Privacy Policy
Last updated: 2026-08-04
This policy describes how ComunicaPro handles personal data under the GDPR. The service processes deeds containing third-party personal data (buyers, sellers) on behalf of the user agencies — which act as controllers; ComunicaPro acts as a processor (art. 28 GDPR).
1. Data processed
Account data: email and authentication identifier (email link or Google).
Documents: the deed PDF uploaded by the user and the data extracted from it (names, NIF, identification documents, values, IBAN, properties).
Records: filing history, corrections made during review and the audit log (who, when, what the AI extracted vs. what was corrected).
2. Purpose and minimisation
Data is processed exclusively to prepare the user's own mandatory IMPIC filing. It is not used for model training, advertising or any other purpose.
3. Retention
The deed PDF is automatically deleted after the retention period (7 days by default). The final XML and the audit log remain in the account while it exists, as proof and history of the filings made.
The email subscribed to the deadline reminders is kept until you unsubscribe: every reminder includes a one-click cancellation link with immediate effect.
4. Sub-processors
Cloudflare (hosting and temporary encrypted PDF storage), Supabase (database and authentication, EU region), Anthropic (automatic extraction of the deed content — documents sent via API are not used for model training) Stripe (payments) and Brevo (authentication emails, notices and deadline reminders, EU region).
For site measurement and outreach: Google (Google Analytics 4), New Relic (error and performance monitoring) and Meta Platforms Ireland (Meta Pixel and Conversions API). ⚠️ In this phase Meta is engaged for every visitor, without prior consent (see §7).
5. Security
Encryption in transit (TLS) and at rest, per-account data isolation at the database level, access control and audit logging. We never request Cartão de Cidadão, Chave Móvel Digital or digital certificates.
6. Data-subject rights
Access, rectification, erasure, restriction and portability: via [email protected]. Business customers may request our Data Processing Agreement (DPA).
7. Cookies and similar technologies
Necessary (always on): the Supabase authentication session, plus the browser local-storage keys comunicapro-consent (your cookie decision), comunicapro-theme (light/dark) and locale (language). The site does not work without these.
Analytics (on by default): Google Analytics 4 (_ga, _ga_*, up to 2 years) and the New Relic agent, to measure usage and detect errors. We run Google Consent Mode with the advertising signals denied, so this data does not feed personalised advertising.
Marketing (active without prior consent): the Meta Pixel and the _fbp and _fbc identifiers (up to 90 days), plus the server-side Conversions API. ⚠️ In this phase we show no cookie banner and no in-site way to refuse: the pixel runs and events are sent to Meta for every visitor, from the browser and from our server, on the basis of our legitimate interest in measuring our campaigns. You can block them in your browser settings or object using the contacts listed on the site.
If we return to requiring consent, this section automatically says so and the “Cookie settings” control reappears in the footer.