Privacy Policy

This document provides an overview of how the Ideias Dinâmicas Group processes the personal data in its possession, in accordance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council — the General Data Protection Regulation (GDPR) — and other applicable legislation regarding privacy and data protection, including local legislation that supplements the GDPR.

Whenever personal data is required, the use of such data is described in accordance with this document and in compliance with data protection laws.
The Privacy Policy of the Ideias Dinâmicas Group, hereinafter referred to simply as the Group, outlines key information regarding the data collected, the purposes for which it is collected, and how data subjects may access it, among other matters.

1) The Ideias Dinâmicas Group

The Ideias Dinâmicas Group comprises a network of internationally oriented companies dedicated to providing services across various business sectors.

It is made up of teams with recognized expertise in their respective fields, evaluating new business opportunities and creating conditions for various entrepreneurs to develop and formalize their ideas and projects. It provides solid platforms for launching new business ventures, considering the degree of innovation as a differentiating factor.

The Group consists of the following companies:
In Portugal: ITGest – Software and Information Systems, Lda.; Kentra Technologies, Lda.; Ideias Dinâmicas Services, Lda.; Ideias Dinâmicas, Lda.; Ideias Dinâmicas Consulting, Lda.; Ideias Dinâmicas Real Estate Investments, Lda.; Pedaços D’Casa – Construction and Renovation, Lda.; Wise ID, Lda.; ITGest IS – Infrastructure and Security, Lda.; Bee2Solutions, Lda.; Bee2Fire, Lda.; ProdFarmer, Lda.; House & House Real Estate Investments, Lda.; Invest Seguro, Lda.; and Compta Emerging Communications, Lda.
In Angola: ITGest, Lda.; Ideias Dinâmicas Serviços, Lda.; ICA – Internacional Consulting & Accounting, S.A.; Think Tank – Marketing, Communication, and Design, Lda.; TT – Nova Architecture & Interior Design; Kentra Tecnologias, Lda.; and Ideias Dinâmicas Tecnologias, Lda.
In Mozambique: ITGest Moçambique, Lda.; Ideias Dinâmicas Investimentos Moçambique, Lda.; and Invest Prime, Lda.
In Spain: ITGest España, Lda.
In Cape Verde: ITGest – Software e Sistemas, Lda.
In Mauritius: ITGest, Lda.

2) Scope of Application

The Group is committed to protecting the privacy and personal data of its Employees, Customers, Website Users, and Service Providers and, in this context, has drafted this Privacy Policy to demonstrate its commitment to and respect for privacy and personal data protection rules.

3) Definitions

Personal Data 1 – any information related to the Data Subject that allows for the Data Subject’s identification.

Data Subject – any identified or identifiable natural person to whom the Personal Data relates. The natural person may be identifiable or identified, directly or indirectly, including through their name, civil or tax identification number, location data, or online identifiers (such as IP addresses and logs). Identification may also be based on physical, physiological, genetic, mental, economic, cultural, or social factors. Users of the website, applications, and digital platforms are considered Data Subjects in relation to the Group.

Processing – any operation performed on Personal Data, whether by automated means or not, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction. Any other operation provided for under the GDPR is also considered Processing of Personal Data.


[1]Personal data includes: racial or ethnic origin; political opinions; religious beliefs; philosophical beliefs; trade union membership; genetic data; biometric data used to uniquely identify a person; and health-related data.

4) Responsible Entity and Responsibilities

The Group has established an internal “Personal Data Protection Committee,” which is responsible for ensuring compliance with and adaptation to the provisions of the GDPR.

This Committee consists of the Data Protection Officer from each Group company, representatives from the Information Technology Department, representatives from the Legal Department, as well as representatives from the Human Resources Department and the Organization and Quality Department.

You may contact the Committee regarding any matter related to this privacy policy via:

  • Email address: dpd@ideiasdinamicas.com or—using the contact information listed below (from 9:00 a.m. to 12:00 p.m. and from 2:00 p.m. to 6:00 p.m.):
  • Mailing Address: Grupo Ideias Dinâmicas
    Personal Data Protection Committee
    Rua Álvaro Castelões, 821 – 2nd Floor, Room 2.2
    4450-043 Matosinhos
  • Phone: 229 398 320

5) Data Collection and Processing

The Group collects only the data deemed essential and processes it as necessary depending on the purpose.

The collection of your data, including personal data, occurs during interactions with the Group, specifically:

  • Contacts;
  • General requests for information;
  • Downloading of documentation;
  • Commercial processes;
  • Sales processes;
  • Customer management processes;
  • Accounting, tax, and administrative management;
  • Compliance with legal and regulatory obligations;
  • Litigation management;
  • Human resources management processes;
  • Marketing and event management (in-person and/or online);
    Information security controls;
  • Information security controls;
  • Other data contained in documentation provided to the company or obtained as a result of the established relationship.

Depending on the nature of the interaction, and only when necessary, the Group may request certain personal data, such as: name, email address, mailing address/city, telephone number, cell phone number, national ID/passport number, tax identification number (in both physical and digital formats), date of birth, nationality, marital status, educational qualifications, profession, bank account information, and, in general, any documentation and information regarding contacts with the customer through various channels, including marketing campaigns.

Data processing for marketing purposes will be carried out in accordance with the consent option selected by the data subject. Consent must be prior, freely given, informed, specific, and unambiguous, and must be expressed in a written or oral statement or by selecting an option. The data subject may object to the processing of data for marketing purposes at any time and by any means.

Optionally, the data subject may authorize the collection of additional data that may assist the Group in providing better and more personalized customer service or services.

6) Purpose of Personal Data Processing

Personal data provided by the data subject or generated in connection with the service provided will be processed and stored electronically for use by the Group.

The Group collects and processes only the data that is strictly necessary, which is requested only when relevant to the purpose at hand and for legitimate purposes, such as:

  • Providing an appropriate and targeted response to requests for information or proposals;
  • Communicating more effectively with data subjects regarding relevant matters and only as frequently as necessary, based on the nature of their data and their preferences;
  • Fulfilling business purposes, specifically, using statistical data to improve the performance of the various services provided;
  • Fulfilling human resources management requirements;
  • Complying with legal or regulatory requirements, upon which the validity of certificates for certain services provided depends, namely training programs;
  • Billing for services/products.

Personal data is processed by the Group only for as long as necessary to fulfill the specified purpose.

The Group collects and processes only the data that is strictly necessary, which is requested only when relevant to the purpose in question, and for legitimate purposes, such as:

– Human Resources Management

This includes the data processing necessary for the conclusion, fulfillment, and termination of an employment contract; management of work hours, absences, and vacation time; processing of salaries and other benefits; dealings with tax authorities and Social Security; promotions and career development; training; performance evaluations; business entertainment expenses; communication with employees; and the exercise of disciplinary authority.

– Internal and Business Management

This includes activities such as project planning, recording of working hours, management of company assets, provision of centralized services to increase operational efficiency, conducting audits and investigations, implementation of management controls, use of internal databases, records management, insurance, prevention, and conflict preparation and management.

– Occupational Safety, Hygiene, and Health

Includes activities related to occupational safety, hygiene, and health; the protection of employees and company assets; employee authentication; and access management.

– Analysis and Management

This includes activities such as satisfaction surveys, managing mergers, acquisitions, and sales of business units, and processing employee data for reporting and analysis purposes.

– Compliance with Legal Obligations

This includes the processing of personal data strictly necessary to comply with legal obligations, such as the disclosure of data in response to court orders, cooperation with regulators, and the protection of the Group’s legitimate interests.

– Protection of Vital Interests

The processing of personal data to protect employees’ vital interests.

– Recruitment

This includes recruitment activities such as search and selection, as well as related activities. In this context, data related to payroll processing and human resources management will also be processed.

– Contract Execution

This includes activities such as entering into contracts with clients and partners, as well as communicating with third parties involved in the contracts (insurance companies, beneficiaries, intermediaries).

– Service Development and Improvement

This includes activities necessary for the development and improvement of the services provided by the Group, as well as analysis of operations and processing for statistical and scientific purposes.

7) Automated Decision-Making

To establish and carry out the business relationship, the Group generally does not use decision-making procedures based solely on automated processing, as provided for in the GDPR. Should the Group currently use or come to use this procedure, data subjects will be informed.

8) Access to and Sharing of Personal Data

Within the Group, access to data is granted to employees who need it to fulfill contractual, pre-contractual, or legal obligations, or for processing for which explicit and informed consent has been given.

The data may be used by Group companies in the context of providing shared services among Group companies and for internal reporting purposes, always upholding the principle of lawful processing.

They may also be made available to suppliers and other subcontractors who, under the GDPR, may access the data for these specific purposes, but subject to data protection safeguards and always acting on behalf of and for the Group.

Under certain circumstances, certain personal data may need to be disclosed to public authorities, such as the Labor Conditions Authority, the Health Regulatory Authority, the courts, and law enforcement agencies.

Data transfers to other countries (countries outside the European Union) occur only if the data subject has given express consent for this purpose or if such a transfer is required by law. If it is necessary to engage service providers from third countries, they will be required to comply with written instructions on this matter to ensure compliance with the level of data protection applicable in the European Union.

Whenever applicable, the transfer of health data must, in addition to complying with the established contractual clauses, ensure confidentiality and compliance with applicable requirements, particularly regarding HDS (Hébergement de Données de Santé). If health data is transferred to other countries (countries outside the European Union), this will be disclosed via this link.

9) Data Retention Period

Personal data is retained for varying periods of time, depending on the purpose for which it is intended and taking into account legal criteria, the principle of necessity, and the principle of data minimization, or for the periods legally defined for criminal investigations and legal proceedings or for medico-legal purposes.

Once the retention period has ended, personal data is destroyed.

10) Rights of Data Subjects

The Group guarantees all rights of data subjects regarding the processing of their data at any time. Specifically:

  • Lawfulness of processing and conditions applicable to consent (Art. 6 and Art. 7)
  • Data subject’s right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to object (Article 21)
  • Right to data portability (Article 20)

In addition, without prejudice to the possibility of filing a complaint with the Group, the data subject may file a complaint directly with the Data Protection Supervisory Authority using the following channels:

  • Phone: +351 21 392 84 00
  • Website: http://www.cnpd.pt/
  • Mail: Comissão Nacional de Proteção de Dados – CNPD Ava D. Carlos I, 134 – 1o 1200-651 Lisboa

At any time, the Group’s customers or potential customers, as data subjects, may withdraw any consent previously given and exercise any of the rights mentioned above.

Requests to exercise these rights may be submitted via:

  • Email address: dpd@ideiasdinamicas.com;
  • Mailing address: Grupo Ideias Dinâmicas
    Personal Data Protection Commission
    Rua Álvaro Castelões, 821 – 2nd floor, room 2.2
    4450-043 Matosinhos
    Phone: 229 398 320

11) Obligation to Provide Personal Data

Within the scope of the business relationship, you must provide the personal data necessary to establish and create a business relationship and to fulfill the resulting pre-contractual and contractual obligations and procedures, as well as any data that the Group is legally required to collect. Without this data, the Group will generally have to refuse to enter into the contract or will be unable to maintain the contract and will have to terminate it.

12) Security of Personal Data

The Group protects your personal data against destruction, loss, accidental or unlawful alteration, and unauthorized disclosure or access. To this end, the Group employs security systems, rules, and other procedures to ensure the protection of personal data, as well as to prevent unauthorized access to the data, misuse, disclosure, loss, or destruction.

13) Changes to the Privacy Policy

The Group may amend this Privacy Policy at any time and without prior notice. In accordance with established practices, this policy is reviewed at least once a year.

Changes will be duly published (on the website).

When a change to the Privacy Policy has a substantial impact on processing carried out based on your consent, the Group will contact the data subjects or, if individual contact proves impractical, make every effort to clarify this change to obtain new consent.

14) Cookies

We use cookies to improve your experience on this website. We use session cookies and third-party cookies. Session tokens serve to improve the website’s functionality, and third-party cookies enable social media features and traffic analytics.

Third-Party Cookies:

– Facebook;
– Linkedin;
– Google Analytics;

You can always delete these cookies in your browser settings. To learn more about how these companies handle privacy, please visit their respective websites.