Privacy Policy
Last updated: June 2026
This Privacy Policy describes how Portal, Lda ("Company", "we", "us", or "our") collects, uses, and shares your personal information when you use Faturado ("Service"). This policy is compliant with the General Data Protection Regulation (GDPR) and Portuguese data protection law.
Important for Hosted MCP pilots
- We store provider credentials encrypted and use them only to provide the connections you configure.
- AI clients receive read-only provider data according to grants you authorize. They do not receive your provider credentials.
- Customer email and tax identifiers are processed transiently where possible and stored as hashes or provider identifiers when retained.
- You can revoke provider credentials, grants, and OAuth access where supported by the Service.
1. Data Controller
Portal, Lda is the data controller for personal data collected through the Service. You can contact us at:
- Email: [email protected]
- Address: Lisbon, Portugal
2. Information We Collect
2.1 Information You Provide
- Account Information: Email address, name, business name when you create an account
- Billing Information: Payment details processed through Stripe (we do not store full card numbers)
- Integration Credentials: API keys and OAuth tokens for TOConline and InvoiceXpress, provider account identifiers, and credential metadata needed to maintain the connection (stored encrypted)
- Hosted MCP Configuration: Client company labels, provider selections, OAuth grants, grant revocation status, and MCP setup preferences
- Support Communications: Messages you send to our support team
2.2 Information Collected Automatically
- Transaction Data: Payment details received from Stripe webhooks, such as amount, currency, payment status, and provider document references. Raw customer email and tax identifiers are processed transiently where possible and retained as hashes or provider identifiers.
- Provider Data: Read-only provider records returned by TOConline or InvoiceXpress when you use Hosted MCP, including document status, customer references, company references, and accounting metadata
- Usage Data: Features used, pages visited, actions taken within the Service
- Technical Data: IP address, browser type, device information, operating system
- Cookies: See our Cookie Policy
2.3 Information from Third Parties
- Stripe: Transaction details, customer information associated with payments
- TOConline/InvoiceXpress: Invoice status, document IDs, company records, customer references, and provider metadata needed to provide the Service
- Connected AI Clients: OAuth authorization state and read-only requests made by AI clients that you connect to Hosted MCP
3. How We Use Your Information
We use your information for the following purposes:
- Service Delivery: Creating invoices, processing transactions, sending emails, and providing Hosted MCP read-only access to authorized AI clients
- Account Management: Authentication, account recovery, subscription management, credential validation, credential refresh, grant management, and revocation
- Communication: Service updates, security alerts, support responses
- Analytics: Understanding usage patterns, improving the Service
- Legal Compliance: Tax reporting, legal obligations, fraud prevention, audit trails, security monitoring
4. Legal Basis for Processing
We process your data based on:
- Contract Performance: Necessary to provide the Service you requested
- Legitimate Interests: Analytics, service improvement, fraud prevention
- Legal Obligation: Tax and accounting requirements
- Consent: Marketing communications (where applicable)
5. Data Sharing
We share your information with:
- Service Providers: Hosting (cloud infrastructure), email delivery, analytics
- Integration Partners: Stripe, TOConline, InvoiceXpress as configured by you
- Connected AI Clients: Read-only provider data shared with AI clients you authorize through Hosted MCP, limited by grants configured in the Service
- Legal Authorities: When required by law or legal process
We do not sell your personal data to third parties. We do not share Provider Credentials with Connected AI Clients.
6. International Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA). When this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions.
7. Data Retention
We retain your data for:
- Account Data: Duration of your account plus 90 days
- Transaction and Invoice Data: Up to 10 years where required for Portuguese accounting and tax retention. GDPR deletion requests may anonymize or restrict personal identifiers while preserving legally required financial records.
- Provider Credentials and Grants: Until revoked, replaced, expired, or no longer needed to provide the Service
- Usage Logs: 12 months
- Support Communications: 3 years
8. Your Rights (GDPR)
Under GDPR, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data (subject to legal retention requirements)
- Restriction: Request limitation of processing
- Portability: Receive your data in a machine-readable format
- Objection: Object to processing based on legitimate interests
- Withdraw Consent: Where processing is based on consent
To exercise these rights, contact us at [email protected]. We will respond within 30 days.
9. Data Security
We implement appropriate security measures including:
- Encryption of data in transit (TLS) and at rest
- Secure credential storage using encrypted credential envelopes for provider secrets
- Access controls and authentication
- Read-only Hosted MCP allowlists and grant enforcement
- OAuth revocation and provider credential revocation controls
- Rate limiting and abuse monitoring
- Regular security assessments
- Audit logging of sensitive operations
10. Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. The "Last updated" date at the top indicates when the policy was last revised.
12. Complaints
If you have concerns about our data practices, please contact us first. You also have the right to lodge a complaint with the Portuguese Data Protection Authority (Comissao Nacional de Proteccao de Dados - CNPD).
13. Contact
For privacy-related inquiries:
Email: [email protected]