1. Introduction
This Privacy Policy explains how Lusoliv, Lda (“Lusoliv”, “we”, “our”, “us”) collects, uses, discloses, and protects personal data of Clients, Providers, applicants, and visitors to lusoliv.com and the Lusoliv Platform (the “Platform”). It has been prepared in accordance with Regulation (EU) 2016/679 (“GDPR”), Portuguese Law no. 58/2019 of 8 August, Law no. 41/2004 of 18 August (ePrivacy) and its implementing regulations, and applicable guidance from the Comissão Nacional de Proteção de Dados (“CNPD”) and the European Data Protection Board.
2. Data Controller
Corporate name: Lusoliv, Lda
NIPC: 518900940
Registered office: Rua Hermano Neves 18, Piso 3, Escritório 7, 1600-477 Lisboa, Portugal
Contact for privacy matters: contact@lusoliv.com
Lusoliv is not currently required to appoint a Data Protection Officer under Article 37 GDPR. Should this obligation become applicable, the DPO’s contact details will be published on this page and notified to the CNPD.
3. Scope
This Policy applies to personal data processed in the context of:
Clients — natural persons booking, or intending to book, services through the Platform.
Providers — natural persons applying to become, and active, service providers on the Platform.
Visitors — persons visiting lusoliv.com without registering.
Correspondents — third parties communicating with Lusoliv via email, WhatsApp, or other channels for business purposes.
4. Categories of Personal Data Processed
4.1 Client Data
Identification and contact: name, email address, mobile telephone/WhatsApp number.
Service address and any additional access information provided at Booking.
Booking data: history of Bookings, preferences, service notes, ratings issued.
Payment data: processed by the payment processor (Stripe); Lusoliv receives only limited transaction confirmation data and does not store full card details.
Optional tax identification number (NIF), where the Client chooses to provide it for invoicing.
Communications with customer support, including transcripts and metadata.
4.2 Provider Data — Application Stage
Identification and contact: name, email, WhatsApp number, general location.
Professional information: service categories offered, areas of Lisbon covered, prior experience, self-declared rate expectations, references.
Application form responses, including transport/means of movement and equipment.
Note on data minimisation at application stage: Sensitive documents (identity document, criminal record certificate, NIF proof, bank details) are deliberately NOT collected at application stage. They are requested only after an intro call, once the applicant has been shortlisted, to reduce risk exposure both for applicants and for Lusoliv.
4.3 Provider Data — Onboarding and Active Stage
Identity document (Cartão de Cidadão or equivalent) — for identity verification and DSA trader traceability requirements.
Criminal record certificate (registo criminal).
Tax identification number (NIF) and, where applicable, activity code (CAE).
Bank account or payment account details, via the payment processor’s onboarding flow.
Profile photo, service description, and self-declared skills.
Job history, ratings received, earnings data, and performance metrics.
4.4 Visitor and Analytics Data
Technical data: IP address (truncated or hashed where possible), device and browser type, operating system, referring URL.
Usage data: pages visited, interaction events, session duration.
This data is processed only with the User’s consent (via the cookie banner) or where strictly necessary to provide the service requested.
5. Purposes of Processing and Legal Basis
Personal data is processed for the following purposes and on the following legal bases:
5.1 Performance of a Contract (Article 6(1)(b) GDPR)
Creation and management of the User’s account.
Facilitation of Bookings, including matching Clients with Providers, communication of Booking details, and payment processing.
Issuance and delivery of invoices.
Provision of customer support in relation to Bookings.
5.2 Legal Obligation (Article 6(1)(c) GDPR)
Retention of accounting, tax, and invoicing records under the Portuguese General Tax Law (retention period generally 10 years).
Provision of information to public authorities where legally required (tax, judicial, Digital Services Act supervisory bodies including ANACOM).
Trader identification and traceability under Article 30 of Regulation (EU) 2022/2065 (DSA) and Law no. 12-A/2026 of 15 April.
Compliance with anti-money-laundering, consumer protection, and fair trading obligations.
5.3 Legitimate Interest (Article 6(1)(f) GDPR)
Vetting of Providers to ensure the safety and reliability of the Platform, balanced against the reasonable expectations of applicants.
Fraud prevention, security monitoring, and enforcement of the Terms of Use.
Product analytics and improvement of the Platform, using aggregated or pseudonymised data where possible.
Direct communication to existing Users about relevant service updates.
5.4 Consent (Article 6(1)(a) GDPR)
Non-essential cookies and similar tracking technologies.
Optional marketing communications (email newsletter, promotional messages).
Any voluntary collection of data outside the strict need to operate the service.
Consent may be withdrawn at any time, without effect on the lawfulness of processing carried out before withdrawal, by clicking the unsubscribe link in marketing communications or by contacting us at contact@lusoliv.com.
6. Recipients of Personal Data
Personal data is shared, strictly to the extent necessary, with the following categories of recipients:
6.1 Data Processors (Subprocessors)
Stripe Payments Europe, Limited (Ireland) — payment processing.
Sharetribe Oy (Finland) — marketplace platform infrastructure.
InvoiceXpress (Portugal) — certified electronic invoicing under AT (Autoridade Tributária) certification.
Make.com — workflow automation between operational tools.
Brevo (Sendinblue SAS, France) — transactional and marketing email.
Microsoft Corporation — Microsoft 365 email and productivity.
PostHog Inc. — product analytics.
Airtable, Inc. — provider pipeline management.
Tally — application forms.
Google LLC — where used for authentication or productivity.
Each processor is bound by a Data Processing Agreement (or equivalent contractual clauses) in compliance with Article 28 GDPR.
6.2 Business Counterparts
Matched Providers receive the Client’s name, address, contact number, and Booking details as necessary to perform the service.
Matched Clients receive the Provider’s name, contact number, profile information, and ratings.
6.3 Professional Advisors
Lusoliv’s certified accountant and legal counsel, bound by professional secrecy.
6.4 Public Authorities
Personal data may be disclosed to competent tax, judicial, or regulatory authorities where required by law, including under the Digital Services Act framework (Articles 9 and 10 DSA).
7. International Transfers
Where processors are located outside the European Economic Area, transfers are made only where one of the following safeguards applies: (i) an adequacy decision of the European Commission; (ii) Standard Contractual Clauses adopted by the European Commission; (iii) any other lawful transfer mechanism under Chapter V of the GDPR. In particular, transfers to processors established in the United States rely on the EU–US Data Privacy Framework, where applicable, or on Standard Contractual Clauses.
A list of active subprocessors and their location is maintained by Lusoliv and available on request to contact@lusoliv.com.
8. Retention Periods
Client account and Booking data: for the duration of the account plus the statutory retention period under Portuguese tax law (currently 10 years for invoicing and accounting records) for records with tax relevance.
Provider active records, including onboarding documents: for the duration of the engagement plus the statutory retention period thereafter.
Unsuccessful Provider applications: 90 days after final decision, unless the applicant expressly requests to remain in consideration for future roles, in which case retention is extended by up to 12 months.
Marketing consent records: until consent is withdrawn.
Support communications: 3 years from the date of last interaction.
Analytics cookies data: as set out in the Cookie Policy (typically no more than 13 months).
Data collected under the Livro de Reclamações Eletrónico: 3 years, in accordance with Decree-Law no. 74/2017.
9. Data Subject Rights
Under the GDPR, data subjects have the following rights:
Right of access (Article 15).
Right to rectification (Article 16).
Right to erasure (“right to be forgotten”) (Article 17).
Right to restriction of processing (Article 18).
Right to data portability (Article 20).
Right to object to processing based on legitimate interest, including profiling, and in particular the right to object to direct marketing at any time (Article 21).
Right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Article 22). Lusoliv does not currently make such decisions.
To exercise any of these rights, contact us at contact@lusoliv.com. Lusoliv will respond within one month of receipt, extendable by two further months where necessary given the complexity or volume of requests.
Data subjects also have the right to lodge a complaint with the Comissão Nacional de Proteção de Dados (CNPD) — www.cnpd.pt — or, where the data subject is habitually resident in another EU Member State, with the supervisory authority of that Member State.
10. Security Measures
Lusoliv applies appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage, including:
Encryption of data in transit (TLS) and, where technically appropriate, at rest.
Access controls with least-privilege principles.
Multi-factor authentication on administrative accounts.
Regular review of processor security posture and Data Processing Agreements.
Logging of access to sensitive information.
Documented incident response procedures.
Users are responsible for keeping their own login credentials confidential and for notifying Lusoliv of any suspected compromise of their account.
11. Data Breach Notification
Where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons, Lusoliv will notify the CNPD within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk, the affected data subjects will also be notified without undue delay.
12. Special Provisions
12.1 Minors
The Platform is not directed at persons under 18. Lusoliv does not knowingly process the personal data of minors. If we become aware that we have collected personal data from a minor without appropriate parental consent, we will delete that data promptly.
12.2 Sensitive Categories
Lusoliv does not intentionally collect special categories of personal data (Article 9 GDPR) except for the criminal record certificate collected from Providers at the onboarding stage, which is processed only under Article 10 GDPR read with Article 18(2) of Portuguese Law no. 58/2019, on the basis of the legitimate interest in ensuring the safety of Clients receiving services in their homes and only for as long as strictly necessary.
13. Cookies
The use of cookies and similar technologies is described in the Cookie Policy, available at /legal/cookies.
14. Amendments
This Privacy Policy may be updated from time to time. Material changes will be notified to registered Users by email or Platform notice at least 15 days before taking effect. The date at the top of this Policy indicates the version currently in force.
15. Contact
Lusoliv, Lda
Rua Hermano Neves 18, Piso 3, Escritório 7, 1600-477 Lisboa, Portugal
contact@lusoliv.com
