Privacy Policy and Personal Data Processing
General Data Protection Regulation
Organizado Brand
Competência Segurada – Gestão de Serviços, Lda
Organizado, Lda
Effective date: 10 August 2026
1. Preamble and Legal Framework
This Privacy and Personal Data Processing Policy aims to establish the rules and procedures adopted by the Organizado brand with regard to the collection, processing, protection and retention of the personal data of its Clients, prospective Clients, Users, Partners, Suppliers and Employees.
Our activities are governed by strict compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation – GDPR), Law No. 58/2019 of 8 August (Law implementing the GDPR in Portugal), as well as the sector-specific legislation applicable to Credit Intermediation and Insurance Mediation activities, including the regulations of the Bank of Portugal (BdP) and the Insurance and Pension Funds Supervisory Authority (ASF).
2. Identification of the Data Controllers
The Organizado brand operates commercially through two distinct legal entities, which act as Independent Controllers or Joint Controllers of Data Processing (pursuant to Article 26 of the GDPR).
The essence of the joint controllership agreement and the division of services establishes that:
- Competência Segurada – Gestão de Serviços, Lda. acts as the entity responsible for data processing exclusively within the scope of Insurance Mediation and Credit Intermediation.
- Organizado, Lda. assumes responsibility for data processing relating to the remaining services, management of the commercial brand and its own platforms, also acting as a processor for Competência Segurada in the centralisation and technological management of data.
For Insurance Mediation and Credit Intermediation activities:
Company: Competência Segurada – Gestão de Serviços, Lda.
Registered Office: Rua do Vigário Geral, 1C e 1D, 9500-443 Fajã de Baixo, Ponta Delgada
Tax Identification Number (NIF): 514558075
ASF Registration: Insurance Agent No. 417456724
BdP Registration: Tied Credit Intermediary No. 0006353
For related services and commercial brand and platform management:
Company: Organizado, Lda.
Registered Office: Avenida dos Inventores, 1, 2.º Esquerdo, 9560-421 Rosário, Lagoa
Tax Identification Number (NIF): 518835723
We inform you that the entities do not have an appointed Data Protection Officer (DPO).
For the exercise of any right or for clarification of any questions regarding this Policy, the Data Subject may contact the Data Controllers through the single email address:
3. Principles of Data Processing
The collection and processing of personal data by our entities are governed by the principles of lawfulness, fairness and transparency; purpose limitation; data minimisation (collecting only what is strictly necessary); accuracy; storage limitation; and integrity and confidentiality.
4. Categories of Personal Data Processed
The nature and complexity of our services require the collection of several categories of personal data from our ecosystem (Clients, Partners, Suppliers and Employees), namely:
- Civil Identification and Contact Data: Full name, gender, date of birth, place of birth, nationality, tax and residential address, identification numbers (Citizen Card, Tax Identification Number, Social Security Number, National Health Service User Number), marital status, matrimonial property regime, telephone/mobile phone number and email address.
- Household Composition Data (Clients): Identification of spouse/partner and dependants, for the purposes of assessing debt-service capacity and tax framework.
- Financial and Socioeconomic Data: Proof of income (Salary Slips, IRS Tax Return and Tax Assessment Notice), bank statements, IBAN, employer identification, employment relationship, professional seniority and Credit Responsibilities Map issued by the Bank of Portugal.
- Sensitive Data (Special Categories of Data – Article 9 GDPR): Health data, medical history and lifestyle information (e.g. smoking), collected exclusively through medical questionnaires for the purpose of subscribing to Life Insurance, Health Insurance or Personal Accident Insurance, strictly necessary for risk assessment by Insurance Companies.
- Human Resources Data (Employees): Professional category, remuneration, attendance records and data required for payroll processing and internal contractual management.
- Institutional and Business Data (Partners and Suppliers): Institutional contacts, invoicing data, credentials and data relating to service provision agreements.
- Interaction, Communication and Physical/Digital Channel Data: Video recordings (video surveillance in physical stores for the safety of people and property), telephone call recordings (when legally required or with consent for quality monitoring), records of conversations and interactions via WhatsApp, SMS, Social Networks (Facebook, Instagram, LinkedIn), institutional emails and messages submitted through website forms.
- Technical and Web Browsing Data: IP address, session and persistent cookies, device and browser type, and browsing logs on the www.organizado.pt portal.
5. Data Collection Channels and Methods
Data are collected directly from the Data Subject (or their legal representative) through the following means:
- In person: At our physical Stores and offices.
- Digitally and Remotely: Through our Management Platform, forms on the institutional website, lead generation campaigns (Meta Ads/Google Ads), WhatsApp messages, email, SMS, direct messages on social networks and telephone calls.
6. Purposes, Legal Grounds and Retention Periods
Below, we comprehensively map the purposes for which we process your data, the legal basis that legitimises such processing (Articles 6 and 9 of the GDPR), and the applicable retention periods.
| Purpose of Processing | Legal Basis (Lawfulness) | Legal/Operational Retention Period |
|---|---|---|
| Advice, Simulation and Presentation of Credit and/or Insurance Proposals | Pre-contractual steps at the request of the Data Subject (Article 6(1)(b) GDPR) | 6 months after the proposal is presented, if it does not result in a contract being entered into. |
| Formalisation, Management and Performance of Credit and Insurance Contracts | Performance of a Contract and Provision of Services (Article 6(1)(b) GDPR) | During the term of the contract and up to 10 years after its termination (statutory limitation and prescription periods). |
| Compliance with Legal and Regulatory Obligations (BdP, ASF, Tax Authority) | Legal Obligation of the Data Controller (Article 6(1)(c) GDPR) | 10 years for tax and contractual purposes. |
| Prevention of Money Laundering and Terrorist Financing (Law No. 83/2017) | Legal Obligation and Public Interest (Article 6(1)(c) and (e) GDPR) | 7 years (after the end of the business relationship or occasional transaction), extendable according to instructions from the competent authorities. |
| Collection and Processing of Health Data for Life/Health Insurance | Explicit Consent of the Data Subject (Article 9(2)(a) GDPR) | During the term of the contract and related obligations (managed directly by the Insurers). |
| Customer Support (Telephone, Stores, WhatsApp, Social Networks) | Legitimate Interest and Contractual Performance (Article 6(1)(b) and (f) GDPR) | Until the request is resolved and during the applicable legal warranty/contract periods. |
| Direct Marketing (Newsletters, Promotional SMS, Campaigns) | Consent of the Data Subject (Article 6(1)(a) GDPR) | Until the Data Subject withdraws consent (opt-out). |
| Video Surveillance on Physical Premises | Legitimate Interest in the security of people and property (Article 6(1)(f) GDPR) | 30 days (with the recordings being destroyed after this period, unless required as judicial evidence). |
7. Profiling and Automated Decision-Making
Within the scope of the submission of credit applications, the assessment of the Client’s creditworthiness requires an analysis of their financial profile (borrowing capacity, debt-service ratio and credit history). This pre-assessment may involve profiling.
Partner lending Banking Institutions may use automated individual decision-making processes (risk scoring algorithms) for the approval or rejection of credit.
The Data Subject has the right to obtain human intervention, express their point of view and contest any automated decision taken by the partner institutions.
8. Sharing and Transfer of Data to Third Parties
In order to fulfil the purposes indicated and ensure excellence in the provision of services, your data are integrated into a proprietary Management Platform managed by Organizado, Lda., and may be disclosed to the following entities:
- Insurance Companies: Partner insurers for the issuance of quotations, policies and claims management.
- Credit Institutions and Lenders: Banking or financial entities with which we have a tied agreement.
- Official and Regulatory Entities: Bank of Portugal (BdP), Insurance and Pension Funds Supervisory Authority (ASF), National Data Protection Commission (CNPD), Tax Authority (AT) and Judicial/Police authorities (in compliance with the law or pursuant to mandates).
- Technology and Management Data Processors (Article 28 GDPR): In order to centralise our operations, data are processed on a proprietary platform developed and maintained by our technology partner Leap Forward, Unipessoal, Lda., which operates under strict contractual instructions (Data Processing Agreement) and is prohibited from using the information for its own purposes. Other Data Processors include web/cloud hosting services, accounting firms and SMS/E-Mail delivery platforms.
9. International Data Transfers
Organizado seeks to host and process personal data exclusively within the European Economic Area (EEA).
However, through the use of certain digital platforms (e.g. Google, Meta/WhatsApp tools), data may be transferred outside the EEA.
In such cases, we ensure that such transfers take place on the basis of appropriate safeguards, such as European Commission Adequacy Decisions or the adoption of Standard Contractual Clauses (SCCs), ensuring a level of protection equivalent to that required within the EEA.
10. Security and Confidentiality Measures
The financial and health information processed by Organizado is highly sensitive. As such, we implement a rigorous framework of Technical and Organisational Measures (TOMs), which include:
- Centralisation of data in a secure and dedicated cloud infrastructure, monitored by our team and our technology partners;
- Restricted and segmented access to information, granted only to employees with a need to know (need-to-know basis);
- Two-factor authentication (2FA) on the IT systems of our platform;
- Encryption protocols (SSL/TLS) for the transmission of data through our website;
- Physical access controls at Stores and offices;
- Ongoing training of the team in Data Protection and Prevention of Money Laundering;
- Strict confidentiality clauses signed by all employees, partners and software suppliers.
11. Rights of Data Subjects
The GDPR grants you a broad set of rights, which we fully respect:
- Right of Access (Article 15): To obtain confirmation that your data are being processed and to access a copy thereof.
- Right to Rectification (Article 16): To request the correction of inaccurate or outdated data.
- Right to Erasure or “Right to be Forgotten” (Article 17): To request the deletion of your data. Note: Deletion may be refused if there is a superior legal obligation requiring their retention (e.g. tax laws or anti-money laundering legislation).
- Right to Restriction of Processing (Article 18): To request the temporary suspension of processing in specific situations (e.g. while the accuracy of the data is being contested).
- Right to Data Portability (Article 20): To receive the data in a structured, commonly used and machine-readable format and to transmit it to another controller.
- Right to Object (Article 21): To object to processing based on legitimate interests or to object, at any time, to processing for direct marketing purposes.
- Right to Withdraw Consent (Article 7(3)): Whenever processing is based on consent (such as health data or marketing), consent may be withdrawn at any time, without affecting the lawfulness of processing carried out up to that point.
12. Exercise of Rights and Complaints
To exercise any right provided for by law, the Client may submit a written request to the email address geral@organizado.pt or by registered letter to the registered office of the respective company.
Requests shall be assessed and responded to within a maximum period of 30 days.
The Client also has the inalienable right to lodge a complaint with the national supervisory authority:
National Data Protection Commission (CNPD)
Rua de São Bento, No. 148 – 3rd Floor
1200-821 Lisbon
Portugal
Tel.: +351 213928400
Website: www.cnpd.pt
13. Update of the Privacy Policy
This document shall be reviewed periodically.
This version reflects the transition to our new centralised management platform.
Significant updates shall be communicated through our website and displayed in a visible location at our Stores.