Skip to content
Joselita Azevedo · Advanced aesthetics

Privacy Policy

Last updated: 20/08/2026

Courtesy translation. The Portuguese version prevails.

1. Data controller

This policy applies to the website joselitaazevedo.pt, operated by:

Controller
Joselita Azevedo — Empresário em Nome Individual
Tax number (NIF)
258585617
Registered address
R. Giovanni Antinori loja B, 1300-670 Lisboa, Portugal
Email
joselitaazevedo.instituto@gmail.com
Phone
+351923335946

For any question about your personal data, contact us at joselitaazevedo.instituto@gmail.com.

2. What data we collect and why

DataPurposeLegal basis
Name, phone, emailManaging and confirming bookingsPerformance of a contract (Art. 6(1)(b) GDPR)
Booking and service historyDelivering the service and client historyPerformance of a contract
Booking notes (free text)Preferences you provide for the servicePerformance of a contract
WhatsApp / Instagram messagesAnswering requests and arranging bookingsContract / consent
Messages you write to the website assistantUnderstanding your request and booking, changing or cancelling visitsPerformance of a contract
Record of your acceptance of the Terms and the Privacy PolicyDemonstrating that we met our legal information dutiesLegal obligation (Art. 5(2) GDPR)
Session and authentication data (essential cookies)Keeping your session and securityNecessary for the service / legitimate interest

We do not currently use analytics or marketing cookies, nor do we send marketing communications. We do not collect special categories of data (e.g. health data): allergies, medication, pregnancy or skin conditions are discussed with you in person, before the treatment, and are not recorded on the site — so please do not include sensitive information in the booking notes field.

3. How long we keep data

  • Booking and client data: for the duration of the relationship and up to 10 years after the last interaction, unless a longer legal retention applies.
  • Billing data: for the applicable statutory tax period (generally 10 years).
  • Session data: expires at the end of the session or per the technical lifetime of the cookie.

4. Who we share data with

We use processors acting on our behalf, in particular:

  • Supabase — hosting of the bookings database and authentication.
  • Hostinger — website hosting.
  • Resend — sending transactional emails (booking confirmations and reminders).
  • Anthropic — interpreting the messages you write to the website assistant. What you type is sent to this provider to be understood; when you ask to see or change a visit, the list of your bookings is sent along with it. We never send them your name, email, phone number or password.
  • Meta Platforms — when you contact us via WhatsApp or Instagram.

We do not sell your personal data.

5. International transfers

Some providers may process data outside the EEA. Specifically, the messages you write to the website assistant are processed by Anthropic, based in the United States of America. Where that happens, we ensure appropriate safeguards (EU Standard Contractual Clauses or adequacy decisions).

6. Your rights

You have the right to access, rectify, erase, restrict and object to processing, to data portability, and to withdraw consent at any time. Three of those you can exercise yourself, immediately, from your account:

  • Access and portability — under “My account → Privacy”, “Download my data” gives you a file with your profile, every visit you have booked, and your consent records.
  • Rectification — you can correct your name, email and phone under “My account → Profile”.
  • Erasure — “Delete my account” immediately removes your login and the data that identifies you. If you have an upcoming visit, cancel it first.

What remains after you delete your account: because we are legally required to keep billing records, the record that a service took place stays, but with nothing that identifies you — no name, no email, no phone number (Art. 17(3)(b) GDPR). Any notes the team wrote about you, and the notes you wrote on your own bookings, are deleted.

For the remaining rights — including asking for a full copy that also covers the team's internal notes — contact joselitaazevedo.instituto@gmail.com. We respond within one month.

You also have the right to lodge a complaint with the supervisory authority: Comissão Nacional de Proteção de Dados (CNPD) — https://www.cnpd.pt.

7. Security

We apply technical and organisational measures to protect your data, including role-based access control (Row Level Security) and encrypted communications.

8. Alternative Dispute Resolution

In a consumer dispute, you may turn to an alternative dispute resolution entity. The competent entity is: Centro de Arbitragem de Conflitos de Consumo de Lisboa (CACCL) (https://www.centroarbitragemlisboa.pt). More information at www.consumidor.gov.pt.

9. Complaints Book

We provide a Complaints Book in physical and electronic format. You may file a complaint at www.livroreclamacoes.pt.