DizQuando!
EN PT

Privacy & Data Protection

This page explains which data may be processed in DizQuando, for what purposes, for how long, with whom it may be shared, and how data protection rights can be exercised.

Last updated: 2026-07-09

Data minimisation Only what is needed Name, responses, optional email and essential technical logs.
Retention 30 days After closure, personal event data is automatically anonymised.
Rights Access and erasure Requests for access, correction, objection, restriction and erasure can be submitted.

Roles and scope

The event organiser normally defines the event content, invited participants and final decision. The DizQuando platform operator processes data required for hosting, security, technical logs, configured email delivery and service operation.

The exact qualification of controller and/or processor roles depends on how the platform is operated. For formal identification of the controller applicable to your case, use the contact shown at the end of this page.

Data processed

  • Event data: title, description, location/platform, dates, time ranges, closure status and creation date.
  • Participant data: name entered in the vote, availability responses and, if provided, email address.
  • Invitations: email addresses entered by the organiser to send invitations and voting links.
  • Optional notifications: indication that the participant wishes to be notified of the final decision.
  • Technical and security data: audit logs, minimal operational metadata, administrative actions and data required for abuse prevention and security.

Purposes and legal bases

  • Providing the service requested by the user/organiser: event creation, vote collection, vote closure and result display.
  • Performing participant-requested actions: recording the vote and, when selected, sending the final decision notification by email.
  • Legitimate interest in security, abuse prevention, service integrity, logging relevant actions and defending legal claims.
  • Compliance with applicable legal obligations, where required.

Recipients and transfers

Data may be accessed by the event organiser, authorised platform administrators and technical providers strictly necessary for service operation, such as hosting, database, email delivery and technical monitoring providers.

By default, there is no intention to disclose data publicly beyond what the event itself shows to participants. If any technical provider operates outside the European Economic Area, use of that provider should rely on a valid transfer mechanism and appropriate safeguards.

Retention, anonymisation and deletion

Closed events are automatically anonymised after 30 days. The retention period is configurable by the platform administrator.

Anonymisation replaces the participant name with “Anonymous”, removes the email address and disables the notification preference, preserving only statistical information needed for the functional event history.

The organiser or an authorised administrator may also export or anonymise event data to respond to legitimate data subject requests.

Cookies and technical identifiers

  • Language cookie (`lang`) to store the user’s language preference.
  • Session and authentication cookies only in the administrative area, with reinforced security attributes whenever HTTPS is available.
  • No marketing cookies or advertising trackers should be used in this base application configuration.

Security and incident handling

The platform uses technical and organisational measures proportionate to the risk, including web security headers, session protection, private administrative links, rate limiting, audit logs and data minimisation.

If a security incident affects personal data or service continuity, it should be assessed and handled in accordance with the GDPR and, where applicable, national cybersecurity legislation implementing NIS2.

Data subject rights

  • Right of access to personal data being processed.
  • Right to rectify inaccurate or incomplete data.
  • Right to erasure, where applicable.
  • Right to restriction of processing and right to object, where applicable.
  • Right to data portability, where legally applicable.
  • Right to withdraw an email notification option and request anonymisation of data linked to a vote.
  • Right to lodge a complaint with the competent supervisory authority, in Portugal the CNPD.

Automated decision-making

In this base configuration, DizQuando does not make automated decisions with legal effects or similarly significant impact on data subjects. Displayed counts and results only support the organiser’s decision.

Contact

For requests concerning access, correction, erasure, objection, restriction or clarifications about data protection, contact the event organiser or the platform privacy contact point.

[email protected]

Supervisory authority (CNPD)

Back to homepage