Smart Ideal World

Effective date: 13 September 2026
Last updated: 13 September 2026
Version: 2.0

1. Introduction

Smart Ideal World respects your privacy and is committed to protecting personal data in accordance with applicable data-protection and privacy laws.

This Privacy Policy explains how Smart Ideal World collects, uses, discloses, stores, transfers and protects personal data when you:

  • visit or interact with the Smart Ideal World corporate website;
  • submit a contact, partnership, investment, enterprise or media inquiry;
  • communicate with us through an email address published on our website;
  • subscribe to newsletters or business communications;
  • apply for a role or otherwise submit recruitment information;
  • interact with an official Smart Ideal World social-media page where this Privacy Policy is referenced; or
  • otherwise communicate with Smart Ideal World in connection with the corporate website.

This Privacy Policy also explains your privacy rights and how you may exercise them.

This Privacy Policy is a transparency notice. It is not a request for consent to every processing activity described in it. We rely on the appropriate legal basis for each processing activity, as explained below.


2. Identity of the Data Controller

The data controller responsible for the personal data covered by this Privacy Policy is:

Smart Ideal World, Unipessoal, Lda
NIPC: 516 868 780
Privacy email: privacy@smartidealworld.com

In this Privacy Policy, “Smart Ideal World,” “SIW,” “we,” “us” and “our” refer to Smart Ideal World, Unipessoal, Lda.

For questions concerning this Privacy Policy or the processing of personal data, contact:

privacy@smartidealworld.com

Smart Ideal World has not designated the privacy email address as a formal Data Protection Officer contact unless a Data Protection Officer is expressly identified in a future version of this Privacy Policy.


3. Scope of This Privacy Policy

This Privacy Policy applies to personal data processed by Smart Ideal World in connection with its corporate website and the related communication channels described above.

3.1 Separate products and platforms

This Privacy Policy does not govern personal data processed through:

  • the SyncMLS platform;
  • Route Command Center;
  • Lux Properties;
  • Evolution Property Management;
  • another Smart Ideal World product, platform, brand or service that publishes a separate privacy notice; or
  • a third-party platform or business linked from the Smart Ideal World website.

Each separate product or platform should provide its own privacy notice describing the applicable controller, purposes, data categories, recipients, retention periods and international transfers.

3.2 APMLS

Associação Portuguesa de MLS, or “APMLS,” is an independent association.

APMLS is not a subsidiary, branch or department of Smart Ideal World. Personal data processed by APMLS for membership, accreditation, ethics, compliance, disciplinary or MLS-governance purposes is subject to the applicable APMLS privacy notice and governance documents.

Where Smart Ideal World processes personal data on behalf of APMLS through a technology-services arrangement, that processing is governed by the applicable agreement and data-processing terms rather than this corporate website Privacy Policy.

3.3 Processing on behalf of customers

Where Smart Ideal World processes personal data solely on behalf of a business customer or another controller, Smart Ideal World acts as a processor or service provider in accordance with the applicable contract and data-processing agreement.

In those circumstances, the relevant customer or organization is generally responsible for providing the applicable privacy notice and responding to requests concerning the personal data it controls.


4. Personal Data We Collect

“Personal data” means any information relating to an identified or identifiable individual.

Depending on how you interact with us, we may collect the following categories of personal data.

4.1 Identity and contact information

This may include:

  • full name;
  • email address;
  • telephone number;
  • postal address, where relevant;
  • country or region;
  • preferred language;
  • company or organization;
  • position, title or professional role; and
  • other identifying or contact information you voluntarily provide.

4.2 Inquiry and communication information

When you contact us, we may collect:

  • the subject and content of your inquiry;
  • the type of inquiry selected;
  • information concerning a proposed partnership, investment, project or business relationship;
  • information concerning a request for a demonstration, meeting or introduction;
  • records of correspondence;
  • meeting notes;
  • attachments you provide;
  • your communication preferences; and
  • information reasonably necessary to respond to or manage your request.

4.3 Business and professional information

Where relevant to an inquiry or prospective relationship, we may collect:

  • employer or business name;
  • professional role;
  • sector or industry;
  • business address;
  • professional contact details;
  • publicly available professional information;
  • business interests;
  • partnership requirements;
  • procurement or contracting information; and
  • information concerning an existing or prospective commercial relationship.

4.4 Newsletter and marketing information

Where newsletters or marketing communications are offered, we may collect:

  • name;
  • email address;
  • company or professional role;
  • communication interests;
  • subscription status;
  • consent records;
  • unsubscribe records;
  • communication preferences; and
  • engagement information, such as whether a communication was opened or a link was selected, where such measurement is enabled and legally permitted.

4.5 Recruitment and career information

When you apply for a position or submit an open application, we may collect:

  • name;
  • contact details;
  • CV or résumé;
  • cover letter;
  • employment history;
  • education history;
  • professional qualifications;
  • skills and experience;
  • portfolio or work samples;
  • professional profile links;
  • language abilities;
  • availability;
  • location;
  • work authorization information;
  • salary or compensation expectations, where relevant;
  • references and referee contact information;
  • interview notes;
  • assessment results;
  • communications concerning your application; and
  • other information you voluntarily provide during the recruitment process.

Where reference information relates to another individual, you should ensure that you are authorized to provide it and that the individual understands how their information may be used.

4.6 Technical, device and security information

When you access the website, our systems and service providers may automatically process technical information such as:

  • Internet Protocol address;
  • date and time of access;
  • requested pages or resources;
  • referring page or website;
  • browser type and version;
  • operating system;
  • device type;
  • general geographic region derived from an IP address;
  • language and time-zone settings;
  • server and application logs;
  • diagnostic and error information;
  • security events;
  • suspicious or unauthorized activity;
  • cookie or similar technology identifiers; and
  • information required to operate, protect and troubleshoot the website.

4.7 Cookie and consent-preference information

We may collect:

  • cookie choices;
  • consent or refusal records;
  • date and time of consent;
  • the version of the notice presented;
  • consent-management identifiers; and
  • records of a later withdrawal or change of preference.

4.8 Social-media information

Where you interact with an official Smart Ideal World social-media page, we may receive information made available by the relevant platform, such as:

  • profile name;
  • username;
  • public profile information;
  • message content;
  • reactions;
  • comments;
  • professional information; and
  • other information you choose to make available.

The relevant social-media provider may also process your information as an independent controller under its own privacy terms.

4.9 Information from third parties

We may receive personal data from:

  • a person who refers or introduces you;
  • business partners;
  • event organizers;
  • professional advisers;
  • recruitment providers;
  • publicly available professional sources;
  • professional directories;
  • corporate websites;
  • social-media or professional-networking platforms; or
  • service providers supporting our website and communications.

Where required by law, we will provide any additional information applicable to personal data that was not collected directly from you.


5. Information We Do Not Request Through the Website

Unless specifically requested for a lawful and necessary purpose, you should not submit the following through a general contact form or ordinary email:

  • passwords;
  • payment-card information;
  • bank-account credentials;
  • government identification numbers;
  • passport or identity-card copies;
  • health information;
  • biometric information;
  • information concerning racial or ethnic origin;
  • political opinions;
  • religious or philosophical beliefs;
  • trade-union membership;
  • genetic information;
  • information concerning sex life or sexual orientation;
  • criminal-conviction information;
  • confidential information belonging to another organization; or
  • information concerning another person that you are not authorized to disclose.

If such information is submitted without being requested, we may delete it where it is not necessary or lawful for us to retain it.

Where sensitive information is genuinely required for recruitment, legal compliance or another specific process, we will provide additional information and obtain consent or rely on another lawful basis where required.


6. How We Collect Personal Data

We may collect personal data:

6.1 Directly from you

For example, when you:

  • complete a form;
  • send an email;
  • request information;
  • subscribe to communications;
  • arrange a meeting;
  • submit a job application;
  • communicate with us through social media; or
  • otherwise provide information voluntarily.

6.2 Automatically

We may collect technical and security information automatically through:

  • servers;
  • hosting systems;
  • security tools;
  • essential cookies;
  • consent-management tools;
  • website logs; and
  • similar operational technologies.

6.3 From third parties

We may receive information from a referral source, event organizer, recruitment provider, business partner or publicly available professional source.


7. Purposes and Legal Bases for Processing

We process personal data only where we have a lawful basis for doing so.

Depending on the circumstances, the applicable legal bases may include:

  • your consent;
  • taking steps at your request before entering into a contract;
  • performance of a contract;
  • compliance with a legal obligation;
  • protection of vital interests in exceptional circumstances; or
  • our legitimate interests or the legitimate interests of another party, provided those interests are not overridden by your rights and freedoms.

7.1 Responding to inquiries

We process contact, identity, business and communication information to:

  • receive and evaluate inquiries;
  • respond to questions;
  • provide requested information;
  • arrange meetings;
  • manage partnership or investment discussions;
  • consider proposed projects;
  • direct an inquiry to the appropriate person; and
  • maintain records of our response.

The applicable legal bases are generally:

  • taking steps at your request before entering into a contract; and
  • our legitimate interest in receiving, managing and responding to business communications.

7.2 Managing prospective and existing business relationships

We may process personal data to:

  • evaluate a prospective business relationship;
  • conduct appropriate due diligence;
  • prepare proposals;
  • negotiate commercial terms;
  • communicate with representatives of an organization;
  • administer a relationship;
  • maintain business records; and
  • protect our commercial and legal interests.

The applicable legal bases are generally:

  • taking steps before entering into a contract;
  • performance of a contract;
  • compliance with legal obligations; and
  • our legitimate interest in operating and managing our business.

7.3 Recruitment and career management

We may process candidate information to:

  • review an application;
  • assess qualifications and suitability;
  • communicate with candidates;
  • arrange interviews;
  • perform permitted assessments;
  • verify information;
  • contact references where appropriate;
  • make recruitment decisions;
  • prepare an offer;
  • comply with employment-related obligations; and
  • establish, exercise or defend legal claims.

The applicable legal bases may include:

  • taking steps at your request before entering into an employment or contractor relationship;
  • our legitimate interest in recruiting and selecting appropriate personnel;
  • compliance with employment, immigration, tax, equality or other legal obligations; and
  • consent where we ask to retain an application for future opportunities and consent is the appropriate basis.

Submission of an application does not guarantee an interview, offer, employment relationship or future contact.

7.4 Sending newsletters and marketing communications

We may process contact and preference information to send:

  • newsletters;
  • company announcements;
  • event invitations;
  • product or project updates;
  • business-development communications; and
  • other communications concerning Smart Ideal World.

We send electronic marketing only where:

  • you have provided valid consent;
  • an existing customer exception or similar legal permission applies; or
  • another lawful basis permits the communication under applicable law.

You may unsubscribe at any time.

7.5 Operating and securing the website

We process technical and security information to:

  • deliver website content;
  • maintain website availability;
  • detect and prevent unauthorized access;
  • protect forms and communication channels;
  • identify errors;
  • troubleshoot technical problems;
  • manage infrastructure;
  • prevent fraud and misuse;
  • maintain security logs;
  • investigate incidents; and
  • protect our systems, users and business.

The applicable legal bases are generally:

  • our legitimate interest in operating and protecting the website and our information systems; and
  • compliance with legal obligations concerning information security and personal-data protection.

7.6 Managing cookies and privacy choices

We process consent and preference information to:

  • record your cookie choices;
  • implement your preferences;
  • demonstrate compliance;
  • prevent non-essential cookies from being activated without the required consent; and
  • allow you to withdraw or modify consent.

The applicable legal bases are:

  • compliance with legal obligations;
  • our legitimate interest in documenting compliance; and
  • consent for any non-essential cookie or similar technology requiring consent.

7.7 Improving website performance and communications

Where legally permitted, we may process aggregated, statistical or limited usage information to:

  • understand website performance;
  • improve website structure;
  • identify broken pages;
  • improve communications;
  • understand general audience interest; and
  • make the website more useful.

Where this processing requires non-essential cookies or similar tracking technologies, it will be based on consent.

Basic operational analysis derived from essential server logs may be based on our legitimate interests in maintaining and improving the website.

7.8 Compliance, investigations and legal claims

We may process personal data to:

  • comply with applicable laws;
  • respond to lawful requests;
  • cooperate with courts, regulators and public authorities;
  • conduct internal investigations;
  • enforce our rights;
  • prevent unlawful conduct;
  • establish, exercise or defend legal claims;
  • obtain legal advice; and
  • comply with record-keeping obligations.

The applicable legal bases are generally:

  • compliance with a legal obligation; and
  • our legitimate interest in protecting our legal and business interests.

7.9 Corporate transactions

Personal data may be processed where reasonably necessary in connection with:

  • financing;
  • investment;
  • restructuring;
  • merger;
  • acquisition;
  • sale of assets;
  • reorganization;
  • insolvency; or
  • another corporate transaction.

The applicable legal bases are generally:

  • our legitimate interests in evaluating and completing a legitimate corporate transaction;
  • compliance with legal obligations; and
  • performance of contractual or pre-contractual measures.

Appropriate confidentiality and data-protection safeguards will be used.


8. Our Legitimate Interests

Where we rely on legitimate interests, those interests may include:

  • operating and protecting the website;
  • communicating with website visitors and business contacts;
  • responding to inquiries;
  • evaluating prospective commercial relationships;
  • managing existing business relationships;
  • recruiting suitable personnel;
  • maintaining appropriate records;
  • improving website functionality;
  • preventing fraud and misuse;
  • maintaining network and information security;
  • protecting our rights and property; and
  • establishing, exercising or defending legal claims.

Before relying on legitimate interests, we consider:

  • the purpose of the processing;
  • whether the processing is necessary;
  • the nature of the information;
  • the relationship between you and Smart Ideal World;
  • your reasonable expectations;
  • the potential effect on your rights and freedoms; and
  • the safeguards available to reduce privacy risks.

You may object to processing based on legitimate interests as explained in Section 16.


9. When Providing Information Is Required

Certain information may be required in order for us to:

  • respond to your request;
  • evaluate a proposal;
  • communicate with you;
  • consider an application;
  • take steps toward a contract; or
  • comply with a legal obligation.

Required form fields should be clearly identified.

Where required information is not provided, we may be unable to respond, process an application, consider a proposal or provide the requested communication.

You are responsible for ensuring that information you submit is accurate and that you are authorized to provide any information relating to another person.


10. Cookies and Similar Technologies

10.1 Strictly necessary technologies

The website may use strictly necessary cookies or similar technologies required to:

  • provide core website functionality;
  • transmit communications;
  • maintain security;
  • prevent misuse;
  • remember privacy choices;
  • operate forms; and
  • manage cookie consent.

Strictly necessary technologies do not require consent where they are genuinely necessary to provide the website or a service requested by the user.

10.2 Non-essential cookies

Preference, analytics, advertising, retargeting or behavioural-tracking cookies will not be activated unless:

  • they are actually used by the website;
  • they are accurately identified in the Cookie Notice and consent interface; and
  • valid prior consent has been obtained where required by law.

At the date of this Privacy Policy, Smart Ideal World does not intend to activate analytics, advertising or behavioural-profiling cookies unless they are expressly disclosed in the current Cookie Notice and made subject to the required consent controls.

10.3 Cookie choices

Where non-essential cookies are available, you must be provided with a genuine choice to:

  • accept them;
  • reject them;
  • select individual categories; and
  • later withdraw or change your consent.

Rejecting non-essential cookies should be as accessible as accepting them.

10.4 Browser controls

You may also control cookies through your browser settings. Blocking strictly necessary cookies may prevent parts of the website from functioning correctly.

10.5 Cookie Notice

Current information concerning the cookies and similar technologies actually used by the website, including their providers, purposes and durations, should be provided in the separate Cookie Notice and consent-management interface.

The Cookie Notice, consent banner and actual website configuration must remain consistent with each other.


11. Newsletters and Marketing Communications

Where you subscribe to a newsletter or another marketing communication, we may use your contact information to send the communications you requested.

Every electronic marketing communication should provide a clear and accessible way to unsubscribe.

You may withdraw your consent or object to marketing at any time by:

Withdrawal of consent does not affect the lawfulness of processing performed before consent was withdrawn.

After you unsubscribe, we may retain a limited suppression record containing information such as your email address and opt-out date. This is used only to ensure that your preference is respected and to demonstrate compliance.

Transactional, legal, security or direct responses to a request are not marketing communications and may still be sent where necessary.


12. Disclosure and Sharing of Personal Data

We do not sell personal data.

We also do not disclose personal data for cross-context behavioural advertising or similar targeted-advertising purposes unless this is expressly disclosed and the applicable legal requirements have been satisfied.

We may disclose personal data to the following categories of recipients where necessary and lawful.

12.1 Website and technology providers

This may include providers supporting:

  • website hosting;
  • domain and DNS services;
  • content-delivery networks;
  • website administration;
  • form processing;
  • cloud infrastructure;
  • backup and recovery;
  • information security;
  • spam and bot prevention;
  • error monitoring;
  • development and technical maintenance; and
  • consent management.

12.2 Communications providers

This may include providers supporting:

  • business email;
  • contact-form delivery;
  • newsletters;
  • meeting scheduling;
  • video conferencing;
  • customer or business relationship management; and
  • other business communications.

12.3 Recruitment providers

This may include:

  • recruitment platforms;
  • applicant-tracking systems;
  • recruitment agencies;
  • assessment providers;
  • background-screening providers, where lawful;
  • interview providers; and
  • secure document-storage providers.

12.4 Professional advisers

We may disclose relevant information to:

  • lawyers;
  • accountants;
  • auditors;
  • insurers;
  • financial advisers;
  • tax advisers;
  • compliance advisers; and
  • other professional advisers bound by appropriate duties of confidentiality.

12.5 Public authorities and legal recipients

We may disclose personal data to:

  • courts;
  • law-enforcement authorities;
  • regulatory authorities;
  • tax authorities;
  • data-protection authorities;
  • government departments; and
  • other parties where disclosure is required or permitted by law.

12.6 Corporate transaction recipients

Information may be disclosed under appropriate confidentiality and security obligations to potential:

  • investors;
  • lenders;
  • purchasers;
  • sellers;
  • merger partners;
  • corporate advisers; or
  • transaction counterparties.

12.7 Referrals requested by you

Where you ask us to refer or direct your inquiry to a separate company, organization, product operator or business partner, we may share the information reasonably necessary to fulfil that request.

Where the recipient is a separate controller, its own privacy notice will apply to its subsequent processing.

12.8 Service-provider requirements

Service providers processing personal data on our behalf must, where required:

  • act only on documented instructions;
  • process personal data only for authorized purposes;
  • maintain confidentiality;
  • implement appropriate security measures;
  • assist with applicable data-protection obligations;
  • impose equivalent requirements on authorized subprocessors;
  • notify us of relevant security incidents;
  • return or delete personal data when the service ends, subject to lawful retention; and
  • provide information reasonably necessary to demonstrate compliance.

13. International Data Transfers

Smart Ideal World is established in Portugal, but its business operations, service providers and authorized support resources may operate internationally.

As a result, personal data may be:

  • stored outside Portugal;
  • processed outside Portugal;
  • accessed remotely from another country; or
  • transferred to a service provider located outside the European Economic Area, or “EEA.”

For clarity, an international transfer may occur where a separate service provider, contractor or other recipient outside the EEA is permitted to access personal data remotely, even if the primary server storing the information is located within the EEA.

Some countries outside the EEA may not provide a level of personal-data protection considered equivalent to that available within the EEA.

Where personal data is transferred outside the EEA, Smart Ideal World will use an appropriate legal transfer mechanism as required by applicable law.

Depending on the recipient and destination, this may include:

13.1 Adequacy decisions

We may transfer personal data to a country, territory, sector or organization recognized by the European Commission as providing an adequate level of protection.

13.2 Standard Contractual Clauses

Where no adequacy decision applies, we may use the European Commission’s approved Standard Contractual Clauses.

Where required, we will also:

  • evaluate the circumstances of the transfer;
  • assess relevant local laws and practices;
  • implement supplementary contractual, technical or organizational safeguards; and
  • periodically review the continued appropriateness of the transfer.

13.3 EU–US Data Privacy Framework

For transfers to an eligible recipient in the United States, we may rely on the EU–US Data Privacy Framework where:

  • the recipient maintains an active certification;
  • the certification covers the relevant recipient and type of personal data; and
  • reliance on the framework is legally available at the time of the transfer.

We will not rely on a provider’s general claim of participation without verifying the applicable certification status and scope.

13.4 Other permitted safeguards

Where appropriate, we may rely on another transfer mechanism permitted by applicable law, such as:

  • binding corporate rules;
  • an approved code of conduct;
  • an approved certification mechanism; or
  • another legally recognized safeguard.

A legal derogation for a specific situation will be used only where permitted and appropriate and not as the ordinary mechanism for systematic transfers.

13.5 Information about safeguards

You may request information about the safeguards applicable to a transfer by contacting:

privacy@smartidealworld.com

Copies of contractual safeguards may be subject to reasonable redactions necessary to protect confidential, commercially sensitive or security-related information.


14. Data Retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including the need to comply with legal, accounting, regulatory, contractual or reporting requirements.

We consider:

  • the nature and sensitivity of the information;
  • the amount of information;
  • the purposes of processing;
  • the relationship with the individual;
  • security risks;
  • applicable legal requirements;
  • limitation periods;
  • the need to resolve disputes; and
  • whether the purpose can be achieved through aggregated or anonymized information.

Our general retention periods are as follows.

14.1 General contact and inquiry information

Contact forms, general inquiries and related correspondence that do not result in an ongoing business relationship may be retained for up to three years after the last substantive communication.

Information may be retained longer where reasonably necessary for a legal claim, investigation or legal obligation.

14.2 Business-development and partnership information

Information concerning a prospective partnership, investment, commercial project or enterprise relationship may be retained:

  • while the matter remains active; and
  • for up to three years after the last substantive communication where no contractual relationship results.

Where a contractual or formal business relationship is established, relevant records may be retained for the duration of the relationship and applicable legal or limitation periods.

14.3 Contractual, tax and accounting records

Records required for contractual, accounting, tax or legal purposes may be retained for up to ten years, or for another period required under applicable law.

14.4 Newsletter and marketing information

Active newsletter and marketing-subscription information may be retained until:

  • you unsubscribe;
  • you withdraw consent;
  • you successfully object to the processing; or
  • the communication program is discontinued.

Where appropriate, inactive marketing records may be reviewed after 24 months without meaningful engagement.

A limited suppression record may be retained for up to five years after an opt-out, or longer where necessary to continue honoring the opt-out or demonstrate compliance.

14.5 Recruitment information

Information submitted for a specific role may generally be retained for up to 12 months after the recruitment process closes, unless:

  • a shorter period is required;
  • a longer period is required for a legal claim or legal obligation; or
  • you are hired, in which case relevant information becomes part of the applicable personnel record.

Where you provide valid consent for us to consider you for future opportunities, relevant application information may be retained for up to 24 months, after which renewed permission should be obtained or the information deleted.

14.6 Technical and security logs

Routine website and security logs may generally be retained for up to 90 days.

Relevant logs may be retained longer where they are required to:

  • investigate a security incident;
  • prevent recurring misuse;
  • comply with a legal obligation;
  • cooperate with authorities; or
  • establish, exercise or defend a legal claim.

14.7 Cookie-consent records

Cookie and consent-preference records may generally be retained for up to 24 months, subject to:

  • earlier withdrawal;
  • changes to the technologies or purposes;
  • the need to refresh consent; or
  • a shorter period required by law or regulatory guidance.

14.8 Legal disputes and investigations

Information relevant to an actual or reasonably anticipated dispute, investigation or legal claim may be retained until:

  • the matter is finally resolved;
  • applicable appeal periods expire; and
  • the relevant legal limitation or record-keeping periods expire.

14.9 Deletion and anonymization

At the end of the applicable retention period, personal data will be:

  • securely deleted;
  • anonymized so that it can no longer identify an individual; or
  • isolated and restricted where deletion must be delayed for legal, technical or security reasons.

Backup copies may remain for a limited period until they are securely overwritten through the normal backup cycle. Access to backup data will remain restricted.


15. Data Security

We implement technical and organizational measures designed to protect personal data against:

  • unauthorized or unlawful processing;
  • accidental loss;
  • destruction;
  • damage;
  • unauthorized access;
  • unauthorized disclosure;
  • alteration; and
  • misuse.

Depending on the circumstances, these measures may include:

  • role-based access controls;
  • least-privilege access;
  • authentication controls;
  • multi-factor authentication;
  • encryption in transit;
  • encryption at rest where appropriate;
  • secure hosting configurations;
  • logging and monitoring;
  • backup and recovery controls;
  • vulnerability management;
  • malware protection;
  • network security;
  • personnel confidentiality obligations;
  • provider due diligence;
  • data-processing agreements;
  • incident-response procedures;
  • access reviews; and
  • restrictions on production-system access.

Access to personal data should be limited to persons who require it for an authorized business purpose.

No website, online service, storage environment or electronic transmission can be guaranteed to be completely secure. While we take reasonable steps to protect personal data, we cannot guarantee absolute security.

You should not send highly sensitive or confidential information through an ordinary contact form or unencrypted email unless specifically instructed to do so.


16. Your Privacy Rights

Depending on the circumstances and applicable law, you may have the following rights.

16.1 Right of access

You may request confirmation as to whether we process your personal data and obtain access to the relevant information.

16.2 Right to rectification

You may request correction of inaccurate personal data and completion of incomplete information.

16.3 Right to erasure

You may request deletion of personal data in circumstances provided by law.

The right to erasure is not absolute. We may retain information where processing remains necessary for:

  • compliance with a legal obligation;
  • the establishment, exercise or defense of legal claims;
  • protection of another person’s rights;
  • public-interest grounds; or
  • another lawful purpose permitting continued retention.

16.4 Right to restriction

You may request that processing be restricted in circumstances provided by law.

16.5 Right to data portability

Where processing is based on consent or contract and performed by automated means, you may have the right to receive personal data you provided in a structured, commonly used and machine-readable format and to request transmission to another controller where technically feasible.

16.6 Right to object

You may object to processing based on legitimate interests.

Where you object, we will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is required for the establishment, exercise or defense of legal claims.

16.7 Right to object to direct marketing

You have the right to object to direct marketing at any time.

Where you object to direct marketing, your personal data will no longer be processed for that purpose.

16.8 Right to withdraw consent

Where processing is based on consent, you may withdraw consent at any time.

Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

16.9 Rights concerning automated decision-making

You may have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects you, subject to applicable exceptions.

16.10 Right to complain

You have the right to lodge a complaint with a competent data-protection authority.

You may complain to the authority in:

  • the country of your habitual residence;
  • the country of your place of work;
  • the country where the alleged infringement occurred; or
  • Portugal, where Smart Ideal World is established.

17. How to Exercise Your Rights

To exercise a privacy right, contact:

privacy@smartidealworld.com

Your request should clearly explain:

  • your identity;
  • your relationship with Smart Ideal World;
  • the right you wish to exercise; and
  • the information or processing concerned.

We may request additional information reasonably necessary to verify your identity and protect personal data against unauthorized disclosure.

We will not request more identity information than reasonably necessary.

We will respond without undue delay and generally within one month after receiving a valid request.

Where permitted by law, that period may be extended by up to two additional months due to the complexity or number of requests. We will inform you of any extension and the reason for it.

Rights are generally exercised without charge. Where a request is manifestly unfounded or excessive, particularly because it is repetitive, we may:

  • charge a reasonable fee reflecting the administrative cost; or
  • refuse to act on the request,

as permitted by applicable law.


18. Automated Decision-Making and Profiling

The Smart Ideal World corporate website is not intended to make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals.

We may use basic automation to:

  • route inquiries;
  • filter spam;
  • detect malicious activity;
  • manage communication preferences;
  • organize applications; or
  • support website security.

Such operational automation is not intended to make a legally or similarly significant decision about you without appropriate human involvement.

If we introduce automated decision-making that is legally significant, we will provide additional information concerning:

  • the existence of the processing;
  • meaningful information about the logic involved;
  • the significance and expected consequences;
  • the applicable legal basis; and
  • the rights and safeguards available.

19. Children’s Privacy

The Smart Ideal World corporate website is intended for adult business visitors, professionals, employment candidates and other individuals capable of making business or professional inquiries.

It is not directed to children under the age of 18.

We do not knowingly request or collect personal data from children through the corporate website.

If you believe that a child has submitted personal data to us, contact:

privacy@smartidealworld.com

We will review the matter and delete or otherwise address the information where appropriate.


20. Third-Party Websites and Services

The Smart Ideal World website may contain links to:

  • product websites;
  • portfolio brands;
  • partner websites;
  • social-media platforms;
  • professional-networking services;
  • event platforms;
  • external publications;
  • recruitment platforms; or
  • other third-party websites and services.

A link does not necessarily mean that Smart Ideal World controls the third party or its personal-data processing.

Third parties may act as independent controllers and apply their own privacy notices, cookie policies and legal terms.

You should review the applicable privacy information before providing personal data to a third-party service.

Smart Ideal World is not responsible for the privacy or security practices of an independent third party, except to the extent responsibility cannot lawfully be excluded.


21. Social-Media Pages

Smart Ideal World may maintain pages or accounts on social-media and professional-networking platforms.

When you interact with those pages:

  • the platform may process your information for its own purposes;
  • the platform may provide us with aggregated or identifiable interaction information;
  • Smart Ideal World may process your message, comment or inquiry to communicate with you; and
  • the platform’s own privacy terms will apply to its processing.

Depending on the platform and activity, Smart Ideal World and the platform may act as separate controllers or, for certain statistical page functions, joint controllers as determined by applicable law.

You should use the privacy settings provided by the relevant platform and review its privacy notice.


22. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in:

  • our website;
  • business operations;
  • communication channels;
  • service providers;
  • processing activities;
  • security practices;
  • international transfers;
  • legal requirements; or
  • regulatory guidance.

When this Privacy Policy is updated, we will revise the “Last updated” date and version number.

Where a change is material, we may provide additional notice through:

  • a prominent website notice;
  • the cookie or consent interface;
  • direct communication; or
  • another appropriate method.

Previous versions may be retained for compliance, audit and record-keeping purposes.


23. Contact Information

Questions, concerns and privacy requests may be directed to:

Smart Ideal World
Privacy email: privacy@smartidealworld.com


24. Portuguese Data-Protection Authority

You have the right to lodge a complaint with the Portuguese supervisory authority:

Comissão Nacional de Proteção de Dados — CNPD
Av. D. Carlos I, 134, 1.º
1200-651 Lisboa
Portugal

General email: geral@cnpd.pt
Telephone: +351 213 928 400

We encourage you to contact Smart Ideal World first so that we have an opportunity to review and address your concern. This does not affect your right to contact the CNPD or another competent supervisory authority directly.