H1F

Privacy notice

Last updated: 20/07/2026

The Portuguese-language version of this notice prevails; this English text is a courtesy translation.

Who we are

Portal H1F is operated by Hoje1Fascinio - Mendes Veloso, Lda, which is the controller of your personal data.

  • Tax number (NIF): 510612326
  • Address: Rua D. Jerónimo de Azevedo, Nº 470, 2º, Hab. 20, 4250-238 Porto, Portugal
  • Data-protection contact: hnveloso@h1f.pt

No formal Data Protection Officer (DPO) has been appointed — one is not mandatory for this controller. The email address above is the contact point for any data-protection matter.

Scope

This notice covers Portal H1F, the maritime survey management web application at portal.h1f.pt. It applies to two audiences:

  • Staff — internal users (admin, manager, inspector, accountant) who run the survey and invoicing work.
  • Clients — external users who submit and follow their own services.

It explains what personal data the application processes, why we process it, and the rights you have.

What personal data we process

  • Account and authentication — your name, email, a hashed password (bcrypt), your role, your client or inspector association, and session and login metadata. Your session is revoked when the password changes.
  • Client and business data — client and contact-person names, business references, vessel and port details, service details, free-text notes, and commercial and financial data (values, fees, invoices, payment status). The financial data is visible only to internal staff, never to clients.
  • Security and audit — a change log that records who changed what and when ("audit_log"). Secrets are scrubbed out.
  • Error diagnostics — technical error reports from the browser and the server, together with breadcrumbs ("app_errors"). Secrets are always scrubbed; traces may still contain business data.
  • Usage analytics — which pages and features are used and how (page views plus grid interactions such as filter, sort, search, view switch, export, copy, keyboard shortcuts, pagination and time spent on a page). Staff events are attributed to the individual staff user. Client events are role-only: they carry no user id and never the client code, so a client is never identified. An anonymous, per-browser-tab session id is used only to put events in order. The search text you type is never stored — only whether a search happened and how many results it returned. Sensitive values are scrubbed before anything is written.

Source of data. Most personal data is provided by you directly (staff and client accounts) or is generated as you use the portal. Some personal data — in particular the names of client-side contact persons — is provided to us by our clients rather than collected from those individuals directly.

Why we process it and our legal basis

PurposeLegal basis
Delivering the survey-management service (managing services, clients and invoicing)Performance of a contract and/or our legitimate interests in operating the business
Authentication, access control and session securityNecessary to provide the service and our legitimate interests in securing it
Keeping an audit logLegal obligation and our legitimate interests (accountability, security, fraud prevention)
Error diagnosticsOur legitimate interests (keeping the service working and secure)
Usage analyticsOur legitimate interests (understanding real usage in order to improve the portal)

For usage analytics we carried out a balancing test (a legitimate-interests assessment). Staff usage data is not used for individual performance evaluation or for disciplinary purposes. Wherever we rely on legitimate interests, you can object to that processing — see Your rights.

Cookies and local storage

All of the items below are first-party. There are no advertising or third-party tracking cookies.

Name / mechanismPurposeEssential?Duration
Authentication cookies (Auth.js — session, CSRF, callback)Keep you signed in and secure the sign-in flowYesRolling / idle session
NEXT_LOCALE — cookieRemembers your interface language (EN/PT)No (preference)Persistent preference
Sidebar collapsed state — cookieRemembers whether the sidebar is collapsedNo (preference)Up to about 1 year
Data-grid preferences (rows per page, density, saved view) — cookieRemembers your table preferencesNo (preference)Up to about 1 year
h1f.usage-session — sessionStorageAnonymous per-tab id used to order usage-analytics eventsNo (legitimate interest)Cleared when the tab closes
Idle-logout coordination and one-time UI hints — localStorageCoordinates idle logout across tabs and remembers one-time hints (for example, "edit hint seen")No (functional)Until cleared

The only analytics identifier is the anonymous, per-tab session id stored in the browser's sessionStorage; it is not a cookie and it is not your login session. It is used under legitimate interest, and you can object to it. Portal H1F does not use a cookie consent banner: it sets no advertising or third-party tracking cookies, and the first-party preference cookies and the analytics session id are relied on under legitimate interest (with your right to object), not consent.

Who has access

  • Internal staff, on a need-to-know basis governed by role-based access control.
  • Vercel — hosting — EU (Frankfurt).
  • Neon — database — EU (Frankfurt).
  • Resend — transactional and operational email (for example, password-recovery and user-invitation emails, and internal system alerts such as durability-monitoring notifications). This involves a transfer to the USA.
  • OpenAI (USA) — an optional AI "ask the data" feature exists but is currently disabled. It is not active and no data is sent to OpenAI. If it is ever enabled, this notice will be updated and the transfer appropriately safeguarded.

International data transfers

Hosting and the database are in the EU (Frankfurt). Sending email through Resend involves a transfer to the USA, carried out under the EU Standard Contractual Clauses (SCCs). The OpenAI feature is not active, so no data is transferred to it.

How long we keep it

DataRetention
Account dataWhile the account is active; removed on account closure, subject to any legal retention
Business and invoicing dataKept for the legally required accounting/tax period (10 years under Portuguese law)
Audit log12 months
Error diagnostics90 days
Usage analyticsRaw events for 90 days; aggregated, non-identifying statistics (no user id, collapsed to role) are kept longer for trends
Deleted-item recovery (trash / undo)30 days, then permanent deletion

Your rights

You have the right to access, rectification, erasure, restriction, objection (including to processing based on legitimate interests, such as usage analytics) and portability of your personal data.

To exercise any of these rights, email the controller at hnveloso@h1f.pt. There is currently no self-service "download my data" feature — such requests are handled manually by the controller. The portal already supports account and client deletion, and it keeps an audit trail as required by the legal bases above.

You also have the right to complain to the supervisory authority: CNPD — Comissão Nacional de Proteção de Dados (www.cnpd.pt).

Changes to this notice

We may update this notice from time to time. The current version is always the one shown here, and the "Last updated" date at the top tells you when it last changed.

Contact

For any question about this notice or about how your personal data is handled, contact us at hnveloso@h1f.pt.