DATA PROTECTION AND PRIVACY POLICY
www.oadvogado.pt
1. Commitment to Data Protection and Privacy
A INOVALEX, LDA, as the managing entity of the platform Oadvogado.pt, undertakes to guarantee the protection of the personal data of all users, in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and other applicable national legislation.
Privacy, information security, and transparency are fundamental principles of our practice and conduct. All personal data is processed lawfully, fairly, transparently, limited to the intended purposes, and is adequate, relevant, and secure.
2. Data Controller
INOVALEX, LDA
NIPC: 518938085
Email: info@oadvogado.pt
3. Data Protection Officer (DPO)
Priscila Vilhena Ganga
Email: rgpd@oadvogado.pt
The Data Protection Officer can be contacted for any questions relating to the protection of personal data, including exercising the rights of data subjects or reporting incidents.
4. Categories of Personal Data Processed
The platform may collect and process, among others, the following personal data:
Identification: full name, tax identification number (NIF);
Contact information: email, phone number;
Payment details (processed by third-party entities such as Stripe or PayPal);
Information related to the legal consultation: description of the issue submitted, date and time of scheduling, history of interactions;
Technical browsing data: IP address, cookies, session data;
In some cases, special category data (e.g., health, trade union membership, religious beliefs), when voluntarily provided by the user within the scope of describing their legal situation — are processed based on explicit consent and strictly for the execution of the requested service.
5. Purposes and Foundations of Lawfulness
The purposes of processing personal data are:
Contract execution: scheduling and conducting legal consultations, communicating with lawyers, processing payments, and issuing invoices/receipts;
Compliance with legal obligations: tax, accounting and regulatory obligations;
Legitimate interest: management and improvement of the platform, fraud prevention, technical support, and security;
Consent: use of non-essential cookies, sending promotional communications, processing of special category data shared voluntarily.
6. Treatment Principles
INOVALEX, LDA ensures that all personal data processing operations respect the fundamental legal principles enshrined in Article 5 of the GDPR, namely:
Lawfulness, fairness, and transparency: data is processed lawfully, fairly, and transparently, ensuring that data subjects are clearly informed about how their data is used.
Limitation of purposes: the data is collected for specific, explicit and legitimate purposes, and is not processed in a way that is incompatible with those purposes.
Data minimization: only data that is strictly necessary, adequate, and relevant for the purposes for which it is intended is processed.
Accuracy: Data is kept accurate and up-to-date; when inaccuracies are found, they will be corrected or deleted without delay.
Data retention limitation: data is retained only for the period necessary to fulfill the purposes for which it was collected, unless otherwise required by law.
Integrity and confidentiality: appropriate technical and organizational measures are adopted to ensure the security of personal data, protecting it against unauthorized or unlawful processing and against accidental loss, destruction or damage.
Accountability: INOVALEX assumes responsibility for demonstrating compliance with all these principles, adopting internal policies, procedures, and records that ensure compliance with the GDPR.
7. Storage Periods
In compliance with Article 5(1)(e) of the GDPR, personal data is kept only for the period strictly necessary for the purposes for which it was collected or processed, and is subsequently deleted or anonymized.
For example:
Billing and compliance data: kept for the legally required period.
User account data: retained while the account is active; in case of inactivity or a request for deletion, the data will be deleted, unless there are still legal obligations to retain it.
Data from consultations, interactions, and communications: kept for the period appropriate to the contractual purpose and the legitimate interest of defense in case of litigation.
Cookies and technical browsing data: kept in accordance with the terms defined in the Cookie Policy, always respecting the principle of proportionality and the limitation of storage.
INOVALEX is committed to conducting periodic reviews to ensure that data is not retained for longer than necessary, in accordance with the principles of data minimization and data limitation as set out in the GDPR.
8. Data Sharing and Subcontractors
Personal data may be shared with:
Participating lawyers, exclusively for the purposes of the requested consultation;
Payment service providers (e.g., Stripe, PayPal);
IT hosting, maintenance, and support service providers;
Judicial or administrative authorities, when legally required.
INOVALEX only uses subcontractors that offer sufficient guarantees of compliance with the GDPR, through a written contract that imposes obligations regarding confidentiality, security, and data protection.
9. Security Measures
INOVALEX implements appropriate technical and organizational measures to ensure a level of security adjusted to the risk, in accordance with Article 32 of the GDPR.
The measures adopted include:
Access control: restricting access to personal data to authorized employees only, through strong authentication and access logging;
Encryption and pseudonymization: encryption of data in transit (SSL/TLS) and at rest, as well as the use of pseudonymization techniques when applicable;
Regular backups and recovery plans: regularly tested backups, with redundancy and recovery systems in case of an incident;
System monitoring and intrusion detection: use of monitoring tools, firewalls, and up-to-date antivirus software;
Confidentiality policy: all employees and lawyers are bound by duties of secrecy and confidentiality, in addition to those established in the Portuguese Bar Association Statute;
Training and awareness: regular awareness-raising activities on information security and data protection for all stakeholders;
Incident management: internal procedures for detecting, responding to, and reporting security incidents, including mechanisms for notifying authorities and data subjects, where applicable.
The user is equally responsible for adopting appropriate protection measures on the devices and networks used to access the Platform, in particular keeping software updated, using security solutions (antivirus, firewall) and preserving the confidentiality of their access credentials.
10. Cookies and Similar Technologies
This website uses cookies to improve the browsing experience, analyze usage statistics, and enable additional features.
For more details, please consult our Cookie Policy.
11. Rights of Data Subjects
Under the GDPR, data subjects may exercise the following rights at any time and free of charge:
Right of access (Art. 15 GDPR): to obtain confirmation as to whether your data is being processed and to access the relevant information.
Right to rectification (Article 16 GDPR): request the correction of inaccurate or incomplete data.
Right to erasure (Article 17 GDPR): to request the deletion of personal data when one of the legally established grounds applies, especially when the data is no longer necessary or consent is withdrawn.
Right to restriction of processing (Article 18 GDPR): obtain the restriction of processing in certain circumstances, such as in the case of a dispute regarding the accuracy of the data.
Right to object (Article 21 GDPR): to object to the processing of your data in certain situations, including for direct marketing purposes.
Right to data portability (Article 20 GDPR): to receive the personal data you have provided, in a structured, commonly used and machine-readable format, and to transmit that data to another controller.
Right to withdraw consent (Article 7, § 3 GDPR): where processing depends on consent, it may be withdrawn at any time without affecting the lawfulness of processing carried out up to that date.
Exercise procedure
The exercise of these rights can be requested via email: rgpd@oadvogado.pt
Your request will be processed as quickly as possible and, in any case, within a maximum of 30 days, unless the request is complex (Article 12, § 3 GDPR).
When necessary, INOVALEX may request additional information to confirm the applicant’s identity (Article 12, paragraph 6 GDPR).
Complaint to the supervisory authority
In addition to the rights indicated above, the data subject has the right to lodge a complaint with the National Data Protection Commission (CNPD), the competent supervisory authority in Portugal:
Website: www.cnpd.pt
Address: Av. D. Carlos I, 134 – 1st floor, 1200-651 Lisbon
12. Incident Reporting
In the event of a personal data breach that could pose a risk to the rights and freedoms of data subjects, INOVALEX undertakes to:
Notify the CNPD within the legal deadline of 72 hours (art. 33 GDPR);
Notify data subjects whenever the incident could seriously affect their rights (Article 34 GDPR).
13. Changes to the Privacy Policy
This Policy may be amended to reflect relevant legal or operational changes.
Whenever there are significant changes, these will be clearly communicated on the website.
14. Contacts
INOVALEX, LDA
General email:info@oadvogado.pt
Data Protection Officer: Priscila Vilhena Ganga – rgpd@oadvogado.pt
Last updated: October 24, 2025