Last updated: July 12, 2026
Version: 2026-07-12_v3.0
This Policy explains how CriaHub collects, uses, shares, retains and protects personal data on the website, e-commerce store, forms, proposals, communications and in providing its services.
The Terms and Conditions are available at:
https://www.criahub.global/en/terms-and-conditions/
The Cookie Policy is available at:
https://www.criahub.global/en/cookie-policy/
1. Data Controller
- Trade name: CriaHub Digital Business Solutions, also referred to as CriaHub
- Data controller and legal representative: Nivaldo Freitas
- NIF (Tax ID): 322762383
- Professional address: Rua Bento de Jesus Caraça, 17, 1495-686 Oeiras, Portugal
- Email: [email protected]
- Phone and WhatsApp: +351 915 883 495
CriaHub is responsible for processing the data it determines for its own commercial, contractual, administrative, legal and security purposes.
When CriaHub processes personal data exclusively on behalf of a Client, it acts as a processor under applicable contract terms.
2. Scope
This Policy applies to personal data processed through:
- criahub.global and associated pages;
- e-commerce store;
- contact forms and analysis request forms;
- checkout, orders and invoicing;
- email, phone, WhatsApp and video calls;
- onboarding, briefings and Client area;
- proposals, contracts and technical support;
- campaigns, CRM, automation, hosting and other services;
- events and commercial communications.
3. Data we can collect
3.1 Identification and contact data
- name;
- company;
- function/role;
- NIF (Tax ID);
- address;
- email;
- phone and WhatsApp number.
3.2 Commercial and contractual data
- service requested;
- responses to forms;
- contact history;
- proposals;
- orders;
- options and add-ons;
- approvals;
- contract and Terms version;
- project status.
3.3 Invoicing and payment data
- invoicing details;
- amounts;
- invoices;
- payment status;
- identifiers and limited information transmitted by the payment provider.
CriaHub does not receive nor retain complete cardholder data.
3.4 Project and onboarding data
- briefings;
- text, images, videos and logos;
- domain name;
- catalogues;
- technical details;
- required accounts and access credentials;
- communications;
- revisions and approvals.
3.5 Technical and usage data
- IP address;
- device and browser information;
- date and time of activity;
- pages visited;
- security logs;
- source of access;
- cookie data and similar technologies, in accordance with the Cookie Policy.
3.6 Data processed on behalf of Clients
Depending on the service, CriaHub may have access to Client's customer contact or employee data, user data or supplier data.
In such situations, the Client is normally responsible for processing and must ensure its lawfulness.
4. Source of data
Data can be obtained:
- directly from the controller;
- from a company or organization representing them;
- from a Client who contracts CriaHub;
- from platforms used by the controller to contact CriaHub;
- from professional public sources;
- from technical suppliers, when necessary for security purposes or execution of services;
- through cookies, logs and similar technologies.
When data is not collected directly, CriaHub provides information required by law unless an applicable exception applies.
5. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Respond to contacts and analysis requests | pre-contractual measures and legitimate interest in responding |
| Prepare and manage proposals | pre-contractual measures and contract execution |
| Create account, process orders and provide services | execution of contract |
| Manage onboarding, deliveries, revisions and support | execution of contract |
| Invoice, book accounts and comply with tax obligations | legal obligation |
| Collect payments and manage default | execution of contract and legitimate interest in defending rights |
| Prevent fraud, abuse and incidents | legitimate interest in security |
| Maintain records and defend rights | legitimate interest and legal obligations |
| Send service communications | execution of contract |
| Send marketing messages | consent or other basis permitted by applicable legislation |
| Measure and improve the website with optional cookies | consent |
| Recruit and evaluate candidates | pre-contractual measures requested by candidate and legitimate interest |
| Comply with authority requests | legal obligation |
When the legal basis is legitimate interest, CriaHub assesses necessity and balances its interests against those of the controller.
6. Mandatory data fields
Fields marked as mandatory are necessary to respond to a request, issue proposals, process orders, comply with legal obligations or execute services.
Lack of data may prevent response, contracting, invoicing or execution.
Consent for marketing and optional cookies is not a condition of the contract.
7. Commercial communications
CriaHub can send commercial messages:
- with consent;
- in the context of an existing relationship when permitted by law;
- to professional contacts within applicable legal limits.
Each communication allows refusal of future messages free and easily.
Withdrawal of consent does not affect the lawfulness of prior processing.
8. Payments
Payments are processed via Stripe or the payment provider indicated in checkout.
The payment provider processes data according to its own policy and transmits only information necessary for confirmation, reconciliation, refunding and fraud prevention to CriaHub.
9. Recipients and suppliers
Data may be processed by necessary suppliers including:
- hosting and infrastructure;
- email and communications;
- payments and invoicing;
- CRM and commercial management;
- analytics and consent management;
- support, security and monitoring;
- storage and collaboration tools;
- automation and artificial intelligence;
- accounting, legal advisory and other consultants;
- public authorities when legally required.
CriaHub selects appropriate suppliers and concludes necessary contracts.
Data is not sold.
10. Artificial Intelligence
CriaHub may use AI tools to support analysis, drafting, content creation, automation, classification, programming and execution.
CriaHub seeks to minimize data sent and must not introduce sensitive or confidential data into external tools without justification and adequate safeguards.
Relevant results are subject to human intervention.
CriaHub does not make exclusively automated decisions that produce legal effects or significantly affect the controller unless specific information and appropriate legal basis exist.
11. International transfers
Some suppliers may process data outside the European Economic Area (EEA).
In such cases, CriaHub uses an adequate legal mechanism such as:
- adequacy decision;
- standard contractual clauses;
- other guarantees provided for in GDPR.
Additional measures can be applied when necessary.
The controller may request information about the applicable mechanism.
12. Retention periods
Data is retained only for as long as necessary.
| Data type | Period or criteria |
|---|---|
| Commercial requests without contract conclusion | up to 24 months after last relevant contact |
| Unaccepted proposals | up to 24 months after expiry date ends |
| Account, contract, order and project data | during relationship and for limitation of action periods and rights defence periods |
| Invoices and accounting documents | during applicable legal period, normally 10 years |
| Briefings and project materials | during service and generally up to 12 months after completion unless continuity or need for rights defence exists |
| Support communications | during service and as long as necessary for management and rights defence |
| Technical and security logs | generally up to 12 months, except in case of incident or legal obligation |
| Consent-based marketing data | until consent withdrawal or 24 months of inactivity |
| Candidate applications | up to 12 months unless consent is given for longer period |
| Backup copies | until technical deletion cycle ends, normally not exceeding 90 days |
| Data processed on behalf of Clients | according to Client instructions and contract terms |
Data may be retained longer when legal obligation, litigation, investigation, debt or need for rights defence exists.
13. Security
CriaHub applies appropriate measures based on risk level including, depending on service:
- access control;
- authentication;
- encryption in transit;
- backups;
- logging and monitoring;
- infrastructure updates;
- minimization practices;
- supplier contracts;
- incident procedures.
No transmission or system is fully immune to risk.
14. Data breaches
When a personal data breach may represent a risk, CriaHub assesses and fulfills notification obligations to CNPD (National Commission for Personal Data Protection) and communication to controllers.
When acting as processor, CriaHub informs the Client without undue delay after becoming aware of the incident.
15. Controller rights
In accordance with applicable law, a controller may exercise:
- access;
- rectification;
- erasure (right to be forgotten);
- restriction of processing;
- data portability;
- objection;
- withdrawal of consent;
- right not to be subject to exclusively automated decision-making;
- complaint before CNPD.
Rights may have legal limitations, especially when data is necessary for fulfilling obligations, executing contracts or defending rights.
16. How to exercise rights
Requests must be sent to:
CriaHub may request reasonable information to confirm identity.
Response is provided without undue delay and generally within one month. The period can be extended in legally prescribed cases with notification to the controller.
Requests are free unless manifestly unfounded or excessive under applicable law terms.
17. Objection to marketing and legitimate interest
A controller may object to direct marketing at any time.
When processing is based on legitimate interest, objection may be made for reasons related to particular situation. CriaHub ceases processing except when overriding legitimate grounds exist or need for rights defence arises.
18. Complaints to CNPD
The controller may file a complaint with the National Commission for Personal Data Protection (CNPD).
CriaHub recommends prior contact attempting to resolve the issue first.
19. Children's data
Services are not directed at children.
CriaHub does not intentionally collect children's data without legal representative intervention and adequate justification.
20. Client-provided data
A Client providing personal data of third parties must:
- have a legal basis;
- inform controllers;
- limit data to what is necessary;
- respect rights;
- provide lawful instructions.
Clients should not send sensitive data or illegally acquired information.
21. Links and external platforms
The website may contain links to third parties. CriaHub does not control their respective policies.
When a user interacts with WhatsApp, Google, Meta, Stripe or another platform, that entity may process data according to its terms.
22. Cookies
Use of cookies is explained at:
https://www.criahub.global/en/cookie-policy/
Optional cookies should only be activated after valid consent.
23. Changes
CriaHub can update this Policy.
Material changes are identified through date and version number, and when appropriate communicated via available channels.
24. Contact
Privacy questions and rights requests:
- Email: [email protected]
- Address: Rua Bento de Jesus Caraça, 17, 1495-686 Oeiras, Portugal
- Phone: +351 915 883 495