Legal
Privacy policy
How we handle the data submitted through this site.
1. Who is responsible. Personal data collected on this site is processed by Rabbit Would Do, Lda, NIPC 519 465 822, registered office at Campo Grande, 12, 1.º, Escritório 2, 1700-092 Lisboa, Portugal, which operates under the Quiron brand. For any question about this policy or about your data, the address is hello@quironlabs.pt.
2. Data protection officer. No data protection officer has been appointed, and none is required here: the activity does not involve regular and systematic monitoring of data subjects on a large scale, nor large-scale processing of special categories of data, which are the tests set out in article 37 of the GDPR. Requests are handled directly by the controller, at the address above.
3. What is collected. The site has a single point of data entry, which is the contact form. It asks for your name, your company, your email address, the subject (chosen from a list of four options) and your message. Every field is required and nothing else is asked for. The remaining pages are static and collect nothing.
4. IP address. When the form is submitted, the IP address the request comes from is used to limit how often submissions are accepted, currently three in any ten minutes. The address is held in memory by the process handling the request, is not written to a file or a database, is not linked to the content of the message, and disappears when that process ends. An IP address is personal data, so it is declared here even though the use is momentary.
5. Hosting logs. The site is hosted by Vercel. The hosting infrastructure keeps its own technical logs, which may include IP addresses, in order to run and protect the service. Those logs are created and retained by the provider under the provider rules, not by Quiron.
6. What the form data is used for, and on what basis. The data sent through the form is used to answer your request and, where relevant, to prepare a proposal. The legal basis is article 6(1)(b) of the GDPR: steps taken at the request of the data subject prior to entering into a contract. It is not used for marketing messages, is not passed to third parties for commercial purposes, and is not combined with other sources.
7. The authorisation box on the form. The form includes a box that has to be ticked before sending. It makes explicit that the submission is deliberate and that this policy was available beforehand. The legal basis remains the one in point 6, because the request for a reply comes from the person writing, and it does not cease to exist if the box is later unticked. What you can always do is ask for the data you sent to be erased, as described in point 16.
8. Measures against abuse of the form. In addition to the rate limit described in point 4, the form has a hidden field that only an automated program fills in, and a check on the time elapsed between the page opening and the submission. Neither collects additional data about the person writing. The legal basis is article 6(1)(f) of the GDPR, in the legitimate interest of keeping the contact channel usable and free of automated submissions.
9. Who receives the data. The message is delivered by email through Resend, which handles the sending, and arrives in the controller mailbox, on Microsoft 365. The address you give on the form is set as the reply address on the message, so that the reply goes straight back to you. There are no other recipients, and no data is sold or shared for advertising. The content of messages is never written to the application technical logs.
10. Transfers outside the European Union. Resend, Vercel and Microsoft are companies headquartered in the United States, so data may be accessed from there. These transfers rest on the EU-US Data Privacy Framework. On 31 August 2026 the official programme list recorded Vercel Inc. and Microsoft Corporation as certified and active, and Resend as active with its re-certification under review. The status of each participant can be checked at www.dataprivacyframework.gov.
11. How long the data is kept. The message and the data with it stay in the mailbox while the enquiry is being handled and, after that, for as long as the record remains useful to the relationship in question. The period applied is 24 months from the last contact. If the enquiry leads to a contract, statutory accounting and tax retention periods apply instead: article 52 of the Portuguese VAT Code requires records and their supporting documents to be archived and kept in good order for the 10 calendar years that follow. The data used for the rate limit does not survive the ten-minute window or the process that held it. Hosting logs follow the provider periods.
12. Cookies. This site uses no cookies and therefore has no cookie banner and asks for no consent to set them. Two pieces of information may be stored in your browser, both as a result of something you do yourself: your preference between light, dark and GeoCities mode, saved when you press the toggle, and the score of the discovery game hidden in the site, saved only after you find the first target. Neither is sent anywhere, neither identifies anybody, and neither is read by the server. Both fall within the exemption for storage strictly necessary to provide a service the user has expressly requested, set out in article 5(3) of Directive 2002/58/EC and transposed in Portugal by Lei n.º 41/2004. You can remove both by clearing site data in your browser, and the game score also through the start-over button in its own panel.
13. Usage statistics. In this version the site carries no audience measurement tool of any kind. If one is installed, this policy will be updated before measurement begins.
14. Automated decisions and profiling. No automated decisions with legal or similarly significant effects are taken, and no profiling is carried out. Messages are read and answered by a person.
15. Minors. This site addresses companies and professionals, not minors. No data relating to minors is knowingly collected. If we become aware that a message was sent by a minor, the data is deleted.
16. Your rights. You may request access to the data concerning you, its rectification, its erasure, restriction of processing and portability, and you may object to processing based on legitimate interest. Where processing rests on your consent, you may withdraw it at any time, without affecting what was done before. Requests are made by email to hello@quironlabs.pt and are answered within one month, extendable by a further two months where the request is complex, in which case you will be told within the first month. Additional information may be requested in order to confirm the identity of the person asking.
17. Complaints. If you consider that the processing of your data breaches the law, you may complain to the Comissão Nacional de Proteção de Dados, the Portuguese data protection authority: Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, geral@cnpd.pt, www.cnpd.pt. A complaint to the CNPD does not depend on contacting us first, but we would welcome the chance to settle the matter directly.
18. Changes to this policy. This policy may change when the site changes or when the way data is handled changes. The version in force is always the one published on this page, with the date shown beside it. Changes affecting what has already been submitted are notified by email to anyone with an open enquiry.