Data Protection Policy

Last updated: Junt 7, 2026

Table of Contents

  1. Introduction
  2. General Principles of Processing
  3. Data Controller
  4. Categories of Data Processed
  5. Purposes of Processing
  6. Legal Bases for Processing
  7. Data Retention Periods and Criteria
  8. Processors and Service Providers
  9. Data Sharing with Third Parties
  10. International Data Transfers
  11. Security Measures
  12. Personal Data Breach Management
  13. Data Subject Rights
  14. Internal Procedures and Compliance
  15. Audits and Reviews
  16. Data Protection Officer (DPO)
  17. Changes to this Policy
  18. Data Protection Contacts

1. Introduction

This Data Protection Policy sets out the principles, rules, and procedures adopted by Ptgal Business, regarding the processing of personal data, ensuring compliance with the General Data Protection Regulation (GDPR), Portuguese Law No. 58/2019, and all applicable data protection legislation.

This Policy ensures that all internal processes involving the collection, use, storage, disclosure, and deletion of personal data are conducted in accordance with the principles of security, transparency, and accountability.


2. General Principles of Processing

Ptgal Business adheres to the following principles established under the GDPR:

  • Lawfulness, fairness, and transparency – personal data is processed in a lawful and transparent manner.
  • Purpose limitation – data is collected for specified, explicit, and legitimate purposes.
  • Data minimization – only data necessary for the intended purposes is processed.
  • Accuracy – data is kept accurate and up to date whenever necessary.
  • Storage limitation – data is retained only for as long as necessary.
  • Integrity and confidentiality – data is protected against unauthorized access, disclosure, or misuse.
  • Accountability – MG Group maintains records and documentation demonstrating compliance with data protection obligations.

3. Data Controller

The entity responsible for the processing of personal data is:

Ptgal Business
Rua José Simões Baião, 67
2240-008 Águas Belas FZZ – Portugal
Phone: +351 910 689 460
Email:


4. Categories of Data Processed

Ptgal Business may process the following categories of personal data:

  • Identification data (name, telephone number, email address);
  • Professional information (company, position, department);
  • Website usage data (IP address, approximate location, access logs);
  • Technical and analytical browsing data;
  • Information voluntarily submitted through forms;
  • Data required to comply with legal and regulatory obligations.

5. Purposes of Processing

Personal data may be processed for the following purposes:

  • Managing inquiries, requests, and communications;
  • Managing relationships with customers, partners, and suppliers;
  • Compliance with legal, tax, and regulatory obligations;
  • Website security and fraud prevention;
  • Continuous improvement of services and internal processes;
  • Internal administrative management;
  • Statistical analysis and website performance measurement.

6. Legal Bases for Processing

Personal data is processed based on one or more of the following legal grounds:

  • Consent of the data subject;
  • Performance of a contract or implementation of pre-contractual measures;
  • Compliance with legal obligations applicable to Ptgal Business;
  • Legitimate interests pursued by Ptgal Business in relation to internal management, security, business operations, and the effective functioning of its websites and systems.

7. Data Retention Periods and Criteria

Personal data is retained only for the period necessary to fulfil the purposes for which it was collected, unless longer retention periods are required by law or necessary for the establishment, exercise, or defence of legal claims.


8. Processors and Service Providers

Ptgal Business may engage external service providers to support technical operations, hosting, cybersecurity, maintenance, and other business functions. These providers act as data processors and are contractually required to:

  • Ensure the confidentiality of personal data;
  • Comply with the GDPR and applicable legislation;
  • Implement appropriate technical and organisational security measures;
  • Process personal data solely for the agreed purposes.

9. Data Sharing with Third Parties

Personal data may be shared with:

  • Companies within MG Group;
  • Contracted service providers;
  • Public authorities where legally required;
  • Commercial partners strictly necessary for the provision of services.

Personal data is never sold to third parties.


10. International Data Transfers

International transfers of personal data outside the European Union or European Economic Area will only occur where:

  • The destination country provides an adequate level of protection;
  • Standard Contractual Clauses approved by the European Commission are implemented;
  • Explicit consent has been obtained from the data subject where required;
  • Other appropriate safeguards have been established in accordance with applicable legislation.

11. Security Measures

Ptgal Business implements robust technical and organisational measures to protect personal data, including:

  • Access control and permission management;
  • Firewalls, active monitoring, and intrusion detection systems;
  • Encryption of sensitive information where appropriate;
  • Secure backup and recovery procedures;
  • Strict confidentiality obligations for employees and business partners;
  • Regular security reviews and audits.

12. Personal Data Breach Management

In the event of a personal data breach, Ptgal Business will follow all applicable legal requirements, including:

  • Notification to the competent supervisory authority within 72 hours where required;
  • Communication to affected data subjects when there is a high risk to their rights and freedoms;
  • Immediate implementation of corrective and containment measures;
  • Maintenance of detailed incident records and documentation.

13. Data Subject Rights

Data subjects have the right to:

  • Access their personal data;
  • Rectify inaccurate or incomplete information;
  • Request erasure of personal data (“right to be forgotten”);
  • Restrict processing;
  • Receive data portability;
  • Object to processing;
  • Withdraw consent at any time where processing is based on consent.

Requests relating to these rights should be sent to:


14. Internal Procedures and Compliance

Ptgal Business maintains internal policies and procedures covering:

  • Data protection training and awareness;
  • Access management and authorization controls;
  • Periodic review of data processing activities;
  • Documentation of processing operations;
  • Data Protection Impact Assessments (DPIAs) where required.

15. Audits and Reviews

Ptgal Business conducts periodic internal audits and reviews to ensure that its practices remain aligned with GDPR requirements and applicable legislation, addressing any identified compliance issues.


16. Data Protection Officer (DPO)

The Data Protection Officer can be contacted at:

Email: " rel="noopener" data-start="7247" data-end="7273">


17. Changes to this Policy

Ptgal Business may update this Policy whenever legislative, organisational, operational, or technological changes require it. The most recent version will always be made available on the website.


18. Data Protection Contacts

For any questions regarding data protection matters, please contact:

Data Protection Officer (DPO)
Email: " rel="noopener" data-start="7247" data-end="7273">

If you believe that your data protection rights have been infringed, you may lodge a complaint with the competent supervisory authority in your jurisdiction. In Portugal, the supervisory authority is the National Data Protection Commission (CNPD).

 
 

 

PTGAL Business

Rua José Simões Baião, 67
2240-008 Águas Belas
Ferreira do Zêzere | Portugal

T.: +351 910 689 460

@:

© 2026 – PTGAL Business, Lda. | All rights reserves