Privacy Policy
SCOPE
The Simplifae Group (hereinafter, “Simplifae Group” or “Group”) is committed to protecting the personal data entrusted to it and to ensuring information security, providing the highest standards of quality, security, and integrity across all its services.
The Simplifae Group consists of the companies listed in Table 1 and is, in turn, part of the Hubexo Group, the multinational corporate group that ultimately owns it.
The companies of the Simplifae Group provide similar information services through access to business opportunities and market information—such as Lead Generation, Market Intelligence, eTendering, and Project Information services—as well as complementary services, such as electronic invoicing, digital certification, and time stamps.
The Simplifae Group bases its operations on the development of information and communication systems and technologies, pursuing a policy of modernization and ensuring compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (General Data Protection Regulation (“GDPR”)) and other applicable data protection legislation in each country.
In this context, information technologies support the organization’s mission and objectives, forming the foundation of its operations through physical infrastructure (hardware) and applications (software), where information related to the activities carried out and services provided is stored, processed, and made available.
Each of the companies comprising the Simplifae Group acts as the Data Controller for the personal data collected or obtained, in accordance with the need-to-know principle, specifically for the purposes of providing the services offered, verifying and maintaining quality, testing, and operating current systems and those that may be developed in the future, for the period strictly necessary to fulfill the intended purpose, for the duration of the contractual relationship, as evidence thereof, or for the period during which, under applicable law, it is mandatory to retain such data.
For this reason, all personal information is processed and protected with due diligence, always in accordance with the law applicable to the country in question and with the GDPR.
This Privacy Policy explains who we are, for what purposes we may process your personal data, how we process it, to whom we may disclose it (namely customers and/or other companies in the Simplifae Group), where it may be transferred, and what your rights are.
Table 1 – Simplifae Group Companies
| Company | Registered Office | Jurisdiction | Privacy Contact |
|---|---|---|---|
| VORTAL, SGPS, S.A. NIPC 509963404 |
Rua General Firmino Miguel, n.º 6-B, piso -2, 1600-300 Lisboa | Portugal | privacidade@simplifae.com |
| VTBD, S.A. NIPC 516087738 |
Rua General Firmino Miguel, n.º 6-B, piso -2, 1600-300 Lisboa | Portugal | privacidade@simplifae.com |
| SIMPLIFAE PORTUGAL, S.A. NIPC 505141019 |
Rua General Firmino Miguel, n.º 6-B, piso -2, 1600-300 Lisboa | Portugal | privacidade@simplifae.com |
| ACADEMIA VORTAL – FORMAÇÃO E INOVAÇÃO, UNIPESSOAL, LDA. NIPC 508567416 |
Centro Comercial Brasília, Praça Mouzinho de Albuquerque, n.º 113, 5.º, 4100-359 Porto | Portugal | privacidade@simplifae.com |
| VORTAL CONNECTING BUSINESS, S.A.U. Tax ID A-85765469 |
Calle José Echegaray, 8 – Edificio 3, Planta baja, Parque Empresarial Alvia, 28232 Las Rozas (Madrid) | Spain | protecciondatos@vortal.biz |
| SIMPLIFAE TECHNOLOGIES SPAIN, S.A.U. Tax ID A-81727810 |
Calle José Echegaray, 8 – Edificio 3, Planta baja, Parque Empresarial Alvia, 28232 Las Rozas (Madrid) | Spain | privacidad@simplifae.com |
| ARMILAR BUSINESS SERVICES, S.L. Tax ID B-88177613 |
Calle José Echegaray, 8 – Edificio 3, Planta baja, Parque Empresarial Alvia, 28232 Las Rozas (Madrid) | Spain | privacidad@armilar.biz |
| SIMPLIFAE POLAND S.A. KRS 0000041441 |
ul. Domaniewska 49, 02-672 Warszawa | Poland | rodo@marketplanet.pl |
| SIMPLIFAE TECHNOLOGIES POLAND Sp. z o.o. KRS 0000578182 |
ul. Domaniewska 49, 02-672 Warszawa | Poland | rodo@marketplanet.pl |
DATA CONTROLLERS AND JOINT CONTROLLERS
Use of the services provided by the companies of the Simplifae Group implies acceptance of this Privacy Policy. Each company in the Group is a Data Controller with respect to the personal data it collects for the provision of its services.
To the extent that they jointly determine the purposes and means of processing—particularly in the context of shared functions and services within the Group—the companies of the Simplifae Group act as joint data controllers, pursuant to Article 26 of the GDPR. The key terms of this joint controller arrangement are made available to data subjects, without prejudice to each company’s continued responsibility for complying with its legal obligations
WHAT DATA WE COLLECT
Each company in the Simplifae Group collects, stores, and uses personal data to provide its services, which are primarily offered on the electronic platforms and other services under its management.
Only the data strictly necessary for the provision of the services in question is collected, in accordance with the information provided on the platform and the User’s preferences; such data is appropriate, relevant, and limited to what is necessary for the purposes for which it is processed, namely:
- Customers, customer employees, counterparties, suppliers, partners, and employees: identification data, professional data, data related to professional activity, or accounting data — of the individuals themselves, in the case of natural persons, or of their representatives, in the case of legal entities — such as the representative’s name and respective user(s), email address, phone number, job title, and duties, as well as any other data whose processing is strictly necessary for the performance of the contract or compliance with legal obligations;
- Contact requests: identification data, such as name, email address, and phone number;
- Newsletter subscription: email address. You may, at any time, choose to opt out of receiving newsletters, marketing campaigns, or other communications using the subscription/unsubscription tools provided by the respective company;
- Job applications: identifying information, such as name and email address, and any information contained in the resume.
We collect personal data from individuals who (i) use our services and websites in the course of their professional activities (Users), (ii) apply for job openings (Candidates), (iii) are our employees, and (iv) represent our clients (including potential clients).
Most of this data is provided directly by the User when they contact us, submit an application, attend an in-person event, participate in telephone conversations, or contact us regarding our services. We may also obtain data from other sources, such as professional social networks (for example, LinkedIn).
All employees of Simplifae Group companies who process personal data, regardless of their employment status, are legally and contractually bound to confidentiality and may not disclose or use such data, except where required by law or court order.
FOR WHAT PURPOSES DO WE PROCESS YOUR PERSONAL DATA
- Communication of products, services, and sales — communication or sale of new products or services; updates on services; guides and tips for using the platform and contracted services; alerts about opportunities relevant to your business; training offers and other special offers; analysis and definition of consumer profiles; adaptation and development of new products or services; research and processing of analytical information (data analytics); communication of events and webinars;
- Customer management and service provision — filling out registration forms on websites; managing contacts, information, or requests; managing installation, activation, or deactivation; managing complaints or malfunctions; managing billing, collections, and payments; managing the customer experience; assessing satisfaction through surveys; Call recording as evidence of the business transaction and for service quality monitoring;
- Accounting, tax, and administrative management — accounting and billing; tax information, including the submission of information to the Tax Authority;
- Litigation management — judicial and extrajudicial collection;
- Network and systems management — support and improvement of the networks and applications that support the service; monitoring, improvement, and support of the service; quality assurance and maintenance, testing, and operation of current and future systems;
- Compliance with legal obligations — processing necessary to comply with legal obligations, such as accounting, tax, or document retention obligations;
- Information security control — access and log management; backup management; security incident management;
- Human resources management, recruitment, and selection—through application forms, processing of resumes, payroll processing, among others.
Your personal data will not be used for purposes other than those described in this Policy without first informing you or, where applicable, obtaining your consent.
LEGAL BASIS FOR PROCESSING YOUR DATA (LAWFULNESS OF PROCESSING)
Your data will only be processed when at least one of the following conditions applies:
- Contract performance and compliance with legal obligations [Article 6(1)(b) and (c) of the GDPR] — applicable to the processing of data regarding customers, customers’ employees, counterparties, suppliers, partners, and employees, for purposes directly related to the performance of the respective contracts or to compliance with legal obligations, including recruitment, hiring, contract management, work management, accounting, commercial activities, customer management, communication, and the submission of proposals;
- Consent [Article 6(1)(a) of the GDPR] — applicable to processing for purposes other than those mentioned above, namely data collected through the company’s website or in response to email messages requesting contact. Consent is freely given, specific, informed, and unambiguous, and may be withdrawn at any time, without affecting the lawfulness of the processing carried out on the basis of such consent up to that point;
- Legitimate interest [Article 6(1)(f) of the GDPR] — applicable when processing is necessary for the pursuit of the Group’s legitimate interests (including the sharing of data within a corporate group for internal administrative purposes, as recognized by Recital 48 of the GDPR), provided that the data subject’s interests or rights, freedoms, and safeguards do not override them. In such cases, the Group conducts and maintains the corresponding legitimate interests assessment (balancing test).
Special categories of data. The Simplifae Group does not, as a general rule, process special categories of personal data (Article 9 of the GDPR). Should this prove strictly necessary, the processing will be based on one of the conditions set forth in Article 9(2) of the GDPR and on the additional conditions required by applicable national law, with enhanced safeguards.
Electronic marketing communications. With regard to electronic communications directed at customers and/or users, the legal basis varies depending on whether or not there is a prior contractual relationship or relationship involving the use of services:
A. If a contractual relationship or a relationship involving the use of services already exists with the customer:
- (i) in the case of products or services similar to those previously purchased, no new consent is required, and the processing is based on the legitimate interest of the Data Controller (use of contact information obtained in the context of the transaction for direct marketing of similar products or services), without prejudice to the right to object;
- (ii) in the case of products or services different from those previously purchased, the respective company must obtain your prior and express consent.
B. If there is no prior legal relationship (contractual or involving the use of services), marketing communications will only be possible with your prior and express consent.
In any case, you may object to the processing of your data for direct marketing purposes and unsubscribe at any time, easily and free of charge.
Your data will be processed using appropriate technical and organizational measures to ensure a high level of security, in accordance with the GDPR.
HOW LONG WE RETAIN YOUR DATA
Your personal data is retained only for the minimum period necessary and proportionate to the fulfillment of the purposes described; after that period, it is deleted or anonymized. To determine this period, we take into account, in particular, the following criteria:
- the duration of the contractual relationship and the period necessary for its management and as evidence;
- the retention periods imposed by applicable legal obligations (e.g., accounting and tax obligations);
- applicable statutes of limitations or expiration periods, when the data is necessary for the assertion, exercise, or defense of a right in legal proceedings;
- the data subject’s consent, when this is the basis for processing and as long as it has not been withdrawn.
In the case of employees, data is retained for the purpose of complying with the legal obligations of Simplifae Group companies. As for legal representatives and contact persons, data is retained for the duration of the contract or any of its obligations and, thereafter, for the period necessary to comply with legal obligations or to defend rights in legal proceedings.
WITH WHOM WE SHARE YOUR INFORMATION
Your information may be disclosed:
Within the Simplifae Group and the Hubexo Group. The companies of the Simplifae Group are part of a multinational business group. Your personal data, including customer or employee data, may be processed for internal administrative purposes by other Group companies, provided that the applicable legal basis is observed, in the context of shared services and for internal reporting purposes. Sharing may also be necessary to improve our service offerings, conduct satisfaction surveys, and offer similar or complementary services. Data may also be shared when this is a prerequisite for contracting a specific service, in which case the customer will be informed of this circumstance in advance.
To third-party service providers (subcontractors). When necessary, we engage third-party entities that provide services on our behalf and that may have access to your data. These entities operate under subcontracting agreements that comply with Article 28 of the GDPR and are required to process data only in accordance with our instructions and to implement appropriate security measures.
To public authorities. Under applicable law, the Simplifae Group may be required to disclose data, specifically to tax authorities, social security agencies, and judicial authorities.
INTERNATIONAL DATA TRANSFERS
The companies of the Simplifae Group are established within the European Economic Area (EEA), so the sharing of data among them does not constitute a transfer to a third country.
If the processing involves the transfer of personal data outside the EEA, the Simplifae Group ensures that such a transfer complies with Chapter V of the GDPR, either through the existence of an adequacy decision by the European Commission or, in its absence, through the adoption of appropriate safeguards, specifically the standard contractual clauses approved by the European Commission, along with any supplementary measures that may be necessary.
SECURITY OF PERSONAL DATA
In the course of its activities, the Simplifae Group uses a set of physical and logical security technologies and procedures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction, in accordance with Article 32 of the GDPR, namely:
- Access control (physical and logical);
- Authentication and access management, including multi-factor authentication (MFA);
- Data encryption and cryptographic policies;
- Segregation of user profiles and of production and non-production environments;
- Privileged access management;
- Daily and incremental backups;
- Three levels of firewalls and VPN (site-to-site);
- Clear-screen and acceptable use policies for assets;
- Malicious code control and preventive measures against malware;
- Vulnerability management and patch updates;
- Incident management, including alerts and monitoring of events and incidents;
- Penetration testing (pentesting) and disaster recovery planning;
- Secure development policy;
- Collection, maintenance, and protection of logs and audit evidence;
- Infrastructure monitoring with high availability (99.5%);
- Time-stamping services (TSA);
- Risk management and data masking.
DATA PROCESSING AND ARTIFICIAL INTELLIGENCE
The Simplifae Group may process personal data provided by the customer and/or user when using services that rely on artificial intelligence solutions.
Customers and/or users who choose to use these solutions are responsible for the information and data they transmit and share, and are obligated to use them responsibly and prudently, specifically by (i) refraining from providing personal data beyond what is strictly necessary and (ii) not using or disclosing confidential information or information protected by copyright and intellectual property rights.
In the solutions it develops using artificial intelligence, the Simplifae Group ensures responsible use and compliance with the GDPR and applicable legislation regarding artificial intelligence, including Regulation (EU) 2024/1689 (Artificial Intelligence Regulation), with a view to ethical, transparent, and trustworthy artificial intelligence, with adequate human oversight.
Protecting data privacy in the age of artificial intelligence is a priority for the Simplifae Group. To this end, proactive measures are adopted, such as the implementation of robust data quality and security protocols—ensuring that data is used only for its intended and authorized purpose—and the development of transparent, impartial, and auditable systems that allow for the explanation, inspection, and reproduction of decisions and data usage, while respecting fundamental rights.
WHAT ARE YOUR RIGHTS
As a data subject, you may exercise the following rights:
- Access—to know what data is being processed and to obtain information about the operations performed;
- Rectification—to correct any inaccurate or incomplete personal data;
- Erasure — to have your data erased (“right to be forgotten”), where applicable;
- Restriction of processing — when the accuracy, lawfulness, or necessity of the processing is disputed, though the data may be retained to defend legal claims;
- Portability — to receive the data you have provided to us in a structured, commonly used, and machine-readable format, when the legal basis is a contract or consent;
- Objection — to object to processing based on legitimate interests, as well as, at any time, to processing for direct marketing purposes;
- Withdrawal of Consent — to withdraw consent at any time, without affecting the lawfulness of prior processing;
- Automated decisions — not to be subject to decisions made solely on the basis of automated processing, including profiling, that produce legal effects concerning you, except in the situations permitted by Article 22 of the GDPR.
To exercise your rights, contact the single point of contact or the Data Controller of the respective company using the contact information provided in Table 1, specifying the right you wish to exercise and providing your identification details. You may be asked to provide proof of identity to ensure that the information is shared only with the data subject.
Your requests will be handled with special care. You will be informed of the measures taken within one month of receipt of the request; this period may be extended to two months, when necessary, given the complexity and number of requests, and you will be notified of such an extension, in accordance with Article 12(3) of the GDPR.
RIGHT TO LODGE A COMPLAINT
Without prejudice to any other means of redress, you have the right to lodge a complaint with the competent supervisory authority, namely:
- Portugal — National Data Protection Commission (CNPD), www.cnpd.pt;
- Spain — Agencia Española de Protección de Datos (AEPD), www.aepd.es;
- Poland — Prezes Urzędu Ochrony Danych Osobowych (UODO), uodo.gov.pl.
CHANGES TO THIS POLICY
This Privacy Policy, which you should read carefully, is subject to change. Changes take effect as of the date of their publication on the website, with explicit reference to the update date. We recommend that you review this Policy periodically.
Version 6.0. Updated on 23/07/2026.