top of page

Privacy Policy

A legal disclaimer

Last updated: August 2026

This policy explains what personal data I collect, why I collect it, and what rights you have over it. It follows the EU General Data Protection Regulation (Regulation (EU) 2016/679) and Portuguese Law 58/2019.

1. Who is responsible for your data

I am the data controller for the personal data described here.

Susana Gomes, trading as Sugo & Co, an independent strategic marketing and communication consultancy.

• Based in Portugal

• Email: hello@sugoand.co
 

I work alone. There is no data protection officer, and none is required for a business of this size and activity.

2. What this policy covers

 

This policy covers this website and the direct contact that follows from it — enquiries, and the work that may come out of them.

 

Not every situation below applies at all times. Where a service is not currently offered on the site, that section simply does not come into effect until it is.

 

This policy does not cover other websites I link to. If you follow a link to LinkedIn or Substack, that platform's own policy applies to what happens there.

 

3. What I collect and why

 

When you contact me

 

What: your name, your email address, and whatever you choose to write in your message. If you tell me about your company or your project, that is part of the message.

 

Why: to read your enquiry and reply to it.

 

Legal basis: legitimate interest — you wrote to me and expect an answer. If the conversation turns into work, the basis becomes performance of a contract, or steps taken before entering one.

 

When you subscribe to the newsletter

 

What: your email address, and your name if you give it.

 

Why: to send you CEO by the Sea.

 

Legal basis: consent. You can withdraw it at any time using the unsubscribe link at the bottom of every email.

 

When you book a session

 

What:your name, email address, the time slot, and any details you add when booking.

 

Why: to schedule the session, send you the invitation, and prepare for it.

 

Legal basis: steps taken at your request before entering into a contract.

 

When you pay for a service

 

What: your billing details and the transaction record. Card details are entered directly with the payment provider — I never see or store your card number.

 

Why: to take payment and to meet my invoicing and tax obligations.

 

Legal basis: performance of a contract, and legal obligation for the accounting records.

 

When you visit the site

 

What: basic usage data — pages viewed, approximate location by country, referring site, device type. This is aggregated and does not identify you personally.

 

Why: to understand which pages people read and whether the site works.

 

Legal basis: consent for any non-essential cookies or identifiers; legitimate interest where the data is fully anonymous.

 

When we work together

 

What: whatever the work requires — company documents, strategy material, content, internal information you share with me, and the contact details of people on your team.

 

Why: to deliver the work you hired me for.

 

Legal basis: performance of a contract.

 

Client material is confidential. I do not publish, quote or reference client work without permission, and case studies are anonymised unless you have agreed otherwise in writing.


 

4. Who else handles your data

 

A small number of providers keep this business running. They process data on my instructions, under their own obligations as processors under the GDPR. This list is kept current — a provider appears here once it is actually in use.

 

Provider |

Website hosting: Wix / Google Workspace / Squarespace 

Email: Google Workspace 

Analytics: Google Analytics

Newsletter: Substack 

Scheduling: Google Calendar 

Payments: Stripe  

 

I do not sell your personal data and I do not share it for advertising. It goes elsewhere only where the law requires it, or where I need professional advice on a matter that involves it — for example an accountant or a lawyer, bound by confidentiality.

 

5. Data sent outside the EU

 

Some of these providers are based in the United States or store data there. Where that happens, the transfer relies on the European Commission's adequacy decision for the EU–US Data Privacy Framework, or on Standard Contractual Clauses approved by the Commission.

 

You can ask me which safeguard applies to a specific provider.

 

6. How long I keep it

 

Enquiries that go nowhere:up to 12 months, then deleted.

Newsletter subscribers: until you unsubscribe.

Client records and contracts:for the duration of the work and up to 5 years afterwards, in line with the limitation period for contractual claims.

Invoices and accounting records: 10 years, as required by Portuguese tax law.

Analytics:** as set by the provider, typically up to 14 months.

 

7. Cookies

 

The site uses cookies that are strictly necessary for it to function. These do not require your consent.

 

Anything beyond that — analytics or measurement — is only set if you agree, and you can change or withdraw that choice at any time through the cookie banner or your browser settings.

 

8. Your rights

 

Under the GDPR you have the right to:

 

  • access the personal data I hold about you

  • correct anything inaccurate or incomplete

  • erase your data, where there is no legal reason for me to keep it

  • restrict how I use it while a question about it is resolved

  • object to processing based on legitimate interest

  • portability receive your data in a machine-readable format, or have it sent to someone else

  • withdraw consent at any time, without affecting anything done before you withdrew it

 

To exercise any of these, email me at hello@sugoand.co. I will reply within one month. If the request is complex I may extend that by two further months and will tell you why. There is no charge, unless a request is clearly unfounded or repetitive.

 

9. Security

 

Your data sits on reputable platforms with access controls and encryption in transit. My devices are password-protected and encrypted, and I am the only person with access.

 

No system is completely secure. If a breach occurs that is likely to put your rights at risk, I will notify the supervisory authority within 72 hours and tell you directly where the law requires it.

 

10. Children

 

This site is for a professional audience. I do not knowingly collect data from anyone under 18. If you believe a child has given me personal data, write to me and I will delete it.

 

11. Complaints

 

If you think I have handled your data badly, tell me first — most things are resolved that way.

 

You also have the right to complain to the Portuguese supervisory authority:

 

Comissão Nacional de Proteção de Dados (CNPD)

Av. D. Carlos I, 134 — 1.º, 1200-651 Lisboa, Portugal

geral@cnpd.pt · www.cnpd.pt

 

If you live in another EU country, you can complain to your own national authority instead.

 

12. Changes to this policy

 

If this policy changes, the new version goes here with a new date at the top. Material changes affecting data you have already given me will be communicated directly.

 

13. Contact

 

Susana Gomes | Sugo & Co

hello@sugoand.co

Portugal

bottom of page