Identification
This Policy describes how Atelier Noiva Lusa (hereafter "Atelier", "we") collects, processes and protects the personal data of those who interact with us, in compliance with the General Data Protection Regulation (Regulation EU 2016/679, "GDPR") and applicable Portuguese law.
The Atelier's contacts for privacy-related matters are at the end of this document, in the section Contact and complaints.
Data collected
We only collect the data needed to respond to a request, book a fitting, fulfil an order or provide the bridal gown sale and alteration service. Depending on the channel and purpose, the data may include:
- Identification data: first name, surname, expected wedding date, and in the case of booking for alterations or purchase, tax identification number (NIF) for invoicing.
- Contact data: email, phone, postal address (only when needed for gown delivery or postal communication).
- Fitting context data: date and time of booking, possible companions (for space management only), style preferences shared voluntarily.
- Payment data: bank reference, IBAN or transfer receipt. We do not store full credit card data.
- Site technical data: IP address, browser type, pages visited, in anonymised/aggregated format for website operation and improvement purposes.
We do not collect special categories of personal data (health, religion, political opinion) and we ask that you do not share such data with us through the form or by email.
Purpose of processing
Your data is processed for the following purposes:
- Booking and managing fittings at the atelier or the outlet (including pre and post-fitting communications, reminders, schedule changes).
- Replying to information requests submitted via the form, email, phone or social networks.
- Managing the contractual relationship for the sale and alteration of the gown, including invoicing, warranty, intermediate alterations and final delivery.
- Compliance with legal obligations in tax, accounting and consumer protection matters.
- Improving the website and the online experience through aggregated traffic analysis (without individual profiling).
We do not use your data for automated direct marketing nor share your information with third parties for commercial purposes.
Legal bases
The processing of your data is based on the following legal bases set out in Article 6 of the GDPR:
- Performance of a contract (Art. 6(1)(b)) for managing the booking, the fitting and the sale of the gown.
- Consent (Art. 6(1)(a)) when you submit a voluntary request via the contact form or accept this policy before sending a message.
- Compliance with a legal obligation (Art. 6(1)(c)) for tax, accounting and statutory warranty matters.
- Legitimate interest (Art. 6(1)(f)) for aggregated website traffic analysis and operational communications essential to the contracted service.
Data subject rights
As the data subject, you have at any time the following rights under the GDPR:
- Right of access to the data we hold about you.
- Right of rectification of incorrect or outdated data.
- Right to erasure ("right to be forgotten"), except where there is a legal obligation to retain.
- Right to restriction of processing in certain circumstances.
- Right to portability of the data you provided to us, in a structured format.
- Right to object to processing based on legitimate interest.
- Right to withdraw consent at any time, without compromising the lawfulness of prior processing.
To exercise any of these rights, send a written request to info@noivalusa.pt, identifying yourself unambiguously. We reply within a maximum of 30 days.
Retention periods
Personal data is kept only for the time needed to fulfil the purposes for which it was collected, observing the following reference periods:
- Information requests not converted: up to 12 months after the last contact, for the purpose of possibly resuming the dialogue.
- Fittings completed: up to 24 months after the last interaction, for follow-up and process history.
- Contractual and tax documents (invoice, payment receipts, warranty): for 10 years, as required by Portuguese tax law.
- Browsing technical data: as per the cookie policy (see Cookie Policy).
Subprocessors
To deliver the service, we use a restricted set of providers acting as subprocessors, under the Atelier's instructions and in accordance with data processing agreements (DPA) signed under Art. 28 of the GDPR:
- Web hosting and CDN: Vercel Inc. (servers in the European Union when available).
- Online booking system: BUK Software (calendar and reservation manager).
- Transactional email service: SMTP provider used to send replies and booking confirmations.
- Accounting and invoicing: certified accountant and fiscal management software bound by professional confidentiality.
We do not perform international data transfers outside the European Economic Area without adequate safeguards (European Commission standard contractual clauses or adequacy decisions).
Security and cookies
We apply technical and organisational measures appropriate to protect your data against unauthorised access, accidental loss, alteration or disclosure. Communications between your browser and our website are encrypted via HTTPS/TLS, and access to internal data is restricted to team members strictly necessary.
For detailed information about cookies and similar technologies used on the website, see our Cookie Policy.
Contact and complaints
For any question related to this Policy, the exercise of rights or clarification on the processing of your personal data, you can contact us via:
- Email: info@noivalusa.pt
- Phone: +351 936 338 903
- Address: Rua Dom Henrique de Cernache 139, Vila Nova de Gaia, Portugal.
If you consider that the processing of your data does not comply with the GDPR, you have the right to lodge a complaint with the competent supervisory authority in Portugal, the National Data Protection Commission (CNPD), or with another supervisory authority competent in your Member State of residence.
You may also use the Electronic Complaints Book for matters related to the service provided.
Changes to this policy
This Policy may be updated to reflect legislative changes, new technologies or adjustments to the service provided. Whenever this happens, the updated version is published on this page with a new date at the top of the document.
We recommend periodic review. Continued use of the website or our services after any change to the Policy implies tacit acceptance of the new version.
last updated