WHO ARE WE?

Maria’s Tuk Tuk is committed to protecting the personal data of customers/users of Maria’s Tuk Tuk products and services, as well as personal data in all situations where personal data processing occurs. In this context, we have prepared this Policy, which is based on our commitment to respecting the rules of personal data protection.

WHY THIS PERSONAL DATA PROTECTION POLICY?

This Policy aims to inform customers/users about the general rules for processing personal data, which are collected and processed in strict compliance with the legislation on the protection of personal data in force at any given time, particularly Regulation (EU) 2016/679 of the European Parliament and the Council of April 27, 2016 (“GDPR”).

Maria’s Tuk Tuk adheres to best practices in the field of security and the protection of personal data, having taken the necessary technical and organizational measures to comply with the GDPR and ensure that the processing of personal data is lawful, fair, transparent, and limited to authorized purposes.

Maria’s Tuk Tuk is committed to protecting the confidentiality and integrity of personal data, having adopted measures it deems appropriate to ensure the accuracy, integrity, and confidentiality of personal data, as well as all other rights of the respective data subjects.

The rules set out in this Data Protection Policy complement the provisions regarding the protection and processing of personal data set forth in contracts that customers/users enter into with Maria’s Tuk Tuk, as well as the rules outlined in the terms and conditions governing the various products and services, which are duly advertised on the website.

WHAT DOES THIS DATA PROTECTION POLICY COVER?

This Data Protection Policy exclusively applies to the collection and processing of personal data for which Maria’s Tuk Tuk is responsible for processing, in the context of the services and products provided to its customers/users and in all situations involving the processing of personal data by Maria’s Tuk Tuk.

Maria’s Tuk Tuk’s website may include links to other websites that are unrelated to Maria’s Tuk Tuk. Providing such links is done in good faith, and Maria’s Tuk Tuk cannot be held responsible for the collection and processing of personal data carried out through these websites, nor does Maria’s Tuk Tuk assume any responsibility for these websites, including their accuracy, credibility, and features.

WHAT ARE PERSONAL DATA?

Personal data refers to any information of any nature and regardless of its medium, including sound and image, related to an identified or identifiable individual.

An identifiable person is someone who can be identified, directly or indirectly, notably by reference to a name, identification number, location data, electronic identifiers, or one or more specific elements of their physical, physiological, genetic, mental, economic, cultural, or social identity.

WHAT DOES PERSONAL DATA PROCESSING INVOLVE?

Personal data processing consists of an operation or set of operations performed on personal data or sets of personal data, whether by automated means or not. This includes the collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, comparison, interconnection, limitation, erasure, or destruction of data.

WHO IS RESPONSIBLE FOR PERSONAL DATA PROCESSING?

The entity responsible for processing personal data is Maria’s Tuk Tuk itself, which determines the purposes and means of data processing.

To contact the data controller, the data subject can use the following methods and contact information:

Through the Maria’s Tuk Tuk website – using the contact form or alternative contact methods provided in the website footer.

WHO IS THE DATA PROTECTION OFFICER?

The Data Protection Officer plays a relevant role in personal data processing, ensuring, among other aspects, compliance with current data protection regulations, verifying compliance with this Data Protection Policy, and establishing clear rules for personal data processing. This officer ensures that all data subjects who entrust their personal data processing to Maria’s Tuk Tuk are aware of how Maria’s Tuk Tuk processes their data and the rights they have in this matter.

Therefore, data subjects can communicate with the Data Protection Officer regarding matters related to personal data processing, using the contact details on the “Contact” page, if desired.

WHAT TYPES OF PERSONAL DATA ARE PROCESSED?

In the scope of its activities, Maria’s Tuk Tuk processes the personal data necessary for providing services and/or supplying products, as well as for social intervention. This includes data such as name, address, phone number, and email address, as further detailed for data subjects.

Without prejudice to compliance with legal requirements regarding data retention and transmission for the purpose of investigating, detecting, and prosecuting serious crimes, as well as other processing to which Maria’s Tuk Tuk is legally obligated, traffic data, geographic location, profile, and/or consumption data of customers/users will be processed by Maria’s Tuk Tuk to the extent necessary for the provision of services. Accordingly, based on location, profile, and/or consumption, customers/users will have access to specific features of the services, content suggestions, and local information services.

Location information may also be recorded and transmitted to organizations with legal competence to receive emergency calls for the purpose of responding to received calls.

Personal data, traffic data, geographic location, profile, and/or consumption data are also processed for marketing or advertising purposes, if the data subject has provided consent.

Personal data will also be processed, if the data subject has given consent, for the disclosure of informative services and directories within the framework of universal service, including transmission to third parties for the publication of said directories and the provision of informative services.

If there is prior consent from the customer/user, it can be withdrawn at any time, without compromising the legality of the processing carried out based on the previously given consent.

WHEN AND HOW DO WE COLLECT YOUR PERSONAL DATA?

Maria’s Tuk Tuk collects your personal data, including through telephone communication, in writing, and via the website, always ensuring the prior consent of the data subject when necessary.

Certain personal data are essential for the execution of the contract, and in case of their absence or insufficiency, Maria’s Tuk Tuk cannot provide the relevant product or service.

If the data subject is not a customer/user of Maria’s Tuk Tuk, their personal data will only be processed when provided, such as through the subscription to newsletters. In such cases, this Data Protection Policy applies.

The collected personal data can be processed by automated or non-automated means, always ensuring strict compliance with personal data protection legislation. They are stored in specific databases created for this purpose, and the collected data will never be used for purposes other than those for which they were collected or for which consent was given by the data subject.

WHO ARE THE RECIPIENTS OF PERSONAL DATA?

Without prejudice to the recipients mentioned throughout this Data Protection Policy, Maria’s Tuk Tuk may disclose the personal data of the customer/user for the purpose of complying with legal obligations, namely to law enforcement, judicial, tax, and regulatory authorities.

WHAT ARE THE PURPOSES OF PROCESSING PERSONAL DATA?

In general, the personal data collected are used for managing the contractual relationship, providing the contracted services, and tailoring services to the customer/user’s needs and interests. Maria’s Tuk Tuk may also, when legally admissible, use the personal data provided by the data subject for other purposes, such as sending suggestions, disseminating brand institutional information, informing customers about campaigns, promotions, advertising, and news regarding Maria’s Tuk Tuk’s products and/or services, as well as conducting market research or evaluation surveys.

HOW LONG DO WE RETAIN YOUR PERSONAL DATA?

The period during which personal data are stored and retained varies according to the purpose for which the information is processed.

Indeed, legal requirements may impose a minimum retention period for data. Thus, when there is no specific legal requirement, the data will be stored and retained only for the minimum period necessary for the purposes for which they were collected or further processed, as defined by law.

WHAT ARE YOUR RIGHTS AS A DATA SUBJECT?

As data subjects, customers/users are guaranteed the right to access, rectify, update, limit, and erase their personal data (except for data that is essential for the provision of services by Maria’s Tuk Tuk, as identified in the form as mandatory or for the fulfillment of legal obligations to which the data controller is subject), the right to object to their use for commercial purposes by Maria’s Tuk Tuk, and the right to withdraw consent, without compromising the lawfulness of the processing based on the previously given consent, as well as the right to data portability.

HOW CAN YOU ACCESS, RECTIFY, UPDATE, LIMIT, ERASE, OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA, OR WITHDRAW YOUR CONSENT?

Without prejudice to the provisions of the GDPR, data subjects can do so directly or by written request addressed to the respective Data Controller through the contact information provided in this document, as well as other contact information provided by Maria’s Tuk Tuk.

HOW CAN YOU OBJECT TO RECEIVING MARKETING CONTACTS?

Maria’s Tuk Tuk may promote the disclosure of new products or services to customers/users, particularly through phone calls, email, SMS, MMS, or any other electronic communications service, provided that the data subject has given their consent.

If data subjects no longer wish to receive these communications, they can withdraw their consent to the use of their data for marketing purposes at any time.

HOW CAN YOU FILE A COMPLAINT?

Without prejudice to the possibility of filing a complaint directly with Maria’s Tuk Tuk, using the provided contact information, customers/users can also directly file a complaint with the Supervisory Authority, which is the National Data Protection Commission (CNPD), using the contact information provided by this entity for this purpose.

WHAT MEASURES HAS Maria’s Tuk Tuk IMPLEMENTED TO ENSURE THE SECURITY OF YOUR PERSONAL DATA?

Maria’s Tuk Tuk is committed to protecting the security of the personal data provided to it and has approved and implemented strict rules in this regard. Compliance with these rules is an obligation for all those who legally access them.

Given Maria’s Tuk Tuk’s concern and commitment to the defense of personal data, various security measures have been adopted, both technical and organizational, to protect the personal data provided against their dissemination, loss, misuse, alteration, unauthorized access, or any other form of unlawful processing.

Additionally, third parties that, in the context of service provision, process customer/user personal data on behalf and on behalf of Maria’s Tuk Tuk, are contractually required to implement the necessary technical and security measures to protect personal data against accidental or unlawful destruction, accidental loss, alteration, unauthorized disclosure, or access, as well as against any other form of unlawful processing.

In this regard, on the Maria’s Tuk Tuk website, the personal data collection forms require encrypted browser sessions, and all personal data provided are securely stored in Maria’s Tuk Tuk’s systems, which are located on Maria’s Tuk Tuk’s server, protected by all necessary physical and logical security measures as determined by Maria’s Tuk Tuk for the protection of personal data.

Despite the security measures taken by Maria’s Tuk Tuk, it is advisable for all internet users to take additional security measures. This includes ensuring that they use an up-to-date computer and browser with appropriately configured security patches, an active firewall, antivirus, and anti-spyware protection. Users should also verify the authenticity of the websites they visit on the internet and avoid websites they do not trust.

UNDER WHAT CIRCUMSTANCES ARE DATA SHARED WITH OTHER ENTITIES (THIRD PARTIES AND SUBCONTRACTORS)?

In the course of its activities, Maria’s Tuk Tuk may use third parties to provide certain services. Sometimes, providing these services requires these entities to access the personal data of customers/users. In such cases, Maria’s Tuk Tuk takes appropriate measures to ensure that the entities with access to the data are reputable and offer the highest guarantees at this level, as explicitly provided for in contracts between Maria’s Tuk Tuk and these third parties.

Therefore, any entity subcontracted by Maria’s Tuk Tuk will process personal data of our customers/users on behalf and on behalf of Maria’s Tuk Tuk and will take the necessary technical and organizational measures to protect personal data against accidental or unlawful destruction, accidental loss, alteration, unauthorized disclosure, or access, as well as against any other form of unlawful processing.

In all cases, Maria’s Tuk Tuk remains responsible for the personal data provided to it.

UNDER WHAT CIRCUMSTANCES ARE YOUR PERSONAL DATA TRANSFERRED?

The provision of certain services by Maria’s Tuk Tuk may involve the transfer of your data outside of Portugal, including outside the European Union or to International Organizations.

In such cases, Maria’s Tuk Tuk will strictly comply with the applicable legal provisions, including determining the adequacy of the destination country or countries regarding the protection of personal data and the requirements applicable to such transfers, including the execution of appropriate contractual instruments that guarantee and respect the legal requirements in force.

HOW CAN YOU BE INFORMED OF ANY CHANGES TO THE Maria’s Tuk Tuk DATA PROTECTION POLICY?

Maria’s Tuk Tuk reserves the right to make adjustments or changes to this Data Protection Policy at any time, and such changes will be duly publicized through various communication channels of Maria’s Tuk Tuk.