Privacy Policy
How we handle the data you share with us — through the contact form, your portal account, and what we store in your browser.
Who we are
This site (bolalabs.pt) and its associated client portal are operated by BolaLabs, the brand under which Bruno Silva Marques provides software engineering and applied AI consulting services.
For any question about this document or the data we process, contact bruno@bolalabs.pt.
Data controller
The data controller is Bruno Silva Marques, Lisbon, Portugal. Contact: bruno@bolalabs.pt.
Contact form data
When you submit the contact form, we collect your name, email, company (optional field), the type of service you're interested in, and the message you write. If you fill them in, we also collect three optional context fields — company size, current system and expected timeframe — so we arrive at the conversation already informed. This data is stored in our database (Convex), in a table dedicated to incoming messages.
Submitting the form requires accepting this Privacy Policy; we store that fact (and the date/time you accepted it) alongside your message, as a record of consent.
Only an authenticated administrator session can read these messages — they are never shared with third parties or used for any purpose other than responding to your inquiry.
We use this data only to respond to your contact request; the email you enter is validated on the server before being accepted.
Account and portal session
To access the portal as a client, you provide an email. We do not create the account at that moment: we send a single-use confirmation link to that email, valid for 15 minutes. Only after you click it is the client account created (the first time) or reactivated, and the session begins — this ensures only whoever has access to that mailbox can sign in. Administrator accounts do not use this confirmation email: they always require an additional access key, validated on the server, and the session is created immediately.
To generate the confirmation link, we temporarily store, linked to your email: a cryptographic digest of the token (never the token itself), its expiry time, and whether it has already been used. This record is deleted automatically shortly after it expires or is used.
To prevent abuse, we also limit how many access or confirmation requests can be made in a short period from the same email; this counter is not linked to any other data about you and is likewise deleted automatically.
Once authenticated (after confirming your email, or after validating the administrator key), we create a session with a token stored in your browser, valid for 30 days. When you log out, or once that period elapses, the token is no longer accepted by the server.
Data stored in your browser
This site does not use cookies. It only uses browser local storage (localStorage) to hold three values:
- bolalabs_theme — your theme preference (light or dark).
- bolalabs_lang — your language preference.
- bolalabs_session_token — your portal session, only after you log in.
You can clear these values at any time in your browser settings; doing so does not affect public browsing of the site — it only ends your portal session, if any.
Third parties and hosting
The site's typefaces (Archivo, IBM Plex Sans, JetBrains Mono) are self-hosted — none are loaded from an external CDN.
We do not currently use any traffic analytics, advertising or tracking cookie tool. A cookieless, self-hosted analytics tool is planned for a later phase; when that happens, this policy will be revised before it goes live.
Sending the access confirmation email (see previous section) depends on an external email delivery provider that has not yet been chosen or configured; until that happens, that email simply is not sent and new client accounts cannot be created — this is a deliberate choice, not a failure. Once a provider is configured, this policy will be updated to name it.
The site's backend (database, authentication and server functions) is provided by Convex. Convex, Inc. acts as a data processor under its data processing agreement (DPA), with the data hosted and processed in the United States on the basis of EU standard contractual clauses.
Data retention period
Contact messages are kept for a maximum of 24 months after the last contact. Account data is kept for as long as the account remains active and deleted on request.
Your rights (GDPR)
Under the General Data Protection Regulation, you have the right to:
- Access the personal data we process about you.
- Rectify inaccurate or incomplete data.
- Request the erasure of your data.
- Restrict the processing of your data in certain circumstances.
- Request the portability of your data to another service.
- Object to the processing of your data.
To exercise any of these rights, contact bruno@bolalabs.pt.
Data protection officer
No data protection officer (DPO) has been appointed: given the size and nature of this activity, such an appointment is not required by the GDPR. Any question about personal data can be addressed directly to bruno@bolalabs.pt.
Complaints to a supervisory authority
The competent supervisory authority in Portugal is the CNPD — Comissão Nacional de Proteção de Dados (www.cnpd.pt, geral@cnpd.pt), with which you can lodge a complaint.
Changes to this document
Should any material changes be made to this policy, this page will be updated.