Digital IndexDigital Index

Legal

Privacy Policy

Last updated: 2026-09-01

This policy explains what personal data we process, where it comes from, on what legal basis, who we share it with, how long we keep it and what rights you have over it. It applies to digitalindex.pt, to the signed-in area and to the published index. The Portuguese version prevails in case of divergence.

1.Controller

The controller of the data described in this policy is Apollotec Unipessoal, Lda. (“Digital Index”), NIPC 515769070, registered office at Complexo Tecnológico de Coimbra, Rua Coronel Júlio Veiga Simão, 3025-307 Coimbra, registered at the Conservatória do Registo Comercial de Coimbra sob o número 515769070, email hello@digitalindex.pt.

For any data protection matter, including exercising your rights, write to hello@digitalindex.pt. We have not appointed a Data Protection Officer because none of the cases in Article 37 GDPR applies; should that change, this policy will be updated with the relevant contact details.

Regulation (EU) 2016/679 (GDPR) applies, together with Portuguese Law 58/2019 of 8 August, which implements it, and Law 41/2004 of 18 August as regards storing information on your terminal equipment.

2.Who this policy covers

We process personal data of two groups of people, with different information duties, so it is worth telling them apart from the outset:

  • Platform users: anyone who creates an account, claims a company profile, submits a request to join the index, disputes a measurement or writes to us. Here the data comes from you.
  • People identifiable through indexed entities: sole traders, independent professionals, companies whose name includes a person's name, and holders of public social media profiles. Here the data does not come from you: it comes from public sources and data providers, and we inform you under Article 14 GDPR.

Data about legal persons is not personal data and the GDPR does not apply to it. Because the two cases cannot always be separated up front (a sole trader is both), the index flags internally the entities that may contain personal data and handles them with the safeguards described here.

3.What data we process

Account and authentication: email address, display name, profile picture when you sign in with a Google account, preferred language, last sign-in date and the identifier assigned to you by our authentication provider. Your password is not accessible to us: it is managed and stored, encrypted, by that provider. If you enable two-factor authentication, the one-time-code secret is likewise held by that provider.

Usage and security: audit records of relevant actions taken on your account and on an entity profile, with timestamp, action, IP address and browser identification. They exist to investigate unauthorised access, profile ownership disputes and incidents.

Requests to join the index: company name, tax number, domain, sector, location and, where given, contact name and email.

Profile claims and ownership verification: method used, evidence provided, status and dates. If you choose verification through Google Search Console, you authorise us, only with your consent and only for this purpose, to read your Google email address and the list of properties you administer there. We keep the address, the verification outcome and, strictly for the duration of the verification session, the access credentials issued by Google.

Organisations and teams: organisation name, member roles, invitations sent (invitee email, inviter, status and expiry).

Help requests and disputes: name, email, phone where given, the text of the request, the moment and version of the consent wording accepted, and the IP address from which consent was given.

Contact messages: name, email, subject and message you write in the contact form.

Communications we send you: recipient address, delivery status, whether the message was opened and whether a link was followed, bounces and opt-out requests. We also keep a suppression list of addresses that asked not to be contacted, precisely so that request is honoured.

Use of the platform: which profiles were viewed, which comparisons were made, which links to company sites were followed and which campaign tags brought the visit, with a timestamp and a session identifier that lasts as long as the visit. When you are signed in, these records are linked to your account; when you are not, they are linked only to that session. We do not store your IP address or the full address of the page you came from, only the domain, so we can tell whether the visit came from outside.

If you consent to audience measurement, Google Analytics collects its own data about the visit in parallel: pages viewed, device and browser type, approximate location and traffic source. That data is processed by Google as our processor, stays in our account in that tool, and is not cross-referenced by us with your account on the platform. The IP address is used by Google to infer approximate location and is not retained by us. Without consent, none of this is collected.

Preferences: chosen language, active organisation and display options for the signed-in area.

Data about indexed entities, which may identify a person where the business is run in an individual capacity: trading and legal name, tax number, domain, postal address and postcode, geographic coordinates, phone number, social profiles and channels, business description, sector, year founded, headcount and financial indicators, results of technical website measurements, press mentions and mentions in language-model answers.

Candidates identified during prospecting: username and given name attached to a public profile, biography, business category, city, follower count, external links, phone, address, postcode, coordinates and public ratings, where the source platform makes them public. They only enter the index once validated as an economic activity.

Subscriptions and billing: the subscribing entity's legal or trading name, tax number, billing address, postcode, town, country and billing email address, the plan taken, the subscription history and the invoices issued. Where the entity is a sole trader, this is also personal data.

We do not process special categories of data under Article 9 GDPR, nor criminal conviction data. We neither see nor store your card details: payment happens on pages hosted by our subscription management provider, which handles them directly, and the platform receives only the subscription status and the amounts invoiced.

4.Where data we did not get from you comes from

A substantial part of the index was not collected from the data subject. Under Article 14(2)(f) GDPR, the sources are:

  • The companies' own websites, requested by our automated probes at public paths (home page, robots.txt, llms.txt, sitemap) and by reading TLS certificates and public DNS records.
  • Google's PageSpeed Insights API, for performance measurements, including the aggregated real-user data that tool publishes about the measured site.
  • The Google News search feed, for press mentions (headline, date and publisher).
  • Apollo.io, a firmographic data provider, for legal name, domain, sector, size, location and channels.
  • Apify, an automated collection platform, for publicly available data on social networks, directories and maps.
  • Third-party language models, which we ask sector questions in order to record which brands appear in the answers.
  • Official public sources and commercial registries, for identification and economic information.

When someone asks us for the specific sources of a data point about them, we identify them, with the collection date.

How we discharge the duty to inform people who did not give us their data: the index covers tens of thousands of entities and, in most cases, we hold no personal contact with which to notify each data subject individually, and we do not wish to start holding one, since doing so would mean collecting exactly the contact data we do not collect. Under Article 14(5)(b) GDPR we therefore make this information publicly available: this policy is permanently accessible on the site, every entity has a public page showing what the index holds about it, and the methodology page explains how each value is computed. When we do email an entity, that message identifies who we are, why we are contacting them and where to read this policy.

5.Why we use the data and on what basis

Performance of a contract (Article 6(1)(b)): creating and maintaining your account, authenticating you, giving you access to the signed-in area, handling a profile claim, managing your organisation and invitations, answering the requests you submit and, if you take a paid plan, managing the subscription, which covers billing details, payment, renewal and cancellation.

Legitimate interests (Article 6(1)(f)): building, computing and publishing the index and rankings; identifying and qualifying entities for inclusion; contacting companies at professional email addresses to tell them their position and that they may claim the profile; keeping the platform secure and investigating abuse; keeping audit records; and defending our rights. The legitimate interest here is market information on the digital presence of economic activities, weighed against the impact on data subjects, taking into account that the data concerns the professional sphere, comes from public sources, is neither used for behavioural advertising nor sold, and that there is a right to object which we honour. The balancing assessment is documented and available on request.

Consent (Article 6(1)(a)): site audience measurement with Google Analytics and any cookie that is not strictly necessary, help requests in which you authorise sharing your contact details with a partner, sending the contact form, and reading the properties you administer in Google Search Console to verify domain ownership. Consent may be withdrawn at any time, without affecting processing already carried out.

Compliance with a legal obligation (Article 6(1)(c)): responding to requests from data subjects and authorities, issuing and archiving the tax documents Portuguese law requires, and retaining what the law requires.

We do not use your data for behavioural advertising, we do not sell it and we do not pass it to data brokers.

6.Automated scoring and profiling

The index assigns scores and positions automatically, from technical measurements and public signals, applying a versioned and published methodology. There is no human intervention in the computation.

That score concerns the digital presence of an economic activity. It does not assess people, it is not used to decide on access to credit, employment, insurance or services, and it produces no legal effects on a natural person nor similarly significantly affects one, so it is not a solely automated decision within the meaning of Article 22(1) GDPR.

Even so, and because a wrong measurement is always possible, anyone with a verified profile may dispute any specific measurement. A person reviews the dispute, there is a response deadline, and where it succeeds the value is corrected and, if the edition is already published, a correction note is issued. The methodology in force, the weights and the definition of each metric are published on the methodology page.

7.Who we share with

We use processors that handle data on our behalf under contracts meeting Article 28 GDPR:

  • Supabase: authentication, database and file storage, hosted in the European Union.
  • Vercel: application hosting and delivery.
  • Apify: automated collection of publicly available data.
  • Apollo.io: firmographic data enrichment.
  • Google Ireland Limited: Google account sign-in, Search Console verification, the PageSpeed Insights API and site audience measurement (Google Analytics), the last of these only with your consent.
  • Cookiebot (Usercentrics A/S, Denmark): collecting and recording consent for cookies, and blocking those that have not been consented to.
  • Chargebee: subscription management and hosted payment pages.
  • Moloni: issuing and archiving tax documents.
  • Resend: sending transactional email and notifications, and recording delivery status.
  • An S3-compatible storage provider: retention of collection records.
  • Language model providers, for the generated-answer visibility questions.

If and when we engage accountants, lawyers or auditors, we share only what is necessary and under a duty of professional confidentiality. We share with public authorities where the law requires it.

The partners in help requests are not processors: they are independent controllers. When you expressly authorise a help request, we transmit your contact details to the partner named in that request, and that transmission is logged with its date. From that moment it is that partner who answers for what it does with them, under its own privacy policy, and it is to them that requests about that processing should be addressed. Without your express authorisation, nothing is transmitted.

Part of the information about indexed entities is public by nature: name, sector, location, domain, score and position are published on the site and may be reproduced by third parties, including the press. Contact details of individuals are not published.

8.Transfers outside the European Economic Area

The database, authentication and file storage stay in the European Union. That covers all account and index data at rest.

There are nonetheless processors established outside the European Economic Area, or processing data from outside it, in particular Vercel, Apollo.io, Chargebee and Resend, the language model providers and, where you consent to it, Google Analytics. Those transfers rely on the standard contractual clauses approved by the European Commission or, where applicable, on the adequacy decision for the EU-US Data Privacy Framework, supplemented by additional technical and organisational measures.

You may ask us for a copy of the safeguards applicable to a specific transfer.

9.How long we keep data

  • Account data: for as long as the account exists. Deletion from the signed-in area is immediate: name, address, picture, preferences, notifications and verification credentials go the moment you confirm, and what remains is kept without any element that identifies you, except what must be kept by legal obligation or to defend a right in proceedings.
  • Audit and security records: no time limit. They are the proof of who decided what about a profile and of how an account was accessed, and are kept under Article 17(3)(e) GDPR, for the establishment, exercise and defence of legal claims. The database prevents both rewriting and deleting them, which is the property that makes them proof. When an account is erased they no longer carry the name or address of whoever held it: they stay attached to an internal number that resolves to nobody.
  • Platform usage (profiles viewed, comparisons made, links followed): 12 months. Data collected by Google Analytics, where consented to, is retained by Google for the period configured in that tool, which is 14 months.
  • Requests to join the index, disputes and help requests: 3 years from the decision, as they are the record of what was decided and why.
  • Contact messages: 2 years.
  • Billing data and tax documents: 10 years from the end of the financial year they relate to, as required by Article 52 of the Portuguese VAT Code and Article 123 of the Corporate Income Tax Code. This period prevails over an erasure request, and is the legal exception referred to in the first item of this list.
  • Records of communications sent: for as long as the account exists, leaving with it when the account is erased. Where there is no account — email to companies that never signed up — the address is deleted after 3 years, leaving only the delivery status, with no recipient. The address suppression list is kept indefinitely, because it is what guarantees a request not to be contacted is honoured in future.
  • Google Search Console verification sessions: credentials are deleted as soon as verification ends or the session expires; the outcome stays attached to the profile.
  • Automated task execution logs: 30 days. Intermediate prospecting datasets: 6 days.
  • Indexed entity data, measurements, scores and positions: kept with no time limit, including after the business ceases trading. The index is an archive: the historical series and comparability across editions are the product itself, and a 2026 measurement deleted in 2032 robs every edition that cites it of meaning. This retention rests on the legitimate interests of Article 6(1)(f), and its counterweight is the right to object: anyone identifiable through an entity may request removal, in which case the associated measurements are detached from any element identifying a person rather than continuing to point at them.

The periods above are maximums: whenever a data point stops being necessary sooner, it is deleted sooner.

10.Your rights

You have the right of access, rectification, erasure, restriction of processing, portability and objection, under Articles 15 to 22 GDPR, and the right to withdraw consent where processing is based on it.

If you object to processing based on our legitimate interests, we stop processing unless we demonstrate compelling grounds overriding your interests and rights. If the objection concerns direct marketing, we stop immediately and without needing a reason.

Two of these rights need no message to us: in the signed-in area, under Security, you can download a file with your data and you can delete your account. Deletion is immediate and final, and the screen tells you, before you confirm, what goes and what stays, in particular that the company remains in the index, because its position is not your data.

To exercise any of these rights write to hello@digitalindex.pt, saying what you want. We answer within one month, extendable by two months in complex cases, in which event we will tell you. We may ask for additional details where there is reasonable doubt about your identity, and only for that purpose.

If an indexed entity believes a data point is wrong, there are two routes: correcting the data, requested at the contacts above or by dispute from the verified profile, and removing the entity from the index, also requested at the same contacts. We review both and always answer, including when the answer is a reasoned refusal.

If you consider the processing unlawful, you may complain to the Portuguese supervisory authority, Comissão Nacional de Proteção de Dados (CNPD), Av. D. Carlos I, 134, 1.º, 1200-651 Lisbon, geral@cnpd.pt, www.cnpd.pt, without prejudice to going to court.

11.Cookies and storage on your device

We use no advertising cookies, the platform carries no social network tag and we do no advertising profiling. We do use a third-party audience-measurement tool, Google Analytics, which is only loaded after you consent to it. This is what may be stored on your device:

  • di_lang: our own cookie holding the language we show the site in: the one you chose or, on a first visit, the one inferred from your country and browser preferences. Valid for one year.
  • di_sid: our own session cookie, for audience measurement. It holds thirty-two randomly generated characters and nothing else: no data about you, no reference to your account. It lets us tell which profile views and comparisons belong to the same visit, such as how many profiles are viewed before two companies are compared, for instance. It has no expiry date because it disappears when you close your browser, and that is the difference between a visit identifier and a person identifier: it cannot recognise you on a later visit. It is not readable by scripts on the page and is not shared with anyone.
  • Authentication session: stored in your browser's local storage by our authentication provider, to keep you signed in between visits. It disappears when you sign out.
  • Active organisation: stored in local storage, so the signed-in area opens on the organisation you were in.
  • CookieConsent: the cookie of the tool that manages your consent (Cookiebot). It holds the choice you made in the banner, by category, so that you are not asked again on every page. It exists so that a refusal is honoured, which makes it strictly necessary in its own right. Valid for one year.
  • _ga and _ga_<identifier>: Google Analytics cookies, which distinguish visits and visitors so we can tell how many people use the site, how they arrive and which pages they see. Valid for two years. They are neither loaded nor written before you consent, and refusing prevents them from existing at all. Unlike ours, they allow the same browser to be recognised on a later visit, and the data is processed by Google, which may relate it to other signals it holds.

di_lang, the authentication session, the active organisation and CookieConsent are strictly necessary to the service you request, under Article 5(3) of Law 41/2004, and therefore do not depend on consent. di_sid and the Google Analytics cookies are not necessary: they exist so we can measure use of the platform, and we say so plainly rather than filing them under what is necessary.

You can refuse, and refusing is as easy as accepting. On a first visit a banner lets you choose by category; the choice can be changed at any time through the cookie settings link at the foot of any page. Until you consent to the statistics category, Google Analytics is not loaded — the blocking happens before the script runs, not after.

Nothing on the platform stops working because you refused: what we lose is the count, nothing is withheld from you. Clearing cookies in your browser settings has the same effect, except that it also clears the necessary ones, in which case you will have to pick your language, sign in again and answer the banner once more.

We have not enabled Google's advertising features in Google Analytics, in particular Google signals and data sharing for ads personalisation. The measurement tells us how the site is used; it does not feed advertising targeting, ours or anyone else's.

The badge that verified companies may place on their site reads the score from an address of ours and writes nothing on the device of whoever visits that site.

12.Security

Communications with the platform are encrypted in transit. Access to data in the database is restricted by row-level security rules, access to the internal panel requires two-factor authentication, and every sensitive action is recorded in the audit log. Provider keys are kept out of the code and are rotated.

No measure is infallible. If a personal data breach occurs that entails a high risk to your rights and freedoms, we will inform you and notify the CNPD within the deadlines in Article 33 GDPR.

13.Minors

The platform is aimed at professionals and businesses and is not intended for people under 18. We do not knowingly collect minors' data; if we learn that we have, we delete it.

14.Changes to this policy

This policy may change. The date of the last update is at the top, and where a change is substantial we inform account holders by email or by notice on the platform, with reasonable advance warning.