Last updated 2026-09-06
Privacy Policy
What data OperadorPT processes, on what basis, where it is stored, who has access to it, and what you can demand in respect of it. Written to be read, not to be signed unread.
Data controller
The full identification of the entity operating OperadorPT is not yet published on this page. Until it is, you can request it — legal name, tax number, and registered address — from the support address at the end of this document, and it will be sent to you.
1.Who decides what about your data
There are two distinct roles in this tool, and it is worth separating them, because each person’s rights depend on which applies. For account data — who registers, with which email address, in which working language — OperadorPT is the data controller.
For the operational records the customer company enters — completed tasks, temperatures, notes, incidents, proof photos, and who did what and when — the controller is the company that subscribed to the service. OperadorPT processes those records on its behalf, as a processor, and only in order to provide the service. If you are a worker at one of those companies and want to know what is recorded about you, address the request to your employer first.
2.What data is processed
The data needed for the service is described below. Optional measurement is addressed separately in the cookies section.
- Account: email address, display name, interface language and working language, creation date, last sign-in date and, if you set a password, its cryptographic hash — the password itself is never stored.
- Operations: locations, task templates and their translations, completed tasks with time and author, recorded values (temperatures, for example), notes, incidents and corrective actions, and files attached as proof.
- Security and sessions: open sessions, IP addresses and anomalous-activity signals used to rate-limit access attempts, and an audit log of sensitive operations performed on the account.
- Billing: where there is a paid subscription, the plan status and the identifiers assigned by the payment processor. Card details are entered at the payment processor and never pass through us.
3.On what legal basis
Account and operational data are processed to perform the service contract (Article 6(1)(b) GDPR). Security and audit records rest on the legitimate interest in keeping the service secure and being able to show who did what (Article 6(1)(f)). Where the law requires us to keep documents — billing records, for instance — the basis is compliance with a legal obligation (Article 6(1)(c)).
There is no behavioural advertising, no sale of data to third parties, and no automated decision-making producing legal effects on individuals.
4.Where the data is stored, and who touches it
The database and attached files are hosted on OVHcloud infrastructure in the Gravelines region, France — that is, inside the European Union. Files uploaded as proof are kept in private storage and are only opened through temporary links generated by the service itself.
The operational providers are listed below. Optional Google measurement is addressed separately in the cookies section.
- OVHcloud — hosting of the application, the database, and file storage, within the European Union.
- Stripe — processing of subscription payments, where these exist. It receives payment details directly from you; we receive only the subscription status.
- Email delivery — the contracted transactional email delivery provider, to deliver sign-in links and service notices.
5.For how long
Let us be exact, because this is where it is easiest to promise what is not delivered: there is currently no automatic deletion once a period elapses. Account data and operational records are kept for as long as the account exists, and are deleted when deletion is requested — a process handled manually today by the support team, within the legal deadline of one month from the request.
Email sign-in links expire in about twenty minutes and are single-use. Sessions lapse through inactivity. Billing documents are kept for the period tax law requires, even after the account is closed.
6.Your rights, and how to use them
You have the right to know what data exists about you, to correct it, to ask for it to be erased, to restrict or object to certain processing, and to receive the data you provided in a portable format.
These requests are handled today by email, to support@operadorpt.pt, and not through a button inside the application — we say so here rather than letting you find out on your own. We reply within one month. You may be asked to confirm your identity, so that one person's data is not handed to another.
If you consider that your data is not being handled as it should be, you may lodge a complaint with the Comissão Nacional de Proteção de Dados (CNPD), the supervisory authority in Portugal, or with the authority of the country where you live.
7.Cookies and optional Google Analytics
Google Analytics is disabled in this version. We do not load its tag or send requests to Google, even with a saved choice, until the privacy and measurement-settings review is complete.
Purpose and choice: understand use of public pages, based on your consent. Earlier permission for first-party metrics does not authorise Google. Declining does not restrict the service. Withdraw through Change privacy choice in the footer.
When enabled and accepted, Google receives the IP address needed for the connection, technical browser/device data and cookie identifiers, plus a normalised public path and a fixed title. This is not anonymous measurement. We do not send full URLs, queries, fragments, referring pages, free text, forms, financial values or account, property or report identifiers.
Authenticated, private, analysis and report areas are excluded. Internal operational events are not connected to Google. Advertising, Google signals, personalisation, user-provided data collection and enhanced measurement are not enabled.
The measurement-choice cookie lasts up to 180 days. A local reminder of the choice remains until browser storage is cleared. The _ga and _ga_* cookies have a configured 90-day lifetime without automatic renewal. Withdrawal stops the measurement context and deletes these cookies on this domain. Do Not Track and Global Privacy Control prevent loading.
Google receives measurement data when measurement is enabled and accepted; processing outside the European Economic Area may occur. The contractual provider identity, processing locations, transfer safeguards and Google-property retention must be confirmed and published before activation. This change does not attest that review or replace the contacts and rights described in this policy.
8.Security, and what we do if something goes wrong
Traffic is encrypted in transit, sensitive fields are encrypted in the database, passwords are stored only as a cryptographic hash, uploaded files go through a check before becoming available, and sensitive operations are logged. You can close sessions open on other devices from within the application itself.
If a personal data breach occurs that poses a risk to the people affected, we notify the supervisory authority within seventy-two hours and inform the affected customers.
9.Changes and contact
If this policy changes materially, the date at the top changes with it and account holders are notified by email before the change takes effect.
This policy is drafted in Portuguese and also made available in English and Spanish. In the event of any discrepancy between versions, the Portuguese version prevails; the translations are provided for convenience.
For any privacy question, including exercising the rights above: support@operadorpt.pt.