Privacy and Cookies Policy
This document clearly explains what data we collect when you visit our websites and applications or use our services, what it is used for, and how you can maintain control over it at any time. Where relevant, we also indicate the corresponding GDPR article to ensure this document retains its full legal validity.
We comply with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (“General Data Protection Regulation” or “GDPR”), Law No. 58/2019 of 8 August, and other applicable national and European legislation.
The Rede Vistorias Platform consists of a set of technologies, methodologies, and procedures aimed at conducting, managing, and analyzing real estate inspections, such as photographic recording, information gathering, and report generation. Inspections are carried out directly on-site, with this information recorded at the time the service is provided. When using the Rede Vistorias Platform (both the trial version and the version made available to clients and partners), some data may be processed as explained in this Policy to allow the execution of services.
We update this Policy whenever necessary to reflect changes in legal, technological, or practical aspects of our business. It's worthwhile to revisit this page from time to time, and if there are significant changes, we will post them on our website.
Acceptance of the Privacy Policy
Definitions found in this document
To make this document easy to follow, we explain here some technical terms that appear throughout the text, in line with Article 4 of the GDPR:
- Cookies: A simple text file, the composition of which depends on the email address visited, that stores basic information, including browsing preferences, in text format.
- Personal data: any information relating to an identified or identifiable natural person (“data subject”).
- Special categories of personal data (sensitive data): Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as genetic data, biometric data for
Unequivocally identifying a person, data concerning health or data concerning a person's sex life or sexual orientation (Article 9 of the GDPR).
- Data Controller: The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Subcontractor (Operator): The natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
- Data Protection Officer (DPO): The person designated to act as a communication channel between the data controller, data subjects and the supervisory authority, pursuant to Articles 37 to 39 of the GDPR.
- CNPD: The National Data Protection Commission is the competent supervisory authority in Portugal for overseeing the application of the GDPR.
- Data subject: The natural person to whom the personal data being processed refers.
- Anonymized data: data that, through appropriate techniques, no longer allows for the direct or indirect identification of its owner.
- Pseudonymization: processing of personal data in such a way that it can no longer be attributed to a data subject without the use of additional information, provided that this information is kept separately and subject to technical and security measures.
organizational.
- Treatment: any operation performed on personal data, including collection, recording, organization, structuring, storage, adaptation, consultation, use, disclosure, transmission, dissemination, comparison, interconnection, restriction, erasure or destruction.
- Personal data breach: A breach of security that accidentally or unlawfully leads to the destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
Roles and Responsibilities in Data Processing
Considering the group's transnational architecture, we made clear what the role of
each entity involved:
- Rede Vistorias Portugal (Master Franchisee): This entity decides the purpose and processing of data subjects' information in Portugal, acting as the Data Controller.
- Brazil Inspection Network: It carries out processing operations on behalf of and under the documented instructions of the Rede Vistorias Portugal network, under an intra-group data processing agreement, which includes the Standard Contractual Clauses approved by the European Commission.
- Amazon Web Services (AWS): It is our technology infrastructure provider, responsible for cloud hosting and processing, under a Data Processing Addendum (DPA).
- authority oftroll: In Portugal, it is the CNPD. If you reside in another European Union country, you can also complain to the local supervisory authority in your place of work or where the alleged infringement occurred (Article 77 of the GDPR).
Data collected
We collect different types of data, depending on how you interact with us:
- Registration details: Name, marital status, profession, place of birth, Tax Identification Number (or Taxpayer Identification Number, when applicable), telephone number, email address, gender, language, country, and other information required to complete forms.
- Navigation data: collected by cookies and Google's marketing and SEO tools, which record anonymous data such as location, IP address, and how you arrived at our site (search, direct access, or third-party hyperlink). We track the
Google's privacy policy.
- Meta Pixel/Facebook: It tracks actions performed on the website (such as adding an item to the cart), generating reports with anonymous data, without identifying who is using it.
- WhatsApp: By clicking the WhatsApp button, we gain access to your name and phone number, which we may save for business contact. You can block us or request to be removed at any time.
- Facebook Chat/Meta: When you use the chat, we collect your name and email address, which we may store for business contact. You can request removal at any time.
- Google Forms: We collect data through Google Forms, requesting full name, phone number, email, and general information about your business.
- WordPress cookies: Our platform uses cookies to make browsing more efficient (e.g., server caching), based on anonymous data. They do not access files or programs on your device, and you can remove them whenever you want through your browser history.
- Push notifications: You only receive them if you authorize it, and you can revoke that authorization at any time in your browser or device settings.
- Newsletter: We only collect your email address with your consent to send you offers, promotions, and commercial communications. You can unsubscribe via the cancellation link, by emailing dpo@redevistorias.pt, or through our contact form.
What are cookies and how do we use them?
Cookies are small text files stored in your browser or device when you visit a website. They serve to recognize your preferences and adapt our pages to your needs. For example, the next time you visit our website, your browser will be recognized and configured according to your previous choices.
Cookies typically have an expiration date: some are automatically deleted as soon as you close your browser (session cookies), while others remain stored on your device for longer, until they are manually deleted or expire (persistent cookies).
In this Policy, we may use the following types of cookies:
- Strictly necessary cookies: Essential for our pages to function correctly, for example, to authenticate your login. It is not possible to refuse this type of cookie if you wish to continue accessing our pages.
pages, as they are based on our legitimate interest in ensuring the security and operation of the website (Article 6, paragraph 1, point f, of the GDPR).
- Analytical cookies: These help us understand how our pages are used and how often they are visited, so we can improve the content and your user experience.
- Functionality cookies: They store information you've previously given us, such as your language preferences, to make browsing simpler and more personalized.
Analytics and functionality cookies are only installed with your consent, given via the cookie banner displayed when you visit our website (Article 6, paragraph 1, point a) of the GDPR).
How to manage or reject cookies
If you prefer to refuse the installation of cookies on your device, or remove those that are already there, you can do so directly in your browser settings. Each browser has its own process, so we recommend consulting the manufacturer's instructions:
- Firefox
- Chrome
- Safari
- Microsoft Edge
Third-party cookies
Some pages may include cookies installed by third parties — for example, analytics tools or social networks. We are not responsible for the use that these third parties make of their own cookies, which may continue to monitor your browsing activity.
Online activity continues even after you leave our website. Therefore, we recommend that you regularly manage the cookies installed on your browser.
Does the Inspection Network process children's data?
The Portugal Inspection Network does not collect, nor does it intend to collect, personal data from children. Our services are intended for individuals over 18 years of age, as already explained in the section "Acceptance of the Terms of Use and Privacy Policy". If you are a mother, father, or legal guardian of a child whose data has been provided to the Portugal Inspection Network, please contact us through our Data Protection Officer at [email address] so that this information can be immediately deleted.
Why can we use your data?
Special categories of data (sensitive data)
As a general rule, we do not collect or process sensitive data in the provision of our property inspection services. If, exceptionally, this is necessary, for example, in recruitment processes or due to a specific legal obligation, we will only do so with your explicit consent, or under another condition provided for in Article 9(2) of the GDPR, informing you beforehand of the purpose and the applicable legal basis.
Newsletter and marketing communications
The sending of newsletters and other marketing communications (offers, promotions, news, invitations to events) always depends on your voluntary and active consent (“opt-in”), in accordance with Article 6(1)(a) of the GDPR.
- Voluntary participation: You will only receive communications after expressly indicating this wish, by subscribing to the newsletter or checking a box that is not pre-checked. No marketing options are activated by default.
- Free, specific, informed, and unambiguous consent: We informed you in advance about the purpose, the channels used (email, WhatsApp, push notifications, among others) and the possibility of withdrawing your consent at any time, without affecting the legality of what was done before.
- Independence from the job: accepting marketing communications is never... A condition for using our services. You can be our client without subscribing to the... newsletter (art. 7(4) GDPR).
- Consent registration: We keep a record of when, how and why you gave your consent, so that we can demonstrate our compliance to the CNPD (Portuguese Data Protection Authority), if necessary (principle of accountability, Article 5, paragraph 2, of the GDPR).
- How to unsubscribe (“opt-out”): at any time, simply, via the unsubscribe link in each communication, by email at dpo@redevistorias.pt or through our contact form. Unsubscribing takes effect immediately, with a short technical period required to update the systems.
How we handle your data
- We follow the principles of Article 5 of the GDPR: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; and integrity and confidentiality.
- Our website uses the HTTPS protocol, which ensures that information travels securely, using standard internet encryption.
- We collect your information lawfully for commercial communication, the sale of our services and products, and customer support.
- Unless legally or judicially required, we never provide your data to third parties nor use it for purposes other than those for which it was collected.
- Access to information is limited to our subcontractors, the data controller, and our Data Protection Officer (DPO), always preserving its integrity.
- We may use cookies to confirm your identity, personalize your access, and understand how you use our website to improve your browsing experience.
- There is always a support channel available: dpo@redevistorias.pt, for any questions about your personal data.
International data transfers
Some personal data is processed and stored outside the European Economic Area (EEA), namely:
- United States of America: through the Amazon Web Services (AWS) cloud computing infrastructure.
- Brazil: through the Rede Vistorias Brasil network, which processes data on our behalf.
These transfers comply with the safeguards required by Chapter V of the GDPR:
- Standard Contractual Clauses (SCCs):approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, included both in the agreement with Rede Vistorias Brasil and in the AWS Data Processing Addendum.
- AWS Certification in the EU-US Data Privacy Framework: When applicable to the processing regions used, as additional security for transfers to the United States.
- Technical and organizational measures:Data encryption in transit and at rest, access control, and other measures described in the AWS Security Standards, attached to the respective DPA.
Remote access to data by teams from the Rede Vistorias Brasil network (for technical support, information technology, or legal matters) is also considered an international data transfer for the purposes of the GDPR and is subject to the same contractual safeguards.
You can request a copy of the contractual guarantees applicable to these transfers by contacting our Data Protection Officer at dpo@redevistorias.pt.
Data sharing
We work in partnership with other organizations, such as Google Analytics, one of the most widely used and trusted analytics tools, which helps us understand how the site is used and improve your experience.
These cookies can track time spent on the site and pages visited, helping us to produce more relevant content. To learn more, please visit the official Google Analytics page.
Rights of Data Subjects
The GDPR guarantees you the following rights regarding your personal data:
- Access: to confirm that we process your data and to access it (Article 15).
- Rectification: request the correction of incorrect or incomplete data (art. 16).
- Erasure (“right to be forgotten”): Request the deletion of your data, under the conditions set out in the GDPR (Article 17).
- Treatment limitation: to request the suspension of treatment in certain circumstances, for example while the accuracy of the data is being verified (Article 18).
- Portability: to receive the data you have provided to us, in a structured and machine-readable format, and to transmit it to another responsible party (Article 20).
- Opposition: to object, on grounds relating to their situation, to processing based on legitimate interest (including profiling), or to processing for direct marketing purposes (Article 21).
- Automated decisions: not to be subject to decisions taken solely on the basis of automated processing which produce legal effects or significantly affect him (Article 22).
- Withdraw consent: at any time, without affecting the legality of treatment performed prior to withdrawal.
- Complaint: to file a complaint with the CNPD or another competent supervisory authority in the European Union (Article 77).
You can exercise these rights by contacting our Data Protection Officer at dpo@redevistorias.pt. We will respond within one month of receiving your request, a period that may be extended by a further two months if necessary, taking into account the complexity and number of requests (Article 12, paragraph 3, of the GDPR).
Data Retention and Preservation Policy
Compliance notice: Brazilian legislation does not define specific retention periods for each type of data, which, in practice, can lead to its indefinite retention. However, the General Data Protection Regulation (GDPR) establishes that personal data should only be kept for the time necessary to fulfill the purpose for which it was collected. For this reason, for this policy applicable in Portugal, the retention periods indicated in the table above have been defined, based on applicable legal deadlines and specialized legal guidance.
Data deletion and anonymization
After the applicable retention period has ended, or at your request, in the exercise of your right to erasure, we securely and permanently delete your personal data from our systems and the systems of our subcontractors or, alternatively, we irreversibly anonymize it. This deletion or anonymization does not apply when there is a legal basis to retain the data for a longer period, namely to comply with legal obligations or to exercise rights in legal proceedings.
Security incident management and data breaches
We maintain internal procedures for detecting, containing, and responding to security incidents that affect personal data, in coordination with our subcontractors, including AWS, which is contractually obligated to notify us without undue delay as soon as it becomes aware of an incident.
In accordance with Article 33 of the GDPR, we undertake to notify the CNPD within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to your rights and freedoms, unless such a breach is not likely to result in such a risk.
Whenever a breach is likely to result in a high risk to your rights and freedoms, we also communicate the breach directly to the data subjects affected without undue delay (Article 34 of the GDPR).
Safety measures
We follow current legislation and adopt best security and privacy practices to ensure the integrity and confidentiality of your data, working exclusively with cloud computing providers recognized for their reliability and compliance, such as AWS.
By using our services and registering your information on our platform, you acknowledge that your data may be processed, transferred, and stored in other countries, under the terms and with the guarantees described in the "International Data Transfers" section.
Changes to this Policy
This Policy may be updated periodically to reflect legislative, technological, or business practice changes. It is worthwhile to consult it from time to time, and if there are significant changes, we will announce them on our website.
Last updated: July 2026.
Contacts
Do you have any questions about this Policy or about the processing of your personal data?
Speak to our team.
- Responsible for Treatment: REDE VISTORIAS FRANCHISING S/A, operating in Portugal through its Master Franchisee “Rede Vistorias Portugal”.
- Data Protection Officer (DPO): Paul Eipper
- DPO email: dpo@redevistorias.pt
- Supervisory authority: National Data Protection Commission (CNPD),
www.cnpd.pt
We'd be pleased to hear from you!