Skip to main content
← Back to home

Privacy Policy

Last updated: 25 September 2026

1. Data Controller

This website is operated by Nelson Alexandre da Silva Lima, the data controller for personal data processed through this site. The project operates under the Domicilia brand.

For data protection enquiries and to exercise your rights, contact us at privacidade@domicilia.pt.

2. Data We Process and How

We process personal data only in the situations described below. This website uses no analytics, no behavioural tracking and no personalised advertising. We do not share data with third parties for commercial purposes on any of our surfaces.

Processing activity Data Legal basis Retention
Website access (Cloudflare CDN) IP address, browser, country, URL requested Legitimate interest (making the site available) Ephemeral Cloudflare logs (technical processing only)
Direct email contact Email address + message content Legitimate interest (responding to correspondence) Period necessary to respond
WhatsApp link click No data sent by this site N/A — user leaves this site voluntarily N/A (processed under Meta/WhatsApp policies)

Waitlist form (discontinued): this website used to carry an email sign-up form, since removed. We no longer collect email addresses that way. Addresses collected while the form was active, with the consent of those who submitted them, are kept until app launch plus 6 months, or until a deletion request. They were processed by Web3Forms, which forwarded them to the controller's inbox, under Standard Contractual Clauses (SCCs).

We do not carry out automated decision-making or profiling based on data processed through this site.

Data processed in the Domicilia app

In the application (employer and worker accounts), we additionally process:

  • Account data: name, username, recovery email and phone (encrypted at rest) — legal basis: performance of contract.
  • Worker data: tax number (NIF), social-security number (NISS) and address, encrypted at rest — legal basis: the employer's labor and social-security obligations.
  • Labor records: contracts, day/time records, salary calculations, issued payslips and social-security payments — legal basis: legal obligation (Portuguese labor and tax retention).
  • Sickness absences: when recording a working day, you can mark it as a sickness absence. That marking is health information and therefore a special category of data. We do not collect any diagnosis, medical certificate or other clinical detail: we store only the type of the day — legal basis: Art. 9(2)(b) GDPR (obligations in the field of employment and social security law).
  • Messages and support: employer–worker conversations and support tickets (support content encrypted at rest) — legal basis: performance of contract.
  • Subscription and payment: your plan, the status of your subscription and the history of purchases made inside the app. Purchases are processed by the App Store and Google Play, which return only the status of your access entitlement: we never receive card details or the payer's bank details — legal basis: performance of contract. Sub-processor in section 3.
  • Notifications: a delivery identifier assigned to your phone and the device's operating system, so we can send you the app's alerts. That identifier does not reveal who you are and is not used to track you — legal basis: performance of contract. Sub-processor in section 3.
  • Usage statistics: screen visited, action completed, app and OS version, and a user identifier put through a cryptographic hash on the phone. They tell us which features are used and where the app fails. No cookies and no device identifiers are used, and no name, contact details, tax number, amounts or contract data are sent — legal basis: legitimate interest (improving and fixing the app). Sub-processor in section 3. You can object to this processing inside the app, under Settings → Privacy: from then on the app sends no statistics at all, and the choice follows your account onto any phone you sign in on.
  • Crash reports: when the app fails, it sends the error type, the point in the code where it happened, the latest requests to the server (without content or parameters), the device model, and the app and OS versions. Before sending, the phone strips the user identifier, email addresses and any number of nine or more digits, such as a tax number, social security number or IBAN. The IP address is not stored — legal basis: legitimate interest (fixing app failures). Sub-processor in section 3.

Account deletion: you can delete your account directly in the app (Settings → Privacy → Delete account). Deletion becomes effective 30 days after the request (a grace period you can cancel by signing in again). After execution, account data, notifications and tasks are deleted; labor and tax records (contracts, work records, day notes, issued payslips, social-security payments) are kept without your contact details or tax identification, for the retention period required by Portuguese labor and social-security law — Art. 17(3)(b) GDPR. You can also request deletion without the app; the steps and retention periods are on Account deletion.

3. Sub-processors and International Transfers

We use the following sub-processors to operate the website and run the app:

  • Cloudflare, Inc. (USA) — hosting, CDN, and DDoS protection. Transfer covered by Standard Contractual Clauses (SCCs) issued by the European Commission.
  • RevenueCat, Inc. (USA) — manages subscriptions and access entitlements for purchases made on the App Store and Google Play. It receives the account identifier and the purchase status; it does not receive payment details. Transfer covered by SCCs.
  • Expo (650 Industries, Inc.) (USA) — delivery of the app's notifications. It receives the phone's delivery identifier and the text of the alert. Final delivery to the device is carried out by Apple and Google, as operators of their platforms' notification services. Transfer covered by SCCs.
  • TelemetryDeck GmbH (Germany) — mobile app usage statistics. Data is hosted exclusively within the European Union, so there is no transfer to a third country. Receives only pseudonymised, aggregated data, with no cookies and no device identifiers; the user identifier is put through a cryptographic hash on the phone before it is sent, so there is no way to tie it to a person.
  • Sentry (Functional Software, Inc.) (USA) — mobile app crash reports. Data is hosted in the European Union (Frankfurt). Receives the reports described in section 2, already filtered on the phone. Transfer covered by SCCs.

When you click the WhatsApp channel link, you are redirected to a third-party platform (Meta Platforms, Inc.) and your data is then processed under that entity's privacy policy.

4. Your Rights Under the GDPR

Under the General Data Protection Regulation (GDPR), you have the right to:

  • Access: request a copy of the personal data we hold about you
  • Rectification: correct inaccurate or incomplete data
  • Erasure: request deletion of your data (right to be forgotten)
  • Portability: receive your data in a structured, transferable format
  • Restriction: limit how your data is used
  • Objection: object to processing based on legitimate interest — for usage statistics, directly in the app (Settings → Privacy)
  • Withdrawal of consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing

To exercise any of these rights, email privacidade@domicilia.pt with a clear description of your request — this channel also works for data subjects without an account in the app. App users may alternatively use the built-in support ticket system (Profile → Support), the primary day-to-day support channel. We will respond within one month (extendable by a further two months in cases of particular complexity, with prior notification).

If you believe your rights have been infringed, you have the right to lodge a complaint with the competent supervisory authority (see section 5).

5. Supervisory Authority

Comissão Nacional de Proteção de Dados (CNPD)
Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, Portugal
Tel: +351 21 392 84 00
Email: geral@cnpd.pt
Website: www.cnpd.pt

6. Legal Compliance

This privacy policy was prepared in compliance with:

  • Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR)
  • Law No. 58/2019 — Portuguese Data Protection Act
  • Law No. 41/2004 — Processing of personal data in electronic communications