Vexia Logo

Vexia

← Back to home

Privacy Policy

Website www.vexia.com · Integrated B2B and B2C models

Version 1.0 · 15/06/2026

Loading…

Introduction

This Privacy Policy explains how VEXIA, LDA. (“Vexia”, “we”, “our”) and the other companies in its group process personal data in connection with the use of the website www.vexia.com, the forms made available on it, the booking of meetings (“Book a Meeting”), the management of contacts, and the activity of technology, media, performance marketing, analytics, AdTech, reporting, custom data processing and custom modelling. The website is the common institutional point of presence of the Vexia group, covering operations in Portugal, Brazil and Malta.

Vexia is a technology and media agency specialised in performance marketing and digital advertising, with a strong presence in the iGaming, sports betting, casino and poker sector. In this context, Vexia provides services to brands and operators (B2B model) and, when running campaigns on behalf of those clients, processes and impacts the data of end consumers — users, audiences, leads and players (B2C data processing model).

This Policy has been designed to expressly cover both business models and identifies, in each relevant section, what applies to each of them and the legal role assumed by Vexia in each processing activity.

Vexia undertakes to process personal data lawfully, fairly, transparently, limited to the communicated purposes, minimised, accurate, retained only for the necessary period, and protected by appropriate technical and organisational measures.

This Policy should be read together with the Cookie Policy and the Website Terms and Conditions of Use. The Cookie Policy independently identifies the categories of cookies and similar technologies, the providers, the purposes, the duration, and the consent management mechanism.

The two business models and what this Policy covers

To make the scope of application clear, two levels of relationship are distinguished:

2.1. B2B model — institutional and commercial relationship

This corresponds to the direct relationship between Vexia and brands, operators, advertisers, agencies, partners and suppliers, as well as their representatives and professional contacts. This is the level that encompasses browsing the website, requesting a meeting through “Book a Meeting”, the exchange of proposals, and the management of the commercial relationship. With respect to this data, Vexia acts, as a rule, as data controller.

2.2. B2C model — processing of end consumer data

This corresponds to the data of end consumers, users, audiences, leads and players that is processed when Vexia plans, runs, measures and optimises digital campaigns on behalf of its operator clients, namely through advertising platforms, DSPs, social networks, analytics tools, and measurement and modelling technologies.

It should be emphasised that, at the B2C level, the relationship is not a contractual consumer relationship between Vexia and the consumer: Vexia does not sell services to the end consumer through the website, does not manage player accounts, does not accept bets, and does not process gaming payments. The “B2C” therefore translates into a processing of consumer data in the context of campaigns, and not into direct contracting with those consumers.

For this reason, in the B2C model Vexia typically acts as a processor (when it processes data according to the documented instructions of the operator client) or as a joint controller (when it determines jointly with clients or platforms the purposes and means of certain processing activities, in particular in targeting, audiences, conversions and attribution). Only exceptionally will it act as an autonomous controller vis-à-vis the end consumer.

Also included in this model is the consumer who is merely exposed to Vexia advertising materials when browsing the websites and apps of partner publishers, without visiting the Vexia website or interacting directly with it. In that context, the technical collection that occurs in the publisher environment (such as IP address, device type, operating system, approximate location by country and region, and date and time of access) is intended to enable the display, measurement and frequency capping of the ads. Vexia seeks, wherever possible, not to directly identify these consumers from the data thus collected. Vexia's legal role in this scenario varies depending on the campaign and must be qualified and documented on a case-by-case basis, with Vexia possibly acting as a processor of the operator client or as a joint controller, in particular when it defines audiences, measurement, attribution or frequency capping in that inventory.

Data controller and DPO contact

With respect to the data processed under the B2B model and to the processing activities in which Vexia determines the purposes and the means, the data controller is:

VEXIA, LDA.

NIPC: 516723286

Registered office: Alameda das Antas, 30, 4350-413 Porto

Website: www.vexia.com

Vexia has appointed a Data Protection Officer (DPO), who may be contacted for any matter relating to the processing of personal data, the exercise of rights, or clarification regarding this Policy:

DPO email: dpo@vexia.com

In the B2C processing activities in which Vexia acts as a processor, the data controller is the operator client on whose behalf the campaign is run; in such cases, the data subject should, in the first instance, address that controller, without prejudice to Vexia providing the assistance due.

The website www.vexia.com is the common institutional point of presence of the Vexia group, which includes, in addition to VEXIA, LDA., other companies in different jurisdictions. Depending on the operation, the market and the location of the data subject, the processing of personal data may be carried out by one of these companies, which assumes, to that extent, the position of data controller. The group companies are, namely:

  • VEXIA, LDA. — NIPC 516723286; registered office at Alameda das Antas, 30, 4350-413 Porto, Portugal (operational parent company of the group);
  • LSPT, UNIPESSOAL LDA. — NIF/NIPC 513410961; registered office at Alameda das Antas, 30, 4350-413 Porto, Portugal;
  • LS BRASIL LTDA. — CNPJ 61.886.151/0001-83; registered office at Av. Pref. Osmar Cunha, 416, Edif. Koerich, salas 1108/2104, CEP 88.015-100, Centro, Florianópolis, Santa Catarina, Brazil;
  • LS MALTA HOLDING and LS MALTA LIMITED — LS Malta Limited with registration number C110898, VAT number MT31611502, registered office at 2, Triq Sir Augustus Bartolo, Ta’ Xbiex, XBX 1091, Malta.

Depending on the applicable jurisdiction, the processing of personal data may be subject, in addition to the General Data Protection Regulation (GDPR) in the European Union, to the Brazilian General Data Protection Law (Law No. 13,709/2018 — “LGPD”) with regard to activity and clients in Brazil, and to the Maltese data protection regime with regard to activity conducted from Malta. Depending on the case, the competent supervisory authority may be the National Data Protection Commission (CNPD) in Portugal, the National Data Protection Authority (ANPD) in Brazil, or the Information and Data Protection Commissioner (IDPC) in Malta. Where they wish to exercise rights or obtain clarification, the data subject may address the group DPO, who will forward the request to the competent responsible entity.

Scope of application

This Policy applies to the personal data processed in relation to:

  • visitors and users of the website www.vexia.com (B2B);
  • persons who use the “Book a Meeting” functionality or other contact forms (B2B);
  • representatives, employees, collaborators or professional contacts of clients, operators, prospective clients, suppliers and partners (B2B);
  • end consumers, users, audiences, leads or players impacted by digital campaigns, conversions, reporting, analytics, custom audiences, first-party data, custom data processing or custom modelling carried out by Vexia on behalf of clients (B2C);
  • users of any restricted areas, dashboards or accounts associated with Vexia, where they exist (B2B);
  • persons who interact with Vexia by email, social networks, telephone, meetings, events or other digital channels (B2B).

Vexia's roles: controller, processor or joint controller

Vexia's legal qualification depends on the specific processing activity and the applicable model, and must be documented on a case-by-case basis:

  • data controller (mainly in B2B): when it determines the essential purposes and means, for example in the management of the website, of “Book a Meeting”, of contacts, of its own communications, of security, of internal administration and of its channels;
  • processor (mainly in B2C): when it processes consumer data on behalf of an operator client, according to documented instructions, in the context of campaigns, media buying, analytics, reporting, dashboards, custom processing or technical services;
  • joint controller (mainly in B2C): when it determines jointly with clients, platforms, partners or social networks the purposes and means of certain processing activities, in particular in targeting, audiences, conversions, attribution, social media and AdTech operations.

Wherever applicable, the qualification must be reflected in contracts, data processing addenda (Article 28 GDPR), joint controllership arrangements (Article 26 GDPR), risk assessments, data protection impact assessments and records of processing activities (Article 30 GDPR).

Categories of personal data processed

6.1. Professional contact data (B2B), provided directly

In the context of the institutional and commercial relationship, we may process data provided through the website, through “Book a Meeting”, through emails, meetings, events or other channels, including:

  • first name and surname;
  • professional email;
  • telephone number;
  • company, brand, operator, job title, function or professional area;
  • country, market of interest and relevant jurisdiction;
  • message, meeting subject or description of the need;
  • scheduling data, meeting date and time, time zone and booking history;
  • communication preferences, consents, objections and permission history;
  • support data, requests for information or requests to exercise rights.

6.2. Technical and website browsing data (B2B)

When you use the website, technical and browsing data may be processed, namely:

  • IP address;
  • session identifiers;
  • date and time of access;
  • pages visited and interactions carried out;
  • access source/referrer;
  • device type, operating system, browser, language and screen resolution;
  • technical logs, security logs and error events;
  • identifiers associated with cookies, pixels, tags or equivalent technologies, where applicable and on the terms legally required.

6.3. Campaign, audience and AdTech data (B2C processing)

In the context of running campaigns on behalf of clients, and depending on the project and the applicable legal qualification, Vexia may process the following categories of end consumer data:

  • audience data, segments, interests, affinities and browsing context;
  • conversion events, clicks, impressions, leads, registrations, installs, application events and performance metrics;
  • online identifiers, advertising identifiers, device IDs, cookie IDs, user IDs or pseudonymised identifiers;
  • approximate location data or geographic market, where necessary for the campaign;
  • campaign, attribution, optimisation, bidding, performance, dashboard and report data;
  • first-party data provided by clients or operators, where contractually provided for and legally admissible;
  • pseudonymised, aggregated or derived data used for custom data processing, custom modelling, optimisation, segmentation or reporting;
  • data necessary for the detection of invalid traffic, fraud, bot traffic, VPN traffic, security, brand safety and compliance with legal or contractual requirements.

Vexia seeks to process, wherever possible, pseudonymised or aggregated data. Campaign identifiers such as GCLID, DCLID, Click ID or FBCLID consist of tokens randomly generated by the platforms to distinguish users; when integrated into Vexia's systems, they function as pseudonymised identifiers, with browsing remaining not directly identifiable until the user consents to the sharing of personal data through forms or direct contacts. Vexia should not receive or process special categories of personal data, within the meaning of Article 9 GDPR, unless this is expressly identified, documented and supported by an appropriate legal basis. In regulated sectors, such as iGaming, betting, casino or digital entertainment, Vexia applies enhanced safeguards, even though the data processed is not, in itself, of special categories.

6.4. Account, restricted area or login data, if applicable (B2B)

  • name, email and company;
  • protected authentication credentials;
  • user profile, permissions and access levels;
  • authentication history, access logs and actions performed;
  • data necessary for account management, security, prevention of unauthorised access and support.

6.5. Social media data and external links

When you interact with Vexia's pages, profiles or content on social networks, we may process data visible on the profile, identifiers, comments, messages, reactions, aggregated statistics and interaction metrics. Social media platforms also process personal data in accordance with their respective privacy policies, as autonomous controllers or joint controllers, as the case may be.

Sources of personal data

Personal data may be obtained:

  • directly from the data subject (B2B), through “Book a Meeting”, emails, meetings, events or digital interactions;
  • automatically, through the device, browser, cookies, pixels, tags, logs, analytics or similar technologies;
  • through clients and operators, advertising platforms, social networks, DSPs, analytics providers, CRM or reporting systems (B2C), in the context of running campaigns;
  • through public or professional sources, where necessary for commercial contacts or pre-contractual steps and always in a proportionate manner (B2B).

Purposes, model, legal bases and retention periods

Vexia processes personal data only where there is an appropriate legal basis. The following table forms part of this Policy and identifies, for each main processing activity, the applicable model (B2B or B2C), the purpose, the legal basis and the maximum retention period.

Unless otherwise indicated, the periods are counted from the collection, the last relevant interaction, the end of the campaign, the end of the contractual relationship, the closure of the request, or the event justifying the retention. Where there is a legal obligation, litigation, audit, investigation, order of a competent authority or a demonstrated need to defend rights, the strictly necessary data may be retained for the applicable additional period.

Processing / purpose (model)Examples of dataLegal basisRetention period
Technical operation of the website (B2B)IP, technical logs, device, browser, error events.Legitimate interest in making the website available and operational.12 months.
Security, fraud prevention and incident response (B2B)Security logs, IP, suspicious events, access attempts, incident evidence.Legitimate interest; compliance with legal obligations where applicable.24 months after the event or closure of the incident.
Management of cookie preferences (B2B)Preference of acceptance, rejection or configuration.Legal obligation and legitimate interest in demonstrating compliance.6 months for the active preference.
Proof of cookie consent or refusal (B2B)Date, time, banner version, choice and consent identifier.Legal obligation and legitimate interest in demonstrating compliance.24 months after the last choice.
Website analytics (B2B)Browsing data, events, pages visited, aggregated or pseudonymised metrics.Prior consent, as they involve non-essential cookies/technologies with access to the terminal (e.g. GA4). Legitimate interest is only admissible for measurement strictly without access to the terminal and without identifiers.14 months.
“Book a Meeting” request or initial contact (B2B)Name, email, company, job title, telephone, message and scheduling data.Pre-contractual steps; legitimate interest in managing the contact.12 months after the meeting, no-show or last contact attempt, if there is no subsequent relationship.
B2B leads and commercial contacts with relevant interactionProfessional contacts, meeting history, commercial notes and preferences.Legitimate interest; pre-contractual steps; performance of a contract with the represented entity.24 months after the last significant interaction.
Management of commercial proposals (B2B)Contact data, needs, documents, proposals and communications.Pre-contractual steps; legitimate interest.3 years after closure of the opportunity, if not awarded.
Commercial communications and professional content to B2B contactsName, professional email, preferences, sending history, opens and clicks.Consent; or legitimate interest/soft opt-in only in the cases legally permitted for professional contacts.Until withdrawal of consent/objection or 24 months without interaction, whichever occurs first.
Proof of marketing consent (B2B)Date, time, source, accepted text, form version and IP where necessary.Obligation to demonstrate consent; legitimate interest.3 years after withdrawal of consent or last sending.
Marketing objection/suppression list (B2B)Email, channel, date of objection and reason if indicated.Legal obligation; legitimate interest in respecting the objection.5 years after the objection request.
Management of clients/operators, partners and contracts (B2B)Contacts, job title, communications, contracts and relationship history.Performance of a contract; legitimate interest; legal obligation.During the contractual relationship. After its termination: contractual, tax and accounting documentation for 10 years (Article 40 of the Commercial Code and tax legislation); remaining relationship data for 3 years, save for the defence of rights.
Campaign execution, reporting and attribution (B2C)Events, conversions, metrics, pseudonymised identifiers and reports.Processing on behalf of the operator (documented instructions); performance of a contract; joint controllership and consent for cookies/pixels where applicable.12 months after the end of the campaign, save for instruction/period set by the controller.
Dashboards and aggregated/pseudonymised reporting (B2C)Performance metrics, aggregated indicators and campaign reports.Performance of a contract; legitimate interest of the operator; processing on its behalf.24 months after the end of the campaign or project.
Custom audiences, lookalikes and segmentation (B2C)Pseudonymised identifiers, segments, conversion events and audiences.Consent of the data subject obtained by the controller/operator where required; joint controllership; legitimate interest only where legally admissible and after a balancing test.6 months after the end of the campaign or withdrawal of consent/objection, whichever occurs first.
Custom data processing, custom modelling and AI applied to campaigns (B2C)Pseudonymised data, models, indicators, performance signals and segments.Processing on the basis of documented instructions; performance of a contract; consent where required at the level of the controller.12 months after the end of the project, save for validated anonymisation.
Detection of invalid traffic, anti-fraud and brand safety (B2C)Bot/VPN traffic signals, IP, technical events and risk indicators.Legitimate interest of the operator and of Vexia in the integrity of the campaigns; processing on its behalf.12 months, save for the need for investigation or defence of rights.
Restricted area, account or login, if applicable (B2B)Account, permissions, protected credentials and access history.Performance of a contract; legitimate interest in security and access management.While the account is active and 24 months after deactivation.
Authentication logs, if applicable (B2B)Date, time, IP, user and login success/error.Legitimate interest in security.12 months.
Social media interactionsMessages, comments, reactions, identifiers and aggregated metrics.Legitimate interest in community management and institutional communication; consent where applicable.24 months after the last interaction, save for earlier deletion by the data subject or the platform.
Requests to exercise rightsIdentification, request, communications and evidence of response.Compliance with a legal obligation.3 years after closure of the request.
Complaints, disputes and defence of rightsCommunications, documents, evidence and data necessary for the defence.Legitimate interest; exercise or defence of rights; legal obligation.Until definitive closure of the proceedings and 6 additional months.
BackupsBackup copies of the applicable systems.Legitimate interest in security, continuity and recovery.Deletion, rotation or replacement within a maximum period of 90 days.

Mandatory or optional nature of the data

In the B2B model, the provision of certain data may be necessary in order to respond to a request, book a meeting, create an account or perform a contractual relationship. Where the data is necessary and is not provided, Vexia may be unable to respond to the request, make the functionality available or provide the service.

In the B2C model, consumer data is, as a rule, collected at the level of the operator client and the platforms, in the context of campaigns; the basis and the mandatory nature are defined by the data controller. Where the processing is based on consent, the provision of the data is optional and its refusal or withdrawal does not prejudice access to the essential functionalities.

Cookies and similar technologies

The website may use cookies and similar technologies, including tags, pixels, SDKs, local storage or equivalent identifiers. Vexia provides a consent management tool that allows non-essential cookies to be accepted, rejected or configured in a free, specific, informed and unambiguous manner.

Strictly necessary cookies may be used to ensure technical operation, security, session management, fraud prevention and the recording of consent preferences. Analytics, measurement, advertising, social media, remarketing, conversion or personalisation cookies should only be used where there is an appropriate legal basis, in particular prior consent where required.

The Cookie Policy contains, in an up-to-date manner, the list of cookies and technologies actually used on the website, including name, provider, purpose, category, duration and indication of international transfers, where applicable.

“Book a Meeting”, forms and restricted areas (B2B)

In “Book a Meeting” and in any website form or restricted area, Vexia ensures clear information at the time of collection, including the purpose, the controller, the link to this Policy, the mandatory fields and, where applicable, the consent options. This functionality is currently operated through a third-party tool (HubSpot or equivalent), which may entail processing by a processor and international transfers, on the terms of sections 13 and 14.

Acceptance of Terms of Use, where it exists, must be separate from the privacy information. The Privacy Policy must not be presented as mandatory consent, save where there is a purpose actually based on consent. Consent for direct marketing, newsletters or sharing with partners must be collected in a separate, granular, non-pre-selected option that can be evidenced.

Direct marketing and electronic communications (B2B)

Vexia's marketing communications are addressed, in the context of the website, to professional contacts of brands, operators and partners. Vexia will only send commercial communications, invitations or professional content where there is an appropriate legal basis, as a rule prior consent, without prejudice to the exceptions legally permitted for professional contacts.

The data subject may withdraw consent or object to the sending of commercial communications at any time, through the mechanisms indicated in the communications or by contacting Vexia through the means indicated in this Policy.

Sharing of personal data

Vexia may share personal data with the following categories of recipients, where necessary and proportionate:

  • Vexia group companies, for internal management, provision of services, support, reporting or compliance with legal obligations;
  • providers of hosting, cloud infrastructure, security, maintenance, development and website management;
  • providers of CRM, email marketing, scheduling and contact management, namely HubSpot, Brevo and Salesforce, for “Book a Meeting”, communications and commercial management (B2B);
  • providers of analytics, consent management, tag management, digital advertising, social media, DSPs, ad servers, conversion platforms, automation, dashboards and campaign measurement, namely Google Analytics 4, Campaign Manager 360, EPOM, Google Ads, Search Ads 360, Adform, Astrad, Meta, YouTube, X, LinkedIn, TikTok, Reddit, Zapier, ManyChat and StatScore (B2C);
  • clients and operators, advertisers, publishers, advertising platforms and social networks, where necessary for running campaigns, reporting, attribution, anti-fraud or brand safety (B2C);
  • external technology partners that support, directly or indirectly, the technology and media teams, namely TRKKN, Axtro Tech and Prime IT, in the context of technical implementation, support and operation of tools;
  • legal, financial, accounting, tax advisers, auditors and insurers;
  • public authorities, courts, regulatory, inspection or supervisory entities, where legally required.
  • third parties involved in a possible corporate transaction, such as a merger, acquisition, restructuring or total or partial sale of Vexia's assets, in which case the personal data may be among the transferred assets, with its protection being maintained on the terms of this Policy and applicable law.

Where third parties process personal data on behalf of Vexia, they must do so under a processing contract that complies with Article 28 GDPR. Where there is joint controllership, the responsibilities of the parties must be defined in an appropriate arrangement on the terms of Article 26 GDPR and communicated to the data subjects where required.

International data transfers

Due to the nature of the media and AdTech activity, some providers and platforms used by Vexia or by its clients — namely Google (Google Ads, Search Ads 360, GA4, Campaign Manager 360, YouTube), Meta, X, LinkedIn, TikTok, Reddit, DSPs such as Adform and Astrad, ad servers such as EPOM, CRM and email tools such as HubSpot, Brevo and Salesforce, and automation tools such as Zapier and ManyChat — may be located outside the European Economic Area, in particular in the United States of America, or may process data in third countries. Although most of these platforms record the user's IP address, that information is, as a rule, not provided to Vexia.

Where there is an international transfer of personal data, Vexia ensures, to the extent of its role, that the transfer is based on a valid mechanism on the terms of Chapter V of the GDPR, including an adequacy decision of the European Commission, participation of providers in the EU-US Data Privacy Framework where applicable, Standard Contractual Clauses and supplementary measures where necessary.

In the B2C processing activities in which Vexia acts as a processor, the selection of the providers and the transfer mechanisms is, as a rule, defined or approved by the responsible operator client, with the support and diligence of Vexia. The list of providers contained in the Cookie Policy indicates, wherever possible, the countries of transfer and the applicable safeguards.

Profiling, segmentation, modelling and automated decisions

In the B2C model, Vexia uses personal or pseudonymised data for segmentation, measurement, reporting, custom audiences, lookalikes, custom data processing, custom modelling, campaign optimisation, anti-fraud and performance analysis, depending on the project, the legal role assumed and the applicable lawful basis.

In the context of the website www.vexia.com, Vexia does not take solely automated decisions that produce legal effects on the user or that similarly significantly affect them. Where there are profiling or modelling operations in B2C campaigns, the definition of purposes and the information to the consumer rest, as a rule, with the responsible operator client; Vexia ensures, depending on its role, a valid legal basis, minimisation, risk assessment and, if necessary, a contribution to the data protection impact assessment.

Where Vexia uses artificial intelligence systems for segmentation, modelling, optimisation or measurement of campaigns, it does so on the basis of pseudonymised or aggregated data wherever possible, under human supervision and with a prior risk assessment. Vexia follows the application of Regulation (EU) 2024/1689 (the Artificial Intelligence Act) and adopts the governance, transparency and documentation measures required in light of its role as provider or as deployer of the system, without prejudice to the responsibilities of the operator client. In any case, these systems do not take, in the context of the website, solely automated decisions with legal or similarly significant effects for the user, within the meaning of Article 22 GDPR.

Minors, regulated sectors and iGaming

Vexia operates in a regulated sector — iGaming, sports betting, casino and poker — and attaches particular importance to the protection of minors and vulnerable audiences. Vexia's website and services are not intended for minors and Vexia does not knowingly collect data of minors through the website.

In the campaigns run on behalf of operators, Vexia applies enhanced safeguards, including the exclusion of minors, the limitation of targeting to audiences aged 18 or over (or the minimum legal age applicable in the jurisdiction), respect for responsible gaming and responsible advertising rules, the assessment of vulnerability risks and the prior compliance validation of each campaign, jurisdiction and operator.

The ultimate definition of the target audience and compliance with licensing, age restriction and responsible gaming obligations rest with the responsible operator client; Vexia refuses, suspends or ceases campaigns where it identifies a risk of non-compliance with these requirements.

Social networks, social buttons and external links

The website may contain links to social networks and third-party platforms. When the user clicks on these links, they begin browsing in an environment external to Vexia, subject to the privacy policies, cookie policies and terms of use of those platforms.

If the website uses social buttons, plugins, pixels, tags, SDKs or social login that allow data collection, such collection is described in the Cookie Policy and depends on consent where legally required. Social media platforms also process data as autonomous controllers or joint controllers, as the case may be.

Security of personal data

Vexia adopts technical and organisational measures appropriate to the risk, intended to protect personal data against destruction, loss, alteration, disclosure or unauthorised access, whether accidental or unlawful. These measures may include, depending on the system and the risk:

  • access control and management of permissions by profile;
  • strong authentication, individual credentials and MFA wherever applicable;
  • encryption or pseudonymisation where appropriate;
  • access logs and monitoring of security events;
  • backups and continuity measures;
  • segregation of environments and the principle of least privilege;
  • incident and personal data breach management procedures;
  • assessment of providers and processing contracts;
  • internal policies on confidentiality, security and data protection.

In the event of a personal data breach, Vexia assesses the risk and, where it acts as data controller, notifies the CNPD on the terms of Article 33 GDPR, without undue delay and, wherever possible, within 72 hours, communicating to the data subject on the terms of Article 34 where the breach is likely to result in a high risk to their rights and freedoms. Where it acts as a processor, Vexia informs the data controller without undue delay, providing it with the cooperation due. Vexia keeps an internal record of breaches, of the measures adopted and of the respective justification.

Rights of the data subjects

Under the GDPR, data subjects may exercise, where applicable, the following rights:

  • the right of access to personal data;
  • the right to rectification of inaccurate or incomplete data;
  • the right to erasure of the data;
  • the right to restriction of processing;
  • the right to object to processing, including objection to direct marketing;
  • the right to data portability, applicable only to processing based on consent or on the performance of a contract and carried out by automated means;
  • the right to withdraw consent at any time, without compromising the lawfulness of the processing carried out on the basis of the previously given consent;
  • the right not to be subject to solely automated decisions, including profiling, where they produce legal effects or similarly significantly affect the data subject, on the terms legally provided for;
  • the right to lodge a complaint with the competent supervisory authority.

To exercise rights, the data subject may contact Vexia through the email dpo@vexia.com, the DPO contact. Vexia may request additional information strictly necessary to confirm the identity of the requester or to understand the request.

Vexia responds to requests to exercise rights within one month from receipt of the request, extendable by up to two additional months depending on the complexity or the number of requests, with the data subject being informed of the extension within the first month.

Important: in the B2C processing activities in which Vexia acts as a processor on behalf of an operator client, the data subject should address the request, in the first instance, to that data controller. Vexia will forward the request to the controller or provide it with assistance, on the terms of the applicable contract, it not being for Vexia to decide autonomously on that data.

Vexia does not treat the data subject in a discriminatory or unfavourable manner by reason of their exercise of any of the rights provided for in this Policy and in the applicable data protection legislation.

“Do Not Track” (DNT) signals: some browsers allow “Do Not Track” signals to be sent to websites. As there is currently no recognised uniform standard for their handling, the website does not, at this time, respond to DNT signals or similar mechanisms. The user may, nevertheless, manage their cookie preferences through the consent management tool and the browser settings, on the terms of the Cookie Policy.

Complaints to the supervisory authority and Complaints Book

Without prejudice to being able to contact Vexia or the DPO beforehand, the data subject has the right to lodge a complaint with the competent supervisory authority. In Portugal, it is the National Data Protection Commission (“CNPD”), with website at www.cnpd.pt. Depending on the jurisdiction applicable to the processing, the National Data Protection Authority (“ANPD”) in Brazil or the Information and Data Protection Commissioner (“IDPC”) in Malta may also be competent, without prejudice to the right to lodge a complaint with the supervisory authority of the Member State of habitual residence, place of work or alleged infringement.

This Policy concerns the protection of personal data and does not prejudice other means of complaint or dispute resolution legally available. Since the website is of an institutional and B2B nature, and since Vexia does not establish through it consumer relationships with end consumers, the regime of the Complaints Book and the regime of alternative consumer dispute resolution are not, as a rule, applicable. Should Vexia come to establish direct consumer relationships, it will make available the Electronic Complaints Book and information on the competent alternative dispute resolution entity, on the applicable legal terms.

Retention, deletion and anonymisation

The specific retention periods are set out in the table in section 8 of this Policy, which forms an integral part of the information provided to data subjects.

Once the applicable periods have elapsed, the data will be deleted, anonymised or securely archived where there is an obligation or legitimate basis for additional retention. Irreversibly anonymised data may be retained without a time limit. Deletion in backups occurs by rotation, replacement or technical deletion within the maximum period indicated in section 8.

Changes to this Policy

Vexia may update this Policy whenever necessary, in particular in the event of a change to the website, the tools used, the processing purposes, the providers, the business models, the applicable legislation or the guidance of the competent authorities.

The version in force will be published at www.vexia.com, with an indication of the date of the last update.

Language

This Policy may be made available in Portuguese and in English. In the event of a divergence of interpretation between language versions, and save where the applicable law imposes a different solution, the Portuguese version prevails.