PRIVACY POLICY
THE GENERAL PART
- COLLECTION AND PROCESSING OF USER DATA
In connection with the provision of the websites hosted on https://www.ecm.pt/, https://www.cervejacoral.com and https://www.brisanet.com.pt/en/ (“Website”), the conclusion of any contracts, the provision of information, content, including newsletters, factory visit requests, export requests, suggestions, applications, campaigns/casting, sponsorship requests or “Coral em Casa” service (together, the “Services”) to its customers. users (“User”) and other entities that relate to him/her, the entities that are part of Empresa de Cervejas da Madeira, a sole proprietorship headquartered at PEZO – Parque Empresarial Zona Oeste, 9304-003 Câmara de Lobos, registered at the Commercial Registry Office of Câmara de Lobos under the unique registration and legal person number 511 001 720 (hereinafter “ECM”) may request the User to provide personal data, i.e. information provided by the User that allows ECM to identify and/or contact the User (“Personal Data”).
As a rule, Personal Data is requested when the User applies to be an ECM employee, makes requests for sponsorship, exports and requests factory visits, sends a suggestion, joins campaigns / casting or asks to be called within the scope of the Coral em Casa service.
The Personal Data collected and processed consists essentially of information relating to name, institution, date of birth, address, zip code, e-mail, fax, telephone, data contained in the CV or other similar document, educational qualifications, relevant professional experience, although other Personal Data may be collected that may be necessary or convenient for the provision or collection of Services by ECM.
Once the Personal Data has been collected, ECM will provide the User with detailed information about the nature of the data collected and about the purpose and processing that will be carried out in relation to the Personal Data, as well as the information mentioned in clause 8.
ECM also collects and processes information about the characteristics of the device, its hardware and the browser/software characteristics, as well as information about the pages visited by the User within the Website. This information may include your browser type, domain name, access times, and the links through which you accessed the Website (“Usability Information”). We use this information only to improve the quality of your visit to our Website.
Usability Information and Personal Data are referred to in this Privacy Policy as “User Data”.
For the purposes of this Privacy Policy, a contractual relationship is understood to be and include any and all contracts established between ECM and the entities that relate to it, regardless of its purpose.
1.2. DATA PROCESSORS
In the context of the processing of User Data, ECM uses or may use third parties, data processors, to process User Data on behalf of ECM and in accordance with the instructions given by ECM, in accordance with the applicable data protection legislation and orientations and this Privacy Policy.
These data processors may not transmit User Data to other entities without prior written authorization from ECM and shall also be prohibited from engaging other entities without ECM’s prior authorization.
ECM undertakes to contract only with entities that offer maximum security in the execution of the appropriate technical and organizational measures, in order to guarantee the defense of the User’s rights. All entities contacted by ECM are bound to ECM by means of a written contract which regulates the object and duration of the processing, the nature and purpose of the processing, the type of personal data, the categories of data subjects and the rights and obligations of the parties.
Once the personal data has been collected, ECM will provide the User with information about the categories of data processors that may process data on behalf of ECM in this case.
- GENERAL PRINCIPLES APPLICABLE TO THE PROCESSING OF USER DATA
In terms of general principles regarding the processing of personal data, ECM undertakes to ensure that the User Data it processes is:
- Processed in accordance with the law, fair and transparent with regard to the User;
- Collected for specified, objective and legitimate purposes, and are not subsequently processed in a manner contrary to those purposes;
- Adequate, justified and limited to what is necessary in relation to the purposes for which they are processed;
- Accurate and up-to-date whenever necessary, and all necessary measures are taken to ensure that inaccurate data, taking into account the purposes for which they are processed, are deleted or corrected without delay;
- Stored in a form that allows the User to be identified only for the period necessary for the purposes for which the data is processed;
- Processed in a manner that ensures their safety, including protection against unauthorized or unlawful processing and against loss, destruction or unforeseen damage, and appropriate technical or organizational measures have been taken.
The data processing carried out by ECM is permitted and lawful when at least one of the following situations occurs:
- The User has unequivocally given his/her consent to the processing of the User Data for one or more specific purposes;
- The processing is necessary for the performance of a contract to which the User is a party, or for pre-contractual procedures at the User’s request;
- The processing is necessary for compliance with a legal obligation to which ECM is subject;
- The processing is necessary for the defense of the fundamental interests of the User or of another individual.
The processing is necessary for the purposes of the legal interests pursued by ECM or by a third party (unless the interests or fundamental rights and freedoms of the User that require the protection of personal data prevail).
ECM undertakes to ensure that the processing of User Data is only carried out under the conditions listed above and in compliance with the above-mentioned principles.
Where the processing of User Data is carried out by ECM on the basis of the User’s agreement, the User has the right to withdraw his/her consent at any time. The withdrawal of consent, however, does not compromise the lawfulness of the processing carried out by ECM on the basis of the consent previously given by the User.
The length of time for which data is stored and retained varies according to the purpose for which the information is processed.
In fact, there are legal requirements that require you to keep your data for a minimum period of time. Thus, and whenever there is no specific legal obligation, the data will be stored and kept only for the minimum period necessary for the purposes for which it was collected or subsequently processed and will be deleted at the end of its term.
- USE AND PURPOSES OF THE PROCESSING OF USER DATA
In general terms, ECM uses User Data for the following purposes:
- Applications / Recruitment / Campaigns and Casting of data subjects;
- Fulfillment of requests, namely export requests, request for factory visit and request for sponsorship;
- Sending suggestions by data subjects;
- “Coral em Casa” service in which the data subject enters his/her telephone number so that ECM can call him/her;
- To ensure that the Website meets the User’s needs, by developing and publishing content that is as adapted as possible to the requests and type of User, by improving the search capabilities and functionalities of the Website and by obtaining associated or statistical information regarding the User’s typical profile (analysis of consumption profiles);
- ECM may combine Usability Information with anonymous demographic information for research purposes and may use the result of this combination to provide more relevant content on the Site. In certain restricted areas of the Site, ECM may combine Personal Data with Usability Information to provide you with more personalized content.
User Data collected by ECM is not shared with third parties without the User’s consent, with the exception of the situations referred to in the following paragraph. However, in the event that the User contracts with ECM services that are provided by other entities responsible for the processing of personal data, the User Data may be consulted or accessed by these entities, to the extent that this is necessary for the provision of such services.
Under the applicable legal terms, ECM may transmit or communicate User Data to other entities in the event that such transmission or communication is necessary for the performance of the contract established between the User and ECM, or for pre-contractual steps at the request of the User, in the event that it is necessary for the fulfillment of a legal obligation to which ECM is subject or in the event that it is necessary to obtain the legitimate interests of ECM or a third party. In the event of a transmission of User Data to a third party, reasonable efforts will be made to ensure that the transferee uses the User Data transmitted in an appropriate manner in accordance with this Privacy Policy.
4. TECHNICAL, ORGANISATIONAL AND SECURITY MEASURES IMPLEMENTED
To ensure the security of User Data and maximum confidentiality, ECM treats the information you have provided to us in an absolutely confidential manner, in accordance with its internal security and confidentiality policies and procedures, which are periodically updated as needed, as well as with the terms and conditions provided for by law.
Depending on the nature, scope, context and purposes of the data processing, as well as the risks arising from the processing for the rights and freedoms of the User, ECM undertakes to apply, both at the time of defining the means of processing and at the time of the processing itself, the technical and organizational measures necessary and appropriate for the protection of the User Data and compliance with legal requirements. It also undertakes to ensure that, by default, only the data that is necessary for each specific purpose of the processing is processed and that such data is not made available without human intervention to an indeterminate number of persons.
Communication between the user’s device and the ECM Websites carried out through secure channels and communications that use the HTTPS protocol and the SSL security standard.
Still, in terms of general measures, the ECM adopts the following:
- Regular audits to identify the competence of the technical and organizational measures implemented;
- Awareness and training of staff involved in data processing operations;
- Mechanisms capable of ensuring the permanent confidentiality, availability and resilience of information systems;
- Mechanisms that ensure the restoration of information systems and access to personal data in a timely manner in the event of a physical or technical incident.
- TRANSFER OF DATA OUTSIDE THE EUROPEAN UNION
The personal data collected and used by ECM is not made available to third parties established outside the European Economic Area. If, in the future, such a transfer takes place for the reasons set out above, ECM undertakes to ensure that the transfer complies with the applicable legal provisions, in particular as regards the determination of the suitability of such country with regard to data protection and the requirements applicable to such transfers.
- USE OF COOKIES
When you visit our site, a small text file (Cookie) is created and saved on your computer’s disk, so by browsing the Website you agree to the installation of this text file on your device. This file will allow you to access the Website more easily and quickly, as well as customize it according to your preferences.
_ |
Most browsers accept these files (Cookies), but the User can delete them or automatically block them. In the “Help” menu of your browser you will find how to make these settings. However, if you do not allow the use of cookies, there may be some features of the Website that you will not be able to use.
If you do not want cookies to be installed on your device, you should not browse our website.
For more information related to the Cookies used, as well as how you can manage them, please read our Cookie Policy, available here.
- TOOLS USED BY THE WEBSITE FOR STATISTICAL READING AND USER BEHAVIOR.
Google Analytics
The Website uses Google Analytics, a web analysis service provided by Google Inc (hereinafter referred to as “Google”).
Cookies will be stored that provide information about the use and navigability of the Site. This data, including the User’s IP address, is transmitted to Google’s servers but is not linked to any other data held by Google.
The User can deactivate the tool by downloading and installing a browser add-on available from Google: https://tools.google.com/dlpage/gaoptout?hl=en.
Facebook, Linkedin and:
On the Website there is interactivity with Facebook, Linkedin, Pinterest, Flickr and Youtube through a connection to the servers of these social networks, this will allow to identify the website that the user is visiting and possibly store other data, such as the IP address.
If the User is logged in to Facebook, Linkedin, Pinterest, Flickr and/or Youtube, the data will be associated with their accounts. To prevent this from happening, the User must log out of Facebook, Linkedin, Pinterest, Flickr and Youtube before visiting the page.
Information regarding the data processing carried out by these social networks is available at: https://www.facebook.com/about/privacy/, https://www.linkedin.com/legal/privacy-policy?trk=hb_ft_priv and https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect.
X (Twitter)
The Website provides an interactivity with X (old Twitter Inc.), (hereinafter “X”), through its button, establishing a connection to Twitter’s servers, which will identify the Website you are visiting and possibly store other data, such as your IP address.
The data will be stored in this way only for the purpose of displaying the button. More information about how X processes data is available at: https://twitter.com/privacy.
B RIGHTS OF USERS (DATA SUBJECTS)
- RIGHT TO INFORMATION
8.1. Information provided to the User by ECM (where the data is collected directly from the User):
The identity and contact details of the ECM, controller and, if applicable, its representative;
- The contact details of the Data Protection Officer;
- The purposes of the processing for which the personal data are intended, as well as, if applicable, the legal reasons for the processing;
- If the processing of the data is based on the legitimate interests of ECM or a third party, indication of such interests;
- Where applicable, the recipients or categories of recipients of the personal data;
- Where applicable, an indication that the personal data will be transferred to a third country or an international organization, and the existence or absence of an adequacy decision adopted by the Commission or reference to appropriate or adequate transfer safeguards;
- Period of storage of personal data;
- The right to request access to the personal data, as well as its correction, erasure or restriction, the right to object to the processing and the right to accessibility of the data;
- If the processing of the data is based on the User’s consent, the right to withdraw it at any time, without compromising the lawfulness of the processing carried out on the basis of the consent previously given;
- The right to file a complaint with the CNPD or other supervisory authority;
- Indication of whether or not the communication of personal data constitutes a legal or contractual obligation, or a necessary requirement to conclude a contract, as well as whether the data subject is obliged to provide the personal data and the possible consequences of not providing such data;
- where applicable, the existence of automated decision-making, including profiling, and information relating to the basic concept, as well as the significance and expected consequences of such processing for the data subject;
- In the event that the User Data is not collected directly by ECM from the User, in addition to the information referred to above, the User is also informed about the categories of personal data being processed and also about the origin of the data and, if applicable, whether they are from publicly accessible sources;
- In the event that ECM intends to further process User Data for a purpose other than that for which the data was collected, prior to such processing ECM will provide the User with information about that purpose and any other information of interest as set out above.
8.2. Procedures and measures implemented with a view to fulfilling the right to information.
The information referred to in 8.1. is provided in writing (including by electronic means) by ECM to the User prior to the processing of the personal data concerned. Pursuant to applicable law, ECM is under no obligation to provide the User with the information referred to in 8.1 when and to the extent that the User is already aware of it.
The information is provided by ECM at no cost.
- RIGHT OF ACCESS TO PERSONAL DATA
ECM guarantees the means that allow the User to consult his/her Personal Data.The User has the right to obtain from ECM confirmation as to whether or not the personal data concerning him/her is being processed and, where applicable, the right to access his/her personal data and the following information:
- The purposes of the data processing;
- The categories of personal data concerned;
- The recipients or categories of recipients to whom the personal data have been or will be disclosed, including recipients established in third countries or belonging to international organizations;
- The period of storage of personal data;
- Right to request from ECM the correction, erasure or restriction of the processing of personal data, or the right to prevent such processing;
- Right to file a complaint with the CNPD or other supervisory authority;
- If the data has not been collected from you, the information available on the origin of that data;
- The existence of automated decision-making, including profiling, and information on the underlying logic, as well as the significance and expected consequences of such processing for the data subject;
- Right to be informed about the appropriate safeguards associated with the transfer of data to third countries or international organizations.
Upon request, ECM will provide the User, free of charge, with a copy of the User Data that is being processed. The provision of other copies requested by the User may incur administrative costs.
- RIGHT TO RECTIFICATION OF PERSONAL DATA
You have the right to request the rectification of your Personal Data at any time, as well as the right to have your incomplete personal data completed, including by means of an additional statement.
In the event of rectification of the data, ECM shall notify each recipient to whom the data have been transmitted of the respective rectification, unless such communication is considered impossible or involves a disproportionate effort on ECM.
- RIGHT TO ERASURE OF PERSONAL DATA (“RIGHT TO BE FORGOTTEN”)
You have the right to obtain the deletion of your data from ECM when one of the following reasons applies:
- The User Data is no longer necessary for the purpose for which it was collected or processed;
- The User withdraws the consent on which the processing of the data is based and there is no other legal basis for such processing;
- The User objects to the processing under the right to object and there are no overriding legitimate interests justifying the processing;
- If User Data is processed unlawfully;
- If User Data has to be erased in order to comply with a legal obligation to which ECM is subject.
Under applicable law, ECM is under no obligation to delete User Data to the extent that the processing is necessary for compliance with a legal obligation to which ECM is subject or for the establishment, exercise or defense of ECM’s legal right in a legal proceeding.
In the event of deletion of the data, ECM shall notify each recipient/entity to whom the data has been transmitted of the deletion of the data, unless such communication proves impossible or involves a disproportionate effort on ECM.
Where ECM has made User Data public and is required to erase it under the right to such erasure, ECM undertakes to take reasonable steps, including technical measures, taking into account the available technology and the costs of its application, to inform the controllers of the effective processing of the personal data that the User has requested them to erase the links to such personal data, as well as copies or reproductions thereof.
- RIGHT TO RESTRICTION OF THE PROCESSING OF PERSONAL DATA
The User has the right to obtain from ECM the restriction of the processing of User Data, if one of the following situations applies (the limitation consists of inserting a mark on the personal data retained for the purpose of restricting its processing in the future):
- If you contest the accuracy of the personal data, for a period that allows ECM to verify its accuracy;
- If the processing is unlawful and the User opposes the deletion of the data, requesting, in return, the limitation of its use;
- If ECM no longer needs the User Data for the purposes of processing, but the data is required by the User for the establishment, exercise or defense of legal claims;
- If the User has objected to the processing, until it is verified that ECM’s legitimate grounds prevail over those of the User;
- Where User Data is restricted, it may, with the exception of storage, only be processed with the User’s consent or for the purposes of establishing, exercising or defending legal claims, defending the rights of another natural or legal person, or for reasons of public interest provided for by law;
- The User who has obtained the restriction of the processing of his/her data in the above cases will be informed by ECM before the restriction of processing is annulled;
- In the event of a restriction of the processing of the data, ECM shall notify each recipient to whom the data have been transmitted of the restriction thereof, unless such communication proves impossible or involves a disproportionate effort on the part of ECM.
- RIGHT TO PORTABILITY OF PERSONAL DATA
You have the right to receive the personal data concerning you that you have provided to ECM in a structured, commonly used and machine-readable format, and the right to transmit such data to another controller if:
- The processing is based on consent or a contract to which the User is a party; and
- The processing is carried out by automated means.
The right to portability does not include inferred data or derived data, i.e. personal data that is generated by ECM as a consequence or result of the analysis of the data being processed.
You have the right to have your personal data transmitted directly between controllers, whenever this is technically possible.
- RIGHT TO OBJECT TO PROCESSING
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you based on the exercise of legitimate interests pursued by ECM or where the processing is carried out for purposes other than those for which the personal data were collected, including profiling, or where personal data is processed for statistical purposes.
ECM will terminate the processing of User Data unless it provides urgent and legitimate grounds for such processing which override the interests, rights and freedoms of the User, or for the establishment, exercise or defense of a right of ECM in a legal proceeding.
Where User Data is processed for the purpose of direct marketing, you have the right to object at any time to the processing of your data for the purposes of such marketing, which includes profiling to the extent that it is related to direct marketing. If you object to the processing of your data for the purpose of direct marketing, ECM will cease processing your data for that purpose.
You also have the right not to be subject to any decision taken solely on the basis of automated processing, including profiling, which has legal effects or similarly significantly affects you, unless the decision:
- It is necessary for the conclusion or performance of a contract between you and ECM;
- is authorized by legislation to which ECM is subject; or
- It is based on the User’s explicit consent.
- PROCEDURES FOR EXERCISING YOUR RIGHTS
The right of access, the right of rectification, the right of deletion, the right to limitation, the right of portability and the right to opposition may be exercised by the User through email privacidade@ecm.pt or by registered letter to the following address: Pezo, Parque Empresarial da Zona Oeste, Ribeira dos Socorridos 9304-003 Câmara de Lobos.
ECM will respond in writing (including by electronic means) to your request no later than one month from receipt of the request, except in particularly complex cases, where this period may be extended up to two months.
If the requests submitted by the User are manifestly unjustified or excessive, in particular due to their repetitive nature, ECM reserves the right to charge administrative costs or refuse to comply with the request.
- PERSONAL DATA BREACHES
In the event of a data breach and to the extent that such a breach is likely to entail a high risk to the rights and freedoms of the User, ECM undertakes to communicate the personal data breach to the User concerned within 72 hours of becoming aware of the incident.
In legal terms, communication to the User is not required in the following cases:
- where ECM has implemented appropriate protection measures, both technical and organizational, and those measures have been applied to the personal data affected by the personal data breach, in particular measures that make the personal data incomprehensible to any person not authorized to access such data, such as encryption;
- Where ECM has taken subsequent steps to ensure that the high risk to your rights and freedoms is no longer likely to materialize; or
- If the communication to the User involves a disproportionate effort on the part of ECM. In such a case, ECM will make a public communication or take a similar action by which the User will be informed.
C FINAL PART
- CHANGES TO THE PRIVACY POLICY
ECM reserves the right to change this Privacy Policy at any time. In case of modification of the Privacy Policy, the date of the last change, available at the end of this Policy, is also updated. If the change is substantial, a notice will be posted on the Website.
- APPLICABLE LAW AND JURISDICTION
The Privacy Policy, as well as the collection, processing or transmission of User Data, are governed by the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 and by the laws and regulations applicable in Portugal.
Any disputes arising from the validity, interpretation or execution of the Privacy Policy, or that are related to the collection, processing or transmission of User Data, shall be submitted exclusively to the jurisdiction of the judicial courts of the district of Lisbon, without prejudice to the applicable mandatory legal rules.