Information notice
Privacy Policy
How the directory collects, uses, displays, protects, and retains account, listing, submission, public-source, communication, and technical data.
- Last updated:
- 4 August 2026
- Version:
- 1.0
This page contains general website information for Find HACCP Consultants. It is not legal advice.
Data controller
The data controller is Joao Reis, trading as Find HACCP Consultants, at Lisbon, Portugal. Privacy questions can be sent to info@findhaccpconsultants.com.
Information collected
- Account information, such as email address, authentication identifiers, account role, and account profile details.
- Provider information, such as business name, public contact details, location, service areas, services, industries, profile text, logos, website links, and status labels.
- Claim and submission information, including relationship details, evidence, moderation status, admin messages, and change history.
- Public-source information used to create or maintain unclaimed listings.
- Communications, including reports, correction requests, claim conversations, and notification metadata.
- Technical and security data, including cookies, IP-derived security signals, browser and device data, logs, rate-limit events, and bot-protection results.
- Payment metadata where paid services are added in future, such as invoice identifiers, plan status, and payment-provider references.
Sources of information
Information may come from account holders, providers, submitters, claimants, reporters, public business sources, directory moderation activity, authentication providers, security tools, and service providers used to operate the site.
Purposes and legal bases
Data is processed to operate accounts, publish and manage listings, review submissions and claims, respond to requests, maintain security, prevent abuse, send service notifications, comply with legal obligations, keep records, and improve directory quality. Legal bases may include contract necessity, legitimate interests, consent where required, and legal obligation.
Legitimate interests
Legitimate interests include operating an independent directory, keeping listing information useful and accurate, preventing misuse, protecting users and providers, maintaining records, resolving disputes, and explaining ranking and moderation decisions. These interests are balanced against individual rights and expectations.
Publicly sourced and unclaimed listings
Unclaimed listings may be created from public business information. The directory seeks to minimise personal data and prefers business information over private information.
Correction, claim, objection, and removal routes are available. Internal source and retrieval information may be maintained so the operator can audit where listing information came from. Private evidence and internal moderation notes are not publicly displayed.
Publicly displayed information
Published profiles may display business names, public service details, public contact channels, locations served, profile descriptions, logos, links, claim status, and last-review information. Private account emails, claim evidence, internal metadata, and admin-only notes are not shown publicly.
Service providers and recipients
| Service | Role | Data involved | Retention note |
|---|---|---|---|
| Supabase | Authentication, database, storage, server-side security and session management. | Account data, provider records, submissions, claim records, audit records, files, and technical security data. | Account and active listing records are kept while needed to operate the service. Closed operational records are reduced or deleted under the retention schedule below. |
| Resend | Transactional email delivery when configured. | Recipient email addresses, message metadata, and email content needed to send notifications. | Delivery records are kept only as long as needed for delivery, troubleshooting, audit and unsubscribe evidence. |
| Google OAuth | Optional sign-in method selected by the user. | OAuth identifiers, email address, profile data returned by Google, and sign-in metadata. | OAuth data is kept while the account uses Google sign-in or while required for account security records. |
| Cloudflare Turnstile | Bot and abuse protection for listing submission flows when configured. | Challenge token, technical request data, and verification result. | Challenge data is processed for short-term abuse prevention and security verification. |
International transfers
Some service providers may process data outside Portugal or the EEA. Where this occurs, appropriate safeguards should be used, such as adequacy decisions, standard contractual clauses, provider data-processing terms, or other lawful transfer mechanisms.
Retention
- Account records are kept while the account remains active and for a reasonable period after closure where needed for security, legal claims, audit trails or abuse prevention.
- Published listing records and profile versions are kept while the listing is active and while needed to evidence source, publication, claim, correction or moderation decisions.
- Sent and cancelled notification outbox records are eligible for deletion after 13 months. Failed or pending records may be retained until delivery issues are resolved or the message is cancelled.
- Closed reports and moderation appeals are eligible for deletion after 24 months unless a legal, safety, abuse-prevention or dispute reason requires longer retention.
- Private evidence files are restricted to authorised review workflows and should be removed or further restricted when the related case no longer requires them.
- Security logs, rate-limit records and bot-protection signals are kept for the shortest period practical for detecting abuse, diagnosing incidents and protecting the service.
Individual rights
Individuals may have rights to access, rectify, erase, restrict, object to, or port personal data, and to withdraw consent where processing is based on consent. Requests can be sent to info@findhaccpconsultants.com.
Objections concerning public listings
People connected to public or unclaimed listings may request correction, claim review, objection, or removal using info@findhaccpconsultants.com. The operator may ask for enough information to verify the request and assess competing legal, public-interest, accuracy, and anti-abuse considerations.
Complaints to CNPD
You can contact the Portuguese data protection authority, Comissão Nacional de Proteção de Dados CNPD, if you believe your data-protection rights have not been respected.
Security
The operator uses technical and organisational measures intended to protect the website, accounts, submissions, and records. No online service can guarantee absolute security.
Children
The directory is intended for business and professional use, not for children. Children should not create accounts or submit provider information.
Automated decision-making
The directory may use filtering, sorting, and security checks, but it does not use automated decision-making that produces legal or similarly significant effects about individuals without human involvement.
Changes
This Privacy Policy may be updated as the directory, service providers, and legal requirements change. The version and last-updated date identify the current policy.
Contact
- General contact
- info@findhaccpconsultants.com
- Legal contact
- info@findhaccpconsultants.com
- Privacy contact
- info@findhaccpconsultants.com
- Listings and corrections
- info@findhaccpconsultants.com
