Legal
Privacy Policy
Last updated: 22 September 2026
This policy explains what personal data Proof of Change collects when you use this website or contact us, why we collect it and what your rights are. We aim to collect as little as possible.
1. Who is responsible
The data controller is Maria Pignatelli, trading as Proof of Change, [registered address], [contact email].
2. What we collect and why
- Contact and booking details. Your name, email, organization, role and the message you send when you write to us or book a call. We use them to answer you and prepare a conversation. Legal basis: steps taken at your request before a contract, and our legitimate interest in replying to enquiries.
- Client and engagement information. Contact details, invoicing details and the material you share so that we can do the work. Legal basis: performing our contract and meeting legal obligations such as accounting and tax.
- Website usage data. If you accept analytics, aggregated data such as pages visited, approximate country, device type and referrer. Legal basis: your consent. Without consent we do not run optional analytics.
- Technical data. Your IP address and browser details are processed by our hosting provider for security and to deliver the site. Legal basis: legitimate interest in keeping the site secure and working.
- Newsletter or updates, if we offer them. Your email address, only if you sign up. Legal basis: your consent, which you can withdraw at any time.
3. What we do not do
We do not sell your personal data, we do not use it for automated decisions that affect you, and we do not knowingly collect data from children.
4. Who we share it with
We share data only with service providers that help us run the business, under agreements that protect it:
- Website hosting and delivery: Cloudflare.
- Email, calendar and video-call tools we use to communicate and schedule with you: [provider names].
- Booking tool, if you book a call online: [booking provider].
- Accounting and invoicing: [provider names], and our accountant.
- Authorities, when the law requires it.
5. International transfers
Some providers may process data outside the European Economic Area. When they do, we rely on safeguards such as the European Commission's standard contractual clauses or an adequacy decision.
6. How long we keep it
- Enquiries that do not lead to work: up to 12 months.
- Client records and engagement files: for the length of the engagement plus the period we are legally required to keep accounting records (typically up to 10 years for invoices), and file content for up to 3 years after the engagement ends unless you ask us to delete it sooner.
- Analytics data: in aggregated form, up to 14 months.
7. Confidential client material
Documents and data you share for an engagement are treated as confidential, used only for that work, kept in access-controlled storage and deleted or returned when the engagement ends, as agreed with you.
8. Your rights
Under the GDPR you can ask us to access, correct, delete or restrict the use of your data, to object to processing based on legitimate interest, to receive your data in a portable format, and to withdraw consent at any time without affecting earlier processing. Write to [contact email] and we will reply within one month. You can also complain to your local data protection authority (in Portugal, the Comissão Nacional de Proteção de Dados, cnpd.pt).
9. Cookies
See our Cookie Policy for details, and use the Cookie settings page to change your choices at any time.
10. Security
We use reasonable technical and organizational measures, including encrypted connections (HTTPS), access controls and password managers. No system is perfectly secure, and we will notify you and the authorities of a breach when the law requires it.
11. Changes
We may update this policy. The date at the top shows the latest version. Material changes will be highlighted on this page.