Privacy Policy
This policy explains, in plain language, which personal data we process when you visit our website, for which purposes and on which legal bases, and what your rights are.
1. Controller
The controller for personal data collected through this website is Leticia Araujo Carlins, attorney-at-law, admitted to the Portuguese Bar Association (professional licence no. 69724-L) and the Brazilian Bar Association (OAB/PR no. 95.087), with professional address at Rua do Viveiro, n.º 402, 2765-294 Estoril, Cascais, Portugal.
For any question regarding the processing of your personal data, you can contact us at leticiacarlins.adv@gmail.com.
2. Scope
This policy describes the processing of personal data of visitors to leticiacarlins.com, in accordance with Regulation (EU) 2016/679 (GDPR), Portuguese Law no. 58/2019 of 8 August and Law no. 41/2004 of 18 August. Data processing within a client engagement is covered by separate information provided directly to the client.
3. Contact form
When you send us a request through the contact form, we process the data you provide: full name, phone number, email address, requested service and the description of your case.
Purpose: to respond to your request and, where applicable, to prepare a potential client engagement. Legal basis: pre-contractual steps taken at your request (Article 6(1)(b) GDPR) and our legitimate interest in answering enquiries (Article 6(1)(f)).
Retention: the data is kept only as long as necessary to handle your request and for a maximum of 12 months after the last contact, unless an engagement is established or a legal retention obligation applies.
Communications addressed to a lawyer are covered by professional secrecy under the Statute of the Portuguese Bar Association (Law no. 145/2015 of 9 September).
4. Cookies and analytics
We use Google Analytics only if you give your consent via the cookie notice (Article 6(1)(a) GDPR and Law no. 41/2004). Until you consent, no analytics cookies are placed on your device.
Google Analytics helps us understand, in aggregate, how the website is used. IP addresses are processed in anonymised form. Recipient: Google Ireland Limited and, as sub-processor, Google LLC (USA). Analytics data is retained for a maximum of 14 months.
You can withdraw your consent at any time via “Cookie settings” in the website footer; withdrawal does not affect the lawfulness of prior processing. The website also stores your language preference and your cookie choice in your browser’s local storage — this information does not identify you and is not shared with third parties.
5. Technical logs (hosting)
When you visit the website, our hosting provider processes technical data (such as IP address, date and time of access and browser type) in server logs, to the extent necessary to deliver the website securely and reliably. Legal basis: legitimate interest (Article 6(1)(f) GDPR).
6. Recipients, processors and international transfers
We use the following processors:
- Vercel Inc. (USA) — website hosting;
- Resend Inc. (USA) — delivery of contact form messages, via servers located in the European Union;
- Google Ireland Limited / Google LLC — analytics, only with your consent.
Where data is transferred outside the European Economic Area, such transfers are based on the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework and/or standard contractual clauses, in accordance with Articles 45 and 46 GDPR.
We do not sell your data and do not share it with third parties for marketing purposes.
7. Your rights
Under Articles 15 to 21 GDPR, you have the right to access your data, to have it rectified or erased, to restrict or object to processing, and the right to data portability. Where processing is based on consent, you may withdraw it at any time.
To exercise your rights, contact us at leticiacarlins.adv@gmail.com.
You also have the right to lodge a complaint with the supervisory authority: Comissão Nacional de Proteção de Dados (CNPD), Av. D. Carlos I, 134, 1.º, 1200-651 Lisbon, Portugal — www.cnpd.pt.
8. Security
The website is served exclusively over an encrypted connection (HTTPS/TLS). We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss or improper disclosure, and restrict access to the data to those strictly required.
9. Changes to this policy
This policy may be updated to reflect legal, technical or website changes. The version published on this page is the version in force.
Last updated: 27 July 2026