Last updated: April 25, 2026
The data controller for your personal data is:
Kortilink
Website: kortilink.com
Email: privacidade@kortilink.com
Headquarters: Lisbon, Portugal
By using our services, you accept the practices described in this Privacy Policy.
We process your personal data for the following purposes and legal bases under the GDPR (General Data Protection Regulation — EU 2016/679):
We use cookies and similar technologies to ensure the correct functioning of the platform, remember your preferences and analyse service usage. See our Cookie Policy for detailed information.
You can manage your cookie preferences at any time in your browser settings or through our consent management tool.
We may share your data with the following third parties, who act as subprocessors:
We use Google OAuth for optional authentication. Google may process data according to its own privacy policy. Learn more at policies.google.com/privacy.
We offer Facebook login as an authentication alternative. Meta processes data according to its privacy policy at facebook.com/privacy/policy.
Payments are processed by Stripe, Inc. We do not store credit card data. Stripe is PCI-DSS Level 1 certified. See their policy at stripe.com/privacy.
We may use cloud infrastructure providers (such as Supabase/Firebase), CDN and transactional email services (such as SendGrid). All providers are contractually obligated to protect your data and process only strictly necessary data.
We do not sell your personal data to third parties for marketing purposes.
We retain your personal data only for as long as necessary for the described purposes:
As a data subject residing in the EU/EEA, you have the following rights:
To exercise any of these rights, contact us at privacidade@kortilink.com. We will respond within 30 days.
You also have the right to lodge a complaint with the competent supervisory authority — in Portugal, the CNPD (National Data Protection Commission): www.cnpd.pt.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure or destruction. These measures include:
In the event of a data breach that may affect your rights, we will notify the competent authorities within 72 hours and inform you if the risk is high.
We may update this Privacy Policy periodically. When we do, we will change the "last updated" date at the top of the page. For significant changes, we will notify users by email or through a prominent notice on the platform.
We recommend that you review this policy regularly to stay informed about how we protect your data.
For privacy-related questions, data protection, or to exercise your rights:
Kortilink — Data Protection Officer
Email: privacidade@kortilink.com
General support: suporte@kortilink.com
Headquarters: Lisbon, Portugal