and authority to represent an organisation;
- negotiation history;
- enquiries, proposals, contracts and correspondence;
- information relating to goods, supplies, transport and commercial transactions.
5.4. Financial and transactional data
- bank and payment details;
- information contained in invoices and accounting documents;
- transaction history;
- information required for fraud prevention and payment verification.
5.5. Compliance data
- information concerning beneficial owners;
- identification data of directors and representatives;
- results of sanctions, politically exposed persons or other compliance screening;
- information obtained from commercial registers, public authorities and publicly available sources.
5.6. Technical data
- IP address;
- date and time of access;
- browser and device type;
- pages visited;
- technical, security and website usage logs.
The Company does not intend to collect special categories of personal data, including health data, racial or ethnic origin, religion, political opinions or information concerning a person’s sex life, unless strictly necessary, legally permitted and subject to appropriate safeguards.
6. Sources of personal data
Personal data may be obtained:
- directly from the data subject;
- from the organisation represented by the data subject;
- from customers, suppliers, partners or service providers;
- from contracts, correspondence, commercial documents and forms;
- from banks, payment providers, carriers and logistics operators;
- from commercial registers, public databases, professional websites and competent authorities;
- from verification, fraud prevention or compliance service providers;
- automatically during use of the website.
7. Purposes and legal bases
The Company processes personal data only where a valid legal basis exists. Processing is carried out in accordance with the principles established under Article 5 of the GDPR and on the basis of one or more of the legal grounds provided under Articles 6 and 9 of the GDPR, as applicable.
7.1. Enquiries and negotiations
Purposes:
- responding to enquiries;
- preparing proposals;
- taking pre-contractual steps;
- evaluating commercial opportunities.
Legal basis: taking steps prior to entering into a contract; the Company’s legitimate interest in developing and managing business relationships.
7.2. Entering into and performing contracts
Purposes:
- entering into, administering and performing contracts;
- arranging supplies, payments, transport and logistics;
- managing relationships with customers, suppliers and partners.
Legal basis: performance of a contract; legitimate interest in managing commercial relationships with organisations represented by the data subject.
7.3. Legal and regulatory obligations
Purposes:
- complying with tax, accounting, customs and commercial obligations;
- responding to public authorities;
- conducting checks required by applicable law;
- retaining mandatory documentation.
Legal basis: compliance with a legal obligation.
7.4. Security, fraud prevention and risk management
Purposes:
- preventing fraud, misuse and security incidents;
- verifying counterparties and representatives;
- protecting the Company’s systems, assets, rights and interests;
- establishing, exercising or defending legal claims.
Legal basis: the Company’s legitimate interests; compliance with legal obligations, where applicable.
7.5. Commercial communications
Purposes:
- providing information about products, services and commercial opportunities;
- maintaining relationships with customers and partners;
- conducting business development activities.
Legal basis: consent, where required; legitimate interests, where permitted by applicable law.
7.6. Website operation and security
Purposes:
- ensuring the technical operation of the website;
- preventing attacks, errors and misuse;
- analysing and improving website performance.
Legal basis: the Company’s legitimate interests; consent, where non-essential technologies are used.
7.7. Recruitment
Purposes:
- assessing applications;
- contacting applicants;
- selecting employees or service providers.
Legal basis: taking steps prior to entering into a contract; consent, where data is retained for future opportunities; legitimate interest in managing recruitment processes.
The data subject may withdraw consent or object to commercial communications at any time, free of charge.
8. Requirement to provide data
Certain personal data is required in order to respond to enquiries, prepare or perform contracts, process payments, arrange transportation and supply of goods and comply with legal and regulatory obligations. Where data is mandatory, failure to provide it may prevent the Company from commencing or maintaining a business relationship, performing a transaction or fulfilling a request.
9. Recipients of personal data
Personal data may be disclosed, where necessary and proportionate, to:
- authorised Company employees and contractors;
- companies within the same corporate group, where applicable;
- suppliers, customers and partners involved in a transaction;
- commercial agents and service providers;
- carriers, freight forwarders, logistics operators and warehouses;
- banks, financial institutions and payment providers;
- insurers;
- accountants, auditors, lawyers and consultants;
- IT, hosting, storage and security service providers;
- tax, customs, judicial, law enforcement or regulatory authorities;
- other entities where required by law or necessary for performance of a contract.
Service providers processing personal data on behalf of the Company will be contractually bound in accordance with Article 28 of the GDPR and are subject to confidentiality, security and data protection obligations.
10. International data transfers
Due to the international nature of the Company’s activities, personal data may be transferred or made available to recipients located outside the European Economic Area.
International data transfers will be carried out in accordance with Articles 44 to 49 of the GDPR and, where applicable, using the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914. Adequacy decisions adopted by the European Commission, other appropriate safeguards under Article 46 of the GDPR, or derogations under Article 49 of the GDPR may also be used where legally applicable and necessary.
The Company will take reasonable measures to ensure that transferred data receives an adequate level of protection. Data subjects may request further information regarding the safeguards used by contacting hq@tradewindslda.eu.
11. Data retention
Personal data will be retained only for as long as necessary for the purposes for which it was collected and to comply with applicable legal obligations. Retention periods are determined in accordance with the storage limitation principle under Article 5(1)(e) of the GDPR and applicable statutory retention obligations, including Portuguese Decree-Law No. 28/2019.
Unless a longer period is required:
- enquiry and proposal data not resulting in a contract: normally up to 24 months after the last relevant contact;
- contracts, invoices, accounting, tax and transactional documents: normally for 10 years or for any longer period required by law;
- compliance, fraud prevention and counterparty verification data: for the period required by applicable law or necessary for documented risk management;
- data used for commercial communications: until consent is withdrawn, an objection is submitted or the purpose ends;
- minimum marketing suppression records: for as long as necessary to ensure that further communications are not sent;
- technical and security logs: normally up to 12 months, unless required for incident investigation;
- applicant data: normally up to 12 months after completion of the recruitment process, unless consent is given for longer retention;
- complaint and legal proceeding data: until expiry of applicable limitation periods and final completion of the matter.
After expiry of the applicable retention period, data will be deleted, anonymised or securely archived where retention remains legally required.
12. Data security
The Company implements technical and organisational measures appropriate to the identified risks to protect personal data against unauthorised access, loss, destruction or alteration, improper disclosure, unlawful use and security incidents.
Security measures are implemented in accordance with Articles 25 and 32 of the GDPR. Personal data breaches will be assessed and, where legally required, notified in accordance with Articles 33 and 34 of the GDPR.
Such measures may include access controls, authentication, backups, system protection, permission restrictions, confidentiality obligations and incident response procedures. No information system can guarantee absolute security. The Company reviews its security measures in proportion to the risks identified.
13. Cookies and similar technologies
The website may use cookies or similar technologies that are strictly necessary for its operation, security and provision of functions requested by the user.
Analytics cookies, advertising cookies or other non-essential technologies will only be used after the user has provided prior consent, where such consent is legally required. The use of cookies and similar technologies is governed by Article 5 of Portuguese Law No. 41/2004 and the applicable provisions of Directive 2002/58/EC.
Users may withdraw or modify consent through the tools provided on the website or through browser settings. Disabling strictly necessary cookies may affect website operation.
14. Commercial communications
The Company complies with the rules applicable to unsolicited communications and direct marketing. Direct marketing communications are carried out in accordance with Articles 13-A and 13-B of Portuguese Law No. 41/2004 and Article 21 of Portuguese Decree-Law No. 7/2004.
Electronic marketing communications addressed to natural persons will only be sent with prior express consent or where a lawful existing-customer exception applies to similar products or services. For communications addressed to corporate entities, the Company will respect objections and applicable national opt-out lists.
All commercial communications will include a valid, free and simple method of opting out of future messages.
15. Automated decision-making and profiling
The Company does not make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect a data subject. Solely automated decision-making, including profiling, is subject to Article 22 of the GDPR. Should such processing be introduced, the data subject will be informed in advance as legally required.
16. Data subject rights
Data subject rights may be exercised in accordance with Articles 12 to 22 of the GDPR and Portuguese Law No. 58/2019. Subject to applicable law, data subjects may exercise the following rights:
- right of access to personal data;
- right to rectification of inaccurate or incomplete data;
- right to erasure, where applicable;
- right to restriction of processing;
- right to object to processing based on legitimate interests;
- right to object to direct marketing at any time;
- right to data portability, where applicable;
- right to withdraw consent without affecting the lawfulness of previous processing;
- right not to be subject to certain solely automated decisions;
- right to lodge a complaint with the competent supervisory authority.
These rights are not absolute and may be restricted where retention or processing is necessary to comply with legal obligations, protect the rights of third parties or establish, exercise or defend legal claims.
17. Exercising data subject rights
Requests should be sent to hq@tradewindslda.eu, for the attention of Fedor Diasamidze. The request should clearly identify the right the data subject wishes to exercise.
The Company may request additional information strictly necessary to verify the applicant’s identity and prevent unauthorised disclosure of personal data. Requests will be handled without undue delay and normally within one month. This period may be extended where legally permitted, in which case the data subject will be informed of the extension and the reasons for it.
The exercise of rights is normally free of charge. A reasonable fee may be charged, or a request may be refused, where it is manifestly unfounded or excessive, as permitted by law.
18. Complaint to the supervisory authority
Without prejudice to other administrative or judicial remedies, data subjects may lodge a complaint with the Comissão Nacional de Proteção de Dados - CNPD in accordance with Article 77 of the GDPR, without prejudice to the rights provided under Articles 78 and 79 of the GDPR.
CNPD: https://www.cnpd.pt/
Address: Av. D. Carlos I, 134, 1.º, 1200-651 Lisbon, Portugal. E-mail: geral@cnpd.pt.
19. Children’s data
The Company’s services are intended for commercial and professional activities and are not directed at children. The Company does not knowingly collect personal data relating to children. Where improper collection is identified, appropriate measures will be taken to delete the data or otherwise regularise the processing.
20. Amendments to this Policy
The Company may amend this Policy to reflect legislative or regulatory changes, changes to the Company’s activities, changes to systems, services or processing procedures and guidance issued by competent authorities. The updated version will be made available through appropriate channels and will indicate the date of the latest update.
21. Language
This Policy is provided in Portuguese and English. Both versions are intended to have the same meaning. In the event of any inconsistency of interpretation, the Portuguese version shall prevail to the extent permitted by applicable law.