Privacy Policy and Personal Data Protection
1. Framework and Commitment
This Privacy Policy and Personal Data Protection establishes the terms under which CrediSegur processes personal data, in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR) and other applicable national legislation. CrediSegur adheres to the fundamental principles of transparency, security, confidentiality, data minimization, and respect for the rights of data subjects.2. Identification of the Data Controller
CrediSegur is the registered national brand (INPI No. 668183) of CRRF - BROKERAGE, LDA, corporate entity No. 509447970, headquartered at Rua da Terça, No. 11, 3200-010 Casal de Ermio, which acts as: Linked Credit Intermediary, registered with Banco de Portugal under No. 0001290;Insurance Agent, registered with the Insurance and Pension Funds Supervisory Authority (ASF) under No. 421751530.CRRF - BROKERAGE, LDA is the entity responsible for processing personal data.Contact for GDPR and complaints: sede@credisegur.pt 3. Data Subjects
This Policy applies to clients, potential clients, users of digital channels, partners, suppliers, and other individuals whose data is processed in the context of CrediSegur's activities. 4. Categories of Personal Data Processed
CrediSegur may process, namely:- Identification and contact data;
- Biographical, professional, and family data;
- Financial data necessary for solvency analysis;
- Data related to credit and insurance products;
- Browsing and usage data of digital channels;
- Records of written or telephone communications, when applicable.
5. Data Source
Personal data is collected directly from the data subject, through digital channels, electronic communications, telephone or in-person interactions, as well as through partners, when necessary for the execution of the requested services.6. Purposes and Legal Grounds for Processing
Personal data is processed for the following purposes:- Intermediation of mortgage credit and consumer credit;
- Mediation of Life and Non-Life insurance;
- Compliance with legal, regulatory, and supervisory obligations;
- Fraud prevention and money laundering;
- Management of relationships with clients and partners;
- Customer service, support, and process management;
- Development and provision of new business verticals, including energy, telecommunications, travel, health, wellness, and complementary services;
- Referral of contacts to third-party partners, when requested or authorized;
- Communication and marketing, when applicable.
The processing is based on the execution of pre-contractual or contractual diligence, compliance with legal obligations, the legitimate interest of CrediSegur, and, when required, the consent of the data subject. 7. Profiling and Decision Support
CrediSegur may use analysis or pre-qualification mechanisms based on the provided data, exclusively for initial diagnostic support, and no automated decisions with legal effects will be made.8. Sharing of Personal Data
Personal data may be shared with:- Credit institutions and insurers;
- Commercial partners and third parties, within the scope of authorized verticals;
- Providers of technological services and subcontractors;
- Public authorities and regulators, when legally required.
- The sharing is carried out with adequate guarantees of confidentiality and security.
9. Data Retention
Personal data is retained for a base period of 5 (five) years, automatically renewable for equal periods, unless expressly opposed by the data subject in writing, without prejudice to the fulfillment of legal, tax, regulatory obligations or the defense of the rights of CrediSegur.10. Rights of Data Subjects
Under the GDPR, the data subject has the right to access, rectification, erasure, restriction, portability, objection to processing, withdrawal of consent, and to lodge a complaint with the National Data Protection Commission (CNPD).The exercise of these rights can be carried out through the address sede@credisegur.pt.11. Information Security
The CrediSegur adopts appropriate technical and organizational measures to protect personal data against unauthorized access, loss, destruction, alteration, or improper disclosure.12. Cookies and Similar Technologies
The use of cookies is governed by its own policy, available on the digital channels of CrediSegur, ensuring respect for user preferences.13. Changes to the Policy
The CrediSegur reserves the right to update this Policy whenever necessary, with changes duly published.