How we collect, use, store and protect your personal data
The Noria platform is operated by Nelson Kuchar Junior, a sole trader registered as self-employed (the Portuguese “recibos verdes” regime) in Portugal, who is the controller of the personal data of platform users (account holders and authorised users). If the business is later incorporated as a company, this section will be updated with the company number and registered office, with 30 days’ notice on this page.
For matters relating to personal data protection, exercising data-subject rights under the GDPR, or contacting the Data Protection Officer (DPO), please write to contacto@noria.pt with the subject line “GDPR”.
| Data | Purpose | Legal basis (GDPR) | Retention |
|---|---|---|---|
| Full name | Identification and account record | Art. 6(1)(b) — Performance of contract | Term + 5 years |
| Business email | Login, communication, notifications | Art. 6(1)(b) — Performance of contract | Term + 5 years |
| Phone number | Support and verification | Art. 6(1)(b) — Performance of contract | Term + 1 year |
| Company tax ID (VAT/NIPC) | Tenant identification and invoicing | Art. 6(1)(c) — Legal obligation | 10 years (tax law) |
| IP address and User-Agent | Security and audit logging | Art. 6(1)(f) — Legitimate interest | 12 months |
| Access logs | Audit and compliance | Art. 6(1)(f) — Legitimate interest | 12 months |
| Data | Purpose | Noria's role |
|---|---|---|
| WhatsApp phone number | Chat communication | Processor |
| WhatsApp contact name | Identification in the inbox | Processor |
| Exchanged messages | Customer service and history | Processor |
| Lead qualification data | Commercial segmentation | Processor |
| Calendar data (Google Calendar) | Meeting scheduling | Processor |
Noria acts as a processor for these data under Article 28 GDPR. The customer is the data controller and must ensure it has a valid legal basis for processing the personal data of its own customers and contacts.
Your data may be shared with:
Noria does not sell, rent or share personal data with third parties for direct-marketing purposes.
The complete and up-to-date list of subprocessors, with their location and the legal basis for international transfers, is available at noria.pt/legal/subprocessors.
When personal data are transferred outside the European Economic Area (EEA), we apply the safeguards required by Chapter V of the GDPR, namely:
We implement appropriate technical and organisational measures under Article 32 GDPR, taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing, as well as the risks for the rights and freedoms of natural persons:
After contract termination, data are made available for export for 30 days and permanently deleted thereafter, save where a legal retention obligation applies.
Under Articles 15–22 GDPR you have the right to:
To exercise any of these rights, write to contacto@noria.pt with the subject “GDPR”. We respond within 30 days, extendable by 60 days for highly complex requests (Art. 12(3) GDPR), with prior notice to the data subject.
You also have the right to lodge a complaint with the Portuguese supervisory authority — Comissão Nacional de Proteção de Dados (CNPD): www.cnpd.pt · Av. D. Carlos I, 134 — 1.º, 1200-651 Lisboa, Portugal — or with the supervisory authority of your habitual residence.
In compliance with Article 5(3) of the ePrivacy Directive (transposed in Portugal by Law 41/2004) and the GDPR, we only use cookies and similar technologies when strictly necessary or with your prior, free, specific, informed and unambiguous consent.
| Name | Type | Category | Purpose | Duration | Origin |
|---|---|---|---|---|---|
noria_access_token | HttpOnly cookie | Strictly necessary | Authenticated session (JWT) | Up to ~1 hour | First-party (Noria) |
noria_refresh_token | HttpOnly cookie | Strictly necessary | Session renewal | Up to 30 days | First-party (Noria) |
noria_active_tenant | HttpOnly cookie | Strictly necessary | Active tenant | Up to 30 days | First-party (Noria) |
NEXT_LOCALE | Cookie | Preferences | Interface language | 1 year | First-party (Noria) |
noria_cookie_notice / noria_cookie_consent | localStorage | Strictly necessary | Cookie notice or consent record | 12 months | First-party (Noria) |
noria_visitor_id | localStorage | Strictly necessary | Anonymous consent proof ID | 12 months | First-party (Noria) |
whatsapp_saas_* (legacy) | localStorage | Strictly necessary | Legacy session keys; being phased out | Until cleared | First-party (Noria) |
fbm_* / fbsr_* | Third-party cookie | Functional | WhatsApp Embedded Signup (Meta) | Session | Meta Platforms |
Primary authentication uses HttpOnly, SameSite=Strict cookies set by the application proxy. Strictly necessary cookies do not require consent. Meta cookies only after explicit user action in the WhatsApp connection flow.
You can accept, reject or change your preferences at any time. Your choice is recorded with a timestamp, policy version and anonymous identifier, as required by Article 7(1) GDPR (ability to demonstrate consent).
You can withdraw consent at any time without affecting the lawfulness of processing carried out before the withdrawal (Art. 7(3) GDPR).
In line with Article 22 GDPR and the EU AI Act (Regulation (EU) 2024/1689):
When the Customer connects their Google account to the Platform (scheduling integration), Noria accesses Google Calendar data through the Google Calendar API, using OAuth 2.0 authentication and only after explicit consent on Google's authorization screen:
Noria's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The platform is intended for professional use by businesses and is not directed at children under 16. We do not knowingly collect personal data of minors. Where the customer uses the platform to communicate with minors, the customer is responsible for obtaining parental consent under Article 8 GDPR and Article 16 of Portuguese Law 58/2019.
Noria carries out Data Protection Impact Assessments (DPIAs) under Article 35 GDPR for processing operations that pose a high risk to the rights and freedoms of data subjects, in particular for automated decision-making with AI and large-scale processing of communications data.
Material changes are communicated 30 days in advance via email and/or in-product notification. The current version is always available at noria.pt/legal/privacy.
Data controller: Nelson Kuchar Junior (self-employed sole trader) — see section 1.
Data Protection Officer (DPO): Nelson Kuchar Junior — contacto@noria.pt
Single contact point (general, GDPR and DPO): contacto@noria.pt
Please use one of the following subject lines to route your request: “GDPR — access”, “GDPR — erasure”, “GDPR — portability”, “DPO” or “Support”.
Supervisory authority: Comissão Nacional de Proteção de Dados (CNPD) — www.cnpd.pt · Av. D. Carlos I, 134 — 1.º, 1200-651 Lisboa, Portugal · Tel.: +351 213 928 400