This is a courtesy translation. The Portuguese version prevails.
Privacy policy
Last updated: 3 October 2026
This policy explains how we process the personal data of people who visit the website, send us a request or use the owners' portal and the app, in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR).
1. Who the data controller is
The controller of the data collected on the website is Habiteight.
For any privacy question, or to exercise your rights, write to privacidade@habiteight.pt.
In the owners' portal and the app, the controller is the condominium to which your unit belongs. Habiteight processes that data as a processor, on behalf of the condominium.
2. What data we process, why and for how long
When the data is not collected directly from you (for example, when the condominium gives us the owners' contact details), its source is the condominium itself.
Contact and quote requests
- Data
- Name, email, phone (optional), the capacity in which you make the request, message and, for quote requests, details of the condominium (address or postcode, number and type of units, whether there is a lift, who manages it and how much it pays today).
- Purpose
- To reply to your request and to prepare and present a management proposal.
- Legal basis
- Steps taken at your request prior to entering into a contract (GDPR, Article 6(1)(b)) and our legitimate interest in replying to the requests we receive (Article 6(1)(f)).
- Retention
- Up to 12 months after the request, if no contract is entered into. If one is, the data becomes subject to the retention period of the contract.
Applications to the franchise programme
- Data
- Name, email and geographical area of interest.
- Purpose
- To assess your interest and contact you about the franchise programme.
- Legal basis
- Steps taken at your request prior to entering into a contract (GDPR, Article 6(1)(b)) and legitimate interest (Article 6(1)(f)).
- Retention
- 12 months after the application.
Owners' portal and app
- Data
- Identification and contact details, unit, fees and payments, reported repair requests, condominium documents and account authentication data.
- Purpose
- To provide the management service contracted by the condominium and to give access to the condominium's information.
- Legal basis
- For this processing, each condominium is the controller and Habiteight acts as a processor, on behalf of the condominium and following its instructions (GDPR, Article 28). The legal basis is set by the condominium, usually the performance of the contract and compliance with legal obligations (Article 6(1)(b) and (c)).
- Retention
- For the duration of the management contract and, afterwards, for the applicable legal periods.
Requests about this data can be sent to the condominium or to us: we forward them and help the condominium to reply.
Collection of overdue fees
- Data
- Identification of the owner, unit, amounts owed, payment history and contact details (email and phone).
- Purpose
- To send reminders about and collect unpaid fees, on behalf of the condominium, by email, SMS or other means.
- Legal basis
- We act on behalf of the condominium. The processing is based on the legal obligation of the administrator to collect the condominium's income (Portuguese Civil Code, Article 1436; GDPR, Article 6(1)(c)) and on the condominium's legitimate interest in receiving what it is owed (Article 6(1)(f)).
- Retention
- Until the debt is settled and, afterwards, for the applicable legal periods.
Website AI assistant
- Data
- The text of the messages you write in the assistant.
- Purpose
- To answer general questions about our services and about condominium management.
- Legal basis
- Legitimate interest in answering the questions you ask us (GDPR, Article 6(1)(f)).
- Retention
- Conversations are not kept beyond the session, unless they lead to a contact or quote request (in which case the first item above applies). If this changes, conversations will be kept for a maximum of 90 days and this policy will be updated beforehand.
Do not write sensitive data in the assistant, such as health data or identity document numbers.
Marketing communications
- Data
- Name and email.
- Purpose
- To send Habiteight news and commercial communications.
- Legal basis
- Only with your consent (GDPR, Article 6(1)(a)), which you can withdraw at any time, without affecting the processing carried out before then.
- Retention
- Until you withdraw your consent.
You can withdraw your consent through the link included in each communication or by writing to our privacy email address.
Website visit statistics
- Data
- Page viewed, referring website, country and region, device type, operating system and browser, anonymously and in aggregate.
- Purpose
- To know how many people visit the website and which pages are most useful, so that we can improve it.
- Legal basis
- Legitimate interest in understanding how the website is used (GDPR, Article 6(1)(f)).
- Retention
- No cookies are used. The temporary code that makes it possible to count visitors is deleted after 24 hours; only totals are kept.
Website security
- Data
- IP address and technical data of the request.
- Purpose
- To protect the forms against abuse and automated submissions.
- Legal basis
- Legitimate interest in keeping the website secure (GDPR, Article 6(1)(f)).
- Retention
- The IP address is only held in memory, for a few minutes, and is not stored in our database.
The fields marked as required in the forms are needed to respond to your request. Without them, we cannot follow it up.
4. Who we share data with
We use the following service providers, who process data only on our behalf and according to our instructions:
| Provider | Service |
|---|---|
| Supabase | Database and authentication |
| Vercel | Hosting of the website and the platform, and cookie-free visit statistics |
| Resend | Sending emails |
| Twilio | Sending SMS messages |
| IfThenPay | MB Way and Multibanco payments |
| Anthropic | AI model for the website assistant and for extracting data from documents |
We may also disclose data to public authorities, courts or other bodies where required by law. We do not sell personal data.
5. Transfers outside the European Union
Some of these providers are based in the United States or may process data from there. In those cases, the transfer is based on the EU-US Data Privacy Framework, where the provider is certified, and/or on standard contractual clauses approved by the European Commission. You can ask us for information about these safeguards at the privacy email address.
6. Your rights and how to exercise them
Under the GDPR, you have the right to:
- access your personal data;
- ask for inaccurate or incomplete data to be rectified;
- ask for your data to be erased;
- ask for the processing to be restricted;
- receive the data you have provided to us in a structured, commonly used format (portability);
- object to processing based on legitimate interest and, at any time, to processing for marketing purposes;
- withdraw your consent, without affecting the processing carried out before then.
To exercise any of these rights, write to privacidade@habiteight.pt. The request is free of charge. We reply within one month, which may be extended by a further two months for complex or numerous requests, in which case we will let you know. We may ask you for additional information to confirm your identity.
7. Complaint to the CNPD
If you believe that your data is not being processed in accordance with the law, you can lodge a complaint with the Portuguese data protection authority (Comissão Nacional de Proteção de Dados, CNPD), at www.cnpd.pt.
8. Automated decisions
We do not take decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you. The website's AI assistant only gives general information and does not decide anything about you.
9. How we protect data
The technical and organisational measures we apply include:
- encrypted communications (HTTPS) between your device and the platform;
- role-based access, with database rules that limit each user to the data that concerns them;
- mandatory authentication in the private areas;
- internal access restricted to the people who need the data for their work;
- technical records (logs) with personal data masked;
- providers chosen for the security guarantees they offer.
10. Changes to this policy
We may update this policy, for example when we change the way we process data or when the law changes. The date of the last update is always at the top of the page.