Privacidade / privacy
Privacy Policy.
In force since September 2026
This policy sets out how the firm handles personal data received through this website: what we receive, why we hold it, who has access to it, and for how long it is retained.
Should any part of it be unclear, or should you wish to know what we hold concerning you, please write to geral@anabastos-law.com.
1Who is responsible for your data
Personal data collected through this website is controlled by the lawyer identified below, who determines the purposes and the means of its processing. ACB | Law Office is the professional designation under which she practises; it is not a law firm constituted as a separate legal person, so the controller is the lawyer herself.
No Data Protection Officer has been appointed, none being required. Article 37 of the GDPR imposes that obligation only on public authorities, on controllers whose core activities consist of regular and systematic monitoring of data subjects on a large scale, and on those processing special categories of data on a large scale. She falls within none of those categories. Enquiries concerning privacy are addressed to Ana de Carvalho Bastos at the contacts above.
2What this website collects
The site sets no cookies, runs no analytics, and stores nothing on your device. Your language choice is carried in the address of the page itself, with the Portuguese pages under /pt/, so there is nothing for your browser to remember. Article 5(3) of the ePrivacy Directive, transposed into Portuguese law by Article 5 of Law 41/2004 of 18 August, as amended by Law 46/2012, requires consent before anything is stored on a visitor’s device. Since this site stores nothing, no banner is presented, because there is nothing to consent to.
Fonts and images are served from our own domain. Most websites load their typefaces from Google Fonts, with the consequence that every visitor's browser connects to Google and discloses its IP address to a company established in the United States. The typefaces used here are held on our own server, so that reading these pages discloses your data to no one but our host.
Our host keeps server logs. As with any web server, the infrastructure serving this site records each request, including the IP address, the page requested, the time and the browser type. Those logs exist to deliver the site and to protect it from abuse. They are not used to construct any profile of you.
The contact form sends your message to us. On pressing send, the name, email address and text you entered are transmitted to our server and passed on to us as an ordinary email. The message itself is not stored on the website. A short confirmation is sent back to the address you gave, so that you know it arrived; it is the same fixed wording every time and carries nothing from your message but the name you signed it with. So that the form cannot be used to send mail in bulk, the server keeps a short-lived note of when a message was last sent from your connection, identified only by a one-way hash of your IP address and holding no part of what you wrote. The email that reaches us includes, alongside your message, the time it was sent and the language of the page you wrote from.
The same applies to anything sent to us directly by email, telephone or WhatsApp. We process the contact details provided and the content of the message.
3Why we process it, and on what legal basis
Each purpose rests on its own legal basis under Article 6(1) of the GDPR:
Your data is not used for marketing. We publish no newsletter, we do not profile visitors, and no decision affecting you is taken by automated means.
The confirmation box on the contact form records that you have read this policy. It is not itself what renders the processing lawful: replying to an enquiry you have sent rests on Article 6(1)(b). Withdrawing that confirmation therefore does not oblige us to delete correspondence we are otherwise required to retain. Your rights to object and to seek erasure are set out in section 8.
You are under no statutory or contractual obligation to provide data through this website. Without a name and an address to reply to, however, we cannot answer an enquiry. Once we act for you, some information is required by law, including client identification under Law 83/2017, and without it we cannot accept or continue the engagement.
4Who else has access
Your data is never sold, rented, or disclosed for the marketing purposes of others. Beyond the firm, it is seen only by:
- Our hosting provider. This website is served by Hostinger — Hostinger International Ltd, established in Cyprus — whose servers deliver the pages and hold the logs described above. The server for this site is in the European Union.
- Our email providers. Two are involved. The message leaving this website is handed to Resend, which delivers it and signs it so that it is not taken for a forgery; it then rests in the firm's mailboxes, which run on Google Workspace. Both therefore see your name, your address and what you wrote.
- Lawyers with whom we collaborate, where a matter calls for their expertise and you have been informed. They are bound by the same duty of professional secrecy.
- Courts, public authorities and counterparties, where the conduct of your matter requires it or the law compels disclosure.
Suppliers act on our documented instructions under Article 28 of the GDPR and may not use your data for their own purposes.
5Transfers outside the European Economic Area
All three suppliers serve this site from within the European Union: the web server is in the EU, Resend sends from its European region in Ireland, and the mailboxes are contracted through Google Ireland. The ordinary handling of your message therefore stays inside the EEA. Two of the three have a parent company in the United States, so access from outside the EEA cannot be excluded altogether, whether for support or for maintenance of the systems. Where that occurs it is covered by the European Commission's Standard Contractual Clauses, and in Google's case by its certification under the EU–US Data Privacy Framework as well.
Client data is not transferred outside the EEA for our own convenience. Where a matter is itself cross-border, such as an investment in Angola or a transaction with a foreign counterparty, any transfer required in order to conduct the work is covered by Article 49(1)(b) and (e) of the GDPR.
6How long we keep it
Data is not retained indefinitely, nor is it deleted while an obligation to hold it survives. Each record is kept for as long as our professional and legal duties require, and for as long as a right arising from the work may still be asserted, with fixed periods where the law imposes them.
7Professional secrecy
Almost everything a client tells us is covered by professional secrecy under Article 92 of the Estatuto da Ordem dos Advogados. That duty is stricter than data protection law, and it does not expire when the matter ends.
Professional secrecy may limit what we are able to disclose in answer to a data protection request. Where a file contains information concerning another person that is covered by secrecy, we cannot release it merely because you have asked for a copy of your own data. Should that arise, we will identify the part of your request we are unable to meet, and explain why.
If you are writing to us for the first time, please read the note on confidentiality in the Terms of Use before sending anything sensitive.
8Your rights, and how to exercise them
Under the GDPR you may ask us to:
- confirm whether we hold data concerning you, and provide a copy of it;
- correct it, where it is inaccurate or incomplete;
- delete it, where no continuing reason or obligation to retain it exists;
- restrict its processing while a dispute as to its accuracy or as to our grounds is resolved;
- provide it in a portable, machine-readable format, where the processing rests on consent or on a contract and is carried out by automated means;
- cease processing founded on our legitimate interests, on grounds relating to your particular situation.
Where processing rests on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out beforehand.
Requests should be addressed to geral@anabastos-law.com. We reply within one month, and will say so if a complex request requires longer, as Article 12(3) permits. No charge is made unless a request is manifestly unfounded or excessive. We may first need to verify your identity, so that data is not disclosed to someone impersonating you.
If you are not satisfied with the way a request has been handled, you may complain to the supervisory authority:
We would ask that you raise the matter with us first, though you are under no obligation to do so.
9Security
This site is served over HTTPS. Files and correspondence are held on access-controlled systems, and access within the firm is confined to those who require it for the matter in hand. All those working with us are bound by confidentiality, whether as lawyers under the Estatuto or by written undertaking.
No system is entirely secure. Should a breach of personal data occur, we will notify the CNPD within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to your rights, as Article 33 requires. Where it is likely to result in a high risk to your rights, we will also inform you directly, without undue delay, as Article 34 requires.
10Changes to this policy
If our practices change, this page will be updated and the date at the top revised. Material changes affecting persons whose data we already hold will be notified directly. Earlier versions are available on request.
Should anything later be added to this website that stores data on your device, such as an analytics tool or an embedded map, your consent will be sought before it loads and this page will record what it does.
Ana de Carvalho Bastos