This is an archived version. It is published so that customers who ordered while it was in force can read the text that applied to them. It is not the current version — see the current documents.
Simple Smooth Safe, Unipessoal Lda.
Rua Retiro dos Pacatos 50, Ed. Startup, Sala 9
2635-224 Rio de Mouro, Sintra, Portugal
NIF / VAT: PT518264742
info@simplesmoothsafe.com
We are a small company and are not required to appoint a Data Protection Officer. Privacy questions go to the address above and reach a person, not a queue.
The short version
- We do not sell your data, share it with advertisers, or add you to a marketing list you did not ask to join.
- This site sets no cookies and there is no cookie banner, because there is nothing to consent to.
- Analytics are aggregate and cookieless — we can see that a pricing page was read, not who read it.
- Everything we hold about you, you can have deleted by sending one email.
1. What we collect, and why
1.1 Website analytics
We use Plausible Analytics to understand which pages are read and which links are used. Plausible is privacy-focused and EU-hosted: it sets no cookies, stores no personal data, does not fingerprint devices, and does not track visitors across sites or sessions.
It records aggregate page views, referrer, and coarse device and country information derived from the request and then discarded. No profile is built, and nothing collected identifies you.
| Field | Detail |
|---|---|
| Legal basis | Legitimate interest (Art. 6(1)(f) GDPR) — understanding whether our own website works. The balancing test is straightforward because no personal data is stored and no profiling occurs. |
| Retention | Aggregate statistics only. No individual record exists to delete. |
| Consent needed? | No. There is no cookie or device-storage access, so the ePrivacy consent requirement does not arise. |
1.2 When you email us
If you contact us we hold your name, email address, whatever you chose to tell us about your organisation, and the correspondence itself.
| Field | Detail |
|---|---|
| Purpose | To answer you, and to follow up on the specific thing you asked about. |
| Legal basis | Legitimate interest (Art. 6(1)(f)) in responding to an enquiry you initiated, or steps prior to entering a contract (Art. 6(1)(b)) where you are asking to buy. |
| Retention | Up to 24 months after our last exchange, then deleted — unless you become a customer, in which case section 1.4 applies. |
1.3 Early access and enquiry forms
Our forms are hosted on Microsoft Forms. They collect your name, work email, company, tenant or environment details, and whether you are a partner or an end client — behind a required consent question that is not pre-ticked, because a pre-ticked box is not consent.
| Field | Detail |
|---|---|
| Purpose | To contact you about the product you asked about — early access, availability, or a demo. That is the only thing it is used for. |
| Legal basis | Consent (Art. 6(1)(a)), given by ticking the box on the form. |
| Retention | Until you withdraw consent, or until the programme you signed up for closes, whichever is first. |
| Withdrawing | Email us. No reason needed, no effect on anything else, and no retention "for our records". |
1.4 Customer and supplier records
If your organisation becomes a customer we hold business-contact details for the people we deal with — name, role, work email, work phone — plus contracts, invoices and support correspondence.
| Field | Detail |
|---|---|
| Purpose | Performing the contract, supporting the products, and meeting our accounting and tax obligations. |
| Legal basis | Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) for the accounting records. |
| Retention | For the life of the relationship, then 10 years for anything that forms part of the accounting record, which is the retention period Portuguese tax law requires. Contact details not needed for that are deleted within 12 months of the relationship ending. |
1.5 Support access to your systems
Resolving a support case occasionally requires us to look at your environment. When it does, we may see personal data belonging to your staff or your clients. In that situation you are the controller and we are your processor — the Data Processing Agreement governs it, not this policy. Access is on your invitation, for the case, and we do not take copies.
2. What we do not do
- We do not sell, rent or trade personal data. There is no circumstance in which we would.
- We do not use advertising or social-media tracking pixels. There is no Meta pixel, no LinkedIn Insight tag, no Google Analytics, and no advertising network on this site.
- We do not build behavioural profiles or make automated decisions with legal or similarly significant effects. There is no automated decision-making of any kind.
- We do not enrich your details from third-party data brokers.
- We do not add enquirers to a newsletter. If a mailing list ever exists, joining it will be a deliberate act with its own consent.
3. Who else sees it
Only the processors we need to run the business, each bound by a data-processing agreement:
| Processor | Purpose | Location |
|---|---|---|
| Microsoft Ireland Operations Ltd | Email, file storage, Microsoft Forms | EU |
| Plausible Insights OÜ | Cookieless website analytics | EU (Estonia / Germany) |
| Our hosting provider | Serving this website | EU |
| Our accountant | Statutory accounting and tax filing | Portugal |
We will also disclose data where the law requires it. If we are ever compelled to, we will tell you unless we are legally prohibited from doing so.
The Data Processing Agreement carries the sub-processor list that applies when we process data on a customer's behalf, and the notice terms for changing it.
4. International transfers
Our processors are established in the EU and we ask them to keep data in the EU. Where a processor is part of a group that may access data from outside the EEA, transfers rely on the European Commission's Standard Contractual Clauses together with the supplementary measures the transfer requires. We do not transfer personal data to a country without an adequacy decision or appropriate safeguards.
5. Your rights
Under the GDPR you can ask us to:
- Access — tell you what we hold about you and give you a copy.
- Rectify — correct anything wrong.
- Erase — delete it, where we have no overriding obligation to keep it.
- Restrict — stop using it while a dispute about it is resolved.
- Port — supply it in a structured, machine-readable format.
- Object — to processing based on legitimate interest, including any direct marketing, which we will stop immediately and without argument.
- Withdraw consent — at any time, where consent was the basis. Withdrawal does not affect processing carried out before it.
Email info@simplesmoothsafe.com. We answer within 30 days, usually far sooner, and we do not charge for it. We may ask you to confirm your identity where the request concerns data whose disclosure to the wrong person would cause harm.
6. Complaints
If you think we have handled your data badly, tell us first — it is the fastest route to fixing it. You also have the right to complain to a supervisory authority. Ours is the Portuguese data protection authority:
Comissão Nacional de Proteção de Dados (CNPD)
Av. D. Carlos I, 134 — 1.º, 1200-651 Lisboa, Portugal
www.cnpd.pt
If you are in another EU member state you may complain to your own national authority instead.
7. Security
We apply measures appropriate to the risk: multi-factor authentication on every account, encryption in transit and at rest through our platform providers, least-privilege access, and no copies of customer data taken outside the systems above. The products themselves are designed so that your data stays in your tenant, which removes most of the risk rather than managing it.
If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the CNPD within 72 hours and tell you without undue delay where the risk is high.
8. Children
Our products and this website are for business use. We do not knowingly collect data from anyone under 16, and there is no part of what we do that is directed at children.
9. Changes
If we change this policy we update the version and date at the top. Where a change materially affects how we use data we already hold, we will tell the people affected directly rather than relying on them re-reading this page.