Privacy Policy
How Amavela collects, uses, stores and protects personal data under GDPR and Portuguese law.
Amavela
Last updated: January 2026
1. Introduction
This Privacy Policy explains how Amavela collects, uses, stores and protects personal data when you visit or make a purchase on amavela.pt. We comply with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Portuguese data protection laws.
2. Data controller
- Brand: Amavela
- Legal status: Sole trader (Trabalhador Independente / Empresário em Nome Individual – ENI)
- Legal name: Myroslava Khokhlach
- Tax Identification Number (NIF): 326472061
- Registered address:
R DA AREOSA N 5 3 FRT
4200-084 PORTO
PORTUGAL - Contact email: [email protected]
3. Personal data we collect
Data you provide directly:
- Name and surname
- Email address
- Shipping and billing address
- Phone number (if provided voluntarily)
- Order details and purchase history
- Customer support communications
Data collected automatically:
- IP address (anonymised where possible)
- Browser and device information
- Pages visited and interactions
- Approximate location (country/region)
4. Purposes of processing
We process personal data to:
- Process and fulfil orders
- Arrange shipping and delivery
- Communicate with customers
- Comply with legal obligations
- Ensure website security
- Analyse website usage and improve services
5. Legal bases for processing
Personal data is processed based on:
- Contractual necessity
- Legal obligation
- Legitimate interest
- Consent (for analytics cookies)
Consent may be withdrawn at any time.
6. Payments
Payments are processed by third-party providers such as PayPal and Revolut Business. Amavela does not store or process full payment card details.
7. Data processors
We may share data with:
- DigitalOcean (hosting)
- PayPal (payments)
- Revolut Business (card payments)
- Google Analytics (GA4, basic configuration)
- Gmail / Google services (email communication)
All processors are bound by data protection obligations.
8. Analytics and cookies
We use Google Analytics 4 (GA4) in a basic configuration.
- Analytics data is collected only after cookie consent
- No User-ID tracking is used
- No advertising or remarketing features are enabled
9. Data retention
Personal data is retained as follows:
- Orders and invoices: 10 years
- Payment records: 10 years
- Customer support communications: up to 24 months
- Technical and security logs: up to 12 months
- Analytics data: up to 26 months
- Cookie consent records: up to 12 months
10. International data transfers
Some service providers may process data outside the EEA. Appropriate safeguards are applied in accordance with GDPR.
11. Your rights
You have the right to access, rectify, erase, restrict or object to processing, request data portability, and withdraw consent. Requests may be sent to [email protected].
12. Complaints
You may lodge a complaint with the Portuguese Data Protection Authority (CNPD) if you believe your rights have been violated.
13. Data security
We implement appropriate technical and organisational measures to protect personal data.
14. Changes to this policy
We may update this Privacy Policy from time to time. The updated version will be published on this page.