Privacy Policy

How Amavela collects, uses, stores and protects personal data under GDPR and Portuguese law.

Amavela
Last updated: January 2026

1. Introduction

This Privacy Policy explains how Amavela collects, uses, stores and protects personal data when you visit or make a purchase on amavela.pt. We comply with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Portuguese data protection laws.

2. Data controller

  • Brand: Amavela
  • Legal status: Sole trader (Trabalhador Independente / Empresário em Nome Individual – ENI)
  • Legal name: Myroslava Khokhlach
  • Tax Identification Number (NIF): 326472061
  • Registered address:
    R DA AREOSA N 5 3 FRT
    4200-084 PORTO
    PORTUGAL
  • Contact email: [email protected]

3. Personal data we collect

Data you provide directly:

  • Name and surname
  • Email address
  • Shipping and billing address
  • Phone number (if provided voluntarily)
  • Order details and purchase history
  • Customer support communications

Data collected automatically:

  • IP address (anonymised where possible)
  • Browser and device information
  • Pages visited and interactions
  • Approximate location (country/region)

4. Purposes of processing

We process personal data to:

  • Process and fulfil orders
  • Arrange shipping and delivery
  • Communicate with customers
  • Comply with legal obligations
  • Ensure website security
  • Analyse website usage and improve services

5. Legal bases for processing

Personal data is processed based on:

  • Contractual necessity
  • Legal obligation
  • Legitimate interest
  • Consent (for analytics cookies)

Consent may be withdrawn at any time.

6. Payments

Payments are processed by third-party providers such as PayPal and Revolut Business. Amavela does not store or process full payment card details.

7. Data processors

We may share data with:

  • DigitalOcean (hosting)
  • PayPal (payments)
  • Revolut Business (card payments)
  • Google Analytics (GA4, basic configuration)
  • Gmail / Google services (email communication)

All processors are bound by data protection obligations.

8. Analytics and cookies

We use Google Analytics 4 (GA4) in a basic configuration.

  • Analytics data is collected only after cookie consent
  • No User-ID tracking is used
  • No advertising or remarketing features are enabled

9. Data retention

Personal data is retained as follows:

  • Orders and invoices: 10 years
  • Payment records: 10 years
  • Customer support communications: up to 24 months
  • Technical and security logs: up to 12 months
  • Analytics data: up to 26 months
  • Cookie consent records: up to 12 months

10. International data transfers

Some service providers may process data outside the EEA. Appropriate safeguards are applied in accordance with GDPR.

11. Your rights

You have the right to access, rectify, erase, restrict or object to processing, request data portability, and withdraw consent. Requests may be sent to [email protected].

12. Complaints

You may lodge a complaint with the Portuguese Data Protection Authority (CNPD) if you believe your rights have been violated.

13. Data security

We implement appropriate technical and organisational measures to protect personal data.

14. Changes to this policy

We may update this Privacy Policy from time to time. The updated version will be published on this page.