Who the data controller is
The person who decides what happens to your data — and answers for it — is a
person, not a company. terraroot is the trading name; it is not
a limited company.
- Controller
- Tiago Calado Lopes, sole trader
- Address
- Largo José da Cruz, n.º 3, 2260-369 Vila Nova da Barquinha, Portugal
There is no designated data protection officer, and none is required: terraroot
does not process data on a large scale and does not systematically monitor
people. For anything to do with privacy, write to the address above.
What data is collected
Only what you type into the contact form — the one on the home page and the one
on the Contact page, which are the same form. There is
no user registration, no members' area, and no contact lists bought from anyone.
- Name
- Required. It is how we address you in the reply.
- Email
- Required. It is where the reply goes.
- Phone
-
Optional. Only used if you leave it, and only to talk about
your enquiry. Leaving it blank does not stop the form or change the reply.
- What brings you here
-
Optional. One of four options, so we know where you are
before replying. Leaving it unset does not stop the form or change the reply.
- Message
-
Whatever you want to tell us about the project. Write only what is needed —
this is not the place for health data, financial data or other people's data.
The submission also carries which version of the site you were on
— Portuguese or English. It is not a field anyone fills in: it is what lets us
reply in the language you wrote in.
The submission also carries the date and time it arrived, because that comes with
the email, and the form measures how long it took to fill in so that automated
submissions can be discarded. Neither is used for anything else.
To stop abuse, the page that receives the form counts how many requests
arrive from each origin in the last fifteen minutes and refuses any over
the limit. The origin is never kept in the clear: it is turned
into a cryptographic digest using a key drawn afresh each time the server starts,
it lives only in that run's memory, and it goes when the run goes. It is not in
the email, it is not written to any file, and it is not there to identify you — it
is there to count.
The home page and Contact carry an anti-spam
check, which loads together with the page. At that moment your browser
connects to Cloudflare, which receives your IP address and
technical information about your device and browser in order to decide whether a
person is filling the form in. Cloudflare returns a short-lived proof, which
travels with the submission for us to confirm: without it the form does
not send, and that is the point of it — without a check, this form could
be used to make our server send messages to third parties.
On the other sixteen pages this does not happen, and there is
always the alternative of writing straight to
geral@terraroot.pt, where no check stands
in the way. Section 7 explains what changed.
For the same reason and in the same way, the address the automatic
confirmation is sent to is counted too — also as a digest, also only in
that run's memory. It is there to stop anyone using this form to make our server
send messages to third parties. If the limit is reached your enquiry still reaches
us: what stops being sent is the automatic confirmation, not the message.
What it is used for
Two things, and nothing beyond them:
- Answering your request for a proposal — reading what you wrote, looking at what already exists, and sending a concrete quote.
- Talking to you about that request — asking what is missing, arranging a conversation, following up.
You are not signed up to any newsletter, you are not sent campaigns, and your data
is not sold, rented or passed to third parties for commercial purposes. There is
no automated decision-making and no profiling: the person who reads your enquiry
and replies is a person.
If we ever wanted to use your contact details for something else — sending news,
for instance — we would ask you first. Separate permission, for that separate
thing.
The legal basis
The GDPR only allows personal data to be processed with a legal basis behind it.
Here there are three — two for your enquiry, which support one another, and a
third that exists only to keep the form standing:
- Your consent — Article 6(1)(a) GDPR. It is the box you tick before sending the form. It is never pre-ticked, and without it the form does not go through.
- Steps taken at your request prior to entering into a contract — Article 6(1)(b) GDPR. Preparing and sending a proposal you asked for is a step before a possible contract.
- Our legitimate interest in keeping the form usable — Article 6(1)(f) GDPR, which Recital 49 says expressly covers network and information security. It is what supports counting requests per origin, described in section 2. It is the only processing here that does not depend on your consent, and it has to be: it happens before there is any consent at all, because an abusive request is refused without being looked at.
The anti-spam check described in section 2 rests on that same
third basis — our legitimate interest in keeping the form usable,
Article 6(1)(f) GDPR. It runs before the consent box, just as the request count
does, and for the same reason: an automated request is stopped without being
looked at.
And here is something we would rather state than hide. Article
5(3) of the ePrivacy Directive requires, as a rule, prior permission before
anything reads information from your device — and an anti-spam check reads. Our
reading is that it is strictly necessary to provide the service you
asked for, which is sending us a message without the form being usable
against third parties, and that it therefore falls within that same provision's
exception. That is a reading, not a certainty: no Portuguese court or
regulator has ruled on anti-spam checks.
So here is what we do with the doubt: the check runs only on the four
pages with a form, it measures no audiences, it does not follow you
from page to page and it is not used for advertising — and anyone who would
rather not have it in the way has
geral@terraroot.pt, which arrives in the
same place.
This means you can withdraw your consent at any time, and that withdrawing it does
not make unlawful what was done beforehand on the basis of it. The request count is
the one thing that is not switched off on request: without it the form is open to
anyone who wants to use it to send email to third parties, and at that point there
is no form left for anybody.
How long it is kept
Two years from the last contact between us — whether that is your
message, our reply, or a later conversation about the same subject. After that,
the enquiry is deleted.
The period exists for a practical reason: a proposal request that went quiet often
comes back months later, and having the history saves you repeating everything.
Two years is the point beyond which there is no longer a reason to keep it.
If you ask for it to be deleted sooner, it is deleted when you ask — you do not
have to wait for the two years to run out.
Who else touches it
Nobody, beyond three companies that provide the site, the email and the anti-spam
check. None of them uses your data for its own purposes: they process it on
terraroot's behalf and only to keep the service running.
Vercel Inc. — website hosting
The site is hosted by Vercel Inc., a company based in the United States. When you
press send, the message passes through a Vercel server, which forwards it
immediately to terraroot's email. terraroot keeps no copy there: there is no
database on this site, and the code that handles sending does not write your
enquiry anywhere. But the content does cross Vercel's infrastructure, and that is
what matters here — whatever that infrastructure logs on its own account is
governed by their policies, not ours.
Transfer outside the European Economic Area. Because Vercel is
a US company, your data may be processed outside the EEA, where data protection
law is not the European one. That transfer is covered by the European
Commission's Standard Contractual Clauses (Implementing Decision 2021/914),
which Vercel incorporates into the data processing agreement applying to its
customers — the instrument provided for in Article 46 GDPR for transfers to
countries without an adequacy decision. Vercel also states that it is certified
under the EU-US Data Privacy Framework.
Webtuga — domain and email
The terraroot.pt domain and the geral@terraroot.pt mailbox are with Webtuga, a
Portuguese company with servers in Portugal. That is where your message is stored,
like any received email, for the period set out in section 5. Being an EU-based
company, there is no transfer outside the EEA here.
Cloudflare, Inc. — the anti-spam check on the form
The anti-spam check on the four pages with a form is provided by
Cloudflare, Inc., a company based in the United States. It loads
with the page, and at that moment Cloudflare receives your IP address and
technical information about your device — enough to tell a person from a program.
It does not receive what you wrote in the form: the name, the
email and the message never pass through it.
When you press send, our server asks Cloudflare whether that proof is valid, and
your IP address goes with the question. That is the only time your IP
leaves here — for counting requests, as section 2 describes, it is never
used in the clear.
On the other sixteen pages Cloudflare does not come into it, and
writing to geral@terraroot.pt remains a
route with no check in the way.
Transfer outside the European Economic Area. Because Cloudflare
is a US company, the technical data the check collects may be processed outside
the EEA. That transfer is covered by the European Commission's Standard
Contractual Clauses (Implementing Decision 2021/914), which Cloudflare
incorporates into the
data processing agreement
applying to its customers, and Cloudflare states that it is certified under the
EU-US Data Privacy Framework.
Nobody else
There is no CRM, no newsletter platform, no third-party form tool and no analytics
service. Your enquiry goes from the form to an inbox, and stops there.
Cookies and trackers
This site uses no cookies. None — not even the ones the law would
exempt from consent. There is no Google Analytics, no Meta or Facebook pixel, no
heatmaps, no session recording and no advertising. Nothing here follows you from
page to page, or on to other sites.
That is why no cookie banner appears when you arrive: there is still no cookie to
consent to. We would rather have nothing to ask about than ask out of habit.
There is one exception, and only one: the anti-spam check on the
form. Everything any page needs in order to render — the text, the
styles, the icons and the typefaces — comes from terraroot.pt.
On the sixteen pages without a form there is not a single third-party
request: in reading this, your browser has contacted nobody else.
On the four that have a form — the home page and
Contact, in each language — the Cloudflare check
loads with the page, and it is required in order to send. Put
plainly: those four pages make a request to a third-party server before
you have typed anything at all, and the check may store information on
your device while it runs. Cloudflare explains that in its
privacy policy;
what it receives is in section 6, and the legal basis — along with the honest
doubt attached to it — is in section 4.
Until 6 September 2026 this was not the case, and the change is written
down rather than deleted: the site made no third-party request, on any
page. That stopped being true when the form gained a check — what was gained is
that the form can no longer be used to send messages to third parties from our
server. Anyone who would rather not have Cloudflare in the way can write to
geral@terraroot.pt, which arrives in the
same place and is read by the same person.
Until 16 August 2026 there was one exception, and it is worth
stating rather than deleting: the typefaces (Fraunces and
Hanken Grotesk) were served by Google Fonts. They set no cookies and
identified nobody, but every visit made a request to Google's servers, which saw
the IP address of whoever was reading. They were moved to our own domain
precisely so that request would stop happening.
If measuring visits ever becomes necessary, it will be with a tool that uses no
cookies and identifies nobody — and if that is not possible, with proper prior
consent: the script loads only after acceptance, and refusing is as easy as
accepting. Measuring audiences is not the same thing as stopping abuse of a form,
and it does not get in through the door the check opened.
Your rights
The data is yours. The GDPR gives you the following rights over it, and they are
all exercised the same way: an email to
geral@terraroot.pt.
- Access — knowing what data of yours is held here and receiving a copy of it.
- Rectification — correcting anything wrong or incomplete.
- Erasure — asking for it to be deleted (the “right to be forgotten”).
- Restriction — asking for it to be kept but no longer used, while something is being resolved.
- Portability — receiving your data in an open, machine-readable format, to take wherever you want.
- Objection — objecting to the processing, on grounds relating to your particular situation.
- Withdrawal of consent — at any time, without having to justify it. Withdrawing it does not make unlawful what was done beforehand on the basis of it.
Complaining to the CNPD
If you think your data is not being handled as it should be, write to us first —
most situations are settled in one email. But you are not obliged to: you have the
right to complain directly to the Portuguese supervisory authority, under Article
77 GDPR and Portuguese Law 58/2019.
- Authority
- Comissão Nacional de Proteção de Dados (CNPD)
- Address
- Av. D. Carlos I, n.º 134, 1.º, 1200-651 Lisboa, Portugal
- Phone
- (+351) 213 928 400
- Email
- geral@cnpd.pt
- Website
- www.cnpd.pt
The CNPD is the competent authority because the controller is established in
Portugal — that holds wherever in the world you are writing from.
Language of this policy
This English version exists so that people outside Portugal can read it in a
language they work in. It describes exactly the same processing as the original.
The Portuguese version is the binding one. Where there is any
difference between the two, it is the Portuguese text that governs. Portuguese
law applies and the controller is established in Portugal.
The original is at
terraroot.pt/politica-de-privacidade.
Changes to this policy
This policy is revised whenever the site changes in a way that affects your data —
a new form field, a different supplier, a tool coming in. The date below is the
date of the last real change to the text, not today's date generated by a program.
Last updated: 7 September 2026