Privacy Policy
I - ABOUT THE EMBRACE GROUP
O Grupo Embrace desenvolve a sua atividade em várias geografias, operando de forma integrada nos setores das viagens, eventos e tecnologia aplicada ao turismo, através de diversas sociedades especializadas. Em Portugal, as atividades de gestão de viagens, estadias e serviços conexos são asseguradas pela Travel Store – Prestação de Serviços – Viagens, S.A., com sede na Rua Campo Grande, n.º 35, 1.º, 1700-087 Lisboa, com o NIPC 503903310, sendo também a responsável pela gestão do website , e promove as marcas Allways, Meetique, Travelstore American Express GBT, Emotionstore e Lab.
The Embrace Group operates across multiple geographies, working in an integrated manner in the sectors of travel, events and tourism-related technology through various specialised entities. In Portugal, travel management, accommodation and related services are provided by Travel Store – Prestação de Serviços – Viagens, S.A., headquartered at Rua Campo Grande, no. 35, 1.º, 1700-087 Lisbon, with tax number 503903310, which is also responsible for managing the website www.embraceambition.com and promotes the brands Allways, Meetique, Travelstore American Express GBT, Emotionstore and Lab.
A atividade de organização de eventos corporativos é conduzida pela Epic Hemisphere – Corporate Events & Meetings, Unipessoal Lda., com o NIPC 515618462 e sede na mesma morada. A organização de congressos e grandes convenções é da responsabilidade da Mundiconvenius – Sociedade de Congressos e Serviços, Lda., com o NIPC 503269794.
Corporate event organisation activities are carried out by Epic Hemisphere – Corporate Events & Meetings, Unipessoal Lda., with tax number 515618462 and registered at the same address. The organisation of congresses and large-scale conventions is the responsibility of Mundiconvenius – Sociedade de Congressos e Serviços, Lda., with tax number 503269794.
In the area of technology, the Group owns AroundVector – Serviços e Tecnologia para o Turismo, Lda., with tax number 510423086, specialised in the development of IT and technological solutions for the tourism sector and for the various areas of activity of the Embrace Group.
In Spain, Travel Interests SL, headquartered at Avenida de Bruselas, no. 38, Portal B, 4.º Derecha, Alcobendas, Madrid, also provides travel, accommodation and related services, as well as their organisation and management.
In Angola, the activity is developed by TSAngola, Lda., headquartered in Luanda, at Rua Joaquim Kapango, no. 77, with tax number 5417101524, also dedicated to the management of travel and related services.
In Mozambique, operations are carried out by Dana Agency Moçambique, Limitada, headquartered in Maputo, at Avenida Kenneth Kaunda, no. 1170, specialised in corporate business travel solutions.
II - MULTIPLE GEOGRAPHIES, A SINGLE COMMITMENT TO DATA PROTECTION AND INFORMATION SECURITY
The EMBRACE Group operates directly in Portugal, Spain, Angola and Mozambique, within a transnational context that requires the highest standards of diligence and responsibility in the processing of personal data. Recognising from the outset that the protection of personal data is a fundamental right, the EMBRACE Group assumes, on a transversal and continuous basis, the commitment to strictly comply with the applicable legal provisions regarding data protection and information security.
This commitment is reflected, in particular, through strict compliance with Regulation EU 2016/679 of the European Parliament and of the Council of 27 April 2016 General Data Protection Regulation and Law no. 58/2019 of 8 August, which ensures its implementation in the Portuguese legal system, as well as coherent alignment with national legal frameworks in other jurisdictions where the Group operates.
In the specific case of Angola, this alignment is ensured in accordance with Law no. 22/11 of 17 June Personal Data Protection Law and its relevant regulations, guaranteeing, regardless of geography, full respect for the principles of lawfulness, fairness, transparency, proportionality, purpose limitation, accuracy, storage limitation, integrity and confidentiality.
Our global corporate data protection and information security policy is periodically reviewed, audited and improved, ensuring that all employees, partners, suppliers and other stakeholders understand and comply with all legal obligations.
Aware that, in the areas in which EMBRACE Group companies operate, the processing of personal data necessarily involves international transfers, we adopt appropriate organisational and technical measures to ensure that, regardless of geography, the level of protection granted to personal data is substantially equivalent to that required by the high standards of the European GDPR.
Within this framework, we have established internal policies and procedures with transversal and harmonised application across all EMBRACE Group entities and appointed a Data Protection Officer with global responsibility, whose work is coordinated with local data protection and information security specialists, ensuring the effective, coordinated and consistent implementation of appropriate technical and organisational measures for the protection of personal data. This governance structure ensures, in a sustained manner, the promotion of an organisational culture of privacy, information security and regulatory compliance.
III - WHO IS RESPONSIBLE FOR PROCESSING YOUR PERSONAL DATA
The EMBRACE Group is responsible for processing the personal data of its direct clients, potential clients individuals and employees and guests of its institutional clients.
As data controller, the EMBRACE Group determines the purposes and means of processing personal data, ensuring compliance with applicable legal obligations in each jurisdiction, particularly regarding the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability, as standardised under the GDPR.
Controller Contact Details:
Telephone: +351 213565300, available from 8:00 to 20:00 Monday to Friday.
Email: operacoes@embraceambition.pt
EMBRACE Group Portal: https://www.embraceambition.com/
IV - WHAT PERSONAL DATA WE PROCESS
The following categories of personal data may be collected through the channels and services described in this Privacy Policy:
Data collected by the EMBRACE Group:
Contact information
Full name,
Address,
Email address,
Telephone,
Mobile phone number.
Personal information
Date of birth,
Citizen card number and validity date,
Passport number and validity date,
Seat preference on flights.
Professional information
Company name,
Professional category and role within the company,
Department and area,
Employee number and cost centre.
Client history
Customer satisfaction level,
Travel and accommodation history and preferences,
Services purchased, purchase date and respective price.
V - HOW WE COLLECT YOUR DATA, PURPOSES AND LEGAL BASIS
Your personal data may be collected and processed by the EMBRACE Group in the context of providing travel management, events and corporate mobility services, namely in the following situations:
When, following a commercial agreement, your company provides your personal data necessary for organising, booking, monitoring and managing your business or other travel, participation in events and or congresses;
When you contact us directly via digital platforms, telephone, email or in person to request services, information or proposals;
- When you access or use our websites, applications or digital platforms, where you may be asked to provide data for authentication, travel preferences, billing or communications;
- When you participate in events or congresses organised by the EMBRACE Group, where we collect registration, attendance and satisfaction data;
- When you interact with us within marketing campaigns or promotional activities, based on your prior, free and informed consent.
The legal grounds for collecting and processing your personal data are as follows:
Performance of a contract or pre-contractual steps when processing is necessary for entering into, performing or managing a contract, including bookings, ticket issuance, accommodation, event logistics, invoicing and customer support;
- Legal obligations when processing is required to comply with legal duties such as tax, accounting, anti money laundering and counter-terrorism financing obligations, including Directive EU 2016/681 relating to passenger name record data, labour law, health and safety regulations or sectoral requirements;
- Consent when processing depends on your freely given, specific, informed and explicit consent, such as for direct marketing communications, newsletters, preference collection or promotional activities;
- Legitimate interest when processing is necessary for the legitimate interests pursued by the EMBRACE Group, such as system security, fraud prevention, service improvement, relationship management and optimisation of corporate events, provided your rights and freedoms are not overridden.
VI - HOW LONG WE RETAIN YOUR PERSONAL DATA
The EMBRACE Group retains your personal data only for the period strictly necessary to fulfil the purposes for which it was collected or subsequently processed, in accordance with the storage limitation principle.
The retention period may vary depending on the purpose of processing, applicable legal requirements or the existence of limitation periods that justify retaining the data for a longer period, particularly for the fulfilment of contractual, tax or judicial obligations.
Once the applicable maximum retention period has been reached, personal data will be:
irreversibly anonymised, so that the data subject can no longer be identified in which case it may be retained for statistical or aggregated analysis purposes; or
securely deleted through technical procedures that ensure it cannot be recovered and is not exposed to unauthorised third parties.
For direct marketing purposes, personal data will be retained until you withdraw your consent or exercise your right to object, without prejudice to additional legally required or permitted retention periods.
For contact management, customer support and commercial communications purposes, data will be retained for as long as the relationship with the institutional client or data subject remains active and for up to two years after the last relevant contact, unless otherwise required by law.
The EMBRACE Group conducts periodic audits of its databases in order to eliminate unnecessary data or data whose retention is no longer justified under the principles of data minimisation and storage limitation.
VII - HOW WE ENSURE THE SECURITY OF YOUR PERSONAL DATA
Appropriate technical and organisational measures
Because the security of your personal data is a strategic and ongoing priority for the EMBRACE Group, in alignment with our global partner American Express Global Business Travel (AMEX GBT), the EMBRACE Group has adopted and implemented a transversal Information Security Policy based on internationally recognised best practices, incorporating robust technical and organisational measures aimed at protecting the confidentiality, integrity, availability and authenticity of personal data processed. These measures are regularly reassessed in light of technological developments, emerging threats and continuously evolving legal obligations.
This policy reflects a risk-based approach, ensuring the adoption of mechanisms proportionate to the nature, scope, context and purposes of the processing, as well as to the likelihood and severity of risks to the fundamental rights and freedoms of data subjects.Although data transmission over the internet or websites cannot guarantee absolute security against unauthorised access, intrusion or improper exposure, the EMBRACE Group and its service providers or business partners make their best technical and procedural efforts to mitigate such risks, ensuring compliance with the principles of data protection by design and by default.
In accordance with our Information Security Policy, we have implemented, in particular, the following measures:
i. Pseudonymisation and encryption of personal data, whenever technically feasible, appropriate and proportionate;ii. Logical segregation of production, testing and development environments;
iii. Strict authentication and access management controls, based on the principle of least privilege and need to know;
iv. Continuous monitoring of systems and networks to detect incidents and security anomalies;
v. Backup and disaster recovery policies that are properly documented and tested;
vi. Regular information security audits;
vii. Periodic and mandatory training for employees on data protection and cybersecurity;
viii. Systematic recording and assessment of information security incidents, with mandatory reporting to the Data Protection Officer and Security Officer and, where legally required, to the competent supervisory authority;
ix. Recording and mapping of personal data processing activities.
Continuous training of our employees
The EMBRACE Group recognises that the effectiveness of data protection and information security measures largely depends on the awareness and training of its human resources. For this reason, it ensures the implementation of continuous, periodic and mandatory training programmes for all employees, internal service providers and external consultants with access to personal data or information systems.These programmes include specific content on the principles and rules of personal data protection, based on the internationally recognised GDPR standard for all employees and, specifically, in Angola with regard to Law no. 22/11 of 17 June and in Mozambique with regard to Law no. 3/2017 of 9 January.
Information Security Policy and its procedures;
Confidentiality and secrecy obligations applicable to all information and specifically to personal data processing;
Prevention and management of security incidents and data breaches;
Cybersecurity best practices, including password management, protection against social engineering and secure use of devices and networks;
Disciplinary and legal sanction frameworks in case of non-compliance.
Training is adapted to the functional profile of employees and is delivered at onboarding and at regular intervals throughout the employment or contractual relationship and may be supplemented by additional actions depending on regulatory, technological or organisational changes.
This systematic investment ensures a culture of compliance, responsibility and security across the EMBRACE Group.
Careful selection of processors
Within the scope of our activity, the EMBRACE Group may use third-party entities acting as processors to carry out personal data processing operations on our behalf and under our responsibility.Processors are selected based on strict criteria of legal compliance and technical robustness, in accordance with Article 28 of the GDPR
Before any engagement, the EMBRACE Group carries out risk assessments and verification of the processor’s technical and organisational requirements:
Provide adequate guarantees of appropriate technical and organisational measures;
Be bound by a written contract ensuring adequate data protection and defining scope, purpose and obligations;
Process data only on documented instructions from the EMBRACE Group;
Ensure confidentiality obligations for authorised personnel;
Support compliance with data subject rights and legal obligations;
Not subcontract without prior written authorisation;
Delete or return data at the end of the service unless legally required otherwise.
This approach aims to ensure that any entity collaborating with the EMBRACE Group operates in compliance with the highest legal and technical standards in the field of personal data protection, thereby reinforcing data security and the trust of data subjects across all territories in which we operate.
International transfers
Considering the multinational nature of the EMBRACE Group and the transnational scope of its business within the tourism, travel, accommodation and related services industries, your personal data may be subject to international transfer to entities located outside the European Economic Area (EEA), namely suppliers, technology partners or service providers contracted for legitimate purposes consistent with those described in this Privacy and Personal Data Protection Policy.In all cases, the EMBRACE Group ensures that any transfer of personal data, including subsequent processing in a third country or international organisation, is carried out only if the conditions set out in Articles 44 to 49 of the GDPR are complied with by all entities involved in the data processing chain, including onward transfers from the third country or international organisation to another third country or international organisation.
Transfers of personal data outside the EEA are carried out on the basis of appropriate safeguards, including, where applicable, adequacy decisions, European Commission standard contractual clauses, and binding corporate rules;
Transfers of your personal data are preceded by an assessment of the level of protection in the destination country, including legal and administrative practices regarding access by public authorities, as well as all entities involved;
Your personal data remains stored on secure servers, subject to appropriate technical and organisational measures, and access and processing are carried out exclusively in accordance with instructions from the EMBRACE Group or under equivalent contractual obligations imposed on service providers.
VIII - WHAT ARE YOUR RIGHTS AND HOW YOU CAN EXERCISE THEM
As a data subject, you are entitled to a set of legally established rights, the exercise of which is ensured in a fair and transparent manner by the EMBRACE Group, regardless of the jurisdiction in which you are located.
Right of Access – to obtain confirmation as to whether or not your personal data is being processed and, where that is the case, to access such data and the legally required information;
Right to Rectification – to request the correction or updating of inaccurate or incomplete personal data;
Right to Erasure (“right to be forgotten”) – to request the deletion of your personal data, in particular where the purpose that justified the processing has ceased or where consent has been withdrawn (where applicable), unless legal grounds justify its retention;
Right to Restriction of Processing – to obtain the restriction of the processing of your personal data in certain circumstances (for example, while verifying the accuracy of the data);
Right to Object – to object, on grounds relating to your particular situation, to the processing of your data based on legitimate interest or public interest, as well as to decisions based solely on automated processing, including profiling;
Right to Data Portability – to receive the personal data you have provided to us in a structured, commonly used and machine-readable format and to transmit those data to another controller, where the processing is based on consent or on the performance of a contract;
Right to Withdraw Consent – where processing is based on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out prior to withdrawal;
Right to Lodge a Complaint
Whenever there is any reason for complaint due to dissatisfaction or doubt regarding processing, the data subject may immediately submit a complaint or request for information to the Data Protection Officer of the EMBRACE Group through the following contacts:
Email: dpo@embraceambition.com
Telephone: +351 213 565 300, available from 8:00 to 20:00, Monday to Friday
The Data Protection Officer, in accordance with the “Procedure for Exercising Data Subject Rights”, ensures:i. Registration and handling of the complaint or request within a maximum period of 24 working hours;
ii. Transparent, impartial and reasoned responses;
iii. Ongoing information on the status of the process until its final resolution;
iv. The promotion of diligent, fair and rights-respecting processing.
Without prejudice to this secure internal channel, data subjects also have the right to lodge a complaint with a supervisory authority, particularly in the Member State of their habitual residence, place of work or place where the alleged infringement occurred, if they consider that the processing of personal data relating to them infringes the GDPR and/or applicable local law:
- In Portugal: Comissão Nacional de Proteção de Dados (CNPD) via geral@cnpd.pt;
- In Angola: Agência de Proteção de Dados (APD) via geral@apd.ao
- In Mozambique: Instituto Nacional de Tecnologias de Informação e Comunicação (INTIC) via info@intic.gov.mz;
- In Spain: Agencia Española de Protección de Datos (AEPD) via https://sedeaepd.gob.es/sede-electronica-web/vistas/infoSede/tramitesCiudadanoReclamaciones.jsf
IX - MONITORING, REVIEW AND ALIGNMENT WITH OTHER COMPLIANCE SYSTEMS
This Privacy and Personal Data Protection Policy is reviewed whenever there are relevant legislative, regulatory or operational changes, as well as following recommendations, guidelines or binding acts issued by national or European supervisory authorities, relevant judicial decisions, or guidelines and opinions adopted within the framework of the European Data Protection Board (EDPB).
Changes introduced are approved by the competent bodies of the EMBRACE Group and made available through the usual communication channels, ensuring accessibility, clarity and continuous updating. Whenever such changes imply a substantial modification of the terms of personal data processing applicable to data subjects, they are informed in an appropriate, timely and transparent manner, in accordance with applicable legislation.
Without prejudice to compliance with all legal systems applicable to the activities of the entities that form part of the EMBRACE Group, the Group adopts a homogeneous set of guiding principles governing its corporate conduct, reflected in the definition and application of consistent internal policies. This approach ensures a coherent and transversal application of applicable legal and ethical duties, as well as the consistent integration of this Policy with the Group’s commitments in matters of institutional integrity, prevention of corruption and related offences, and the fight against money laundering and terrorist financing, based on duties of diligence, transparency, accountability and control.