Privacy policy
Last updated: 2026-07-21
This Privacy Policy describes how Enbiente - Energia e Ambiente, Lda. (hereinafter "Enbiente") processes personal data collected through its institutional website enbiente.com. Processing complies with Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR") and with Portuguese Law 58/2019 of 8 August, the national implementing legislation.
1. Data controller
The controller of personal data collected through this site is:
- Entity: Enbiente - Energia e Ambiente, Lda.
- Registered office: Rua Santa Isabel, Lote 2, Cave, Repeses, 3500-726 Viseu, Portugal
- NIPC: PT516571516
- Email: [email protected]
- Phone: +351 232 099 900 (call to the national landline network)
No Data Protection Officer (DPO) has been designated, as the processing does not meet the requirements of Article 37 GDPR. All data-protection matters should be addressed to the email above.
2. Data collected
We only collect data you voluntarily provide through the site's forms. The site offers four distinct forms:
Contact form:
- Name - to address you appropriately in our reply.
- Company - to contextualise the request.
- Email - for reply and subsequent communication.
- Phone - alternative contact channel.
- Message (optional) - free text you choose to share.
Newsletter subscription:
- Email - the only required data, to deliver the communications you subscribed to.
Job application (Careers page):
- Name, email and phone - for identification and contact during the recruitment process.
- The role applied for (where applicable) - or a spontaneous application.
- Message (optional) - cover letter or free note.
- Curriculum Vitae - a PDF or DOC/DOCX file, up to 5 MB. Your CV may contain data you choose to include that we do not require (academic and professional history, address, photograph, date of birth). We recommend including only what is necessary to assess the application.
Online meeting booking (Contact page):
- Name, email and phone (phone optional) - for identification and to send the confirmation.
- Message - what the meeting is about.
- Date and time of the slot chosen.
- Guests (optional) - the name and email of other people you wish to invite to the meeting. This data concerns third parties: by providing it, you confirm you are entitled to share it with us, and you are responsible for informing those people that their data has been passed to Enbiente for this purpose. Guests receive the meeting invitation and may exercise all the rights described in section 8 with us.
In addition, the server may log technical information for short periods - IP address and user-agent - for security purposes and prevention of form abuse (per-origin rate limiting).
For aggregate traffic analytics we use Umami, a cookieless analytics service that does not collect personal data nor allow individual identification of the visitor.
3. Purposes of processing
The data is used exclusively to:
- Reply to your contact request.
- Evaluate a potential service proposal and keep you informed during the commercial phase.
- Maintain a minimal history of commercial interactions for the relevant period.
- Send the newsletter, where you have subscribed, and only for as long as the subscription remains active.
- Assess your application to a vacancy or your spontaneous application, and conduct the recruitment process.
- Schedule, confirm and hold the online meeting you requested, including sending the invitation to any guests you named.
- Comply with applicable legal obligations, notably accounting and tax obligations whenever applicable to an established contractual relationship.
We do not use your data for automated marketing, profiling, behavioural advertising, solely automated decisions producing legal effects, or for any purposes other than those listed above.
4. Legal basis
The processing of your personal data relies on the following legal grounds:
- Consent (Article 6(1)(a) GDPR) - provided by submitting any of the forms with the consent checkbox enabled, and in particular when subscribing to the newsletter. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Performance of a contract or pre-contractual steps (Article 6(1)(b) GDPR) - when your request evolves into the negotiation or execution of a service proposal, when you book a meeting at your own request, and in the pre-contractual steps inherent to a recruitment process.
- Compliance with a legal obligation (Article 6(1)(c) GDPR) - notably to satisfy accounting, tax and invoicing obligations applicable to executed contracts.
- Legitimate interest (Article 6(1)(f) GDPR) - for minimal technical security and form-abuse-prevention logs (e.g. per-origin rate limiting), and for limited retention of communication records to the extent strictly necessary for the defence of legal rights.
Providing the data is voluntary. Without the minimum data marked as required in each form we cannot act on the corresponding request - reply to a contact, send the newsletter, assess an application, or confirm a meeting.
5. Recipients and processors
Your data is accessed by:
- The Enbiente team responsible for commercial contact, qualification of the request, recruitment, and any subsequent implementation.
- Enbiente's middleware - an application developed and operated by Enbiente that receives the submission from the site and records it in the company's management system (CRM/ERP). Enbiente determines and controls this processing.
- Enbiente's management system (CRM/ERP), where commercial requests, subscriptions, applications and meeting bookings are recorded.
The operation of the site further relies on the following providers, which act as processors within the meaning of Article 28 GDPR:
- A hosting provider (server) on which the site and the middleware run.
- A content delivery and security provider (CDN/WAF), which sits between your browser and the server and applies protection against abuse and attacks. In doing so it technically processes your IP address.
- The email service used by Enbiente, through which an internal alert is sent to the team when a submission cannot be recorded in the management system (technical failure). This is not a service for sending communications to data subjects, and it is not triggered on every submission: it is an operational alarm.
We do not use any email-marketing, advertising or profiling platform. We do not sell, rent, or transfer your data to third parties for commercial purposes. In the event of a legal obligation to disclose to competent authorities, only what is strictly required by the applicable judicial or administrative order will be provided.
If you wish to know the specific identity of any of the providers above, you may request it at the email given in section 1.
6. International transfers
The data you submit to us is stored on servers located within the European Economic Area (EEA) and is not transferred outside the EEA for commercial, recruitment or scheduling purposes.
We cannot, however, state that no technical data leaves the EEA: some of the infrastructure providers referred to in section 5, notably the CDN/security service, operate global networks and may route traffic (including your IP address) through servers located outside the EEA. Such transfers are covered by the appropriate safeguards set out in Chapter V GDPR, notably standard contractual clauses approved by the European Commission and, where applicable, adequacy decisions.
The same applies to the video and audio platforms referred to in section 10 if you choose to play that content: at that moment you establish a direct connection with those platforms, which are responsible for any processing that follows.
7. Retention period
- Requests without commercial follow-up: data is deleted or anonymised 24 months after the last contact, unless a legal basis justifies longer retention.
- Requests with an established contractual relationship: data is retained for as long as necessary to fulfil the obligations arising from the contract and, after its termination, for the periods required by law - notably 10 years for accounting and tax purposes (Article 123(6) of the Portuguese Corporate Income Tax Code and Article 52(1) of the Portuguese VAT Code).
- Newsletter subscriptions: retained for as long as the subscription remains active. After cancellation, the email is removed from the sending list; a minimal record of the cancellation may be kept as evidence that the request was honoured.
- Applications and CVs: retained for 24 months from the conclusion of the recruitment process, so that you may be considered for future vacancies, unless you request earlier deletion. Applications resulting in a hire become part of the employee's individual file, with its own statutory periods.
- Meeting bookings: the meeting data (including any guests named) is retained in the calendar system for as long as it is needed to follow up the commercial relationship, thereafter following the periods applicable to contact requests.
- Technical security logs: retained for the period strictly necessary for the purpose that justifies them, generally not exceeding 12 months.
Once the applicable periods elapse, data is securely deleted or irreversibly anonymised.
8. Your rights
Under the GDPR, you have the right, at any time, to:
- Access the personal data we process about you (Article 15).
- Request rectification of inaccurate or outdated data (Article 16).
- Request erasure of the data (right to be forgotten, Article 17), in the cases permitted by law.
- Restrict processing (Article 18).
- Request portability of the data you have provided to us, in a structured, commonly used format (Article 20).
- Object to processing based on legitimate interest (Article 21).
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Article 7(3)).
To exercise any of these rights, contact us in writing at [email protected], specifying the right you wish to exercise. We will reply within a maximum of 30 days, extendable by up to two further months for particularly complex requests, with reasons given. For security purposes, we may request additional information to verify your identity before processing the request.
9. Right to lodge a complaint
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with the competent supervisory authority in Portugal:
- Comissão Nacional de Proteção de Dados (CNPD)
- Av. D. Carlos I, 134, 1.º - 1200-651 Lisbon, Portugal
- Phone: +351 213 928 400
- Email: [email protected]
- Site: cnpd.pt
We nonetheless encourage you to contact Enbiente first to attempt an amicable resolution before any formal complaint.
10. Cookies and local storage
Enbiente does not use identification, tracking or marketing cookies on this site.
To support the user's theme preference (light/dark), a single key is stored in the browser's Local Storage (enbiente-theme). This key is strictly functional, contains no personal data, and is never transmitted to the server; it can be removed at any time through the browser's settings.
Aggregate traffic analytics, when active, are provided by Umami, which operates without cookies and without the ability to individually identify the visitor.
The CDN/security provider referred to in section 5 may additionally set a strictly technical cookie, used solely to distinguish legitimate traffic from malicious automated traffic. It is not used for advertising or to build visitor profiles.
Embedded third-party content. Some pages (blog, podcast, Studio) include video and audio hosted on third-party platforms - notably YouTube, Spotify, TikTok and Vimeo. This content is loaded behind a click-to-play mechanism: until you click to start playback, no request is made to those platforms and no third-party cookie is set.
Once you play the content, the relevant platform may set cookies and collect usage data under its own privacy policy, over which Enbiente has no control. We recommend consulting those platforms' policies if you wish to understand that processing.
11. Security
Enbiente adopts technical and organisational measures appropriate to the state of the art and to the risk associated with the processing, in order to ensure the confidentiality, integrity and availability of your data - notably:
- Fully encrypted communication between your browser and the site (HTTPS / TLS).
- Authenticated transmission between the site and Enbiente's middleware, using a time-window rolling key.
- Security headers applied to every response (HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy).
- Filtering of malicious traffic and per-origin rate limiting, at the CDN/security layer and within the application itself.
- Validation of the type and size of files submitted on the Careers page, accepting only PDF and DOC/DOCX up to 5 MB.
- Access controls on the management system and internal systems on a need-to-know basis.
- Logging and periodic review of access and anomalous submission attempts.
No security measure guarantees absolute protection. In the event of a personal data breach involving a high risk to your rights and freedoms, Enbiente will fulfil the notification obligations to the CNPD and communication obligations to data subjects set out in Articles 33 and 34 GDPR.
12. Automated decisions and profiling
We do not take any solely automated decisions, including profiling, that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 GDPR.
13. Minors
The site's forms are intended for professional, commercial and recruitment contacts, and not for minors under 16. We do not knowingly collect data from minors under 16. If you become aware that data of a minor has been provided without the consent of their legal representatives, please contact us so that we may proceed to its deletion.
14. Changes to this policy
This policy may be updated to reflect legal, regulatory or operational changes. The version in force is always the one published on this page; the last-updated date shown at the top is the authoritative reference. Material changes will be signalled visibly before they take effect.