Privacy Policy
Last updated: March 19, 2026
1. Who We Are
Autopagy is a platform that connects automotive dealerships with potential buyers. Autopagy is the data controller for personal data collected through this platform. We are not required to appoint a Data Protection Officer under Art. 37 GDPR. For any questions about your data, contact us at [email protected].
2. What Data We Collect
- Account data: name, email address, and password (stored securely) when you register
- Contact form data: name, email, phone number, and message when you contact a dealer
- Technical data: IP address, user agent, and session information
- Usage data: pages visited and cars viewed
3. Why We Process Your Data
- Service delivery: to operate the platform and connect buyers with dealers — legal basis: contractual necessity (Art. 6(1)(b) GDPR)
- Account management: to authenticate users and manage sessions — legal basis: contractual necessity (Art. 6(1)(b) GDPR)
- Contact requests: to forward your enquiries to the relevant dealer — legal basis: consent (Art. 6(1)(a) GDPR)
- Security: to protect against fraud and unauthorized access — legal basis: legitimate interest (Art. 6(1)(f) GDPR), namely protecting the platform and its users
4. Data Sharing
Your data may be shared with:
- Dealerships: when you submit a contact form, the dealer receives your name, email, phone, and message
- Service providers: hosting, CDN, and security providers that help us operate the platform
We do not sell your personal data to third parties.
5. International Transfers
Some of our service providers may process data outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place, such as the European Commission's Standard Contractual Clauses or an adequacy decision.
6. Data Retention
- Account data: retained while your account is active; deleted within 30 days of account deletion
- Contact form data: retained for up to 12 months, then anonymized or deleted
- Technical data: retained for up to 90 days for security purposes
- Usage data: retained for up to 24 months for service improvement, then aggregated or deleted
You may request deletion of your data at any time by emailing [email protected].
Providing your data is necessary to use the platform. If you do not provide the required data, you may not be able to register or use certain features.
7. Your Rights
Under the GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data
- Port your data in a machine-readable format
- Object to processing based on legitimate interest
- Restrict processing in certain circumstances
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal
To exercise any of these rights, email us at [email protected]. We will respond within one month. If your request is complex, we may extend this by a further two months, and will inform you of the reason for the delay. Exercising your rights is free of charge.
8. Cookies
We use essential cookies for authentication, session management, and storing your language preference. Non-essential cookies are only set with your explicit consent. See our Cookie Policy for details.
9. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on you.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date.
11. Supervisory Authority
You have the right to lodge a complaint with the Portuguese Data Protection Authority (CNPD) at www.cnpd.pt.