Privacy notice
Last updated: 20/07/2026
The Portuguese-language version of this notice prevails; this English text is a courtesy translation.
Who we are
Portal H1F is operated by Hoje1Fascinio - Mendes Veloso, Lda, which is the controller of your personal data.
- Tax number (NIF): 510612326
- Address: Rua D. Jerónimo de Azevedo, Nº 470, 2º, Hab. 20, 4250-238 Porto, Portugal
- Data-protection contact: hnveloso@h1f.pt
No formal Data Protection Officer (DPO) has been appointed — one is not mandatory for this controller. The email address above is the contact point for any data-protection matter.
Scope
This notice covers Portal H1F, the maritime survey management web application at portal.h1f.pt. It applies to two audiences:
- Staff — internal users (admin, manager, inspector, accountant) who run the survey and invoicing work.
- Clients — external users who submit and follow their own services.
It explains what personal data the application processes, why we process it, and the rights you have.
What personal data we process
- Account and authentication — your name, email, a hashed password (bcrypt), your role, your client or inspector association, and session and login metadata. Your session is revoked when the password changes.
- Client and business data — client and contact-person names, business references, vessel and port details, service details, free-text notes, and commercial and financial data (values, fees, invoices, payment status). The financial data is visible only to internal staff, never to clients.
- Security and audit — a change log that records who changed what and when ("audit_log"). Secrets are scrubbed out.
- Error diagnostics — technical error reports from the browser and the server, together with breadcrumbs ("app_errors"). Secrets are always scrubbed; traces may still contain business data.
- Usage analytics — which pages and features are used and how (page views plus grid interactions such as filter, sort, search, view switch, export, copy, keyboard shortcuts, pagination and time spent on a page). Staff events are attributed to the individual staff user. Client events are role-only: they carry no user id and never the client code, so a client is never identified. An anonymous, per-browser-tab session id is used only to put events in order. The search text you type is never stored — only whether a search happened and how many results it returned. Sensitive values are scrubbed before anything is written.
Source of data. Most personal data is provided by you directly (staff and client accounts) or is generated as you use the portal. Some personal data — in particular the names of client-side contact persons — is provided to us by our clients rather than collected from those individuals directly.
Why we process it and our legal basis
| Purpose | Legal basis |
|---|---|
| Delivering the survey-management service (managing services, clients and invoicing) | Performance of a contract and/or our legitimate interests in operating the business |
| Authentication, access control and session security | Necessary to provide the service and our legitimate interests in securing it |
| Keeping an audit log | Legal obligation and our legitimate interests (accountability, security, fraud prevention) |
| Error diagnostics | Our legitimate interests (keeping the service working and secure) |
| Usage analytics | Our legitimate interests (understanding real usage in order to improve the portal) |
For usage analytics we carried out a balancing test (a legitimate-interests assessment). Staff usage data is not used for individual performance evaluation or for disciplinary purposes. Wherever we rely on legitimate interests, you can object to that processing — see Your rights.
Cookies and local storage
All of the items below are first-party. There are no advertising or third-party tracking cookies.
| Name / mechanism | Purpose | Essential? | Duration |
|---|---|---|---|
| Authentication cookies (Auth.js — session, CSRF, callback) | Keep you signed in and secure the sign-in flow | Yes | Rolling / idle session |
| NEXT_LOCALE — cookie | Remembers your interface language (EN/PT) | No (preference) | Persistent preference |
| Sidebar collapsed state — cookie | Remembers whether the sidebar is collapsed | No (preference) | Up to about 1 year |
| Data-grid preferences (rows per page, density, saved view) — cookie | Remembers your table preferences | No (preference) | Up to about 1 year |
| h1f.usage-session — sessionStorage | Anonymous per-tab id used to order usage-analytics events | No (legitimate interest) | Cleared when the tab closes |
| Idle-logout coordination and one-time UI hints — localStorage | Coordinates idle logout across tabs and remembers one-time hints (for example, "edit hint seen") | No (functional) | Until cleared |
The only analytics identifier is the anonymous, per-tab session id stored in the browser's sessionStorage; it is not a cookie and it is not your login session. It is used under legitimate interest, and you can object to it. Portal H1F does not use a cookie consent banner: it sets no advertising or third-party tracking cookies, and the first-party preference cookies and the analytics session id are relied on under legitimate interest (with your right to object), not consent.
Who has access
- Internal staff, on a need-to-know basis governed by role-based access control.
- Vercel — hosting — EU (Frankfurt).
- Neon — database — EU (Frankfurt).
- Resend — transactional and operational email (for example, password-recovery and user-invitation emails, and internal system alerts such as durability-monitoring notifications). This involves a transfer to the USA.
- OpenAI (USA) — an optional AI "ask the data" feature exists but is currently disabled. It is not active and no data is sent to OpenAI. If it is ever enabled, this notice will be updated and the transfer appropriately safeguarded.
International data transfers
Hosting and the database are in the EU (Frankfurt). Sending email through Resend involves a transfer to the USA, carried out under the EU Standard Contractual Clauses (SCCs). The OpenAI feature is not active, so no data is transferred to it.
How long we keep it
| Data | Retention |
|---|---|
| Account data | While the account is active; removed on account closure, subject to any legal retention |
| Business and invoicing data | Kept for the legally required accounting/tax period (10 years under Portuguese law) |
| Audit log | 12 months |
| Error diagnostics | 90 days |
| Usage analytics | Raw events for 90 days; aggregated, non-identifying statistics (no user id, collapsed to role) are kept longer for trends |
| Deleted-item recovery (trash / undo) | 30 days, then permanent deletion |
Your rights
You have the right to access, rectification, erasure, restriction, objection (including to processing based on legitimate interests, such as usage analytics) and portability of your personal data.
To exercise any of these rights, email the controller at hnveloso@h1f.pt. There is currently no self-service "download my data" feature — such requests are handled manually by the controller. The portal already supports account and client deletion, and it keeps an audit trail as required by the legal bases above.
You also have the right to complain to the supervisory authority: CNPD — Comissão Nacional de Proteção de Dados (www.cnpd.pt).
Changes to this notice
We may update this notice from time to time. The current version is always the one shown here, and the "Last updated" date at the top tells you when it last changed.
Contact
For any question about this notice or about how your personal data is handled, contact us at hnveloso@h1f.pt.