Privacy Policy
FIO CRBZ Sociedade de Advogados, SP RL
About Us
Welcome to our privacy policy (“Privacy Policy”), which describes how we handle and protect your personal data when you use our website (referred to as “services”).
These services are managed by FIO CRBZ Sociedade de Advogados, SP RL, located at Avenida 5 de Outubro, 56, 8.º andar, 1050-058, Lisbon (referred to as “the Company”, “we”, “our” or “us”). The Company is responsible for the data processing activities detailed in this policy and acts as the data controller.
Unless otherwise specified in this Privacy Policy, the terms used herein have the same definitions as set forth in the European Union General Data Protection Regulation (“GDPR”).
The personal data we collect
Categories of Personal Data Collected
We collect personal data for different purposes related to our business operations as you use our services. In particular, we process:
Basic identification (e.g., name);
Contact details (e.g., email address);
Communication data (e.g., details and content of your inquiries, email exchanges);
Social media activity (e.g., social media profiles);
Professional details (e.g., CV, cover letter, employment history, professional qualifications, position and occupation);
Visual content (e.g., photos/testimonials);
Online identifiers (e.g., IP address, log files);
Survey information and feedback (e.g., testimonials).
You are not required to provide your personal data. However, it is important to know that we cannot provide our services without the personal data essential to fulfill the contractual obligations between you and us.
How we collect it
We obtain information about you as you interact with us. This includes:
Direct collection
When you submit inquiries or feedback through our contact forms;
When you communicate with us by email;
When you provide us with your personal data through the recruitment form;
When you subscribe to our newsletter;
When you provide us with testimonials.
Indirect collection
Through our service providers;
From public sources, social media, and internet searches.
Why we collect personal data
Summary of data processing purposes
Our legal basis for collecting and processing personal data, as described in this Privacy Policy, depends on the category of data collected and the purposes for which it is collected.
Contractual Obligations: We collect and process personal data to fulfill our contractual obligations or take pre-contractual steps related to a contract to be entered into with you. In particular, we rely on contractual obligations to:
Provide our services;
Provide customer support and respond to your inquiries;
Register and manage your application for job opportunities.
Consent: We may rely on your voluntary consent, provided when we collect your personal data. In particular, we rely on your consent to:
Send newsletters and other update and marketing messages;
Publish your testimonials, including photos and job title;
Store your recruitment data for future contact.
Legitimate Interests: We use legitimate interests as a legal basis for processing your personal data, based on the assessment that the processing is necessary and proportionate, without infringing on your fundamental rights or freedoms. In particular, we rely on our legitimate interests to:
Maintain and improve our services through your feedback;
Detect, prevent, and address security threats, as well as prevent fraud and suspicious activities.
Legal Compliance: We process personal data when necessary to comply with legal and regulatory obligations. In particular, we rely on compliance with legal obligations to:
Comply with applicable regulations and legislation;
Legally enforce rights and claims.
Our data processing in detail
Contact forms
You may use the contact forms we provide to contact us with any request. We will process the personal data included in your messages – such as your name, email address, and other information you choose to provide – solely to respond to your request. We do this to take steps before entering into a contract with you, at your request, or to perform an existing contract.
Our vacancies
We present our vacancies on the website, allowing you to apply. To do so, we collect the personal data you provide in the application form, namely your identification data, contact information, as well as your professional and educational details. We store your personal data for a period of 6 months after your application for processing purposes. We do this to take steps at your request before entering into an employment contract with you.
Newsletter subscription
We send newsletters and various notifications via email and other communication channels, and may use third parties to facilitate delivery.
You must provide explicit consent to receive newsletters and other notifications, unless communication is permitted for other legal reasons. We implement the “double opt-in” method for email consent, sending an email with a link to confirm consent. This process aims to prevent misuse by unauthorized third parties. We may record the consent, including the IP address, date, and time.
Newsletters and notifications may include tracking links or pixels, which record whether they were opened and which links were clicked. We use this statistical data to provide newsletters effectively and tailored to the recipients’ preferences.
You may unsubscribe at any time by objecting to the aforementioned data collection. To do so, you can contact us directly or use the unsubscribe link present in the footer of each newsletter.
Links to third-party applications and websites
Our platform contains links to websites or applications that are not operated by us. By clicking on a third-party link, you will be directed to the respective website or application. We do not control the content, privacy policies, or practices of these third parties.
We also maintain a presence on social networks to communicate with clients and potential clients and to promote our products and services. If you have an account on the same network, it is possible that your information will be made available to us when we access your profile.
Below is the list of social networks on which we are present:
LinkedIn: Privacy Policy;
X (Twitter): Privacy Policy;
Instagram: Privacy Policy.
How long we store personal data
We retain personal data for the period necessary to fulfill the purposes for which it was collected, in compliance with applicable legal, regulatory, and contractual obligations. After this period, we delete the personal data or irreversibly anonymize it.
Who we share personal data with
Our service providers
We collaborate with third parties to support the operation of our services, who may access your data only to the extent necessary to perform their functions.
Categories of service providers that may access your personal data:
Cloud, hosting, and infrastructure service providers;
IT and security services;
Software providers;
Email and communication services;
Online meeting providers;
Social media and content platforms.
Transfers to Third Countries
We use service providers located outside the EU/EEA. To ensure the security of your personal data, we adopt appropriate safeguards, such as the European Commission’s standard contractual clauses.
To ensure the security of your personal data during these transfers, we comply with applicable legal obligations by adopting appropriate safeguards. These safeguards include:
– Data transfer to countries that have received an adequacy decision from the European Commission.
– Implementation of standard contractual clauses provided by the European Commission, in accordance with Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as well as supplementary measures for the transfer, whenever we consider that such measures are necessary to ensure a level of protection essentially equivalent to that of the EU. In the event of a transfer to a third country where there are no adequacy decisions or appropriate safeguards, it is conceivable that third-country authorities, such as intelligence services, may access the transferred data. Consequently, the applicability of the data subject’s rights may not be guaranteed.
We and/or our service providers transfer your personal data and process it in countries outside the EU/EEA. These countries include:
– United States of America.
In cases where the transfer to a third country is based on the use of standard contractual clauses provided by the European Commission, you have the right to request a copy of the clauses under which your personal data is transferred to a third country. However, the contract may be redacted in parts that must remain confidential (i.e., the personal data of other people). You can request the applicable copies by contacting: info@fiolegal.com.
Data disclosure
We may disclose your personal data when we sincerely believe that such disclosure is essential for the following purposes:
– To comply with a legal obligation, which includes cases where such disclosure is required by law or in response to legal requests from public authorities, such as a court or a government agency.
– To safeguard the security of our services and safeguard our rights or property.
– To prevent or investigate potential illegal conduct related to our operations.
How we keep personal data secure
We implement reasonable technical and organizational security measures that we consider appropriate to protect your stored personal data against manipulation, loss, or unauthorized access by third parties. Our security measures are continuously updated to align with technological advancements.
We place a significant emphasis on internal data privacy. Our staff and contracted service providers are bound by confidentiality and must comply with relevant data protection laws. Furthermore, they are only granted access to personal data to the extent necessary for the performance of their respective duties or obligations.
We value the security of your personal data; however, please be aware that no method of data transmission over the Internet or electronic storage can be guaranteed to be 100% secure. While we make every effort to employ commercially reasonable measures to protect your personal data, we cannot guarantee absolute security. We recommend the use of antivirus software, firewalls, and similar tools to enhance your system’s protection.
Your rights
You possess the following data protection rights. To exercise these rights, please contact us at the address provided or send an email to info@fiolegal.com. Please note that we may ask you to verify your identity before responding to your requests.
Right of access: You have the right to request a copy of your personal data, which will be provided to you in electronic format.
Right to rectification: You can request that we rectify any inaccuracies or incomplete data.
Right to withdraw consent: If you have given your consent for the processing of your personal data, you have the right to withdraw it at any time, affecting future processing. This applies, for example, when you wish to opt out of receiving marketing communications. Once we receive your withdrawal of consent, we will stop processing your information for the purpose(s) you initially consented to, unless there is another legal basis for the processing. Right to erasure: You have the right to request the erasure of your personal data when it is no longer necessary for the purposes for which it was collected, or if it has been processed unlawfully.
Right to restrict processing: You can request the limitation of our processing of your personal data in cases where you consider it to be inaccurate, unlawfully processed, or no longer necessary for the original purpose, but cannot be erased due to legal obligations or your own request. Right to data portability: You can request that we transmit your personal data to another data controller in a standard format (e.g., Excel), if you have provided us with that data and we have processed it based on your consent or to fulfill contractual obligations.
Right to object to processing: If the legal basis for processing your personal data is our legitimate interest, you have the right to object to such processing based on your specific situation. We will respect your request, unless we have a compelling legal basis for the processing that overrides your interests or if we need to continue processing the data for legal defense purposes. Right to lodge a complaint with a supervisory authority: If you consider that the processing of your personal data violates data protection laws, you have the right to lodge a complaint with a data protection supervisory authority. In the EU and EEA, you can exercise this right by contacting a supervisory authority in your country of residence, place of work, or where you believe the infringement occurred. You can find a list of the relevant authorities here: https://edpb.europa.eu/about-edpb/about-edpb/members.
We will respond to your requests within 30 days of receipt. This response period may be extended if the request is particularly complex, of which you will be promptly informed. Within this timeframe, we will respond to your request or inform you of the reasons why your request cannot be satisfied.
Changes to this Policy
Our privacy policy may be updated periodically. We advise the data subject to periodically check this privacy policy for any changes.
Whenever possible, we inform data subjects before making these changes, notifying them at least 30 days before the changes take effect.
Changes to this privacy policy take effect from the moment they are published on this page.
Contact us
FIO CRBZ Sociedade de Advogados, SP RL
Avenida 5 de Outubro, 56, 8.º andar, 1050-058, Lisbon
info@fiolegal.com