Privacy
Privacy Policy
This policy explains how S4P - Realestate, Lda. (the data controller) collects, uses, and protects personal data when you visit s4p-realestate.pt. It implements the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and Portuguese Law no. 58/2019. Where the Portuguese and other language versions diverge, the Portuguese version governs.
§ 1
Data controller
S4P - Realestate, Lda. · info@s4p-realestate.pt
We have not appointed a Data Protection Officer because the thresholds of Article 37 GDPR are not met. For any privacy question, write to the address above.
§ 2
Scope
This policy covers personal data processed through this website only. There is no public booking flow, no account creation, and no online payments. Off-site interactions (email correspondence, on-site stays) follow the same principles but are governed by separate agreements.
§ 3
Data processed, purposes and legal bases
- Edge request metadata (Cloudflare)
- This site is delivered as static pages from Cloudflare's edge network; we do not operate an origin server that logs your visit. When you load a page, our hosting provider Cloudflare records technical request metadata at its network edge — the IP address, browser User-Agent, requested URL, timestamp, and HTTP status — for security, abuse prevention, and content delivery.
- Contact form
- If you submit the contact form, your browser opens an email message in your mail client addressed to info@s4p-realestate.pt and pre-filled with the name, email address, and message you provided. The submission does not pass through any application server of ours — only the email itself arrives at our mailbox once you press send.
- Cookies
- We set only Cloudflare's strictly-necessary cookies (__cf_bm, cf_clearance) for bot detection and challenge clearance. We do not use analytics, marketing pixels, font CDNs, or third-party embeds. See the dedicated Cookies page for the full inventory.
§ 4
Legal bases (Art. 6 GDPR)
Each processing activity has its own legal basis under Article 6 of the GDPR.
- Edge request metadata
- Article 6(1)(f) GDPR — legitimate interest in maintaining a secure, available, and abuse-free service. A balancing test shows no overriding rights of the data subject.
- Contact form
- Article 6(1)(f) GDPR — legitimate interest in responding to enquiries about the property. The mail you compose is sent from your own email account; we receive it and may reply to the address it came from.
- Strictly-necessary cookies
- Article 6(1)(f) GDPR read with Article 5(2) of Portuguese Law no. 41/2004 (ePrivacy) — strictly-necessary cookies for security and challenge clearance, exempt from consent.
§ 5
Recipients and processors
We share personal data only with the processors strictly required to operate the site. Each is bound by a Data Processing Agreement under Article 28 GDPR.
- Cloudflare, Inc. (USA) — content delivery network, DDoS protection, and bot management; processes IP and request metadata at the network edge.
- Our email host (dominios.pt, Portugal) — stores replies and any further correspondence in our business mailbox.
§ 6
International transfers
Cloudflare is established in the United States. IP addresses and request metadata may be processed there for content delivery and security. Cloudflare is certified under the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795), which provides an adequate level of protection within the meaning of Article 45 GDPR.
As an additional safeguard, our Data Processing Agreements incorporate the EU Standard Contractual Clauses (Decision (EU) 2021/914 of 4 June 2021). You may obtain a copy of these safeguards by writing to the address above.
§ 7
Retention periods
We retain personal data only for as long as is necessary for the purpose for which it was collected, subject to the following ceilings:
- Edge request metadata is retained by Cloudflare under its own retention schedule; we do not keep our own server access logs.
- Contact enquiries (email correspondence sent from the mailto: form and stored in our mailbox) — up to 12 months from last contact, then deleted unless an active business relationship requires retention.
- Business mailbox correspondence — up to 2 years, then archived offline; without prejudice to applicable tax and accounting retention obligations.
§ 8
No automated decision-making
We do not use your personal data for automated decision-making or profiling within the meaning of Article 22 GDPR.
§ 9
Your rights
Under Articles 15 to 22 of the GDPR, you have the right to access your data, have inaccurate data rectified, request erasure (the “right to be forgotten”), restrict our processing, receive your data in a portable format, and object to processing based on legitimate interest. To exercise any of these, write to info@s4p-realestate.pt and we will respond within one month (Article 12(3) GDPR).
Where processing is based on your consent or on Article 6(1)(b) GDPR (pre-contractual steps), you may withdraw at any time without affecting the lawfulness of processing carried out before the withdrawal.
§ 10
Right to lodge a complaint
If you believe your data has been processed unlawfully, you have the right to lodge a complaint with the Portuguese supervisory authority:
Comissão Nacional de Protecção de Dados (CNPD)
Av. D. Carlos I, 134 — 1.º
1200-651 Lisboa, Portugal
§ 11
Children
This site is not directed at children. Under Article 16 of Portuguese Law no. 58/2019, the minimum age for valid consent to information-society services is 13. We do not knowingly collect data from anyone under 13; if we discover we have, we will delete it without delay.
§ 12
Changes to this policy
We may update this policy to reflect changes in our processing or in the law. The “last updated” date at the bottom of this page indicates the most recent revision. Material changes will be communicated through the site itself.
Last updated · 2026-05-21