bikesul Privacy Policy

Personal Data

BIKESUL, UNIPESSOAL LDA respects the privacy of its Customers and adopts technical and organisational measures designed to protect the personal data provided to it.

This Privacy Policy explains which personal data is processed by BIKESUL, the purposes for which it is used, how long it is retained, with whom it may be shared, and how you can exercise your rights.

These rules complement the data protection provisions set out in the contracts entered into between Customers and BIKESUL.

Data Controller

The entity responsible for collecting and processing personal data is:

BIKESUL, UNIPESSOAL LDA
Legal entity no. 509 739 512
Rua Cândido dos Reis, No. 62
8375-105 São Bartolomeu de Messines
Portugal

For questions relating to privacy and data protection, you may contact BIKESUL through the following channels:

Email: [email protected]
Address: Rua Cândido dos Reis, No. 62, 8375-105 São Bartolomeu de Messines, Portugal

Personal Data Processed

In the course of its activities, BIKESUL collects and processes the personal data necessary to manage its Customers, sell products and provide its services.

Depending on the product or service requested, the following data may be processed:

  • Full name.
  • Email address.
  • Telephone number.
  • Tax identification number (NIF).
  • Address.
  • City.
  • Postal code.
  • Country.
  • Date of birth.
  • Type of identification document.
  • Identification document number.
  • Document expiry date.
  • Country of issue of the document.
  • Data required for invoicing and payment processing.
  • Information relating to products purchased.
  • Information about bicycles owned or used by the Customer.
  • Service orders, repairs, maintenance and work carried out.
  • Bookings, rentals, tours and other contracted services.
  • Contracts, quotations, communications, requests, complaints and history of the commercial relationship.
  • Preferences regarding commercial communications.
  • Technical and security records relating to access to and use of BIKESUL’s systems.

BIKESUL only collects data that is adequate, relevant and necessary for each specific purpose.

The NIF, address and identification document details may be requested when necessary to issue tax documents, prepare or perform contracts, carry out rentals, organise tours, confirm the Customer’s identity or comply with other obligations associated with the service.

Some personal data is mandatory. The absence or insufficiency of such data may prevent BIKESUL from preparing the contract, issuing the relevant documentation, making the product available or providing the requested service.

Where applicable, the Customer will be informed of the mandatory nature of providing such data.

Purposes of Processing

The personal data collected may be used for the following purposes:

  • Creating and managing the Customer’s record.
  • Responding to information or contact requests.
  • Preparing quotations and proposals.
  • Preparing, entering into and performing contracts.
  • Processing product sales.
  • Managing bookings, rentals, tours and other activities.
  • Registering bicycles and information necessary to provide the services.
  • Creating and managing workshop service orders.
  • Monitoring repairs, maintenance, warranties and complaints.
  • Issuing invoices, receipts and other accounting documents.
  • Processing payments.
  • Managing the commercial relationship and Customer support.
  • Complying with tax, accounting, administrative and legal obligations.
  • Preventing fraud, unauthorised access and misuse of systems.
  • Maintaining security and audit records.
  • Investigating incidents relating to personal data or IT systems.
  • Exercising or defending BIKESUL’s rights in judicial or extrajudicial proceedings.
  • Sending newsletters, campaigns, information about products, services, events and other commercial communications where there is a valid legal basis.
  • Producing statistics and improving products, services, internal processes and Customer service, preferably using aggregated or anonymised data.

If personal data is requested for a purpose other than those listed in this Policy, the necessary information will be provided at the time the data is collected.

The processing of personal data may be based on:

  • Taking steps requested by the Customer prior to entering into a contract.
  • Entering into and performing a contract.
  • Compliance with legal obligations applicable to BIKESUL.
  • BIKESUL’s legitimate interests in managing its business, providing Customer support, protecting its systems, preventing fraud, ensuring information security and defending its rights.
  • The Customer’s consent, where legally required.

Consent will not be requested for processing that is necessary for the preparation or performance of contracts or compliance with legal obligations.

Commercial Communications

BIKESUL may use contact details to send information about products, services, campaigns, events, news and other commercial communications where there is a valid legal basis.

Where communication depends on consent, BIKESUL will retain the information necessary to demonstrate when, where and how such consent was given.

You may object to the use of your data for direct marketing or unsubscribe from commercial communications at any time by using the option provided in the messages received or by contacting [email protected].

Unsubscribing from commercial communications does not prevent the sending of messages necessary for the performance of contracts, bookings, repairs, rentals, payments or other requested services.

Internal Access to Data

Personal data will only be made available to employees who need it to perform their respective duties.

Access rights are defined according to the employee’s role, department, type of information and the operations that each employee is authorised to perform.

Tax, contractual and identification data are subject to more restricted access and may only be consulted by employees who need such information for invoicing, contract preparation, rentals, tours, bookings or other related services.

BIKESUL may maintain records of consultations, changes, exports, printouts and other actions carried out in its systems. These records are intended to ensure information security, investigate incidents and monitor the use of personal data.

All authorised employees are subject to confidentiality obligations and internal rules regarding the use of systems and the processing of personal data.

Disclosure of Data and External Entities

In the course of its activities, BIKESUL may engage external entities to provide services necessary for its operations.

The provision of such services may involve access to or processing of Customers’ personal data by the following categories of entities:

  • Hosting, server, database, backup and technology infrastructure providers.
  • Developers and companies responsible for the development, maintenance, updating and support of applications used by BIKESUL.
  • IT support, cybersecurity, monitoring and systems protection providers.
  • Invoicing, accounting and auditing service providers.
  • Payment processing service providers.
  • Email, SMS and other communications service providers.
  • Booking and operational management platforms.
  • Insurers, operational partners and suppliers necessary for the provision of rentals, tours, bookings or other requested services.
  • Lawyers, consultants and other professionals providing assistance to BIKESUL.
  • Tax, administrative, police, judicial or regulatory authorities, where disclosure is required by law or results from a legitimate request.

Entities processing personal data on behalf of BIKESUL may only do so in accordance with the company’s documented instructions and for the purposes established in the relevant contract.

Such entities are subject to confidentiality, security, purpose limitation, incident notification, control of other suppliers, and data deletion or return obligations at the end of the service provision.

Whenever possible, access by developers and technical service providers to the live database will be limited, temporary, authorised and logged. Development and testing environments should use fictitious or anonymised data whenever technically possible.

BIKESUL maintains an up-to-date internal record of external entities that may process personal data, the services provided, the categories of data processed, the location of processing and the applicable contracts.

Other Suppliers Used by Subcontracted Entities

Entities contracted by BIKESUL may not allow other suppliers, developers or subcontractors to access personal data without the authorisation required by applicable law and the contractual conditions established.

Where the use of another subcontractor is authorised, that subcontractor will be subject to data protection obligations equivalent to those assumed by the entity initially contracted.

International Data Transfers

BIKESUL seeks to use suppliers that process and store personal data within the European Economic Area.

If any supplier processes or stores data in a country outside the European Economic Area, BIKESUL will ensure that the transfer is based on a valid legal mechanism, such as an adequacy decision or Standard Contractual Clauses approved by the European Commission.

Where necessary, additional measures will be implemented to ensure an adequate level of data protection.

You may request information about the applicable safeguards by contacting [email protected].

Data Interconnection

BIKESUL does not interconnect personal data with databases belonging to other entities for the purposes of creating profiles, making automated decisions or using the data for purposes other than those for which it was originally collected.

The use of technology, accounting, operational or support service providers does not, in itself, constitute data interconnection, provided that such entities process the information solely to provide the contracted services and in accordance with BIKESUL’s instructions.

Data Retention Period

The period for which personal data is stored varies according to the purpose of processing, the duration of the contractual relationship, applicable legal obligations and the periods necessary to defend legal rights.

Where there is no specific legal retention period, data will only be retained for as long as necessary to fulfil the purposes for which it was collected or processed.

In particular:

  • Contractual and operational data will be retained throughout the Customer relationship and for the additional period necessary to comply with legal obligations or defend rights.
  • Tax, accounting and invoicing data will be retained for the period established by applicable legislation.
  • Identification document data will only be retained for the period necessary to prepare and perform the contract and comply with associated obligations, unless there is a legal obligation or documented need for further retention.
  • Data relating to quotations or requests that do not result in a contract will be retained for the period defined by BIKESUL for following up on the request and defending its rights.
  • Data relating to commercial communications will be retained for as long as there is a legal basis for sending such communications and for the period necessary to demonstrate compliance with applicable obligations.
  • Security and audit records will be retained for the period considered necessary to prevent, detect and investigate incidents.

At the end of the applicable retention period, the data will be securely deleted or irreversibly anonymised.

The deletion of data contained in backups may take place according to the relevant technical retention cycle. Until permanent deletion, such data will remain protected and will not be used for other purposes.

Information Security

BIKESUL is committed to protecting the security, confidentiality, integrity and availability of the personal data entrusted to it.

For this purpose, appropriate technical and organisational measures are adopted according to the level of risk, including:

  • Access controls based on employees’ roles.
  • Use of individual accounts.
  • Restricted access to tax, contractual and identification data.
  • Enhanced authentication where applicable.
  • Password protection.
  • Encryption during transmission and storage, where applicable.
  • Logging of access and actions carried out in the systems.
  • Restrictions on exports, printouts and copies.
  • Protection and control of backups.
  • Updating systems and applications.
  • Revocation of access when an employee or service provider no longer requires it.
  • Procedures for identifying, reporting and managing incidents.
  • Training and internal rules for employees.
  • Confidentiality and data protection agreements with external service providers.

No data transmission or storage system is completely risk-free. If a personal data breach occurs, BIKESUL will assess the incident, take containment measures and comply with the legal obligations relating to documentation, notification to the supervisory authority and communication to data subjects, where applicable.

Data Subjects’ Rights

Under applicable legislation, you may request:

  • Access to your personal data.
  • Rectification of inaccurate or incomplete data.
  • Updating of your data.
  • Erasure of your data where the legal requirements are met.
  • Restriction of processing.
  • Data portability, where applicable.
  • Objection to processing based on legitimate interests.
  • Objection, at any time, to the use of data for direct marketing.
  • Withdrawal of consent where processing is based on consent.

Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.

The exercise of certain rights may be limited where BIKESUL is required to retain data to comply with a legal obligation, perform a contract, defend its rights or protect the rights of third parties.

The exercise of rights is free of charge, except where requests are manifestly unfounded or excessive, particularly due to their repetitive nature, as permitted by applicable legislation.

To exercise your rights, you should submit your request using the following contact details:

Email: [email protected]
Address: Rua Cândido dos Reis, No. 62, 8375-105 São Bartolomeu de Messines, Portugal

To protect personal data, BIKESUL may request additional information to confirm the identity of the person making the request.

BIKESUL will respond to the request within the applicable legal deadline.

Complaints

If you believe that your personal data is not being processed in accordance with applicable legislation, you may contact BIKESUL at [email protected].

You also have the right to lodge a complaint with the Portuguese Data Protection Authority:

Comissão Nacional de Proteção de Dados
Avenida D. Carlos I, No. 134, 1st Floor
1200-651 Lisbon
Website: www.cnpd.pt

This right does not affect your ability to bring proceedings before the competent courts.

Automated Decision-Making

BIKESUL does not use the personal data processed in its systems to make solely automated decisions that produce legal effects or significantly affect Customers.

If this situation changes, this Policy will be updated with information about the logic used, the significance of the processing and the envisaged consequences for data subjects.

Changes to the Privacy Policy

BIKESUL may update this Privacy Policy to reflect legal, technical or operational changes or changes relating to the services provided.

The updated version will be made available through BIKESUL’s official channels, with an indication of the date of the latest update.

Last updated: 19/08/2026.
Legal person nº 509 739 512 Rua Cândido dos Reis, Nº 62, 8375-105 São Bartolomeu de Messines, Portugal

Scroll to Top