Privacy Policy

Effective Date: November 18, 2025 · Version 2.1

1. Data Controller Information

1.1 Primary Data Controller

Contact Information:

1.2 Brokerage Services Data Management

We are a company duly incorporated and registered in Portugal, operating as a licensed real estate brokerage under License Number 25990 issued by the Instituto dos Mercados Públicos, do Imobiliário e da Construção (IMPIC).

1.3 Third-Party Data Controller

Managed by Lightspark Payments Europe AS

2. Scope and Applicability

2.1 Covered Services

This Privacy Policy applies to:

2.2 Geographic Scope

This Policy applies to personal data processing for users in the European Union, European Economic Area, and worldwide, in accordance with:

Performance of Contract (Article 6(1)(b))

Legal Obligation (Article 6(1)(c))

Legitimate Interests (Article 6(1)(f))

Consent (Article 6(1)(a))

4. Categories of Personal Data Collected

4.1 Identity and Contact Information

4.2 Financial and Transaction Data

4.3 Technical and Usage Data

4.4 Communication Data

5. Purposes of Processing

5.1 Primary Service Purposes

5.3 Business Operations

6. Data Sharing and Recipients

6.1 Essential Service Providers

Lightspark Payments Europe AS (Data Controller)

Data verification provider (Data Processor by third-party contractor)

6.2 Other Service Providers (Data Processors)

6.3 Business Transfer Recipients

In case of merger, acquisition, or asset sale, personal data may be transferred to successors with equivalent privacy protections.

7. International Transfers

7.1 Within EU/EEA

Primary data processing occurs within the EU/EEA: Portugal (Caenhebo operations), Estonia (Lightspark services), Ireland (cloud infrastructure), Germany (support services).

7.2 Transfers Outside EU/EEA

United States: cloud service providers and analytics providers, protected by Standard Contractual Clauses (SCCs) and adequacy decisions; data types limited to technical and usage data (pseudonymized). Other Third Countries: only with adequate protection measures (SCCs, Binding Corporate Rules, adequacy decisions).

7.3 Transfer Safeguards

All international transfers are protected by EU Commission adequacy decisions, 2021 Standard Contractual Clauses, or approved codes of conduct/certification mechanisms.

8. Data Retention

8.1 General Retention Periods

Active Account Data:

Closed Account Data:

8.3 Data Deletion

After retention periods expire: secure deletion of all personal data, anonymization for statistical purposes only. Exception: legal proceedings or regulatory requirements may extend retention.

9. Your Data Protection Rights

9.1 Core GDPR Rights

9.2 Exercising Your Rights

10. Automated Decision-Making and Profiling

10.1 Automated Processing Activities

10.2 Your Rights Regarding Automated Decisions

You may request human review of automated decisions, express your point of view, and contest the decision and request reconsideration.

11. Cookies and Tracking Technologies

This Privacy Policy is complemented by our full Cookie Policy. Cookie categories: strictly necessary (legitimate interests, cannot be disabled), performance/analytics (consent), functional (consent), and marketing/advertising (consent). A cookie banner provides clear consent options on first visit, with granular control in a settings panel. Do Not Track signals are respected where technically feasible.

12. Data Security Measures

12.1 Technical Safeguards

12.2 Organizational Safeguards

12.3 Incident Response

24/7 security monitoring, defined incident-response procedures, forensic investigation capabilities. Breach notification: CNPD within 72 hours of awareness; affected users without undue delay if high risk.

13. Data Processing

The platform collects directly the following information: government-issued ID, address, phone number, email, bank account details, tax identification number.

14. Children's Privacy

Minimum age requirement: 18 years. Minors will not be able to perform transactions on the Caenhebo platform, aligned with Portuguese law.

15. Marketing Communications

15.1 Types of Communications

Service updates, transaction notifications, promotional content, and newsletter.

Service communications rely on legitimate interests; marketing communications require explicit consent; newsletter requires separate consent.

15.3 Opt-Out Rights

Unsubscribe links in all marketing emails, global communication preferences in account settings, or email request to privacy@caenhebo.com. Opt-out processed within 48 hours.

16. Privacy by Design and Default

Principles applied: proactive not reactive; privacy as the default; full functionality; end-to-end security; visibility and transparency; respect for user privacy. Implemented via data minimization, purpose limitation, storage limitation, technical measures (encryption, access controls, monitoring) and organizational measures (training, policies, procedures).

17. Data Protection Impact Assessments

DPIAs are required for high-risk processing, automated decision-making with significant effects, systematic monitoring, new technologies, and biometric processing. The DPIA process covers scope definition, risk assessment, mitigation measures, stakeholder consultation, authority consultation (CNPD) if high residual risk, and regular review.

18. Supervisory Authority Information

Comissão Nacional de Proteção de Dados (CNPD)

You may lodge complaints, request investigations, and seek remedies including compensation. Other relevant authorities: the European Data Protection Board (EDPB) and the Estonian Data Protection Inspectorate (for Lightspark-related issues).

19. Changes to This Privacy Policy

Annual review, legal assessment, DPO approval, and 30-day advance notice for material changes (email, platform notice, account dashboard). Material changes include new data categories, new purposes, new recipients, reduced rights, or new technologies.

20. Contact Information

Data Protection Officer

Other Privacy Contacts: General Privacy privacy@caenhebo.com · Security Incidents security@caenhebo.com (24/7 monitoring) · Customer Support support@caenhebo.com · Legal Notices legal@caenhebo.com

21. Final Provisions

The authoritative version of this policy is English; a Portuguese translation is available upon request, and in case of conflict the English version prevails. This Privacy Policy is complementary to the Terms and Conditions, Cookie Policy, Security Policy, and Lightspark's Privacy Policy. If any provision is found invalid or unenforceable, the remaining provisions continue in full force and effect.


By using our Platform, you acknowledge that you have read, understood, and agree to the collection, use, and disclosure of your information as described in this Privacy Policy.