Legal
Privacy Policy
This Policy explains how Monolitica collects, uses, shares and protects personal data when you visit the site or engage our AI adoption consulting services. Prepared under the GDPR (Regulation (EU) 2016/679) and Law No. 58/2019 (Portugal's GDPR implementing law).
Last updated: 24 August 2026
1.
Who is responsible for the processing
MONOLÍTICA, LDA (Monolitica), Portuguese company registration number (NIPC) 519544323, registered office at Rua do Sol Nascente, 26, 4.º Direito, 4450-588 Leça da Palmeira, Matosinhos, Portugal. General contact: [email protected]. Data protection contact: [email protected].
2.
What data we collect
Website visitors
Browsing and interaction data (anonymised IP, user-agent, pages visited, referrer, contact clicks and completed bookings), measured in aggregate and without cookies through Vercel Web Analytics; where consent is given, technical and interaction data processed by Google, Meta or LinkedIn for analytics, attribution and advertising; identification and contact data sent by email (name, email, organisation, message); and meeting-booking data (name, email, chosen time slot) processed on Cal.com, accessed from the site via an external link. By following that link, Cal.com receives the visitor's IP address and user-agent, as is standard for any HTTP request. Optional tags and embedded content remain blocked until the applicable choice. See the Cookie Policy.
Clients
Invoicing data (name, tax number, address), contact data of the project's interlocutors and content shared as part of the diagnosis and mapping, workshops, pilots, training and knowledge transfer (processes, documents and technical access required for the project).
Data processed on behalf of clients (subprocessing)
Within the scope of a project, Monolitica may have access to personal data contained in the client's processes, systems or databases (for example, data about residents, employees or service users), to the extent necessary for the diagnosis and implementation of the contracted systems and automations. In these cases, Monolitica acts as a processor under Article 28 GDPR; the client is the controller and the specific rules are set out in the Data Processing Agreement (DPA).
3.
Purposes and legal bases
- Providing and managing the consulting services, performance of contract (Article 6(1)(b) GDPR).
- Invoicing and tax obligations, legal obligation (Article 6(1)(c) GDPR).
- Commercial communications to clients and professional contacts, legitimate interests (Article 6(1)(f) GDPR), with a standing right to object.
- Responding to contact requests and preparing proposals, pre-contractual steps taken at the data subject's request (Article 6(1)(b) GDPR) and legitimate interests (Article 6(1)(f) GDPR).
- Scheduling meetings (Cal.com), accessed via an external link from the site (Article 6(1)(b) GDPR - pre-contractual steps), processed under the terms of the Cookie Policy. Website analytics (Vercel Web Analytics) does not require consent, as it does not use cookies.
- Security, fraud prevention and audit, legitimate interests (Article 6(1)(f) GDPR).
- Optional analytics, attribution and advertising, only with consent (Article 6(1)(a) GDPR), which can be withdrawn at any time through cookie preferences.
4.
AI systems developed within projects
Monolitica designs and implements intelligent agents, automations, dashboards, integrations and internal systems tailored to each client. When a delivered system interacts directly with people (for example, residents or employees of the client), it is the client's responsibility, as the operator of that system, to inform those people that they are communicating with an AI system, in line with Article 50 of the AI Act (Regulation (EU) 2024/1689), applicable from 2 August 2026. Monolitica supports its clients in defining these safeguards during the project.
When a system developed by Monolitica makes or supports decisions based on profiling, with legal or similarly significant effects on people, the safeguards of Article 22 GDPR apply (the right to human intervention, to contest the decision and to express one's point of view), to be ensured by the client as controller. For questions about a specific system, contact [email protected].
5.
Subprocessors and international transfers
Monolitica relies on technology providers to operate the site and, depending on the scope of each project, to design and implement the systems contracted by clients. The current, named list, with the country of processing and transfer mechanism, is published at /sub-processadores. It may include, depending on the case:
- Language model providers (for example, OpenAI, Anthropic, Mistral or Google), when a project involves building intelligent agents or automations for the client. When based outside the EU, transfers rely on Standard Contractual Clauses (SCCs) under Decision (EU) 2021/914 and/or adherence to the Data Privacy Framework (EU-US DPF), depending on the provider.
- Hosting providers and cloud infrastructure, for the institutional website and for systems developed on cloud infrastructure managed by Monolitica: Vercel, Railway and Neon, in European Union regions. Projects may also run on the client's cloud or on-premise.
- Internal project management and communication tools, for tracking work and contacting the client: Google Workspace, with the Europe data region.
Contracted providers are not authorised to use client data or data subjects' data to train their own models, except under a written agreement to the contrary.
Contact forms,
scheduling and website analytics
To manage contact requests, schedule meetings and measure site usage in aggregate, we rely on the following providers:
- Tally BV(Belgium, EU), for the site's contact forms. Monolitica is the controller for the submitted data (name, email, organisation, message) and Tally acts as processor under Article 28 GDPR. Data is encrypted in transit and at rest and stored in the EU (Google Cloud, Belgium region), with no international transfer. See privacy policy/GDPR and data processing agreement.
- Cal.com, Inc. (2261 Market Street #4382, San Francisco, CA 94114, USA), for scheduling meetings. Monolitica is the controller for the booking data (name, email, chosen time slot) and Cal.com acts as processor. Scheduling is accessed via an external link to cal.com (see the Cookie Policy) and involves an international transfer of data to the USA. The applicable transfer mechanism (Standard Contractual Clauses and/or the EU-US Data Privacy Framework) is the one indicated in Cal.com's privacy policy, which can also be contacted at [email protected] for EU data residency. See privacy policy and security.
- Vercel Web Analytics, provided by Vercel Inc. (USA), the same company that hosts the site, to measure aggregate site usage. It is a cookie-free tool, with no persistent identifiers and no cross-site tracking, so it does not require consent. See the Cookie Policy. We also use Google Search Console to track the site's performance in search results; it does not install any script on the site nor collect data from visitors.
- Google Ireland, Meta Platforms Ireland and LinkedIn Ireland, when configured and authorised, for analytics, campaign measurement, attribution, optimisation and remarketing. These providers may receive IP address, user-agent, URL, cookie identifiers and interaction data. Processing relies on consent and may involve international transfers under each provider's policies.
6.
Retention periods
Contractual and invoicing data: retained for the applicable statutory limitation period (10 years for tax purposes, Article 123 of the CIVA (the Portuguese VAT Code) and Article 123 of the CIRC (the Portuguese Corporate Income Tax Code)). Marketing data - until the right to object is exercised. Data processed on behalf of clients within a project: retention periods set out in each project's DPA, by default deleted or anonymised within 90 days of the contract's completion or termination, and exportable in structured format on request within the following 30 days.
7.
Data subject rights
You have the right to access, rectify, erase, restrict, port and object to the processing of your data, as well as the right to withdraw consent when this is the legal basis. Requests are processed within 30 days. Contact [email protected]. You may also lodge a complaint with the Comissão Nacional de Proteção de Dados (CNPD, the Portuguese data protection authority) (cnpd.pt).
8.
Security
We implement appropriate technical and organisational measures - encryption in transit and at rest, least-privilege access control, environment segregation, audit logs, monitoring, an incident response plan and notification to the CNPD within 72 hours of becoming aware of a breach (Article 33 GDPR).
9.
Changes
This Policy may be updated. Material changes are communicated with 30 days' advance notice by email to active clients and flagged at the top of this page.