1. Who is responsible for your data
The controller of your personal data is BOOST2FUTURE UNIPESSOAL LDA (“Taxovate”, “we”, “us”), a single-member private limited company incorporated in Portugal, taxpayer number (NIPC) PT518461467, with registered office at Rua do Vale Cardal n.º 142, 6120-021 Envendos, Mação, Santarém, Portugal. Taxovate operates the website taxovate.pt and the client workspace, which is also reached at www.taxovate.pt and app.taxovate.pt.
For any privacy question, to exercise your rights or to make a complaint, write to clientes@taxovate.pt. We have assessed the requirement under Article 37 of the General Data Protection Regulation (GDPR) and Article 13 of Lei n.º 58/2019 and have not appointed a data protection officer; privacy matters are handled at that address, and we review this assessment periodically.
Where we process data solely on a business client's documented instructions and the engagement scope says so, we act as that client's processor under a separate data processing agreement.
2. What this policy covers
This policy applies when you visit taxovate.pt, use the free calculators or read the blog; create an account or sign in, including with Google; use the client workspace; engage us for tax, accounting or Segurança Social work; or contact us by email or WhatsApp. It also covers people whose data appears in documents our clients give us, such as dependants, employees, tenants, customers or suppliers.
If you are a client, the Privacy Notice in the Client Agreement Bundle you accepted - the current version is published at taxovate.pt/legal/agreement - also applies to your engagement. This policy describes the same processing and does not reduce any protection that notice gives you.
3. The personal data we process
What we process depends on how you use Taxovate:
- Account and contact data - your name, email address, phone number where you give it, communication preferences and the plan or services you choose. Your password is held only by our sign-in service, which runs on our own servers.
- Tax and Segurança Social profile - taxpayer and social-security identification and profile information, and the facts needed for your returns, such as your address, activity, tax regime and the household information relevant to deductions.
- Documents and financial records - documents you upload or send us, documents we retrieve from the tax and social-security portals with your authority, invoices, receipts, declarations and statements, and the accounting records, calculations and drafts we prepare from them.
- Portal access - where you choose to connect Portal das Finanças or Segurança Social, your credentials, session material and multi-factor codes. These are restricted secrets: encrypted at rest, not displayed to ordinary staff after entry, not written to logs and never disclosed to any technology provider, including artificial-intelligence providers.
- Approvals and evidence - what you approved, when and the exact content approved, the record of your acceptance of the Client Agreement Bundle, receipts from the authorities and the audit trail of actions taken on your file.
- Communications and support - messages exchanged with us through the workspace, email or WhatsApp, and support records.
- Payment data - payment status, invoices and billing details. Card details go directly to our payment provider, Stripe, and are never held by Taxovate.
- Technical and security data - IP address, browser and device information, requests to the site, sign-in and security events, and reports of errors that happen in your browser.
- Sign-in with Google - if you use it, the information described in section 6.
Special categories of data. Documents supporting tax deductions can reveal special categories of personal data - health expenses are the most common example in IRS work. We process these only with your explicit consent, requested separately when the document is submitted, or under another condition in Article 9(2) GDPR. Additional safeguards apply: minimisation before automated processing, routing only to providers under zero-retention or equivalent configurations, and exclusion from optional automated analysis.
Data about other people. Documents may contain personal data about third parties, such as dependants, employees, customers or suppliers. We process it only to deliver the services. Please share it only where you have a lawful basis to do so, and do not send us more about other people than the work requires.
4. Why we use it, and our legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and securing your account, including sign-in with Google | Article 6(1)(b) - contract |
| Delivering the services you engage, including preparation, professional review, filings you approve and communications about your file | Article 6(1)(b) - contract |
| Answering questions you send us before you become a client | Article 6(1)(b) - steps taken at your request before entering into a contract |
| Meeting our accounting, tax, professional and record-keeping duties, including keeping records for the statutory periods | Article 6(1)(c) - legal obligation |
| Platform security, fraud prevention, error and anomaly detection and service quality, including security logs and browser error reports | Article 6(1)(f) - legitimate interests |
| Remembering the language and appearance you choose for the site | Article 6(1)(f) - legitimate interests |
| Understanding how people find our website in Google Search, using Search Console statistics for our own website | Article 6(1)(f) - legitimate interests |
| Counting visits to our public pages, without cookies or device identifiers, to understand which content is useful and to improve the website | Article 6(1)(f) - legitimate interests |
| Establishing, exercising or defending legal claims | Article 6(1)(f) - legitimate interests |
| Optional marketing communications | Article 6(1)(a) - consent |
| Special categories of data in documents you submit | Article 9(2)(a) - explicit consent, or another condition in Article 9(2) |
Consent is not the basis for delivering the services or for automated processing. Where we rely on consent, it is specific and separate, you can withdraw it at any time, and withdrawing it does not affect the rest of the services. Where we rely on legitimate interests, we have carried out a balancing assessment, which is available on request.
5. Automated and AI-assisted processing
We use automation, optical character recognition and artificial intelligence to classify documents, extract data, prioritise work, reconcile records, detect anomalies, create estimates and prepare drafts. These tools assist our people; they do not replace professional judgement.
No decision that produces legal effects for you, or similarly significantly affects you, is taken solely by automated means. Every filing, payment instruction and regulated output is reviewed and approved by a qualified person, who examines the supporting evidence and can change the outcome. Automated tools never submit declarations, never authorise payments, never issue invoices or receipts in your name without prior human approval, and never receive portal credentials.
Your data is not sold and is not used to train, fine-tune or improve any artificial-intelligence model, by us or by any provider. You can ask at any time which automated tools are used, request human intervention, ask for an explanation of an output or ask for it to be corrected. The AI & Automated Processing Annex of the Client Agreement Bundle sets out the full detail.
6. Google user data
Taxovate uses Google in two separate ways, described below. Neither gives us access to your Gmail, Google Drive, contacts, calendar or any other Google service.
Sign in with Google
When you choose “Continue with Google”, Google asks your permission to share basic account information with Taxovate, limited to the “openid”, “email” and “profile” permissions: your Google account identifier, your email address and whether Google has verified it, your name and, if you have one, your profile picture.
We use this information only to authenticate you and connect the sign-in to your Taxovate account. The verified email address is matched to an account already registered on Taxovate; if there is none, no session is created and you are taken to registration. Our sign-in service, which runs on our own servers, keeps your Google account identifier, name and email address with your account so that later sign-ins work. We never receive your Google password, we do not keep the access tokens Google issues at sign-in, and we do not use your profile picture.
You can sign in with your email address and password instead at any time, and you can remove Taxovate's access in your Google Account at myaccount.google.com/connections. Removing that access does not close your Taxovate account; section 9 explains what happens when you do.
Google Search Console, for our own website only
Taxovate's administrator has authorised Taxovate to use the Google Search Console API for taxovate.pt, the website Taxovate owns. We use it to read search statistics for that website - the search queries, pages, clicks, impressions and average positions Google reports for taxovate.pt - and to resubmit our sitemap to Google when we publish articles. The permissions used are “webmasters.readonly” for reading and “webmasters” for sitemap submission.
Clients and visitors are never asked to connect Search Console, and we do not access Search Console data for any other website. The statistics are aggregated by Google and describe how people in general find taxovate.pt: we use them only in internal reports that authorised Taxovate staff can open, we do not combine them with client records and we do not use them to identify anyone. The authorisation is stored on our own servers and can be revoked by Taxovate's administrator at any time.
Limited Use
Taxovate's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- we use information received from Google APIs only to provide and improve the features described in this section - signing you in, and our own website's search reporting and sitemap submission;
- we do not sell it, and we do not use or transfer it for advertising, including retargeting, personalised or interest-based advertising;
- we do not use it to determine creditworthiness or for lending purposes, and we do not use it to train artificial-intelligence or machine-learning models;
- we transfer it to others only where necessary to provide those features, such as to the hosting and security providers listed in section 7, to comply with applicable law, or as part of a merger, acquisition or sale of assets with your prior consent;
- people at Taxovate do not read it unless you have agreed, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or it has been aggregated and anonymised for internal operations.
7. Who receives your data
We share personal data only as far as each recipient needs it:
- authorised Taxovate personnel and the accounting professionals assigned to your file, who are bound by confidentiality and, for our accounting personnel, by professional secrecy under the statute of the Ordem dos Contabilistas Certificados;
- service providers that process data on our behalf, each engaged under a written contract that allows them to act only on our documented instructions and requires them to impose the same duties on anyone they engage;
- public authorities, such as the Autoridade Tributária e Aduaneira and Segurança Social, when we file or act for you with your approval, or where the law requires it;
- professional advisers, and courts or authorities where this is needed to establish, exercise or defend legal claims.
At the date of this policy, our service providers are Contabo (server hosting, Germany), Cloudflare (website delivery, protection against attack, and forwarding of email sent to our taxovate.pt addresses), Google (the Gmail mailbox that receives that email), Resend (transactional email), Stripe (payments), OpenAI (AI-assisted classification, extraction and drafting), Meta / WhatsApp (messages, where you choose WhatsApp), Sentry (browser error reports, EU region) and PostHog (product analytics, EU region); the website and workspace do not currently load PostHog. The subprocessor list sets out what each one receives, where it processes data and the safeguard for any transfer. We give at least thirty days' notice before adding or replacing a subprocessor, and you may object on reasonable data-protection grounds within fifteen days.
Some systems that hold personal data run on our own servers, so no third party receives that data: our sign-in service (Keycloak), our server error tracking (GlitchTip) and our website analytics (Plausible), which we host ourselves.
We do not sell personal data.
8. International transfers
Our servers are in Germany, and where a provider offers processing in the European Economic Area or EU data residency, we choose it. Some providers process data outside the EEA: Resend processes data in the United States; Stripe, OpenAI and Meta / WhatsApp contract through Irish entities with processing in the United States; and Cloudflare and Google operate global networks.
Where personal data leaves the EEA, we rely on a European Commission adequacy decision or on Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914, together with a documented transfer impact assessment and any supplementary measures identified as necessary. You can ask us which countries are involved and which safeguards apply.
9. How long we keep data
We keep personal data only for as long as its purpose requires or the law obliges us to. Accounting records, tax documentation and supporting documents are kept for ten years, as required by Decreto-Lei n.º 28/2019, article 123.º of the Código do IRC, article 52.º of the Código do IVA and article 40.º of the Código Comercial; where a right is exercised whose period is longer, they are kept until the relevant assessment period expires.
| Data | Period |
|---|---|
| Accounting records, declarations, supporting documents and receipts from the authorities | 10 years |
| Engagement records, accepted agreements and signature evidence | 10 years from the end of the engagement |
| Portal credentials and integration secrets | Deleted on revocation or within 30 days of the end of the engagement - and immediately if you close your account |
| Session material and multi-factor codes | The duration of the session |
| Original uploads superseded by a validated extraction | 10 years where they form part of the accounting record; otherwise 24 months |
| Client communications and support records | 5 years |
| Security and access logs | 12 months |
| Website visit statistics | Records of each page view under that day's code, without your name or IP address, kept for 24 months, then deleted |
| Backups | A rolling 90 days, then overwritten |
| Marketing contact data | Until you withdraw consent |
If you close your account, access ends immediately and any government portal credentials we hold are deleted at that moment. The rest of your data is kept for thirty days, during which you can ask us to reverse the closure. After that, data that is not subject to a legal retention duty - such as correspondence, notifications and copies of documents obtained from the portals - is deleted. Returns already filed and their supporting documents, invoices and payment records, and the record of your acceptance of the agreement are kept for the periods the law requires and are not used for any other purpose.
Expired data is securely deleted or irreversibly anonymised, and data in backups is deleted on the backup cycle above. Cookie and browser-storage periods are in section 11.
10. How we protect your data
Our safeguards include encryption in transit and at rest, restricted storage for secrets, role-based access, multi-factor authentication for staff, malware scanning and quarantine-first handling of uploads, audit trails, backups and documented incident procedures. Access is limited to the minimum information each function needs.
No system can promise absolute security. If a personal data breach is likely to result in a high risk to your rights, we will tell you without undue delay, and we report notifiable breaches to the CNPD within 72 hours of becoming aware of them.
Our accounting personnel are bound by professional secrecy under the statute of the Ordem dos Contabilistas Certificados, and every provider with access to client data is contractually bound to confidentiality obligations no less protective than those duties.
12. Your rights
Subject to the conditions the law sets, you have the right to:
- access the personal data we hold about you and receive a copy of it;
- have inaccurate data corrected and incomplete data completed;
- have your data erased;
- restrict how we process it;
- receive the data you gave us in a structured, machine-readable format and have it sent to another controller (portability);
- object to processing based on our legitimate interests;
- withdraw your consent at any time, where processing is based on consent;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, and ask for human intervention, an explanation or a correction of any automated output.
To exercise any of these rights, write to clientes@taxovate.pt. We will need to verify your identity. We answer within one month, which may be extended by two further months for complex requests, in which case we will tell you. The right to erasure does not override the statutory retention duties in section 9: where records must be kept, we restrict their processing to that purpose.
You also have the right to complain to the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (CNPD), at www.cnpd.pt, or to the supervisory authority of the country where you live or work.
13. Children
Taxovate is intended for adults and is not directed at children. Accounts are for people with full legal capacity to enter into a contract, and we do not knowingly create accounts for children or collect personal data directly from them. If you believe a child has given us personal data, contact us and we will delete it unless the law requires us to keep it.
Tax work can involve information about children - for example, dependants in an IRS household. That information is given to us by the parent or guardian who is our client, and we process it only to deliver the services, with the same safeguards as the rest of the file.
14. Changes to this policy
We version this policy and show its effective date at the top of this page. Before a material change takes effect, we will give clear notice - in the workspace and by email if you have an account - and, where the legal basis requires it, ask for your renewed choice before any new processing begins. Changes to the Privacy Notice in the Client Agreement Bundle follow that agreement's own procedure.
15. Contact
BOOST2FUTURE UNIPESSOAL LDA (Taxovate), Rua do Vale Cardal n.º 142, 6120-021 Envendos, Mação, Santarém, Portugal. Email: clientes@taxovate.pt.