Privacy Policy
Last updated: March 2026
Data Controller
Zlar is the data controller for personal data processed through this platform. For data protection inquiries, contact us at privacy@zlar.pt.
Data We Collect
We collect the following categories of personal data:
- Identity data: name, email address
- Tax identification: NIF/tax ID numbers
- Financial data: IBANs, payment records, expense records
- Contact data: phone numbers, postal addresses
- Technical data: IP addresses, user agent strings (for security and audit logging)
- Usage data: session information, error reports (anonymized)
Lawful Basis for Processing
- Contract performance (Art. 6(1)(b)): User account management, condominium management features
- Legal obligation (Art. 6(1)(c)): Tax records retention (10 years), condominium law compliance, meeting minutes retention (5 years)
- Legitimate interest (Art. 6(1)(f)): Error monitoring (anonymized), security logging, audit trails
- Consent (Art. 6(1)(a)): Session replay recordings, analytics
Data Retention
- User accounts: duration of relationship + 30 days
- Financial records: 10 years (Portuguese tax law)
- Meeting minutes: 5 years (condominium regulation)
- Contracts and ownerships: duration + 5 years
- Audit logs: 10 years
Third-Party Processors
We use the following third-party service providers to process your data, each with signed Data Processing Agreements:
- Cloudflare (hosting, database, file storage) — EU data centers
- Stripe (billing and payment processing)
- Salt Edge (open banking integration)
- Sentry (error monitoring — anonymized, EU data region)
Your Rights
Under GDPR and Lei 58/2019, you have the following rights:
- Right of access — request a copy of your personal data
- Right to rectification — correct inaccurate data
- Right to erasure — request deletion of your data (subject to legal retention obligations)
- Right to data portability — receive your data in a machine-readable format
- Right to restrict processing
- Right to object to processing based on legitimate interest
To exercise any of these rights, go to Settings > Privacy in your account, or contact us at privacy@zlar.pt. We will respond within 30 days.
Supervisory Authority
You have the right to lodge a complaint with the Portuguese Data Protection Authority (CNPD): Comissão Nacional de Proteção de Dados, Rua de S. Bento 148-3, 1200-821 Lisboa, Portugal. Email: geral@cnpd.pt