04 / Legal
Privacy and Data Protection Policy
Alambic Labs is committed to protecting your privacy and personal data in strict compliance with the European General Data Protection Regulation (Regulation (EU) 2016/679 – GDPR), Portuguese Law 58/2019, and the EU e-Privacy Directive (Directive 2002/58/EC).
1. Data Controller
The data controller responsible for the processing of personal data collected through this website is Alambic Labs, based and operating in Portugal.
For any inquiries regarding data protection, privacy practices, or to exercise your data subject rights, please contact us directly at [email protected].
2. Personal Data Collected & Purposes
Our data collection practices strictly adhere to the principle of data minimization (Article 5(1)(c) of the GDPR):
- Contact and Demo Inquiries: Name, work or personal email address, product of interest, and the message content submitted. Purpose: responding to inquiries, scheduling software demonstrations, and managing communication initiated by the user.
- Technical Network & Security Data: IP address (processed in an obfuscated format), request integrity tokens, and security browser headers. Purpose: perimeter security, DDoS defense, and bot filtering via Cloudflare Turnstile.
3. Legal Basis for Processing (Article 6 GDPR)
We process your personal data under the following lawful grounds:
- Pre-contractual measures at the request of the data subject (Art. 6(1)(b) GDPR): to process and respond to your requests, proposals, or demo scheduling.
- Legitimate Interest (Art. 6(1)(f) GDPR): to protect website integrity, defend infrastructure against cyber threats, and filter automated spam.
- Compliance with Legal Obligations (Art. 6(1)(c) GDPR): where required by applicable statutory and tax laws.
4. Subprocessors and International Data Transfers
Alambic Labs does not sell, rent, or trade your personal data to third parties for advertising or behavioral tracking. We only engage essential technical subprocessors who adhere to strict security and privacy standards:
- Cloudflare, Inc.: Content delivery network (CDN), DNS management, perimeter WAF security, and Turnstile anti-bot verification. Cloudflare operates under EU Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework.
- Resend / AWS SES: Secure transactional email delivery infrastructure.
5. Data Retention Periods
Personal data submitted through contact forms is retained only for as long as necessary to fulfill the request. If no contractual or business relationship ensues, data is securely erased within a maximum period of 12 months, unless retention is required by statutory regulations or legal dispute preservation.
6. Your Rights Under GDPR
Under Articles 15 to 22 of the GDPR, you have the following enforceable rights:
- Right of Access: Confirmation and copy of personal data processed about you.
- Right to Rectification: Correction of inaccurate or incomplete information.
- Right to Erasure ('Right to be Forgotten'): Deletion of your data when no longer necessary.
- Right to Restriction of Processing: Temporary limitation of data processing under statutory conditions.
- Right to Data Portability: Transfer of your data in a structured, commonly used, and machine-readable format.
- Right to Object: Objection to data processing based on legitimate interests.