365 Warriors

Privacy Policy

Last updated: July 2026

This Privacy Policy explains, in plain language, how we process personal data when you visit the 365 Warriors website, use forms, book an assessment or interact with us through digital channels.

Controller

The data controller is 365 Warriors, Lda. | Tax/company number 519083342 | Rua Florbela Espanca, 20 1º cv. dt., 2725-542 Mem Martins, Portugal | geral@365warriors.com | +351 963 502 451.

365 Warriors has not appointed a data protection officer. For privacy and data protection matters, use geral@365warriors.com.

Data we collect

  • Contact and Cloud Support forms: name, email, subject, message, technical security data, IP address used for rate limiting and Cloudflare Turnstile token.
  • Analytics: aggregated usage data through Google Analytics and Microsoft Clarity (usage metrics and session recording, such as clicks and mouse movement), only after consent for non-essential cookies/technologies.
  • Marketing and advertising: usage and conversion data through the LinkedIn Insight Tag (LinkedIn), only after consent for marketing cookies/technologies.
  • Security and anti-spam: technical data needed to protect forms, prevent abuse and validate legitimate requests.
  • Communications: data needed to respond to messages and send emails through our technical providers.
  • External links: when you open LinkedIn, WhatsApp, Microsoft Bookings or other third-party services, their own policies also apply.

Purposes and legal bases

  • Responding to requests, contacts, assessments and commercial enquiries: pre-contractual steps or legitimate interest.
  • Ensuring security, preventing spam, abuse and misuse of forms: legitimate interest.
  • Measuring website performance and usage with Google Analytics and Microsoft Clarity, including behaviour analysis and session recording: consent.
  • Measuring campaigns and conversions and serving relevant advertising with the LinkedIn Insight Tag: consent.
  • Complying with applicable legal obligations: legal obligation.

Retention

  • Simple contact forms: up to 12 months after the last interaction, unless the contact develops into a commercial relationship.
  • Leads, proposals and commercial conversations: up to 24 months after the last interaction.
  • Cloud Support requests: up to 24 months after the request is closed, unless a legal obligation, contract or need to defend rights requires otherwise.
  • Technical logs, IP address and rate limiting data: up to 90 days. In case of a security incident, they may be retained for the period needed to analyse, mitigate and defend rights.
  • Cookie preference and consent: up to 6 months, after which the choice may be requested again.
  • Google Analytics: user data configured for 14 months and event data currently configured for 2 months. If annual comparative analysis is needed, event data should also be configured for 14 months; for stronger minimisation, keeping events at 2 months is the more conservative option.
  • LinkedIn Insight Tag: data is processed by LinkedIn according to LinkedIn's own retention periods and policies (direct identifiers are removed by LinkedIn within 7 days and remaining data retained for up to 180 days).
  • Microsoft Clarity: usage data and session recordings are processed by Microsoft according to Clarity's retention periods and policies (retained for up to 1 year).

Recipients and processors

We may use technical providers needed for the website and communications: Google (Google Analytics), Cloudflare (Turnstile), Resend (email delivery), Microsoft (Microsoft Clarity for analytics and session recording, Microsoft Bookings and associated services), LinkedIn (Insight Tag for advertising and campaign measurement, in addition to the page/social network) and WhatsApp/Meta (WhatsApp contact).

The specific legal entity for each provider may depend on the terms applicable to each service, account or region. Some providers may process data outside the European Economic Area; where this occurs, appropriate safeguards should be used, such as standard contractual clauses or other GDPR-recognised mechanisms.

Your rights

You can exercise your rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent through geral@365warriors.com. You also have the right to lodge a complaint with the Portuguese Data Protection Authority (CNPD).

We will respond within the legal period of 1 month. In the cases provided for by the GDPR, this period may be extended; we may also request additional information when needed to confirm the requester identity.

Cookies and similar technologies

We use strictly necessary technologies for security and website operation. These do not depend on consent when they are essential to the service requested.

Google Analytics, Microsoft Clarity, the LinkedIn Insight Tag and other non-essential technologies are only enabled after consent, with a separate choice per category (analytics and marketing). You may accept, reject or change your choice at any time.

Changes

This policy may be updated to reflect legal, technical or operational changes. The last updated date indicates the version in force.