Closedata
Data Protection and GDPR Compliance
Last updated: 17 August 2026
Closedata processes personal data in the context of a business information and decision-support platform. This document describes the applicable data protection framework, the roles assumed by Closedata and the commitments it makes to data subjects, complementing the Privacy Policy.
Controller: Summer Agreement, Lda, the company that operates the Closedata brand and platform ("Closedata"), corporate tax number 518 817 717, with registered office in Lisbon, Portugal.
Data protection contact: legal@closedata.co. Data Protection Officer (where appointed): legal@closedata.co.
1. Legal framework
The processing of personal data by Closedata is governed by Regulation (EU) 2016/679 (GDPR), by Portuguese Law no. 58/2019 of 8 August and other applicable legislation, as well as by the guidance issued by the competent authorities.
2. Roles: controller and processor
2.1. Closedata acts as controller in relation to the data of website visitors, commercial contacts and the business information databases it builds and makes available, defining the purposes and means of the processing.
2.2. Closedata acts as processor when it processes personal data on behalf of its clients, in particular when clients enter or manage their own information, notes or contacts on the platform. In those cases, the processing is governed by a Data Processing Agreement entered into under Article 28 of the GDPR, in which the client is the controller and Closedata processes the data in accordance with the client's documented instructions.
3. Principles
Closedata processes personal data in accordance with the principles of lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability, set out in Article 5 of the GDPR.
4. Legal bases
The legal bases relied upon are detailed in the Privacy Policy and include, depending on the purpose, the performance of a contract and pre-contractual steps, consent, compliance with legal obligations and legitimate interests.
5. Third-party source data and the right to object
The business information databases incorporate professional data obtained from registries and public sources, from licensed data providers and from web and press sources, on the basis of the legitimate interest in processing business information.
Data subjects whose data appears in these databases may exercise the right to object, as well as the other rights provided for in the GDPR, through legal@closedata.co. Where an objection is raised and there are no compelling legitimate grounds that override it, Closedata ceases the processing of the data in question.
6. Profiling, automated decisions and artificial intelligence
6.1. The classifications and signals generated by the platform, including the Deal Score and succession signals, result from a deterministic methodology applied to available data and are intended to support client decision making.
6.2. Closedata does not take decisions based solely on automated processing that produce legal effects or similarly significant effects for data subjects. The final decision always rests with the client, with human involvement.
6.3. The conversational layer relies on language models, while scoring, signal calculation and ranking are performed deterministically. Personal data of data subjects and client data are not used to train third-party public models.
7. International transfers
Whenever data is transferred outside the European Economic Area, Closedata ensures appropriate safeguards under Chapter V of the GDPR, in particular adequacy decisions or standard contractual clauses.
8. Security and data breaches
8.1. Closedata implements technical and organizational measures appropriate to the risk, including access control, encryption where applicable, activity logging and system monitoring.
8.2. In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, Closedata notifies the CNPD within 72 hours of becoming aware of it and, where required, communicates it to the affected data subjects.
9. Rights of data subjects
Data subjects may exercise their rights of access, rectification, erasure, restriction, portability and objection, and may withdraw consent, through legal@closedata.co, and may lodge a complaint with the Portuguese Data Protection Authority (CNPD).
10. Processors
Closedata uses carefully selected processors that provide sufficient guarantees to implement appropriate technical and organizational measures, bound by contract under Article 28 of the GDPR. The list of processors is available on request.
11. Data Protection Officer
Closedata may appoint a Data Protection Officer, who can be contacted at legal@closedata.co. The appointment of an Officer is mandatory where the conditions of Article 37 of the GDPR are met, which is assessed according to the scale and nature of the processing.
12. Updates and contact
This document may be updated at any time. For any data protection question, data subjects may contact Closedata at legal@closedata.co. All processing of personal data is carried out in accordance with our Privacy Policy.