Skip to main content

Privacy Policy

In short: Temise is operated by CRIATOPO - PUBLICIDADE UNIPESSOAL LDA, a Portuguese company. We use your personal data to run the platform: to publish your service request, to automatically invite companies that cover that service and area, to deliver quotes and messages, and to confirm awards. A client's contact details stay hidden from companies until a win is confirmed; a company's identity stays masked from the client until the same moment. Companies see only a blind rank ("#2 of 3"), never the other quotes' prices. We do not sell your personal data and we do not use it for third-party advertising. You can ask for a copy of your data, correct it, delete it, or object to how we use it, at any time, by email at contact@temise.com or through our contact page.

Last updated: 26 August 2026

1. Who is responsible for your personal data

1.1. The controller of the personal data described in this policy is:

  • CRIATOPO - PUBLICIDADE UNIPESSOAL LDA (sole-shareholder private limited company, incorporated in Portugal)
  • VAT / NIF: PT513690689
  • Commercial registry number: [commercial registry number] — Conservatória do Registo Comercial de [registry office]
  • Share capital: [share capital]
  • Registered office: Rua 1 de Maio n.º 273 B, Bairro Vale do Forno, 2675-256 Odivelas, Portugal
  • Trading as: Temise — temise.com (temise.pt for Portugal)

1.2. In this policy, "Temise", "we", "us" and "our" mean CRIATOPO - PUBLICIDADE UNIPESSOAL LDA. "You" means any person whose personal data we process: a client, a company (or a person acting for a company), or a visitor.

1.3. The way to reach us on any privacy matter is our contact page. Please mark your message "Data protection" so it is routed to the right person. We also use the contact page as our single point of contact for the purposes of Articles 11 and 12 of Regulation (EU) 2022/2065 (the Digital Services Act).

1.4. Data Protection Officer. We have assessed Article 37 GDPR and we have not appointed a Data Protection Officer, because our processing does not consist of large-scale regular and systematic monitoring of data subjects or large-scale processing of special categories of data. If that changes, we will appoint one and update this policy. [Confirm this assessment before launch and record it in writing.]

2. What this policy covers — and what it does not

2.1. This policy applies to the Temise websites (temise.com, temise.pt and their subdomains), to the emails and notifications we send, and to any offline handling of the same data by us.

2.2. Temise is an intermediation platform. The service contract is concluded exclusively between the client and the company. We are not a party to it, we do not perform the services, and we do not employ or control the companies.

2.3. This has a direct privacy consequence. When a win is confirmed and we reveal mutual contact details, the client and the company each become an independent controller of the data they then receive about the other. From that moment, how the company uses the client's address, phone number and job details — and how the client uses the company's details — is governed by their own privacy practices, not by this policy. If you have a question about what a company did with your data after the award, contact that company; we will help you identify it if you ask us.

2.4. This policy does not cover third-party websites you reach through links on Temise.

3. The roles we process data for

3.1. Visitors. Anyone browsing Temise without an account, including people reading public company profiles, portfolios and reviews.

3.2. Clients. Consumers or businesses who post a service request, receive quotes and accept one.

3.3. Companies (business users). Service providers who register a profile, receive invitations, submit quotes and confirm wins. Data about a company is not always personal data — but it usually contains some: the name and contact details of the owner, manager or staff member using the account, and, in the case of a sole trader (empresário em nome individual), essentially all of the company's identifying data.

3.4. Other people who contact us, report a suspicious request, submit a notice under the DSA, or are named in content someone else uploads.

4. What personal data we collect

4.1. Account data (clients and companies)

  • Name and, for companies, business name, NIF/VAT number and legal form.
  • Email address, password (stored only as a one-way hash, never in readable form), phone number where you provide one.
  • Address or, for clients, at least the city or area where the service is needed.
  • For companies: the services covered (from our list of approximately 190 services in 22 categories), the geographic areas served, profile description, logo, opening details and any other information you choose to publish.
  • Account settings, notification preferences, language, and the record of the terms you accepted and when.

4.2. Service request data (clients)

  • The service and category chosen, and the answers you give in the category-specific form fields — these differ per service and can include, for example, dimensions and floor of a property, number of rooms, vehicle type and registration category, pick-up and delivery locations, weight or volume, number of guests, event type, and similar operational details.
  • City or location of the job, desired date or period, and any conditions or free-text description you add.
  • Photos or files you attach to the request, if the form allows it.
  • The status and lifecycle of the request: when it was published, which companies were invited, when it was closed, whether it was frozen after reports, and whether it auto-closed.

Please only include what is needed. The free-text fields are seen by the companies invited to quote. Do not put your full address, phone number, email, ID or payment details in them — we reveal your contact details automatically at the right moment (see section 8). Do not include health data, data about your beliefs, or other special categories of data (Article 9 GDPR) unless it is genuinely necessary for the job; we do not ask for it and we do not want it.

4.3. Quote, ranking and messaging data (companies and clients)

  • Quote amount, currency, validity, and the message the company writes to the client. Submitting a quote is free of charge.
  • The blind rank we calculate and show the company ("#2 of 3") — the company never sees the other quotes' amounts.
  • Messages exchanged through the platform between a client and a company, including timestamps and attachments.
  • For transport services: Return Routes published by a company — origin, destination, dates, free capacity and vehicle details — and the matches generated against them.

4.4. Award and transaction data

  • Acceptance of a quote by the client, the 48-hour confirmation window, and the company's confirmation or failure to confirm.
  • The numbered award confirmation we issue: an immutable snapshot of the agreed scope, price, parties and timestamps. It is a record of what was agreed on the platform; it is not a contract and it does not replace an invoice.
  • Success fee data: the fee tier applied (€2.99 / €7.99 / €14.99 / €24.99 by job value; €0 during the launch period, and the first win is always free), the amount charged, invoice data, and — once we introduce payments — the payment status and the reference given to us by the payment provider. We do not store full card numbers.
  • Tax and reporting identifiers we are required to collect from companies (see section 7.3 on DAC7): name, address, NIF/TIN, VAT number, business registration number, and, where applicable, financial account identifier and the consideration paid.

4.5. Reviews and reputation data

  • Star rating and written review, which only a client with an awarded job can leave; the company's public reply, if it writes one.
  • The company's average rating and its "N jobs won" counter, which is calculated automatically from confirmed awards.

4.6. Portfolio images (companies)

Photos uploaded by a company to illustrate work it has actually won, up to 3 images per service. These are processed as described in section 6.

4.7. Technical, device and log data (everyone, including visitors)

  • IP address, approximate location derived from it (country/region level), date and time of requests, pages and URLs requested, referrer, HTTP status and response size.
  • Browser and device information: user agent, operating system, language, screen characteristics reported by the browser.
  • Session identifiers, authentication tokens, error and security logs, and records of failed log-in attempts.
  • Cookies and similar technologies — see section 15.

4.8. Trust, safety and moderation data

  • Reports submitted by companies about suspicious requests (free of charge; two independent reports freeze a request pending review), notices submitted under Article 16 DSA, and the outcome of our review.
  • Statements of reasons we issue when we remove content or restrict an account (Article 17 DSA), internal complaints and appeals (Article 20 DSA; Article 11 of Regulation (EU) 2019/1150), and correspondence about them.
  • Records related to fraud, abuse, non-payment or breach of our terms.

4.9. Communications

Messages you send us through the contact page, support tickets, complaints, and our replies. If you consent, your marketing preferences and whether you opened or clicked our marketing emails.

5. Where your data comes from

5.1. From you — almost everything above.

5.2. Generated by the platform — matching results, blind ranks, jobs-won counters, award confirmation numbers, logs.

5.3. From other users — a review a client writes about a company; a report a company files about a request; a message the other party sends you.

5.4. From official public sources — for companies only, we may verify the VAT/NIF number against the European Commission's VIES service and check public commercial registry information, to confirm that a business account is genuine. [Confirm the exact verification sources used in production.]

6. Portfolio images and automated logo removal

6.1. A company may publish photographs of work it has won, up to 3 images per service. Portfolio images are public: anyone can see them on the company's profile, and search engines can index them.

6.2. What happens to an image after upload, in plain terms:

  1. You upload the photo to Temise.
  2. We send it to an automated image-processing service, which uses a third-party artificial-intelligence model, for one purpose: to detect and remove visible logos, brand names and watermarks from the picture. This keeps the public directory neutral and avoids publishing other people's trade marks.
  3. The processed image comes back to us, is converted to WebP format (a compressed web image format) and resized for the web.
  4. The final image is stored on our own server, located in the European Union, and published on the company's profile.

6.3. The image-processing provider acts as our processor: it processes the image only on our instructions, under a data processing agreement that meets Article 28 GDPR. We require it not to use uploaded images to train its own or third-party models. [Confirm this restriction in the provider's contract/DPA before launch, and record the provider's name and place of establishment in section 9.]

6.4. The removal is automatic and is not perfect. It targets visible logos and branding. It does not reliably remove faces, vehicle number plates, house numbers, street signs, documents, screens or anything else that could identify a person or a property. You are responsible for what you upload: do not upload images showing identifiable people without their consent, do not upload images that reveal a client's address or private premises without permission, and do not upload images you do not have the right to publish.

6.5. We may keep the original, unprocessed upload for a limited period so that we can handle moderation, complaints and appeals, after which it is deleted. [Confirm the retention period for original uploads — see section 12.]

6.6. You can delete a portfolio image from your profile at any time. Copies may remain in our backups for a short period (section 12) and may persist in third-party search engine caches, which we do not control.

7. Why we use your data, and our legal bases

7.1. We only process personal data where we have a legal basis under Article 6 GDPR. The table below sets out the main purposes.

PurposeMain data usedLegal basis
Creating and managing your account; giving you access to the platform; authentication Account data (4.1), technical data (4.7) Performance of a contract — Art. 6(1)(b) GDPR (our Terms of Use with you)
Publishing your request and automatically matching and inviting companies whose profile covers that service and area, including matching against published Return Routes Request data (4.2), company profile data (4.1) Art. 6(1)(b) — this is the core of the service you asked for; and Art. 6(1)(f) legitimate interest in operating and refining an effective matching system
Collecting and delivering quotes; calculating and showing the blind rank; masking company identity and client contact details until confirmation Quote data (4.3) Art. 6(1)(b), and Art. 6(1)(f) legitimate interest in a fair marketplace where bidders cannot see each other's prices and users are not contacted outside the platform
Handling acceptance, the 48-hour confirmation window, revealing mutual contact details and issuing the numbered award confirmation Award data (4.4) Art. 6(1)(b)
Charging the success fee and issuing invoices Award data, billing data (4.4) Art. 6(1)(b) for charging; Art. 6(1)(c) legal obligation for invoicing and bookkeeping
Tax reporting on platform sellers under Council Directive (EU) 2021/514 (DAC7), as transposed into Portuguese law Company identification and consideration data (4.4) Art. 6(1)(c) legal obligation
Publishing reviews, star ratings, company replies and the jobs-won counter Review data (4.5) Art. 6(1)(b) and Art. 6(1)(f) legitimate interest in a trustworthy marketplace where reputation is based on real, awarded jobs
Publishing portfolio images and removing visible logos/branding automatically Portfolio images (4.6) Art. 6(1)(b) and Art. 6(1)(f) legitimate interest in a neutral directory and in respecting third-party trade marks
Preventing and detecting fraud and abuse; handling reports of suspicious requests; freezing a request after two independent reports; content moderation and notice-and-action Trust and safety data (4.8), technical data (4.7) Art. 6(1)(f) legitimate interest in protecting users and the platform; Art. 6(1)(c) where the DSA imposes the duty
Platform security, availability, backups, incident detection and response Technical and log data (4.7) Art. 6(1)(f) legitimate interest in security; Art. 6(1)(c) read with Art. 32 GDPR
Measuring and improving the service; aggregate statistics; debugging Technical data, usage data Art. 6(1)(f) legitimate interest in improving our own service (analytics cookies, where used, additionally require your consent — section 15)
Service messages: request invitations, quote notifications, acceptance and confirmation alerts, deadline reminders, security and account notices Account data, request and quote data Art. 6(1)(b) — these are not marketing and cannot be switched off entirely while your account is open, although you can adjust some categories in your settings
Marketing emails and newsletters about Temise Email address, preferences Consent — Art. 6(1)(a) GDPR and Art. 13-A of Decreto-Lei 7/2004; you can withdraw at any time via the unsubscribe link or the contact page
Non-essential cookies and similar technologies Cookie and device identifiers Consent — Art. 5(3) of Directive 2002/58/EC as implemented by Art. 5 of Lei 41/2004
Handling support requests, consumer complaints, the Livro de Reclamações Eletrónico, and internal complaint handling for business users under Art. 11 of Regulation (EU) 2019/1150 Communications (4.9), account and transaction data Art. 6(1)(b), Art. 6(1)(c) and Art. 6(1)(f)
Establishing, exercising or defending legal claims; responding to authorities and courts Any relevant data Art. 6(1)(f) legitimate interest, and Art. 6(1)(c) where we are legally required

7.2. Legitimate interests. Where we rely on legitimate interest, we have weighed our interest against your rights and freedoms. You can ask us for a summary of that assessment through the contact page, and you can object at any time (section 13).

7.3. DAC7. Council Directive (EU) 2021/514 requires operators of platforms that facilitate the provision of relevant services to collect, verify and report information about their sellers to the tax authority, which then exchanges it with other Member States. Where this applies to Temise, we must collect the identification data listed in 4.4 from companies, verify it, and report it annually. If a company does not provide the required data, we may be legally required to restrict or close its account. [Confirm the scope of DAC7 for Temise's model — in particular whether it applies while Temise does not process payment of the consideration between client and company — and cite the Portuguese transposing instrument.]

7.4. Special categories of data. We do not intend to process data revealing health, religious or philosophical beliefs, trade union membership, political opinions, sexual life or biometric data. If such data appears in a free-text field or an image, we process it only to the extent necessary to run the service you asked for or to defend legal claims (Art. 9(2)(f) GDPR), and we may remove it.

8. Who sees what on Temise

8.1. This is the part of the service most people ask about, so we set it out precisely. Temise is designed so that neither side can bypass the platform before a job is awarded.

DataWho can see itFrom when
The content of a service request: category-specific fields, city, conditions, desired date, description and attachments Temise, and the companies invited or eligible to quote for that service and area As soon as the request is published
The client's name, email, phone number and exact address Not visible to any company. Visible only to Temise — and then to the winning company alone Only after the client accepts a quote and the company confirms within 48 hours
The amount of each quote Only the client, and Temise As soon as the quote is submitted. Competing companies never see it
A company's position among the quotes That company only, as a blind rank ("#2 of 3") without any prices While the request is open
The identity of a quoting company Shown to the client in masked form — for example "C*****o" — together with the star rating and jobs-won count Revealed in full to the client when the win is confirmed
Company public profile: business name, services, areas, description, logo, portfolio images, reviews, average rating, jobs-won counter Everyone, including visitors who are not registered and search engines Always, while the profile is published
A review and star rating you write as a client, and the company's public reply Everyone — reviews are public and shown under the display name configured for your account [confirm the display format used] On publication
Messages between a client and a company The two parties, and Temise staff where needed for moderation, support, safety or legal reasons When sent
A report of a suspicious request Temise only. We do not disclose the reporting company's identity to the reported user unless we are legally required to When submitted
The numbered award confirmation The client and the awarded company On confirmation of the win

8.2. A request is open for 7 days and auto-closes 72 hours after that with no decision. Requests that are closed or expired stop being visible to companies, but we keep them as described in section 12.

8.3. If we introduce protected payment (escrow). We may introduce a service where the client's funds are held by a licensed payment provider and released when delivery is confirmed. If we do, the payment provider will receive the data it needs to run the payment and to meet its own anti-money-laundering obligations, and it will act as an independent controller for that. We will update this policy before that feature goes live.

9. Who else receives your data

9.1. Our own people. Authorised staff and contractors of CRIATOPO, on a need-to-know basis and under confidentiality obligations.

9.2. Processors acting on our instructions, under written data processing agreements meeting Article 28 GDPR:

Type of recipientWhat it doesWhere
Hosting / infrastructure provider Runs the virtual private server on which the Temise application, database and uploaded files are stored the operator's own dedicated server infrastructure — data centre in the European Union, Lithuania (EU)
Email delivery provider Sends transactional and notification emails (invitations, quote alerts, confirmations) and, where you consented, marketing emails contact@temise.com
Automated image-processing service (third-party AI model) Receives uploaded portfolio images and removes visible logos and branding before publication (section 6) Google Ireland Limited (Gemini API), Ireland
Payment service provider Will process success-fee payments and, if introduced, protected payments. Not yet active while the success fee is €0 [payment provider name and place of establishment]
Error monitoring / analytics tools Help us detect faults and understand aggregate usage, where such tools are used [list any such tools, or state that none are used]

9.3. Other users of the platform, strictly as described in section 8.

9.4. Professional advisers — our accountant, auditors and lawyers, bound by professional secrecy.

9.5. Public authorities, where we are legally required or where it is necessary to defend legal claims: the Portuguese tax authority (including DAC7 reporting), the CNPD, courts, police and judicial authorities, the consumer authority (ASAE / DGC), and the authorities and the European Commission under the Digital Services Act. Statements of reasons for content removals are submitted to the European Commission's DSA Transparency Database, in the anonymised form required by Article 24(5) DSA.

9.6. In a corporate transaction — if the business is transferred, merged or restructured, data may pass to the acquirer, who must respect this policy or notify you of any change.

9.7. We do not sell your personal data, we do not rent it, and we do not share it with third parties for their own advertising.

10. International transfers

10.1. Our servers are located in the European Union, and we aim to keep your data within the European Economic Area (EEA).

10.2. Some providers — in particular for email delivery and for the AI-based image-processing service — may operate, or use sub-processors, outside the EEA. Where that happens, the transfer takes place only if one of the safeguards in Chapter V GDPR is in place:

  • an adequacy decision of the European Commission for the destination country; or
  • the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914), together with a transfer impact assessment and any supplementary technical and organisational measures that assessment requires.

10.3. You can ask us for a copy of the safeguards applied to a specific transfer, or for the current list of our sub-processors, through the contact page.

11. Automated decision-making, matching and profiling

11.1. Matching is automated, and we want you to know exactly what it does. When a request is published, our system compares it against company profiles and selects the companies to invite, using objective parameters: the service and category requested, the services declared by the company, the geographic areas the company covers, the company's account status, and — for transport requests — whether the request matches a published Return Route (a trip with free capacity), which gives those companies priority in the invitation. Up to 3 companies can then submit quotes.

11.2. The blind rank ("#2 of 3") shown to a company is also calculated automatically, from the quotes received.

11.3. These automated operations do not produce legal effects concerning you, and do not similarly significantly affect you within the meaning of Article 22(1) GDPR. They determine which businesses are invited to quote for a job; they do not decide anything about a person's rights, access to services, credit, employment or finances. We do not carry out profiling with legal or similarly significant effects, we do not score individuals, and we do not build behavioural advertising profiles.

11.4. Decisions that could affect you meaningfully — removing content, freezing a request after two independent reports, suspending or terminating an account — are reviewed by a person before they become final wherever we can, and automated tools are used only to flag cases for that review. If we take such a measure we give you a statement of reasons and you can challenge it through our internal complaint-handling system (Article 20 DSA; Article 11 of Regulation (EU) 2019/1150), through an out-of-court dispute settlement body, or in court.

12. How long we keep your data

12.1. We keep personal data only as long as we need it for the purposes in section 7, or as long as the law requires.

DataRetention
Account dataWhile the account is open, and for 24 months after you close it, so that we can handle disputes, abuse and re-registration checks
Requests, quotes, blind ranks and platform messages5 years from the closure of the request, to evidence and defend claims arising from the transaction
Award confirmations5 years — they are immutable records of what was agreed and cannot be edited after issue
Invoices and accounting records10 years, as required by Portuguese law (Article 40 of the Código Comercial; Article 52 of the Código do IVA)
DAC7 seller records and reportsFor the period required by the Portuguese instrument transposing Directive (EU) 2021/514 [confirm the exact period]
Reviews, ratings and company repliesPublished while the company profile exists. If the reviewing client closes their account, we anonymise the reviewer's display name and keep the rating [confirm the chosen approach]
Portfolio images (published)Until the company deletes them or the account is closed
Portfolio images (original, unprocessed upload)they are not retained: the original upload is discarded once the processed WebP image is stored for moderation and appeals, then deleted
Server, security and access logs, including IP addresses12 months
Moderation records, reports, notices, statements of reasons and appeals3 years to meet DSA record-keeping and transparency duties
Marketing consent and marketing dataUntil you withdraw consent; we then keep the proof of consent and of its withdrawal for [retention period] to demonstrate compliance
Support and complaint correspondence3 years from closure of the matter
CookiesSee section 15 — each cookie has its own lifetime
BackupsDeleted data can persist in encrypted backups for up to 30 days, after which the backup is overwritten

12.2. Where data is needed to establish, exercise or defend a legal claim, or to comply with a legal obligation, we keep it until that need ends, even if a period above has expired.

12.3. Instead of deleting, we may irreversibly anonymise data and keep it as statistics. Anonymised data is no longer personal data.

13. Your rights

13.1. Under the GDPR and Lei 58/2019 you have the right to:

  • Access — be told whether we process your data and get a copy of it (Art. 15).
  • Rectification — have inaccurate data corrected and incomplete data completed (Art. 16). Most account and profile data you can correct yourself in your settings.
  • Erasure — have your data deleted where one of the grounds in Art. 17 applies. This right is not absolute: we may have to keep invoices, DAC7 records, award confirmations or moderation records for the legal periods in section 12.
  • Restriction — have processing limited while a dispute about accuracy or lawfulness is resolved (Art. 18).
  • Portability — receive the data you gave us, in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible (Art. 20).
  • Objection — object at any time, on grounds relating to your particular situation, to processing based on our legitimate interest (Art. 21(1)); and object at any time, with no need for a reason, to direct marketing (Art. 21(2)), which we will always respect immediately.
  • Withdraw consent — at any time, where processing is based on consent (Art. 7(3)). Withdrawal does not affect the lawfulness of what we did before.
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Art. 22) — see section 11.
  • Be informed of a personal data breach likely to result in a high risk to your rights (Art. 34).

13.2. How to exercise them. Send us a request through the contact page, saying which right you want to exercise. We may ask for information to confirm your identity, so that we do not disclose your data to someone else. We reply within one month; if the request is complex or you have made several, we may extend by up to two further months and we will tell you why within the first month.

13.3. Exercising your rights is free. We may charge a reasonable administrative fee, or refuse to act, only where a request is manifestly unfounded or excessive, in particular because it is repetitive (Art. 12(5) GDPR) — and we will explain why.

13.4. Deleting your account does not automatically delete a public review you wrote or a job record needed for the other party's accounting; tell us what you want removed and we will explain what we can and cannot delete, and why.

14. Complaints

14.1. If you think we have mishandled your data, please tell us first through the contact page — most issues are resolved quickly.

14.2. You also have the right to lodge a complaint with the Portuguese supervisory authority:

  • Comissão Nacional de Proteção de Dados (CNPD)
  • Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, Portugal
  • https://www.cnpd.pt/

14.3. If you live in another EU or EEA country, you may instead complain to the supervisory authority of your habitual residence or place of work. You also have the right to an effective judicial remedy (Arts. 78 and 79 GDPR).

14.4. Complaints that are not about data protection — for example about our own service as a consumer — are handled under our Terms of Use, which explain the Livro de Reclamações Eletrónico (https://www.livroreclamacoes.pt/), consumer arbitration under Lei 144/2015, and the EU online dispute resolution platform ().

15. Cookies and similar technologies

15.1. Cookies are small files stored on your device. Under Article 5 of Lei 41/2004, we may store or read strictly necessary cookies without your consent; everything else requires your prior consent, which we ask for through the cookie banner.

CategoryWhat it doesConsent needed?
Strictly necessaryKeeps you logged in, remembers your session and basket of actions, protects forms against cross-site request forgery, load balancing, and records your cookie choiceNo
FunctionalRemembers preferences such as language, region and display settingsYes
Analytics / performanceAggregate statistics on how the site is used, so we can improve itYes
MarketingMeasuring campaigns or showing you Temise ads elsewhere, if we ever use themYes

15.2. You can change or withdraw your cookie consent at any time through the cookie settings link on the site, and you can block or delete cookies in your browser. Blocking strictly necessary cookies will stop parts of Temise from working — you will not be able to stay logged in.

15.3. [Insert the detailed cookie list — name, provider, purpose, lifetime — generated from the live site, or link to a separate Cookie Policy page once it exists.]

16. How we protect your data

16.1. We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR), including: encrypted connections (HTTPS/TLS) across the site; passwords stored only as one-way hashes; role-based access control and least-privilege access for staff; a firewalled server in the EU with restricted administrative access; regular software updates; logging and monitoring; and regular backups.

16.2. No online service can promise absolute security, and we do not. We do not claim any security certification, and we do not hold insurance covering your data unless we tell you otherwise in writing. Keep your password confidential and use a unique one.

16.3. If a personal data breach occurs, we will notify the CNPD within 72 hours where Article 33 GDPR requires it, and we will inform you directly where the breach is likely to result in a high risk to your rights and freedoms.

17. Children

17.1. Temise is not intended for children. You must be at least 18 years old and have full legal capacity to create an account, post a request, or submit a quote.

17.2. We do not knowingly collect personal data from anyone under 18. If we learn that an account belongs to a minor, we will close it and delete the associated data, except what we must keep by law. If you believe a minor has given us data, tell us through the contact page and we will act promptly.

17.3. Please do not include personal data about children in a request, a message or a photograph unless it is genuinely necessary for the job.

18. Changes to this policy

18.1. We may update this policy when the platform, our providers or the law change. The "Last updated" date at the top always shows the current version.

18.2. If a change materially affects how we use your data, we will notify registered users by email or through the platform before it takes effect. For business users, changes to the terms governing our relationship are notified at least 15 days in advance, in line with Article 3 of Regulation (EU) 2019/1150, and longer where technical or commercial adaptations are needed.

18.3. If a change requires your consent, we will ask for it separately. Continuing to use Temise after a non-consent-based change means the updated policy applies.

19. Contact

19.1. For any question about this policy, to exercise your rights, or to reach our data protection contact, use the Temise contact page. It is the fastest route to us and it is monitored.

19.2. Postal address for formal notices: CRIATOPO - PUBLICIDADE UNIPESSOAL LDA, Rua 1 de Maio n.º 273 B, Bairro Vale do Forno, 2675-256 Odivelas, Portugal.