Data protection
1. Information about the organization and websites
This Privacy Policy informs you about our privacy practices, the choices you can make about how your information is collected online, how that information is used, and your rights when using this website, in accordance with the General Data Protection Regulation 2016/679. This Privacy Policy may be amended from time to time; any amended text will be published on this website and shall come into force automatically.
2. Websites covered by this Privacy Policy
This Privacy Policy applies to all of our websites and domains, including all regional or country-specific sites (collectively, the "Websites"). The Websites may provide links to third-party websites for your convenience and information. If you access those links, you will leave the Websites. We do not control those websites or their privacy practices, which may differ from ours. This Privacy Policy does not cover personal data that you choose to provide to unrelated third parties. We do not monitor or control the information collected by those websites or the privacy practices of third parties, and we are not responsible for their practices or for the content of their websites.
3. Types of information we collect and use
"Personal information" or "personal data" means information about an identifiable individual who is subject to protection under the law of the jurisdiction in which they reside. In some jurisdictions, "personal information" or "personal data" does not include business contact information. The Websites collect information in various ways and for various purposes. If you choose to register on any of the Websites to receive information or to take up our services, you will be prompted to provide contact information (name, address, telephone number, email address). We will use this information in accordance with our legitimate business interests, to provide our services and/or to contact you about those of our website services in which you have expressed an interest. We may also use your contact information to send you information about other services within the group, such as meeting rooms, virtual offices, business continuity plans, offices and coworking, subject to obtaining your consent in accordance with applicable law. If you do not wish to receive these promotional notices on a regular basis, you should notify us so that we can update your preferences. Through the Websites you may subscribe to services and request information. In order to subscribe to a service, we will request information that will be used for the performance of the contract. You will be required to provide contact information (such as the Proponent's name, address and telephone number, and email address) and financial information (such as tax identification number, cardholder name, credit card number and expiry date). The financial information collected is used for tax purposes. If we collect credit card information, it will be used exclusively for payment processing and fraud prevention. Credit card information and other similar sensitive personal data will not be used by the group for any other purpose without your express consent. We do not retain your credit card information after a payment has been processed, unless you allow us to retain it for future purchases. The Websites automatically collect technical information about your visit (such as browser type, internet service provider, platform type, IP addresses, referring/exiting pages, operating system and date/time log). We use this website reporting information in aggregate form to analyse trends, diagnose problems with our server and administer the Websites, to track user movement and usage patterns and to gather aggregate demographic information. We may be required to share information with third parties as a result of applicable law. For example, we may be required to disclose information as a result of a court order, summons or warrant. Additionally, we may, subject to applicable law, voluntarily provide information to assist in a judicial investigation or when disclosure is necessary to protect our systems, our business or the rights of others. LXoffice undertakes to comply with the General Data Protection Regulation and all other national legislation applicable to personal data, adopting the appropriate technical and organisational measures in the processing of personal data. The collection of the Customer's personal data is a necessary requirement for the provision of services to begin or for those services to be used. As data controller in respect of the data provided, LXoffice informs you that such data will be used to ensure the proper performance of the services, namely for customer identification, the invoicing and collection of services, the recording of any complaints or incidents arising in the course of the contract, as well as for the disclosure of any marketing campaigns related to the service provided. LXoffice also informs you that it may use subcontractors to provide certain services necessary for the proper performance of the contract, and that such entities may need to gain access to customers' personal data. In that case, LXoffice will take all necessary and appropriate precautions to ensure that those entities provide guarantees of compliance with the national legislation applicable to personal data protection. The personal data provided will be retained only for the duration of the contract, and may only be kept in accordance with the legal requirements inherent to the purpose of the processing for which it was collected.
4. Notifications
After you request information or subscribe to our services, we will respond to your enquiries, provide the services you have requested and manage your account. We will communicate with you by email or telephone and will make every effort to honour your preference. We do not provide your email address to our business partners, except to the entity that processes Debit/Credit Cards on the website.
5. Sharing of information and transnational transfers
We enter into contracts with service providers and third-party suppliers to offer complete products, services and solutions to customers. These service providers may change, or we may enter into contracts with other service providers to better accommodate the needs of our customers. Our affiliates may provide services to your company or your local affiliate and may receive personal data about you. Your personal data may be transferred across country borders to our affiliate companies in order to provide you with our services. Residents of the EEA and Canada should understand that their personal data may be transferred outside the EEA and Canada, to the United States or to other countries, for the purposes of data consolidation, storage, simplified customer information management, reporting and other internal uses. We have implemented the model contract clauses approved by the EC to ensure compliance with EU data transfer legislation.
6. Children's privacy
We are committed to protecting children's privacy, encouraging parents and guardians to take an active role in their children's online interests and activities. We do not intentionally collect information from, or direct the Websites at, children.
7. Your rights
Data controller in respect of personal data: LXoffice, Lda. Data Protection Officer contact address: [email protected]
As a data subject, you have the right to access, rectify, erase, restrict, port and object to the processing of your data, as well as the right to lodge a complaint with the supervisory authority (CNPD - https://www.cnpd.pt).
In accordance with the terms of applicable legislation, you may exercise your rights of access, rectification, erasure, restriction of processing, portability and objection to the processing of your personal data by contacting us at [email protected]. These rights may be limited, for example, if complying with your request would entail disclosing personal data about another person or violating the privacy rights of others, or if you ask us to delete information whose retention is required by law or in which we have compelling legitimate interests.
8. Keeping your data safe
We cannot guarantee the security of our servers, nor can we guarantee that the information you provide through the Website cannot be intercepted while it is being transmitted over the internet. We follow generally accepted industry technical standards to protect personal data submitted to us, both during transmission and once we receive it. Where we process personal information for marketing purposes or with your consent, we will process the data until you ask us to stop, and for a short period afterwards (to allow us to implement your requests). We also keep a permanent record of the fact that you asked us not to send you direct marketing or not to process your data, so that we can honour your request in the future. If we process personal information in connection with the performance of a contract or Service, or for the purposes of a competition, we will keep the information for a period of 6 years (except for financial information, which we will keep for 10 years) from your last interaction with us.
9. Business Transactions
In the event that we go through a business transition, such as a merger, acquisition by another company, or the sale of all or part of our assets, your personal information will likely be among the assets transferred.
10. Cookies
10.1 What cookies are
Cookies are small text files that are stored on your device (computer, tablet or mobile phone) when you visit this website. They allow the site to recognise your device and remember certain preferences during browsing.
10.2 Data controller
The data collected through cookies is processed by LXoffice, Lda., email [email protected], as data controller, in accordance with Regulation (EU) 2016/679 (GDPR), Law no. 58/2019 and the applicable legislation on electronic communications (Directive 2002/58/EC).
10.3 Which cookies do we use
This website uses only cookies that are strictly necessary for the functioning of the requested service and for preferences, as described below. We do not use advertising cookies or personalisation/profile cookies. For this reason, this website does not display a cookie banner or request consent: it only installs cookies that are strictly necessary for operation, security and payments, which do not require prior consent under Article 5(3) of the ePrivacy Directive.
- Session cookies (strictly necessary): required for the operation, security and stability of the website (e.g. laravel_session). Without these cookies, the website cannot function properly.
- Language preference cookies: remember the language selected (lang, lang_display), to display content in the desired language.
- Form cookies: the subscription and contact forms are provided by Zoho (Zoho public forms, zohopublic.com domain), loaded on this page via an iframe. Zoho may install session and security cookies strictly necessary for the operation and submission of the forms. These are third-party cookies, not controlled by us, and are not used for marketing purposes.
- Payment cookies: the subscription form integrates the Stripe payment processor. When paying, Stripe may install cookies strictly necessary to complete the payment and prevent fraud (__stripe_mid, __stripe_sid). They are not used for marketing purposes and are not controlled by LXoffice.
- Security and functionality cookies: the website is served through the Cloudflare network (CDN and protection against automated access). Cloudflare may install cookies strictly necessary for security and proper operation, such as __cf_bm, cf_clearance and _cfuvid, intended for fraud/bot prevention and traffic balancing.
10.4 Legal basis
The cookies used are installed on the basis of legitimate interest and to the extent strictly necessary for the provision, security and operation of the requested service (Art. 6(1), points (b) and (f) of the GDPR, and Art. 5(3) of the ePrivacy Directive). We do not use cookies that require prior consent (e.g. analytical, marketing or social media cookies).
10.5 Retention period
The information collected by cookies is retained only for the period strictly necessary for the relevant purpose and, in any case, for the validity period of the cookie itself: session cookies are deleted at the end of each visit; language preferences are retained for a maximum of 30 days; payment and security cookies follow the timeframes defined by Stripe and Cloudflare.
10.6 Sharing with third parties
The data collected by cookies is not sold and is only shared with the following subcontractors (processors), to the extent strictly necessary for the operation of the service:
- Zoho Corporation B.V. (https://www.zoho.com): provider of the subscription and contact forms, under a data processing agreement (DPA), with data processed in compliance with the GDPR. Privacy policy: https://www.zoho.com/privacy.html.
- Stripe, Inc. (https://stripe.com): payment processor, in the context of submitting the subscription request, under a data processing agreement (DPA). Privacy policy: https://stripe.com/privacy.
- Cloudflare, Inc. (https://www.cloudflare.com): CDN and protection against automated access, under a data processing agreement (DPA); certified under the EU-US Data Privacy Framework. Privacy policy: https://www.cloudflare.com/privacypolicy/.
10.7 How to manage or delete cookies
You can block, delete or be notified about the installation of cookies through your browser settings. Please note that disabling the strictly necessary cookies may prevent the website from functioning, including subscription and payment.
Terms and Conditions
If you choose to visit our Websites, your visit and any dispute over privacy will be subject to this Privacy Policy and to our Terms and Conditions, including, without limitation, disclaimers of warranty, limitations of liability and arbitration of disputes. If you have any questions about the use we make of your data, please email [email protected].
This policy may be updated periodically, namely whenever there are changes to the cookies used. Last updated: 2026-09-12.