1. What this page means
This page gives a plain-language overview of the privacy measures relevant to the current PMELP website. It supports, but does not replace, our Privacy Policy, project-specific contracts, records of processing, data-processing agreements or legal advice.
It is not a certification. GDPR compliance depends on actual, ongoing practices and must be reviewed whenever the website, suppliers, processing purposes or law change.
2. Current website data flow
- 01You request a page
Your browser sends the technical information needed to reach the website.
- 02Cloudflare delivers and protects it
Cloudflare Pages and security services process ordinary request and security data at the network edge.
- 03Static files are returned
The page loads self-hosted HTML, CSS and JavaScript. It does not call advertising or analytics services.
3. Data protection principles
Use personal data for defined, lawful business or security purposes.
Request and retain only the information reasonably needed.
Explain relevant purposes, legal bases, providers, retention and rights.
Use proportionate access controls, transport encryption, updates and provider safeguards.
Review data and remove or anonymise it when there is no continuing need or legal duty.
Document roles and responsibilities when a project involves personal data.
4. PMELP's role
PMELP acts as a controller for its own website, enquiries, administration and client relationships. In a client project, PMELP may act as a controller, joint controller or processor depending on who determines the purpose and means of processing.
Where PMELP processes personal data on a client's documented instructions, the parties should put an Article 28 data-processing agreement in place before that processing begins, covering confidentiality, security, subprocessors, assistance with rights and incidents, deletion or return, and audit information.
5. Providers and transfers
Providers that process personal data should be selected for an appropriate function and governed by suitable contractual terms. For this website, Cloudflare provides hosting, delivery and security. Direct email is handled by PMELP's email provider.
Where data leaves the European Economic Area, an applicable transfer mechanism and safeguards are required. More detail appears in the Privacy Policy.
6. Rights and response process
Individuals may have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent. PMELP routes requests through mail@pmelp.pt, verifies identity where necessary, searches relevant systems, records the outcome and responds within the period required by the GDPR.
If you are dissatisfied, you may contact the Comissão Nacional de Proteção de Dados (CNPD).
7. Changes that require a new review
PMELP should reassess this baseline before adding a contact form, analytics, advertising, user accounts, payments, newsletters, embedded media, AI features that receive visitor data, new subprocessors, or a product that handles personal data at scale.
8. Contact
Questions, rights requests or privacy concerns can be sent to mail@pmelp.pt. The controller is PMELP – Soluções Digitais e Desenvolvimento de Negócios, Unipessoal Lda, NIPC 516 039 652, Rua dos Amores, Lote 6, R/C Esq., 6300-811 Guarda, Portugal.