Privacy Policy
Last updated: October 2026
This policy is drafted in accordance with the General Data Protection Regulation (GDPR — Regulation EU 2016/679) and Portuguese data protection statutes.
1. Data Controller Identification
This website is operated on an individual basis by Rodrigo Linhas, an independent web developer.
Data Controller: Rodrigo Linhas
Contact email: contact@rodrigolinhas.dev
Country of establishment: Portugal
Processing of personal data is governed by the General Data Protection Regulation (GDPR — Regulation EU 2016/679) and applicable Portuguese data protection legislation.
2. Personal Data Collected
We follow the principle of data minimization. The only personal data collected directly through this website is information submitted voluntarily via the contact form:
• Name (required to address you in our reply)
• Email address (required to send our project response)
• Company or business name (optional)
• Phone number (optional)
• Selected project type and indicative budget range
• Message body containing project requirements
3. Purpose and Legal Basis for Processing
Purpose: Submitted data is used solely to evaluate, scope, and reply to your project enquiries and requests for proposals.
Legal Basis: Processing is carried out pursuant to Article 6(1)(b) of the GDPR (steps prior to entering into a contract at the request of the data subject) and your explicit, voluntary consent provided when checking the confirmation box prior to submission (Article 6(1)(a)).
Your data is never sold, leased, or added to automated mass marketing or newsletter lists.
4. Recipients and Processors (Email Service)
Your personal data is not shared with third parties for marketing purposes.
For reliable and secure transmission of contact form submissions, we may utilize the email delivery service Resend (Resend, Inc.). When enabled, transmission is protected via encrypted TLS/HTTPS connections. Resend processes data in accordance with Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework.
In local development environments or when no external email service is configured, submissions are processed in server memory only and are not forwarded to external third parties.
5. Data Retention Period
Submitted contact data will be retained only for the duration necessary to answer your enquiry and conclude project discussions.
If no commercial engagement or service agreement ensues, correspondence and records are deleted within a maximum period of 12 months following the last exchange.
If a formal commercial engagement ensues, required fiscal and accounting records will be retained in accordance with mandatory statutory periods under Portuguese tax law.
6. Your Rights as a Data Subject
Under the GDPR, you have the right to request at any time:
• Access to your personal data held by us;
• Rectification of inaccurate or incomplete data;
• Erasure of your data ('right to be forgotten');
• Restriction of processing;
• Objection to processing;
• Data portability.
To exercise any of these rights, please email your written request to: contact@rodrigolinhas.dev. Your request will be reviewed and answered within the statutory 30-day timeline.
If you believe that the processing of your data infringes the GDPR, you also hold the right to lodge a formal complaint with the competent supervisory authority in Portugal: Comissão Nacional de Proteção de Dados (CNPD — Rua de São Bento n.º 148-3.º, 1200-821 Lisboa | www.cnpd.pt).
7. Cookies & Local Storage
This website does not use advertising cookies, third-party cross-site trackers, or invasive analytics tools. For this reason, no intrusive cookie consent banner is required.
We use only the browser's local storage (localStorage) to store your preferred interface theme ('light' or 'dark'), ensuring stable and consistent visual rendering across page visits.
8. Information Security
We employ appropriate technical and organizational measures to safeguard data confidentiality and integrity, including HTTPS/TLS encrypted communication, strict input validation using Zod, and rate limiting combined with honeypot spam protection against automated bot abuse.
9. SiteCheck Website Assessments
SiteCheck processes the public website URL you submit and temporarily retrieves publicly available pages, robots.txt files, sitemaps, response headers, and limited HTML required to produce the automated report.
No email address or account is required. Full HTML responses and website assets are not stored. Derived audit results expire automatically, normally after one hour.
The service uses request limits and basic technical logs needed for security and abuse prevention. It does not attempt to access authenticated or private content.