Legal
Privacy Policy
Draft — [date to be set on publication]
Draft for review — this document must be reviewed by the client and legal counsel before publication. Items shown in square brackets are placeholders to be completed.
This Privacy Policy explains how personal data collected through this website is processed, in accordance with the EU General Data Protection Regulation (GDPR) and applicable national law.
1. Data controller
[Registered legal entity name] ([tax ID / VAT number]), part of the AEI24 Pharma Group and operating the SYMBIONA® website, is the controller responsible for the personal data collected through this website.
For any privacy-related matter you can contact us:
- Address: [registered address]
- Email: [privacy / rights email]
- Phone: [public phone]
2. What data we collect
We collect only the data needed to respond to your request:
- Contact form: full name, company, country, business email, company type, market of interest, project or product category, and your message.
- Technical data: server access logs (IP address, user agent, request time), used only for security and abuse prevention.
3. Purposes and legal bases
We process your personal data for the following purposes and on the following legal bases (GDPR):
- Responding to business enquiries and partnership requests: pre-contractual steps at your request and our legitimate interest.
- Complying with legal obligations (e.g. accounting, tax retention): compliance with a legal obligation.
- Preventing spam and abuse of our forms via a hidden honeypot field: legitimate interest. (We do not use a captcha service.)
- Aggregated, non-identifying website statistics, if and when introduced: your consent (via a cookie banner).
4. Processors and transfers
To provide this service we rely on processors bound by appropriate contractual safeguards:
- Resend — sending the transactional email generated by the contact form.
- Supabase — the managed database supporting our content management system.
- [VPS hosting provider, e.g. Hetzner] — hosting of the website and the content management system.
- Where any transfer outside the European Economic Area occurs, it is covered by appropriate safeguards such as the EU Standard Contractual Clauses.
5. Retention
- Contact form submissions: retained for up to [180] days and then deleted automatically, unless a longer legal retention obligation applies.
- Server access logs: retained for up to 30 days.
- Data kept to meet a legal obligation: for the period required by the relevant law.
6. Your rights
As a data subject, you have the right to:
- Access, rectify and erase your data.
- Restrict or object to processing.
- Request data portability.
- Withdraw consent at any time, without affecting the lawfulness of prior processing.
- Lodge a complaint with the competent supervisory authority (for processing in Portugal, the Comissão Nacional de Proteção de Dados — CNPD, www.cnpd.pt; [confirm the authority for your jurisdiction]).
7. Security
We apply appropriate technical and organisational measures, including encrypted transmission (HTTPS), access control on the content management system, limited retention of submissions, and protection of forms against automated abuse.
8. Changes to this policy
This policy may be updated to reflect legal or operational changes. The date of the latest revision is shown at the top of this page.
