Praça
Política de Privacidade
Versão 2 · publicada a 2 de setembro de 2026
Privacy policy
This policy explains how personal data is handled on A Praça, who is answerable for that handling in each case, and what rights the people concerned have.
1. Who is answerable for the processing
Two distinct roles exist side by side on A Praça, and the difference matters when you need to know whom to approach.
A Praça is the controller for the data of those who use the platform as a service: agency user accounts, authentication, activity and security logs, billing and support.
The agencies are the controllers for the data of their own clients, owners, investors and contacts, including data contained in the material they deposit. For that data, A Praça acts as processor, handling it on the agency's behalf and on its instructions, under a separate contract.
In practice: if you are an owner or an investor and you want to exercise your rights, you can approach the agency you deal with, or approach us — we will pass it on.
2. Who this applies to
- Agency users — those who access the platform on behalf of an agency.
- Owners — those given read access to their own property.
- Investors and other external contacts — those who access shared information or contact us.
- Third parties identified in documents — people whose data appears in documents deposited by the agencies, such as land registry or tax records.
- Licence holders who are natural persons — the sole trader holding the estate agency licence under which an agency subscribes to the platform.
3. What data we handle
From agency users: name, email address and profile photograph, obtained at sign-in; the role held on the platform; telephone number, if the messaging channel is enabled; and records of activity carried out.
From deposited material: files, messages and text about properties, received by email, message or direct upload. This material may contain personal data of third parties.
From owners: email address, provided by the agency representing the property, and activity within the access granted.
From investors and external contacts: usage data from presentations, acceptance of the access terms, and technical data such as the IP address, including data collected by mapping services.
From the agency's identification: the estate agency licence number (AMI), the corporate taxpayer number where the public register states one, and the name as it appears in that register, obtained by consulting the public register of the IMPIC; and the record of each consultation, with its outcome, who carried it out and when. Where the licence holder is a sole trader, that name is the name of a natural person and the register states no corporate taxpayer number: in that case these elements are personal data of the holder, and we are the controller of that processing.
From those who send material: the originating email address or telephone number, kept as an irreversible cryptographic digest, which allows the material to be matched to the corresponding profile without keeping the contact details in clear text.
4. Purposes and legal bases
| Purpose | Basis |
|---|---|
| Operating the platform, authenticating and controlling access | Performance of a contract |
| Receiving, organising and analysing opportunities | Legitimate interest of the responsible agency |
| Producing suggestions and drafts with the support of artificial intelligence systems | Legitimate interest |
| Recording activity for evidential purposes between agencies | Legitimate interest — see clause 7 |
| Presenting information to owners and investors | Performance of a contract or pre-contractual steps |
| Measuring interest in presentations | Legitimate interest |
| Verifying that a subscriber holds a valid estate agency licence | Legal obligation and legitimate interest |
| Complying with legal obligations | Legal obligation |
We do not sell personal data and we do not use it for advertising.
5. Who we share with
We use processors who handle data on our behalf, under contract:
- Cloudflare — hosting and storage.
- Microsoft — sign-in.
- Google — maps.
- Resend — sending email.
- Anthropic — content analysis by the platform's assistant, under a zero-retention arrangement: the content is neither kept nor used to train models.
- Meta — sending and receiving messages, when that channel is enabled.
Some of these providers are established outside the European Economic Area. In those cases the transfers rely on standard contractual clauses or an equivalent mechanism.
Information deposited by one agency is accessible to other agencies under the applicable circulation rules. That disclosure is a transfer between independent controllers, and it is for the agency making it to ensure it has a basis for doing so and to inform the individuals concerned.
6. How long we keep it
| Data | Period |
|---|---|
| User account and deposited material | For as long as the agency's subscription lasts, plus the delivery window set out in the Terms of Use |
| Event register | 5 years after the subscription ends |
| History of matches between requests and opportunities | 90 days |
| Message de-duplication records | 7 days |
| Temporary access codes | 2 days after expiry |
| Terms acceptances | For as long as it remains necessary to demonstrate the consent given |
| Agency identification and the record of licence checks | For as long as the subscription lasts, plus 5 years |
Once these periods end, the data is deleted or anonymised.
7. The event register and the right to erasure
The platform keeps a chained register of the actions carried out on it. Its purpose is to make it possible to demonstrate, between agencies, who deposited what and when. That register underpins contractual rules on precedence and attribution.
The register holds no personal data in the content that guarantees its integrity. Who carried out each action is identified by an internal reference, and the personal data associated with that reference sits outside the chain that guarantees integrity.
The practical consequence: exercising the right to erasure anonymises the personal data without affecting the integrity of the register. What remains is the reference, which no longer allows the person to be identified.
8. Third-party data in documents
Anyone depositing documents containing personal data of third parties — for example, owners identified in a land registry record — declares that they have a basis for doing so. That data is treated as confidential and access to it is restricted to what is necessary.
9. Your rights
You have the right to access your data, to correct it, to ask for it to be erased, to restrict or object to its processing, and to data portability.
To exercise any of these rights you can contact us at privacidade@pt-investments.com, or approach the agency you deal with, according to the division of roles described in clause 1.
You also have the right to lodge a complaint with the supervisory authority. In Portugal, this is the Comissão Nacional de Proteção de Dados.
10. Security
We apply appropriate technical and organisational measures: separation between each agency's data, private and encrypted storage of sensitive material, signed document links with a limited lifetime, encrypted retention of originating identifiers, and logging of access carried out by A Praça's staff.
11. Cookies
We use technical cookies to keep your session open and for the authentication process. In presentations we measure usage on the server side, without cookies. Maps provided by Google are loaded only at the request of whoever is viewing the presentation. We do not use non-essential cookies — see the Cookie Policy.
12. Identification and contact
The controller, as set out in clause 1, is ARESTA PROFÍCUA - UNIPESSOAL LDA, company number 518456722, with its registered office at Rua da Aldeia Nova, n.º 551, Madalena, 4405-723 Vila Nova de Gaia, Portugal.
Contact for privacy matters and the exercise of rights: privacidade@pt-investments.com.
13. Changes
This policy is versioned. We publish the version in force together with its date.