Last updated: May 2026
1- Data Controller
The data controller responsible for your personal data is Carlota Leitão, reachable at:
Email: hello@carlotaleitao.photo Phone: +351 91 355 18 21
2. What data we collect and for what purpose
Name, email and phone number — to respond to contact requests and quotes, based on legitimate interest or performance of a contract.
Address and delivery details — for order processing and shipping, based on the performance of a contract.
Payment data — for processing payments via PayPal, based on the performance of a contract.
Browsing data and cookies — for the operation of the website and usage analysis, based on consent.
We do not collect sensitive data or data from individuals under 16 years of age.
3. Who we share your data with
Your personal data is only shared with third parties in the following situations:
— Payment processing: PayPal, subject to its own privacy policy — Shipping services: carriers required for order delivery — Legal obligations: when required by law or a competent authority
We do not sell or transfer your data to third parties for commercial purposes.
4. How long we keep your data
Data is retained only for as long as necessary for the purpose for which it was collected, in compliance with mandatory legal deadlines. Billing data is retained for 10 years, in accordance with Portuguese tax legislation.
5. Your rights
Under the GDPR, you have the right to:
— Access: know what data we hold about you — Rectification: correct inaccurate data — Erasure: request the deletion of your data — Portability: receive your data in a structured format — Objection: object to processing based on legitimate interest — Restriction: request the limitation of processing.
To exercise any of these rights, please contact us by email. You also have the right to lodge a complaint with the CNPD (National Data Protection Commission) at www.cnpd.pt.
6. Cookies
The website uses cookies to ensure its operation and analyse usage. You can manage your preferences through the banner displayed on your first visit to the site or in your browser settings. Refusing non-essential cookies does not affect your ability to browse the website.
7. Security
We adopt appropriate technical and organisational measures to protect your personal data against unauthorised access, loss or destruction.
8. Changes to this policy
This policy may be updated. Any changes will be published on this page with an indication of the update date.