Introduction

Data Protection Policy

Allcost

Introduction

For Allcost, the privacy and protection of your Personal Data is extremely important. Allcost expresses its firm commitment to comply with the legislation in force at all times and to process your personal data in accordance with this privacy policy.
Allcost reserves the right to amend the Privacy Policy in line with new legal and/or regulatory requirements, for security reasons, or to adapt the Policy to the guidelines of data protection supervisory authorities.

Who is responsible for processing your data?

The entity responsible for processing your Personal Data is Allcost, headquartered at Zona Industrial de Vila Nova de Sande, 4805-624 Guimarães, holder of the corporate identification number 509767931.
Data subjects may contact Allcost through the following means:
– Tel.: +351 253 479 260
– Email address: protecaodedados@allcost.pt

What data do we collect, how do we use it, on what basis, and where do we store it?

Allcost collects various types of Personal Data depending on the different purposes, including but not limited to:
Full name / Date of birth / Email address / Telephone number / Address / Citizen Card number / Tax Identification Number (NIF) / Social Security Number (NISS) / Bank Identification Number (NIB) / Biometric data of employees.

The purposes of processing Personal Data are as follows:

a) Execution of the Employment Contract:
Allcost uses your personal data to prepare the employment contract and communicate the employment relationship to entities such as Social Security, the Tax Authority, the company selected by Allcost for occupational health and safety services, the financial institution used for salary transfers, and the insurance provider responsible for mandatory and/or optional insurance (work accidents and health insurance).

b) Communication:
Allcost may use your address, email address, or telephone number to communicate with you, namely to send newsletters about activities developed by Allcost, as well as information about products sold by Allcost and associated promotions or discounts.

c) Access and Attendance Control:
Allcost will collect and use employees’ biometric data for access and attendance control purposes.

d) Video Surveillance:
Certain areas of Allcost facilities, such as the entrance and warehouse, are monitored by duly signposted video surveillance systems. Image capture is intended to ensure the safety of people and property.

e) Recruitment:
During staff selection and recruitment processes, Allcost collects and processes personal data of candidates. The personal data processed includes the information contained in the application form and Curriculum Vitae, as well as any personal data voluntarily provided by the candidate, including but not limited to name, age, gender, photograph, contact details (email and telephone number), education information, employment history, and immigration status (if a work permit is required).

You may unsubscribe from the Newsletter or any of the communications mentioned above at any time by using the email provided above.

Except for processing necessary for the provision of products and services (processing required for contract execution), biometric data collection, video surveillance image capture, and recruitment processing—where processing is based on Allcost’s legitimate interest—the legal ground for data processing is the data subject’s consent.

Personal Data collected for employment contracts or order processing is necessary for the execution of the respective contract. Therefore, if the data subject opposes its processing, Allcost will not be able to fulfil the contract.

Who are the recipients of your data?

Allcost may subcontract other companies to provide specific services, such as tax, accounting, and legal advisory services, insurance, training, IT and communications, or website maintenance. In such cases, these third parties may need access to certain personal information.
Allcost guarantees that these third parties will have limited access to personal data, restricted solely to the data necessary to fulfil the contracted tasks.

Allcost also ensures that a legally binding contract is in place regulating the protection of Personal Data, obliging these third parties not to disclose the data nor use it for purposes other than the contracted services.

Likewise, Allcost may disclose your Personal Data when required by law, within legal proceedings, or during investigations of suspicious activities.

Where do we store your data?

Allcost stores Personal Data on secure servers protected from unauthorised access, use, or disclosure.

Allcost adopts the technical, electronic, and organisational measures necessary and appropriate to ensure the security of your Personal Data and to prevent loss, misuse, or unlawful access.
We process your data solely for the purposes for which it was collected, as outlined in this Privacy Policy.

Allcost regularly reviews its data collection, storage, and processing policies to ensure that only the information essential for service provision or improvement is collected, stored, and processed.

Allcost adopts adequate procedures to ensure that your information is accurate, complete, and up to date, but relies on the data subject to update or correct their personal information when necessary.

Allcost does not make automated decisions.

What are your rights when you provide us with your data?

In accordance with the applicable legislation, Allcost undertakes to respect the confidentiality of your personal data and ensure the exercise of your rights, specifically:

a) Right to be informed:
Employees, clients, and suppliers have the right to clear, transparent, and understandable information about how Allcost uses their Personal Data.

b) Right of access:
In addition to the right to be informed, you may access your personal data that we process and store. In such cases, Allcost will provide a copy of the personal data being processed. When requested electronically, the information will be provided in a commonly used electronic format.

c) Right to rectification:
You have the right to rectify your personal data if it is incorrect, outdated, or incomplete. To do so, you may contact us at protecaodedados@allcost.pt.

d) Right to erasure / right to be forgotten:
You may request the deletion of your data. However, please note that this is not an absolute right, as we may have legal grounds or legitimate interests requiring us to retain the data.

e) Right to object, including to direct marketing:
You may unsubscribe from Allcost’s newsletter or opt out of direct marketing communications at any time by informing us at protecaodedados@allcost.pt.

f) Right to withdraw consent at any time:
You may withdraw your consent when processing is based on consent. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

g) Right to lodge a complaint with the CNPD:
If you believe Allcost has violated data protection legislation, you may lodge a complaint with the National Data Protection Commission (CNPD). We encourage you to contact us before submitting any complaint.

h) Right to data portability:
You have the right to move, copy, or transfer your data from our database to another provider.

i) Right to restriction of processing:
You may request that processing be restricted in the following circumstances:
– if you contest the accuracy of the data;
– if processing is unlawful and you request restriction rather than deletion;
– if the data is no longer necessary for Allcost but still required by the employee/client/supplier;
– if you have exercised your right to object and Allcost is assessing whether its legitimate interests override your rights.

Requests to exercise any of the rights listed above may be submitted via the email or postal address mentioned previously. You may also use these contacts if you have any questions regarding this Privacy Policy.

How long do we store your data?

We store Personal Data only for the time necessary to fulfil the purpose for which it was collected, to meet your needs, or to comply with legal obligations.

To determine the retention period, the criteria below apply. When multiple criteria apply simultaneously, the data is kept for the longest applicable period:

a) Employment contract data: retained for the duration of the contractual relationship and for ten years after its termination, without prejudice to legal obligations.
b) Newsletter subscription data: retained until you unsubscribe or request deletion.
c) Biometric data of employees: retained for the duration of the contractual relationship.
d) Video surveillance images: retained for a maximum of 90 days.
e) Recruitment data: retained for a maximum of 1 year from the end of the recruitment process.
f) Any period legally required by applicable legislation.
g) Until the specific purpose for certain data no longer applies.

If there is an ongoing judicial or administrative proceeding, data will be retained for the duration of the process and up to six months after a final decision.

We may retain some Personal Data as necessary to comply with legal obligations or to manage or defend our rights, including through legal proceedings.

After the retention periods expire, Personal Data will be securely deleted and/or destroyed.

Guarantees

The data subject guarantees that the Personal Data provided to Allcost is accurate and correct and undertakes to notify any changes or modifications. The data subject assumes full responsibility for any losses or damages caused by the communication of incorrect, inaccurate, or incomplete data.