Privacy Policy
Non-binding translation. This English version is a courtesy translation of the Portuguese original. In the event of any inconsistency, ambiguity or divergent interpretation, the Portuguese-language version shall prevail. Legal references (including Regulation (EU) 2016/679 – GDPR, Portuguese Law No. 58/2019 of 8 August, Angolan Law No. 22/11 of 17 June, Mozambican Law No. 3/2017 of 9 January, and Directive (EU) 2016/681) are kept in their original wording and shall be interpreted in accordance with the applicable EU and national continental law.
I. ABOUT THE EMBRACE GROUP
II. MULTIPLE JURISDICTIONS, ONE COMMITMENT TO DATA PROTECTION AND INFORMATION SECURITY
III. WHO IS RESPONSIBLE FOR PROCESSING YOUR PERSONAL DATA
IV. WHICH PERSONAL DATA WE PROCESS
V. HOW WE COLLECT YOUR PERSONAL DATA, THE PURPOSES AND THE LEGAL BASES
VI. FOR HOW LONG WE RETAIN YOUR PERSONAL DATA
VII. HOW WE ENSURE THE SECURITY OF YOUR PERSONAL DATA
VIII. YOUR RIGHTS AND HOW TO EXERCISE THEM
IX. MONITORING, REVIEW AND ALIGNMENT WITH OTHER COMPLIANCE SYSTEMS
I. ABOUT THE EMBRACE GROUP
The Embrace Group operates in several jurisdictions in an integrated manner, in the sectors of travel, events and tourism technology, through several specialised companies. In Portugal, the activities of travel management, accommodation and related services are provided by Travel Store – Prestação de Serviços – Viagens, S.A., with registered office at Rua Campo Grande, no. 35, 1.º, 1700-087 Lisbon, tax number (NIPC) 503903310, which is also responsible for the management of the website www.embraceambition.com, and promotes the brands Allways, Meetique, Travelstore American Express GBT, Emotionstore and Lab.
Corporate event organisation is carried out by Epic Hemisphere – Corporate Events & Meetings, Unipessoal Lda., NIPC 515618462, with registered office at the same address. The organisation of congresses and large conventions is the responsibility of Mundiconvenius – Sociedade de Congressos e Serviços, Lda., NIPC 503269794.
In the technology field, the Group owns AroundVector – Serviços e Tecnologia para o Turismo, Lda., NIPC 510423086, specialised in the development of IT and technological solutions for the tourism sector and for the various areas of activity of the Embrace Group.
In Spain, Travel Interests SL, with registered office at Avenida de Bruselas, no. 38, Portal B, 4.º Derecha, Alcobendas, Madrid, also provides travel services, accommodation and related services, as well as their organisation and management.
In Angola, activity is carried out by TSAngola, Lda., with registered office in Luanda, Rua Joaquim Kapango, no. 77, NIPC 5417101524, also dedicated to travel management and related services.
In Mozambique, operations are carried out by Dana Agency Moçambique, Limitada, with registered office in Maputo, Avenida Kenneth Kaunda, no. 1170, specialised in corporate business travel solutions.
II. MULTIPLE JURISDICTIONS, ONE COMMITMENT TO DATA PROTECTION AND INFORMATION SECURITY
The Embrace Group is directly present in Portugal, Spain, Angola and Mozambique, operating in a transnational context which requires the highest standards of diligence and accountability in the processing of personal data. Recognising from the outset that the protection of natural persons’ personal data is a fundamental right, the Embrace Group undertakes, in a transversal and continuous manner, to ensure strict compliance with the legal provisions applicable to data protection and information security.
This commitment is reflected, in particular, in strict compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation – GDPR), Portuguese Law No. 58/2019 of 8 August (which ensures its implementation in the Portuguese legal order), as well as with the consistent alignment with the national legal regimes in force in the other jurisdictions in which the Group operates.
In the specific case of Angola, such alignment is achieved in accordance with Law No. 22/11 of 17 June – Personal Data Protection Law – and its corresponding regulations, ensuring, regardless of the jurisdiction, full respect for the principles of lawfulness, fairness, transparency, proportionality, purpose limitation, accuracy, storage limitation, integrity and confidentiality.
Our global corporate data protection and information security policy is periodically reviewed, audited and improved, ensuring that all our employees, partners, suppliers and other interested parties understand and comply with all legal obligations.
Aware that, in the areas of activity of the Embrace Group companies, the processing of personal data necessarily implies international transfers, we adopt appropriate organisational and technical measures to ensure that, regardless of the jurisdiction in which we operate, the level of protection afforded to personal data is substantially equivalent to that required by the high standard of the European GDPR.
Within this framework, we have adopted internal policies and procedures with transversal and harmonised application, applicable to all Embrace Group entities, and we have appointed a Data Protection Officer (DPO) with global responsibility, whose work is coordinated with local data protection and information security specialists, ensuring the effective, coordinated and uniform implementation of appropriate technical and organisational measures for the protection of personal data. This governance structure guarantees, in a sustained manner, the promotion of an organisational culture of privacy, information security and regulatory compliance.
III. WHO IS RESPONSIBLE FOR PROCESSING YOUR PERSONAL DATA
The Embrace Group acts as controller (within the meaning of Article 4(7) GDPR) in relation to the personal data of its direct clients, prospective clients (natural persons), and the employees and guests of its institutional clients.
As controller, the Embrace Group determines the purposes and means of the processing of the personal data it collects, ensuring compliance with the legal obligations applicable in each jurisdiction, in particular with regard to the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability, as set out in the GDPR.
Controller’s contact details:
Telephone: +351 213565300, available from 8:00 to 20:00, Monday to Friday
Email: operacoes@embraceambition.pt
Embrace Group portal: https://www.embraceambition.com/
IV. WHICH PERSONAL DATA WE PROCESS
The following categories of personal data may be collected through the channels and services described in this Privacy Policy:
Data collected by the Embrace Group:
Contact information
Full name
Address
Email address
Phone
Mobile phone
Personal information
Date of birth
Citizen card number and validity date
Passport number and validity date
Airline seat preference
Professional information
Name of the company you work for
Professional category and role
Department and/or area
Employee number and cost centre
Client history
Client satisfaction level
Travel and accommodation history and preferences
Services purchased, purchase date and corresponding price
V. HOW WE COLLECT YOUR PERSONAL DATA, THE PURPOSES AND THE LEGAL BASES
Your personal data may be collected and processed by the Embrace Group in the context of the provision of our travel management, events and corporate mobility services, in particular in the following circumstances:
Where, following a business agreement, your company provides us with your personal data, which is necessary for the organisation, booking, coordination and management of your professional or other trips, participation in events and/or congresses;
Where you contact us directly, through digital platforms, telephone, email or in person, to request services, information or commercial proposals;
Where you access or use our websites, applications or digital portals, in which you may be requested to provide data for authentication, travel preferences, invoicing or communications;
Where you participate in events or congresses organised by the Embrace Group, in which we collect registration, attendance and satisfaction data;
Where you interact with us in the context of marketing campaigns or promotional actions, subject to prior, free and informed consent.
The legal bases for the collection and processing of your personal data are the following:
Performance of a contract or pre-contractual steps – where processing is necessary for the conclusion, performance or management of a contract to which you are a direct or indirect party, including bookings, ticket issuance, accommodation, event logistics, invoicing and customer support;
Compliance with legal obligations – where processing arises from the need to comply with legal obligations to which the Embrace Group is subject, such as tax, accounting, anti-money laundering and counter-terrorist financing obligations, in particular compliance with Directive (EU) 2016/681 of the European Parliament and of the Council of 27 April 2016 on the use of passenger name record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime, obligations arising from labour law, occupational health and safety or sectoral regulation;
Consent – where processing depends on your free, specific, informed and unambiguous consent, such as direct marketing communications, newsletters, collection of preferences or participation in promotional initiatives;
Legitimate interests of the controller – where the processing of your data is necessary for the pursuit of the legitimate interests of the Embrace Group, in particular for the purposes of information systems security, fraud prevention, continuous improvement of services, management of the commercial relationship and optimisation of corporate events, without prejudice to your fundamental rights and freedoms.
VI. FOR HOW LONG WE RETAIN YOUR PERSONAL DATA
The Embrace Group retains your personal data only for the period strictly necessary to pursue the purposes for which it was collected or subsequently processed, in accordance with the principle of storage limitation.
The retention period may vary depending on the purpose of the processing, the applicable legal requirements or the existence of limitation periods that justify longer retention, in particular for the fulfilment of contractual, tax or judicial obligations.
Once the applicable maximum retention period has been reached, personal data will be:
irreversibly anonymised, thereby no longer allowing the identification of the data subject (in which case they may be kept for statistical or aggregate analysis purposes); or
securely deleted, through technical procedures that guarantee their non-recoverability and non-exposure to unauthorised third parties.
For direct marketing purposes, personal data will be kept until you withdraw your consent or exercise your right to object, without prejudice to additional periods legally required or admissible.
For contact management, customer support and commercial communications, data will be kept for as long as the relationship with the institutional client or the data subject remains active and up to two years after the last relevant contact, unless otherwise required by law.
The Embrace Group conducts periodic audits of its databases, with a view to deleting unnecessary data or data whose retention is no longer justified in the light of the principles of data minimisation and storage limitation.
VII. HOW WE ENSURE THE SECURITY OF YOUR PERSONAL DATA
Appropriate technical and organisational measures
Because the security of your personal data is a strategic and permanent priority for the Embrace Group, in line with our global partner American Express Global Business Travel (AMEX GBT), the Embrace Group has adopted and implemented a transversal Information Security Policy (ISP), based on international standards of good practice, which incorporates robust technical and organisational measures aimed at protecting the confidentiality, integrity, availability and authenticity (non-repudiation) of the personal data processed. Such measures are regularly reassessed in light of technological developments, emerging threats and continuously updated legal obligations.
This policy reflects a risk-based approach, ensuring the adoption of mechanisms proportionate to the nature, scope, context and purposes of the processing activities carried out, as well as to the likelihood and severity of the risks to the fundamental rights and freedoms of data subjects.
Although data transmission over the internet or via websites cannot guarantee absolute security against unauthorised access, intrusions or improper disclosure, the Embrace Group and its service providers or business partners make their best technical and procedural efforts to mitigate such risks, ensuring compliance with the principles of data protection by design and by default.
In accordance with our Information Security Policy (ISP), we have implemented, in particular, the following measures:
Pseudonymisation and encryption of personal data, whenever technically feasible, appropriate and proportionate;
Logical segregation of production, testing and development environments;
Strict authentication and access management controls, based on the principles of least privilege and “need to know”;
Continuous monitoring of systems and networks for the detection of security incidents and anomalies;
Duly documented and tested backup and disaster recovery policy;
Regular information security audits;
Periodic and mandatory training of employees in data protection and cybersecurity matters;
Systematic recording and assessment of information security incidents, with mandatory reporting to the Data Protection Officer and Security Officer and, where legally required, to the competent supervisory authority;
Records and mapping of personal data processing activities.
Continuous training of our employees
The Embrace Group recognises that the effectiveness of data protection and information security measures depends, to a large extent, on the awareness and capability of its human resources. For this reason, it ensures the implementation of continuous, periodic and mandatory training programmes for all employees, internal service providers and external consultants with access to personal data or information systems.
These programmes include specific content on the principles and rules of personal data protection, based on the internationally recognised GDPR standard for all employees and, specifically, in Angola, in relation to Law No. 22/11 of 17 June (LPDP) and, in Mozambique, in relation to Law No. 3/2017 of 9 January (LTE), including:
Information Security Policy and its procedures;
Confidentiality and secrecy duties applicable to the processing of all information and, specifically, to the processing of personal data;
Prevention and management of security incidents and personal data breaches, enabling incident recognition and immediate action;
Cybersecurity good practices, including password management, protection against social engineering and secure use of devices and networks;
Disciplinary and legal sanctioning framework in the event of non-compliance with applicable rules.
Training is adapted to the functional profile of employees and provided at the time of onboarding (initial training) and in regular cycles throughout the employment or contractual relationship, and may be complemented by extraordinary actions in response to regulatory, technological or organisational updates.
This systematic investment in the qualification of our professionals aims to ensure the culture of compliance, accountability and security that characterises the Embrace Group’s data governance model.
Careful selection of processors
Within the scope of our activity, the Embrace Group may engage third parties – designated as processors – to carry out personal data processing operations on our behalf and under our responsibility.
The selection of processors is carried out on the basis of strict criteria of legal compliance and technical and organisational robustness, in accordance with the standard set out in Article 28 GDPR.
Prior to any engagement, the Embrace Group conducts a risk assessment and a set of prior verifications of technical and organisational requirements in the areas of personal data protection and information security, ensuring that the processor:
provides sufficient guarantees for the implementation of appropriate technical and organisational measures;
is bound by a written contract which, under Article 28 GDPR, ensures a level of protection of personal data appropriate to the risk and sets out, in particular, the subject-matter and duration of the processing, its nature and purpose, the type of personal data and the categories of data subjects, and the obligations and rights of the controller;
undertakes to process the data only on documented instructions from the Embrace Group;
ensures that persons authorised to process the data are subject to legal or contractual confidentiality obligations;
implements appropriate mechanisms to assist the Embrace Group in responding to the exercise of data subjects’ rights and in complying with legal obligations, including personal data breach notifications;
does not engage other processors without prior written authorisation and subjects such sub-processors to the same protection requirements;
undertakes to delete or return all personal data at the end of the service, unless otherwise required by law.
This approach aims to ensure that any entity collaborating with the Embrace Group acts in compliance with the most demanding legal and technical standards on personal data protection, reinforcing the security and trust of data subjects in all the territories in which we operate.
International transfers
Given the multinational nature of the Embrace Group and the transnational nature of the tourism, travel, accommodation and related services industry, your personal data may be subject to international transfers to entities located outside the European Economic Area (EEA), including suppliers, technology partners or service providers engaged for legitimate purposes compatible with those described in this Privacy and Personal Data Protection Policy.
In all situations, the Embrace Group ensures that any transfer of personal data that is or will be subject to processing after transfer to a third country or an international organisation is only carried out where the conditions set out in Articles 44 to 49 GDPR are complied with by all entities involved in the personal data processing chain, including with regard to onward transfers of personal data from the third country or international organisation to another third country or international organisation.
Transfers of personal data outside the EEA are carried out on the basis of appropriate safeguards, including, as applicable, compliance with adequacy decisions, European Commission standard contractual clauses (SCCs) and binding corporate rules (BCRs);
Transfers of your personal data are preceded by an assessment of the level of protection in the country of destination, including legal and administrative practices regarding access by public authorities, as well as of all entities involved;
Your personal data remains stored on secure servers, subject to appropriate technical and organisational measures, and its access and processing takes place exclusively within the scope of the Embrace Group’s instructions or in compliance with equivalent contractual rules imposed on service providers.
VIII. YOUR RIGHTS AND HOW TO EXERCISE THEM
As a data subject, you have a set of rights legally established under the GDPR, the exercise of which is ensured in an equitable and transparent manner by the Embrace Group, regardless of the jurisdiction in which you are located.
Right of access – to obtain confirmation as to whether or not your personal data is being processed and, if so, to access such data and the information legally provided for;
Right to rectification – to request the correction or updating of your inaccurate or incomplete personal data;
Right to erasure (“right to be forgotten”) – to request the deletion of your personal data where, in particular, the purpose justifying the processing has ceased or consent has been withdrawn (where applicable), except where there are legal grounds justifying its retention;
Right to restriction of processing – to obtain restriction of the processing of your personal data in certain circumstances (for example, during the verification of the accuracy of the data);
Right to object – to object, on grounds relating to your particular situation, to the processing of your data based on legitimate interest or public interest, as well as to decisions based solely on automated processing, including profiling;
Right to data portability – to receive the personal data you have provided to us, in a structured, commonly used and machine-readable format, and to transmit that data to another controller, where the processing is based on consent or on the performance of a contract;
Right to withdraw consent – where the processing is based on your consent, you may withdraw it at any time, without prejudice to the lawfulness of processing carried out prior to withdrawal;
Right to lodge a complaint
Whenever any reason for complaint arises due to dissatisfaction or doubt regarding the processing, the data subject may immediately submit a complaint or request for information to the Embrace Group Data Protection Officer, through the following contacts:
Email: dpo@embraceambition.com
Telephone: +351 213 565 300, available from 8:00 to 20:00, Monday to Friday
The Data Protection Officer, under the “Procedure for the Exercise of Data Subjects’ Rights”, guarantees:
Registration and handling of the complaint or request for information within a maximum of 24 working hours;
Transparent, impartial and reasoned responses;
Continuous information on the status of the process, until its final resolution;
Diligent, equitable and rights-respecting handling of the data subject.
Without prejudice to this secure internal channel, data subjects also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement, if they consider that the processing of their personal data infringes the GDPR and/or the applicable local jurisdiction:
Portugal: Comissão Nacional de Proteção de Dados (CNPD) – geral@cnpd.pt
Angola: Agência de Proteção de Dados (APD) – geral@apd.ao
Mozambique: Instituto Nacional de Tecnologias de Informação e Comunicação (INTIC) – info@intic.gov.mz
Spain: Agencia Española de Protección de Datos (AEPD) – https://sedeaepd.gob.es/sede-electronica-web/vistas/infoSede/tramitesCiudadanoReclamaciones.jsf
IX. MONITORING, REVIEW AND ALIGNMENT WITH OTHER COMPLIANCE SYSTEMS
This Privacy and Personal Data Protection Policy is reviewed whenever relevant legislative, regulatory or operational changes occur, as well as following recommendations, guidelines or binding acts issued by national or European supervisory authorities, relevant judicial decisions, or guidelines and opinions adopted within the European Data Protection Board (EDPB).
The changes introduced are approved by the competent bodies of the Embrace Group and made available through the usual channels, ensuring their accessibility, clarity and continuous updating. Whenever such changes entail a substantial modification of the terms of personal data processing applicable to data subjects, the latter shall be informed by appropriate means, in a timely and transparent manner, in accordance with the applicable legislation.
Without prejudice to compliance with all legal frameworks applicable to the activities of the entities that make up the Embrace Group, the Group adopts a harmonised framework of guiding principles that governs its corporate conduct, reflected in the definition and application of uniform internal policies. This approach ensures a consistent and transversal application of the applicable legal and ethical duties, as well as the consistent integration of this Policy with the Group’s commitments regarding institutional integrity, prevention of corruption and related offences, and the fight against money laundering and terrorist financing, based on duties of diligence, transparency, accountability and control.