Privacy policy
Last updated: 16 June 2026
This policy explains what personal data this website processes, why, on what legal basis, for how long, and the rights you have. It is written to be read, not to hide behind jargon. The site is run as a personal project and built around data minimisation: most of it works without collecting anything about you.
1. Who is responsible
Nelson Brilhante (an individual), based in Nazaré, Portugal, is the data controller.
Privacy contact: [email protected]
Supervisory authority: CNPD (Comissão Nacional de Proteção de Dados, Portugal).
2. What we process, why, and the legal basis
Browsing the site
To serve and protect the site, our infrastructure processes technical data inherent to any web request: IP address, browser/device (user-agent), the pages requested, and timestamps. This is kept in short-lived server logs for security and diagnostics. Legal basis: legitimate interest (operating and securing the site).
The BRI assistant (chat)
If you talk to BRI, the conversation is stored so it can answer and so we can follow up if you ask us to. We store: your IP address in anonymised form (the last octet is removed before storage), the browser (user-agent), the language, the messages you send, and any contact details you choose to share (name, e-mail, phone, company). The assistant runs on an AI model that analyses the conversation to extract those details and gauge interest.
Automated analysis (Art. 13(2)(f) GDPR): this scoring is used only to help prioritise a possible human reply. It is not an automated decision producing legal or similarly significant effects on you; any follow-up is done by a person.
Legal basis: legitimate interest in responding and improving the service; and your consent when you voluntarily submit contact details.
Newsletter
If you subscribe, we process your e-mail address and chosen language. Subscription uses double opt-in: you only join after clicking a confirmation e-mail. Legal basis: consent. You can withdraw it at any time via the unsubscribe link in every issue. See our newsletter handling below under processors.
Statistics
We measure aggregate traffic with a self-hosted, cookieless analytics tool. It does not set cookies, does not store your IP address in the clear, and does not allow identifying you individually. Legal basis: legitimate interest in understanding usage.
3. Cookies and local storage
The site uses no advertising or third-party tracking cookies. What it does use is strictly functional and, as such, does not require prior consent:
| What | Purpose | Duration |
|---|---|---|
Cookie locale | Remember your language choice | 30 days |
| Session cookie | Security/state, only if you use a feature that needs it | Session |
| Local storage | Language, theme, dismissed tours/dialogs, and your chat history kept on your own device | Until you clear it |
4. Processors and international transfers
We keep as much as possible on our own infrastructure. The site, the BRI AI model, the newsletter manager (Listmonk) and the analytics are self-hosted. The following third parties process personal data on our behalf:
| Processor | Role | Data / transfer |
|---|---|---|
| Cloudflare | CDN, reverse proxy and security (WAF) for all web traffic | Connection data incl. IP. May involve transfer outside the EU under Standard Contractual Clauses. |
| Resend | E-mail delivery (newsletter confirmations/issues and any replies we send you) | E-mail address and message content. Provider in the USA, under Standard Contractual Clauses. |
The BRI assistant runs on an AI model hosted on our own infrastructure. If an external AI provider is ever used for it, it will be named here.
5. How long we keep it
- Chat without any contact request: deleted after 90 days.
- Chat where you shared contact details / asked to be contacted: kept up to 24 months, then deleted.
- Newsletter: until you unsubscribe.
- Server logs: a short period (around 14 days) for security and diagnostics.
6. Your rights
You have the right to access, rectification, erasure, restriction, portability, and objection, and to withdraw consent at any time. To exercise them, write to [email protected] (we may need a detail such as the e-mail or session used, to locate your data). You may also lodge a complaint with the CNPD.
7. Security
We protect your data with HTTPS/TLS in transit, IP anonymisation for chat, data minimisation, restricted access, self-hosting of the AI, analytics and mailboxes, and automatic deletion once a retention period ends.
8. Minors
The site is not directed at children under 16 and we do not knowingly collect their data.
9. Changes
We may update this policy; the date at the top reflects the latest version.