This Privacy Policy explains how Madeira Friends collects, uses, shares, and protects your personal data when you visit madeirafriends.org (the "Site"), join the community, or use any of our Services. We comply with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and Portuguese Law 58/2019.
1. Data controller
Madeira Friends Community (NIPC / VAT PT516898787), Rua dos Barreiros, 26A, 9060-397 Funchal, Madeira, Portugal, is the data controller. Contact: hello@madeirafriends.org.
2. What we collect
- Contact form data — first name, last name, email, WhatsApp number (with country code), subject, and message you send via the contact page.
- Membership data — name, email, billing details, and account preferences when you sign up on app.madeirafriends.org.
- Booking data — name, email, stay dates, and any information needed to fulfil a coworking, coliving, or event booking (processed by us and/or the relevant partner platform).
- Technical data — IP address, browser, device, referrer, pages visited, and timestamps, collected automatically via standard web logs and (optional) analytics cookies.
- Communications — emails and messages you send us, including via WhatsApp.
- Photographs and recordings — taken at our events for community and promotional purposes. See section 8 of our Terms for opt-out instructions.
3. Why we use your data (legal basis)
- To respond to your contact request — legal basis: Article 6(1)(b) GDPR (steps prior to entering a contract) or Article 6(1)(f) (legitimate interest in responding to enquiries).
- To deliver memberships, bookings, programs, and events — legal basis: Article 6(1)(b) (performance of a contract).
- To comply with legal obligations (tax, invoicing, consumer protection) — Article 6(1)(c).
- To operate, secure, and improve the Site — Article 6(1)(f) (legitimate interest).
- To send community updates and newsletters — only with your consent, Article 6(1)(a). You can unsubscribe at any time via the link in every email.
4. How we collect data via the contact form
When you submit our contact form, the data is sent directly from your browser to our server (a Go application hosted by our provider). The server forwards your submission by email to hello@madeirafriends.org over SMTP. We do not sell, rent, or share contact-form submissions with third-party marketers. A honeypot field is used to filter out automated bots; no other tracking is added to the form.
5. Sharing your data
We share personal data only with:
- Service providers acting as processors — hosting, email delivery (SMTP), payment processing, booking platforms (e.g. madeiraremote.com), and analytics. Each processor is bound by a data-processing agreement consistent with Article 28 GDPR.
- Public authorities — only when legally required, e.g. tax authorities or in response to a valid court order.
- Sister properties of the same operator — only with your explicit consent, where you have asked us to forward an enquiry.
We do not sell your personal data and we do not share it with advertising networks.
6. International transfers
Some of our processors are located outside the European Economic Area. Where this is the case, we rely on the European Commission's Standard Contractual Clauses (SCCs) or an adequacy decision to ensure your data is protected to an equivalent standard.
7. Retention
- Contact-form emails: up to 24 months after the last contact.
- Membership and account data: while your membership is active, plus 5 years for accounting and legal compliance.
- Invoicing and tax records: 10 years, as required by Portuguese tax law.
- Newsletter consent: until you unsubscribe; we keep the proof of consent for 3 years after withdrawal.
- Web logs: up to 12 months for security and abuse-prevention purposes.
8. Your rights under the GDPR
You have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Request erasure ("right to be forgotten"), subject to legal retention obligations;
- Restrict or object to processing based on legitimate interest;
- Receive your data in a structured, machine-readable format (portability);
- Withdraw consent at any time (where consent is the basis);
- Lodge a complaint with the Portuguese supervisory authority (CNPD, Comissão Nacional de Proteção de Dados) or with the supervisory authority of your country of residence.
To exercise any of these rights, email hello@madeirafriends.org. We will respond within 30 days.
9. Cookies
The Site uses a minimal set of cookies. See our Cookie Policy for the full list and your choices.
10. Security
We use TLS encryption for all data transmitted between your browser and our server, restrict access to personal data on a need-to-know basis, and review our security practices regularly. No method of transmission or storage is 100% secure, but we apply industry-standard safeguards.
11. Children
The Services are not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us so we can delete it.
12. Changes
We may update this Privacy Policy from time to time. Material changes will be flagged at the top of this page. The "Last updated" date above reflects the current version.
13. Contact
Questions about this Policy or your data? hello@madeirafriends.org.