This is a courtesy translation. The Portuguese version prevails.

Privacy policy

Last updated: 3 October 2026

This policy explains how we process the personal data of people who visit the website, send us a request or use the owners' portal and the app, in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR).

1. Who the data controller is

The controller of the data collected on the website is Habiteight.

For any privacy question, or to exercise your rights, write to privacidade@habiteight.pt.

In the owners' portal and the app, the controller is the condominium to which your unit belongs. Habiteight processes that data as a processor, on behalf of the condominium.

2. What data we process, why and for how long

When the data is not collected directly from you (for example, when the condominium gives us the owners' contact details), its source is the condominium itself.

Contact and quote requests

Data
Name, email, phone (optional), the capacity in which you make the request, message and, for quote requests, details of the condominium (address or postcode, number and type of units, whether there is a lift, who manages it and how much it pays today).
Purpose
To reply to your request and to prepare and present a management proposal.
Legal basis
Steps taken at your request prior to entering into a contract (GDPR, Article 6(1)(b)) and our legitimate interest in replying to the requests we receive (Article 6(1)(f)).
Retention
Up to 12 months after the request, if no contract is entered into. If one is, the data becomes subject to the retention period of the contract.

Applications to the franchise programme

Data
Name, email and geographical area of interest.
Purpose
To assess your interest and contact you about the franchise programme.
Legal basis
Steps taken at your request prior to entering into a contract (GDPR, Article 6(1)(b)) and legitimate interest (Article 6(1)(f)).
Retention
12 months after the application.

Owners' portal and app

Data
Identification and contact details, unit, fees and payments, reported repair requests, condominium documents and account authentication data.
Purpose
To provide the management service contracted by the condominium and to give access to the condominium's information.
Legal basis
For this processing, each condominium is the controller and Habiteight acts as a processor, on behalf of the condominium and following its instructions (GDPR, Article 28). The legal basis is set by the condominium, usually the performance of the contract and compliance with legal obligations (Article 6(1)(b) and (c)).
Retention
For the duration of the management contract and, afterwards, for the applicable legal periods.

Requests about this data can be sent to the condominium or to us: we forward them and help the condominium to reply.

Collection of overdue fees

Data
Identification of the owner, unit, amounts owed, payment history and contact details (email and phone).
Purpose
To send reminders about and collect unpaid fees, on behalf of the condominium, by email, SMS or other means.
Legal basis
We act on behalf of the condominium. The processing is based on the legal obligation of the administrator to collect the condominium's income (Portuguese Civil Code, Article 1436; GDPR, Article 6(1)(c)) and on the condominium's legitimate interest in receiving what it is owed (Article 6(1)(f)).
Retention
Until the debt is settled and, afterwards, for the applicable legal periods.

Website AI assistant

Data
The text of the messages you write in the assistant.
Purpose
To answer general questions about our services and about condominium management.
Legal basis
Legitimate interest in answering the questions you ask us (GDPR, Article 6(1)(f)).
Retention
Conversations are not kept beyond the session, unless they lead to a contact or quote request (in which case the first item above applies). If this changes, conversations will be kept for a maximum of 90 days and this policy will be updated beforehand.

Do not write sensitive data in the assistant, such as health data or identity document numbers.

Marketing communications

Data
Name and email.
Purpose
To send Habiteight news and commercial communications.
Legal basis
Only with your consent (GDPR, Article 6(1)(a)), which you can withdraw at any time, without affecting the processing carried out before then.
Retention
Until you withdraw your consent.

You can withdraw your consent through the link included in each communication or by writing to our privacy email address.

Website visit statistics

Data
Page viewed, referring website, country and region, device type, operating system and browser, anonymously and in aggregate.
Purpose
To know how many people visit the website and which pages are most useful, so that we can improve it.
Legal basis
Legitimate interest in understanding how the website is used (GDPR, Article 6(1)(f)).
Retention
No cookies are used. The temporary code that makes it possible to count visitors is deleted after 24 hours; only totals are kept.

Website security

Data
IP address and technical data of the request.
Purpose
To protect the forms against abuse and automated submissions.
Legal basis
Legitimate interest in keeping the website secure (GDPR, Article 6(1)(f)).
Retention
The IP address is only held in memory, for a few minutes, and is not stored in our database.

The fields marked as required in the forms are needed to respond to your request. Without them, we cannot follow it up.

3. Cookies

The website only uses strictly necessary cookies and a cookie-free measurement of visits. The details are in the cookie policy.

4. Who we share data with

We use the following service providers, who process data only on our behalf and according to our instructions:

ProviderService
SupabaseDatabase and authentication
VercelHosting of the website and the platform, and cookie-free visit statistics
ResendSending emails
TwilioSending SMS messages
IfThenPayMB Way and Multibanco payments
AnthropicAI model for the website assistant and for extracting data from documents

We may also disclose data to public authorities, courts or other bodies where required by law. We do not sell personal data.

5. Transfers outside the European Union

Some of these providers are based in the United States or may process data from there. In those cases, the transfer is based on the EU-US Data Privacy Framework, where the provider is certified, and/or on standard contractual clauses approved by the European Commission. You can ask us for information about these safeguards at the privacy email address.

6. Your rights and how to exercise them

Under the GDPR, you have the right to:

  • access your personal data;
  • ask for inaccurate or incomplete data to be rectified;
  • ask for your data to be erased;
  • ask for the processing to be restricted;
  • receive the data you have provided to us in a structured, commonly used format (portability);
  • object to processing based on legitimate interest and, at any time, to processing for marketing purposes;
  • withdraw your consent, without affecting the processing carried out before then.

To exercise any of these rights, write to privacidade@habiteight.pt. The request is free of charge. We reply within one month, which may be extended by a further two months for complex or numerous requests, in which case we will let you know. We may ask you for additional information to confirm your identity.

7. Complaint to the CNPD

If you believe that your data is not being processed in accordance with the law, you can lodge a complaint with the Portuguese data protection authority (Comissão Nacional de Proteção de Dados, CNPD), at www.cnpd.pt.

8. Automated decisions

We do not take decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you. The website's AI assistant only gives general information and does not decide anything about you.

9. How we protect data

The technical and organisational measures we apply include:

  • encrypted communications (HTTPS) between your device and the platform;
  • role-based access, with database rules that limit each user to the data that concerns them;
  • mandatory authentication in the private areas;
  • internal access restricted to the people who need the data for their work;
  • technical records (logs) with personal data masked;
  • providers chosen for the security guarantees they offer.

10. Changes to this policy

We may update this policy, for example when we change the way we process data or when the law changes. The date of the last update is always at the top of the page.