Privacy policy

How MIRRORCHALLENGE, LDA collects, uses and protects personal data, and the rights you have under the GDPR.

Last updated: 25 September 2026

Who is responsible for your data

The controller of the personal data described in this policy is:

Legal name
MIRRORCHALLENGE, LDA
NIPC / VAT number
PT516387596
Registered office
Av. Eng. Duarte Pacheco, Amoreiras Torre 2, 12º, 1070-102 Lisboa, Portugal

We have not appointed a Data Protection Officer. For any question about this policy or about your personal data, write to [email protected] with the subject “Privacy request”, or by post to our registered office.

Scope of this policy

This policy explains how we process personal data when you visit www.mirrorchallenge.pro, contact us, or deal with us as a client, prospective client, supplier or partner. It is written to meet our obligations under the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), Portuguese Law no. 58/2019 of 8 August, which implements the GDPR in Portugal, and Law no. 41/2004 of 18 August on privacy in electronic communications.

It does not cover personal data we process on behalf of our clients when we manage their advertising, analytics or tracking. In that case our client is the controller and we act as its processor. See section 5.

What we collect, why, and on what legal basis

SituationPersonal dataPurposeLegal basis (GDPR)
Visiting this websiteIP address, date and time, pages requested, browser and device information, referring page (server logs)Delivering the website, keeping it secure and diagnosing faultsLegitimate interests, Art. 6(1)(f): operating a secure website
Contacting us by email, phone or the contact formName, email, telephone, company, role, website, and anything you include in your messageAnswering your enquiry and preparing a proposalSteps taken at your request before a contract, Art. 6(1)(b); otherwise legitimate interests, Art. 6(1)(f)
ClientsBusiness contact details of client staff, communications, contract and billing information, access credentials to client platforms granted to usDelivering the services, managing the relationship, invoicingPerformance of a contract, Art. 6(1)(b)
Accounting and taxInvoicing data and records of transactionsMeeting accounting, tax and legal obligationsLegal obligation, Art. 6(1)(c)
Suppliers and partnersBusiness contact details, communications, contract and payment informationManaging the supply or partnershipPerformance of a contract, Art. 6(1)(b); legitimate interests, Art. 6(1)(f)
Business updatesName, email, companyOccasional updates about our services to clients and business contactsLegitimate interests or consent, as required by Art. 13-A of Law no. 41/2004; you can opt out at any time
Job applicationsCV and the information you send usAssessing your applicationSteps taken at your request before a contract, Art. 6(1)(b); consent, Art. 6(1)(a), to keep your CV for future roles
Legal claimsAny of the above, as relevantEstablishing, exercising or defending legal claimsLegitimate interests, Art. 6(1)(f)

Giving us personal data is voluntary. If you do not give us the information needed to answer an enquiry or perform a contract, we may be unable to do so.

We do not sell personal data, and we do not use it for automated decision-making, including profiling, that produces legal or similarly significant effects on you.

Cookies and tracking on this website

This website does not use cookies, local storage or similar technologies. It loads no analytics, advertising pixels or third-party content, and its font is hosted on our own server. See our cookie policy.

Data we process on behalf of clients

When we manage advertising accounts, analytics, tag management or reporting for a client, we may process personal data on the client's behalf, for example conversion events, website analytics data or customer lists uploaded to advertising platforms for audience matching.

In that role we act as a processor under Article 28 GDPR, only on the client's documented instructions and under a data processing agreement. The client, as controller, is responsible for informing its customers and website visitors and, where required, for collecting their consent. If you want to exercise your rights over such data, please contact the business concerned. If you contact us, we will pass your request on to them.

Who we share data with

We share personal data only where necessary for the purposes above, with:

  • service providers that process data on our behalf, such as website hosting, email and office software, file storage and accounting software, under data processing agreements;
  • our certified accountant (contabilista certificado), legal advisers and auditors, who are bound by professional confidentiality;
  • advertising and analytics platforms (such as Google, Microsoft, Meta, LinkedIn and TikTok) when we deliver services for a client, under those platforms' own terms;
  • courts, the Portuguese Tax and Customs Authority and other public authorities, where the law requires it.

Transfers outside the European Economic Area

Some of our service providers may process personal data outside the European Economic Area, for example in the United States. Where they do, we make sure the transfer is covered by an adequacy decision of the European Commission (including the EU–US Data Privacy Framework, for certified companies) or by the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, with additional safeguards where needed. You can ask us for a copy of the relevant safeguards.

How long we keep data

DataRetention period
Server logsKept by our hosting provider for the limited period set by its own policy, and then deleted, unless needed to investigate a security incident
Enquiries that do not lead to a contractUp to 24 months after our last contact
Client, supplier and partner recordsFor the duration of the relationship and up to 5 years afterwards, to deal with any questions or claims about the contract, unless the law requires longer
Invoices and accounting records10 years, as required by Portuguese tax law (Article 123 of the Corporate Income Tax Code)
Job applicationsUntil the recruitment process ends; up to 12 months if you consent to us keeping your CV
Opt-out records for business updatesFor as long as needed to respect your objection

When a retention period ends, we delete or anonymise the data.

Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Article 15);
  • have inaccurate data corrected (Article 16);
  • have your data erased in the cases set out in Article 17;
  • restrict how we use your data (Article 18);
  • receive your data in a portable format (Article 20);
  • object to processing based on legitimate interests, and to direct marketing at any time (Article 21);
  • withdraw consent at any time, without affecting processing carried out before you withdrew it (Article 7(3)).

To exercise these rights, write to [email protected] with the subject “Privacy request”. We will reply within one month. For complex or numerous requests we may extend that by up to two further months, in which case we will tell you why. Exercising your rights is free of charge. We may ask for information to confirm your identity before acting on a request.

Complaints to the supervisory authority

If you believe we have processed your personal data unlawfully, you have the right to lodge a complaint with the Portuguese supervisory authority:

Comissão Nacional de Proteção de Dados (CNPD)
Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, Portugal
www.cnpd.pt

You may also complain to the supervisory authority of the EU Member State where you live or work. We would appreciate the chance to address your concern first, so please contact us.

Security

We protect personal data with appropriate technical and organisational measures. These include encrypted connections (HTTPS/TLS), access limited to the people who need it, strong authentication on business systems and confidentiality obligations for anyone who handles the data. No method of transmission or storage is completely secure. If a personal data breach occurs, we will act in line with Articles 33 and 34 GDPR.

Children

Our website and services are intended for businesses and are not directed at children. We do not knowingly collect personal data from children.

Changes to this policy

We may update this policy when our processing or the law changes. The current version is always published on this page, with the date of the last update. Material changes will be highlighted on this website.

This policy is also available in Portuguese. If the two versions differ, the Portuguese version prevails.