Privacy Policy
Last updated: January 2026
1. Data Controller
The controller responsible for processing your personal data is DKRIOL, LDA, with NIF 294698590, registered in São Vicente, Cabo Verde, reachable by email at info@dkriol.com.
2. Data Collected
We collect the following data when you use our contact forms or request a quote:
- Full name
- Email address
- Phone number (optional)
- Message or project description
- Company or organisation (optional)
We also collect anonymous browsing data via Google Analytics (see section 6).
3. Purpose of Processing
Your data is used exclusively to:
- Respond to your enquiries and quote requests
- Deliver the contracted services
- Send commercial communications, if you have given your consent
- Comply with legal and contractual obligations
4. Legal Basis
Processing of your data is based on:
- Consent: by submitting a form, you consent to the processing of your data to respond to your request.
- Contractual performance: when you engage our services, processing is necessary to perform the contract.
- Legitimate interest: for the purpose of improving our services and communicating with existing clients.
5. Data Sharing
We do not sell, transfer or share your personal data with third parties, except in the following cases:
- Technology service providers supporting website operations (e.g. servers, email), bound by confidentiality obligations
- When required by law or court order
6. Cookies and Data Analytics
We use Google Analytics to collect anonymous browsing data (pages visited, session time, traffic source). This data does not allow your personal identification. See our Cookie Policy for more details.
7. Data Retention
Your data is retained only for as long as necessary to fulfil the described purposes or applicable legal obligations:
- Contact requests not converted into a service: 12 months
- Active client data: for the duration of the contract and 5 years after its end
- Billing data: 10 years (legal obligation)
8. Your Rights
Under applicable legislation, you have the right to:
- Access: know what data we hold about you
- Rectification: correct inaccurate data
- Erasure: request deletion of your data
- Objection: object to processing for marketing purposes
- Portability: receive your data in a structured format
To exercise any of these rights, contact us at info@dkriol.com. We respond within 30 days.
9. Security
We adopt appropriate technical and organisational measures to protect your data against unauthorised access, alteration, disclosure or destruction. Our website uses HTTPS protocol with an SSL certificate.
10. Changes to This Policy
We may update this policy periodically. When we do, we will update the date at the top of this page. We recommend that you review this policy regularly.
11. Contact
For any questions related to the privacy of your data, please contact us:
info@dkriol.com · DKRIOL, LDA · NIF 294698590 · São Vicente, Cabo Verde
Annex I — DKRIOL Mail: Email Service Specific Data
When you subscribe to our professional email service (DKRIOL Mail), we also process the content of your messages and attachments, in addition to the data described in the sections above. This section applies specifically to that service.
- Server location: email servers are hosted in the United States of America (Phoenix, Arizona). For clients in the European Union, this constitutes an international data transfer, carried out under appropriate contractual safeguards with our infrastructure provider.
- Retention: messages are retained for as long as the contract remains active. After the service is cancelled, the mailbox and its content are deleted within 30 days, unless the client requests a prior export.
- Backups: we keep rotating backups for service continuity purposes, deleted within an additional period of up to 30 days after the original mailbox is deleted.
- Access: the content of your messages is not accessed, analysed or used for any purpose other than providing the service (e.g. technical troubleshooting at your request).
- Security: connections to the email server are encrypted (TLS/SSL), and domain authenticity is protected through SPF, DKIM and DMARC.