Privacy

Privacy Policy

How EmCurso.PT processes the personal data of those who use the API, the console, the documentation, the assistant and the contact form, under the General Data Protection Regulation.

Version
1.0
Last updated
24 September 2026
1.

Subject matter

What this policy governs

  1. This policy describes the processing of personal data carried out by EmCurso.PT (the “provider”) in connection with the programming interface made available at api.emcurso.pt (the “API”) and the services that accompany it: the public pages, the documentation, the console, the access request, the automated assistant and the contact form.

  2. “Holder” means anyone holding a valid access key under the API Terms of Use; “user”, anyone who visits the site or uses the assistant without a key; and “data subject”, the natural person to whom the personal data relates.

  3. This policy develops article 8 of the API Terms of Use and prevails over the main site's Privacy Policy in everything concerning the API. In all other respects, the latter applies.

2.

Controller

Data controller

  1. The controller is the provider, who can be reached on any data-protection matter at [email protected].

  2. As regards the data the holder processes in its own integration, the holder acts as an autonomous and independent controller, under article 8 of the API Terms of Use. This policy does not cover that processing.

3.

Categories of data

What data is processed

  1. Identification and contact data: name, email address, telephone, organisation, tax number and role, where given in the access request, the console or the contact form.

  2. Technical connection data: IP address, browser or application identifier (User-Agent), request origin, approximate location associated with the IP address (country, region and city) and time of access.

  3. API usage data: the requests made with each key, as set out in article 4 of this policy.

  4. Content of communications: the text of messages addressed to the assistant and of messages sent through the contact form.

  5. The provider does not ask for special categories of data within the meaning of article 9 of the General Data Protection Regulation (GDPR), and asks that none be entered in the forms or the assistant.

4.

API logs

Logging of API requests

  1. Each API request is logged with the endpoint called, the method, the response code and time, the response size, the source IP address, the User-Agent header, the origin, the approximate location associated with the IP address and the time. When the request is authenticated, the log is linked to the key used.

  2. The logs are used to enforce usage limits, detect and investigate abuse, investigate incidents, provide technical support and give the holder statistics on its own usage in the console.

  3. Access keys are stored only as a hash. The provider can verify a key that is presented, but cannot recover its value.

5.

Access and console

Access request and key management

  1. The access request collects the applicant's identification and contact data, the kind of organisation, the integration type, the expected volume, the IP addresses to allow, the stated purpose and the acceptance of the terms. This data is used to assess the application, issue and manage the key and communicate with the holder.

  2. The application undergoes a preliminary automated analysis, which supports the assessment but does not replace it. The decision to grant, limit or refuse access is always taken by a person, so there are no decisions based solely on automated processing within the meaning of article 22 of the GDPR.

  3. Signing in to the console uses a short-lived, single-use code sent by email. The session is kept by a dedicated cookie, lasting at most 14 days, as set out in the Cookie Policy.

6.

Assistant

The automated assistant

  1. The site offers an automated assistant, identified as such, which answers questions about the API and the civil-protection situation. It is not a person, it is not an emergency channel and its answers may contain mistakes. In an emergency, call 112.

  2. Each message sent to the assistant is accompanied by up to ten earlier messages from the same conversation, the language and the identity of the page of the site the user has open. Answers are generated by language models run by an infrastructure provider engaged for the purpose, acting as a processor.

  3. The provider does not keep the content of conversations in its systems. Conversations are stored only in the user's browser, where they can be deleted at any time. On the server side, each answer leaves only a technical record — outcome, language, number of messages, lookups made and duration — without the text exchanged.

  4. The IP address is used to limit the number of messages per minute and per day and to block, for one hour, repeated attempts to get around the assistant's rules. These counters are held in memory and are not retained.

  5. Conversations are not used to train models. Users should not enter into the assistant personal data that the request does not need, nor data about third parties.

7.

Contact

Contact requests

  1. The contact form, available on the contact page and in the assistant, collects name, email address, mobile number, organisation (optional), kind of contact, subject, message and language, as well as the IP address and the browser identifier, to tell senders apart and prevent abuse.

  2. In the assistant, the subject and message text are suggested from what the user wrote and can be freely changed. The request is sent only on the user's express action; the assistant never sends requests on its own initiative.

  3. The request data is used solely to answer it and follow the matter up, and is made known to the provider's team by internal notification.

8.

Data served

The data the API makes available

  1. The data served by the API comes from public sources and describes occurrences, warnings and conditions, not people. The provider adds no personal data to it.

  2. Even so, the combination of location, nature and time may, in particular cases, allow people involved to be identified indirectly. The holder's processing of that information is governed by article 8 of the API Terms of Use.

9.

Legal bases

Purposes and lawful bases

  1. Performance of a contract and pre-contractual steps, under article 6(1)(b) of the GDPR: assessing the access request, issuing and managing the key, the console and communications with the holder.

  2. Legitimate interest, under point (f) of the same paragraph: the security and availability of the service, request logging, enforcing limits, preventing abuse, running the assistant and answering contact requests.

  3. Compliance with a legal obligation, under point (c) of the same paragraph, where the law requires it.

10.

Recipients

Recipients and processors

  1. The data is processed by the provider's team and, as far as necessary, by service providers engaged for hosting, data storage, networking and attack protection, running the assistant's language models, sending email and internal notifications.

  2. These providers act as processors under article 28 of the GDPR, only on the provider's instructions and bound by confidentiality and security obligations.

  3. The provider does not sell personal data or hand it to third parties for their own purposes. Data is disclosed to authorities only where the law requires it.

11.

Transfers

International transfers

  1. Some processors may process data outside the European Economic Area. In those cases, the transfer relies on the mechanisms of chapter V of the GDPR, namely adequacy decisions or standard contractual clauses approved by the European Commission.

12.

Retention

Retention periods

  1. Technical connection data and individual API request logs are kept for at most 12 months. After that period, only statistical aggregates remain, which identify neither individual requests nor IP addresses. Records relating to security incidents may be kept for as long as their investigation lasts.

  2. Access-request and key data is kept while the key is active and, afterwards, for as long as needed to meet legal obligations and to defend rights.

  3. Contact requests are kept for as long as needed to answer them and follow the matter up. The content of conversations with the assistant is not kept by the provider.

13.

Security

Security measures

  1. The provider applies technical and organisational measures appropriate to the risk, under article 32 of the GDPR, including encrypted communications, keys stored only as a hash, session cookies out of reach of page scripts and restricted team access to the data.

  2. In the event of a personal data breach, the provider makes the notifications required by articles 33 and 34 of the GDPR.

14.

Rights

Data subjects' rights

  1. Data subjects have the rights of access, rectification, erasure, restriction of processing, portability and objection, under articles 15 to 21 of the GDPR. Where processing is based on legitimate interest, they may object to it on grounds relating to their particular situation.

  2. Rights are exercised by writing to [email protected]. The provider answers within one month, extendable under article 12 of the GDPR, and may ask for what it needs to confirm the requester's identity.

  3. Data subjects may also lodge a complaint with the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (www.cnpd.pt).

15.

Changes

Changes to this policy

  1. This policy may be changed to reflect changes in the service or the law. Each change is published on this page with a new version and date; those that materially affect key holders may also be notified to them by email.