Privacy policy
Last updated: 22 July 2026
In plain language: we use personal data to answer requests and deliver our services. Optional browser measurement does not start unless you accept it. We do not sell personal data, and we do not send names, email addresses, form contents, or uploaded documents to Google Analytics, Google Ads, or PostHog.
1. Who controls your data
eprportugal.com is operated by Zahard LTD, registered at United Kingdom under registration number 14503377 (tax or VAT number GB 452262020), with registered office at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. Zahard LTD is the data controller for this website and for any service it expressly accepts through it.
For any privacy request or question, email [email protected] or write to the registered office shown above.
2. Scope of this notice
This notice covers eprportugal.com, quote and onboarding forms, the client portal, support communications, and any EPR service expressly accepted in writing. It does not state that an authorised-representative appointment or other regulated capability is currently available. Third-party websites linked from this site have their own privacy notices.
3. Data we collect
- Enquiries and quotes: name, work email, company, website, country or nationality, products sold, messages, and quote inputs.
- Client accounts and service delivery: login email, company and representative details, KYB and identity documents, signed documents, compliance records, support messages, invoices, and payment status. Stripe processes card details; we do not store full card numbers.
- Technical and security data: IP address, browser and device information, requested URL, timestamps, session records, and security logs.
- AI assistant: if you use it, the question, recent conversation, selected language, and current page are sent to Anthropic to generate an answer. Do not enter identity documents, payment details, or other sensitive information in the assistant.
- Optional measurement data: after consent only, pseudonymous browser or cookie identifiers, pages viewed, referrer, campaign and ad-click identifiers, locale, interactions, and conversion type and value. Form fields and contact details are excluded from these events.
4. Why we use data and our legal bases
- To answer enquiries, prepare quotes, and take steps requested before a contract: steps before entering into a contract and our legitimate interests in responding to business enquiries.
- To create accounts, verify clients, deliver an accepted EPR service, process signatures and payments, and provide support: performance of a contract and compliance with legal obligations.
- To protect the service, prevent fraud, maintain audit records, and establish or defend legal claims: our legitimate interests and, where applicable, legal obligations.
- To run optional browser analytics and measure advertising conversions: consent. Refusing has no effect on access to the site or service.
- To improve the portal using limited, pseudonymous server-side product events: our legitimate interest in maintaining and improving the service. These events exclude names, email addresses, free text, and document contents.
5. Cookies and optional measurement
Essential storage keeps the site secure, remembers your language, and records your privacy choice. If you select “Accept all”, Google Analytics, Google Ads conversion measurement, and browser-side PostHog may run. Advertising personalisation and remarketing are disabled. If you select “Essential only”, these optional browser tools are not loaded.
You can withdraw or grant consent at any time using “Cookie settings” in the footer. Withdrawal stops optional browser measurement, removes known optional first-party identifiers from this browser, and does not affect processing that occurred before withdrawal.
Google explains how it processes information received from sites and apps using its services: Google Business Data Responsibility.
| Storage | Category | Purpose | Duration |
|---|---|---|---|
| epr_consent | Essential | Records Accept all or Essential only. | 6 months |
| epr_measurement_receipt | Essential | Keeps the pseudonymous server-side consent receipt linked after session renewal so withdrawal remains effective. | 6 months |
| preferred_locale | Essential | Remembers the selected language. | 12 months |
| *-session / XSRF-TOKEN | Essential | Session security, login, and form protection. | Session or 2 hours of inactivity |
| _ga / _ga_* | Optional measurement | Distinguishes pseudonymous visits and sessions for Google Analytics. | Up to 13 months |
| _gcl_aw | Optional measurement | Attributes a conversion to a Google Ads click. | Up to 90 days |
| ph_* and related browser storage | Optional measurement | Pseudonymous product analytics with PostHog. | Up to 12 months |
| epr_xc7d3179d755a (local storage) | Optional measurement | Prevents the same conversion event being counted twice. | Until withdrawal or browser deletion; maximum 100 event identifiers |
6. Who receives data
We disclose only the data needed for each purpose. Depending on the feature used, recipients include:
- Our contracted hosting and protected document-storage providers; Cloudflare for content delivery and network security; and our EU-hosted n8n workflow and CRM infrastructure.
- Our email delivery provider, Stripe for payments, Yousign for electronic signatures, and Mistral AI for assisted document extraction.
- Anthropic when you use the AI assistant.
- PostHog EU for product analytics and, only after browser consent, Addingwell and Google Ireland Limited for Google Analytics and Google Ads conversion measurement.
- Portuguese authorities, EPR registries, producer responsibility organisations, professional advisers, insurers, courts, or regulators when needed for an accepted service, to comply with law, or to protect legal rights.
We do not sell or rent personal data. Service providers act under contractual confidentiality and data-protection obligations.
7. International transfers
The contracting provider is established in United Kingdom. Some service providers may process data outside that country or the European Economic Area. Where required, we rely on an adequacy decision or approved contractual safeguards, such as the European Commission Standard Contractual Clauses or an applicable transfer addendum. You may contact us for information about the safeguard relevant to your data.
8. How long we keep data
- Enquiries and unsuccessful quotes: up to 3 years after the last meaningful contact.
- Account and authentication data: for the life of the account and normally 1 year after closure.
- Client, KYB, mandate, signature, and compliance records: for the engagement and normally 5 years afterwards, unless a longer period is required for a dispute or by law.
- Invoices and accounting records: up to 10 years where required for tax and accounting compliance.
- Routine technical and security logs: normally no more than 90 days, unless needed to investigate an incident or legal claim.
- Google Analytics event-level data: up to 14 months. Browser identifier durations are listed in the cookie table above.
- AI assistant conversations are not saved as a conversation history in our application; the provider may retain request data for the limited period set out in our service terms with it.
- Anonymous assistant-response metadata (no IP address, session, account, question, or answer) is kept for up to 90 days.
9. Your rights
Depending on the law that applies, you may request access, correction, deletion, restriction, or portability of your personal data, object to processing based on legitimate interests, and withdraw consent at any time. You also have the right to complain to a supervisory authority. Contact us at [email protected]; we may need to verify your identity before acting on a request.
We do not make decisions with legal or similarly significant effects solely by automated means.
You may complain to the UK Information Commissioner’s Office or, where EU GDPR applies, the data-protection authority in the country where you live or work:
10. Security
We use proportionate technical and organisational safeguards, including encrypted connections, access controls, protected document storage, logging, backups, and restricted staff access. No internet service can guarantee absolute security; please contact us immediately if you believe your data or account has been compromised.
11. Changes to this notice
We may update this notice when our services, providers, or legal obligations change. The date at the top identifies the current version. We will provide additional notice where a change materially affects how we use personal data.