DATA PROTECTION AND PRIVACY POLICY

CIF – Clube Internacional de Férias SA (“INTERPASS CLUBE”) is one of the companies in the Interpass Group, led by the holding company Geralgarve – Sociedade Gestora de Participações Sociais S.A. The companies that make up the Interpass Group operate in the areas of tourism, lodging, hospitality, travel, insurance, and services, among others. CIF – Clube Internacional de Férias SA is committed to protecting the personal data of Members/Customers of the products and services offered by the various companies in the group, as well as the personal data of the respective data subjects in all situations where personal data is processed by the various companies and entities of the Interpass Group. In this context, it has drawn up this Policy, which is underpinned by its commitment to comply with personal data protection rules.

This Privacy Policy applies to all companies in the Interpass Group, namely: CIF – Clube Internacional de Férias, S.A.; CIF – Agência de Viagens, S.A.; Interpass Health Equipment, S.A.; NB Seguros – Insurance Brokerage, Lda; NB Energia, Lda; IPSERVE Advertising and Marketing Services, Lda; Zarcotel Hotel Industry S.A.; Alvaflor – Hospitality and Tourism, Lda; IBIS Construction Company, S.A.

PERSONAL DATA PROTECTION POLICY

This Policy is intended to inform Members/Clients of the general rules governing the processing of personal data, which is collected and processed in strict compliance with the provisions of the personal data protection legislation in force at any given time, namely Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (“GDPR”).

INTERPASS CLUBE adheres to best practices in the area of security and personal data protection, and to this end has implemented the necessary technical and organizational measures to comply with the GDPR and ensure that the processing of personal data is lawful, fair, transparent, and limited to authorized purposes.

INTERPASS CLUBE is committed to protecting personal data and ensuring its confidentiality, and has implemented the measures it deems appropriate to ensure the accuracy, integrity, and confidentiality of personal data, as well as to safeguard all other rights of the data subjects.

The rules set forth in this Policy supplement the provisions regarding the protection and processing of personal data contained in the contracts that Members/Customers enter into with INTERPASS CLUBE, as well as the rules set forth in the terms and conditions governing the provision of various products and services, which are duly published on the respective websites.

SCOPE OF THE DATA PROTECTION POLICY

This Data Protection Policy applies exclusively to the collection and processing of personal data for which INTERPASS CLUBE is responsible, in connection with the services and products provided to its Members/Customers and in all situations in which INTERPASS CLUBE processes personal data, particularly through social intervention and development support initiatives.

The Interpass Group’s websites may include links to other websites that are not affiliated with INTERPASS CLUBE. These links are provided in good faith, and INTERPASS CLUBE cannot be held responsible for the collection and processing of personal data carried out through these websites, nor does INTERPASS CLUBE assume any responsibility regarding such websites, particularly with respect to their accuracy, credibility, and the features available on them.

PERSONAL INFORMATION

Personal data means any information, of any nature and regardless of its medium, including sound and images, relating to an identified or identifiable natural person.

A natural person is considered identifiable if they can be identified, directly or indirectly, in particular by reference to a name, an identification number, or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural, or social identity.

PROCESSING OF PERSONAL DATA

The processing of personal data consists of any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, comparison, interconnection, restriction, erasure, or destruction.

DATA CONTROLLER

The entity responsible for processing personal data is the Company or entity within the Interpass Group that determines the purposes and means of such processing.

To this end, if the data subject needs to contact the data controller, they may do so using the contact information provided below:

By sending a written request to the data controller, to:

Email: pdados@interpass.pt

Or

A/C Proteção de Dados
CIF – Clube Internacional de Férias, S.A.
Avenida Elias Garcia, nº 45C
1049-078 Lisboa

DATA PROTECTION OFFICER

The Data Protection Officer plays a key role in the processing of personal data, ensuring, among other things, that data processing complies with applicable laws, verifying compliance with this Data Protection Policy and establishing clear rules for the processing of personal data, ensuring that all those who entrust INTERPASS CLUBE with the processing of their personal data are aware of how INTERPASS CLUBE processes such data and of their rights in this regard.

Therefore, data subjects may, if they so wish, contact the Data Protection Officer regarding matters related to the processing of personal data using the following contact information:

Email: epdados@interpass.pt

Or

A/C Proteção de Dados
CIF – Clube Internacional de Férias, S.A.
Avenida Elias Garcia, nº 45C
1049-078 Lisboa

TYPES OF PERSONAL DATA PROCESSED

As part of its activities, INTERPASS CLUBE processes the personal data necessary for the provision of services and/or products, as well as for social intervention purposes, including data such as name, address, telephone number, and email address, in accordance with the more detailed information provided to data subjects.

Without prejudice to compliance with legal requirements regarding the retention and transfer of data for the purposes of investigating, detecting, and prosecuting serious crimes, as well as other processing activities to which it is legally obligated, the Member’s/Customer’s profile and/or usage data will be processed by INTERPASS CLUBE to the extent necessary for the provision of the respective services. Thus, based on their profile and/or usage, the Member/Customer will have access, in particular, to exclusive services and information.

Personal profile and/or usage data may also be processed for marketing purposes or to promote INTERPASS CLUBE’s goods or services, provided the data subject has given their consent.

If the member/customer has given prior consent, such consent may be withdrawn at any time; however, this shall not affect the lawfulness of the processing carried out on the basis of the consent previously given.

COLLECTION OF PERSONAL INFORMATION

INTERPASS CLUBE collects your personal data, including by telephone, in writing, and through its websites, ensuring, whenever necessary, that the data subject has given prior consent.

Certain personal data is essential for the performance of the contract, and if such data is missing or incomplete, INTERPASS CLUBE will be unable to provide the product or service in question.

If the data subject is not a Member or Customer of INTERPASS CLUBE, their personal data will only be processed when it is provided, specifically through subscription to newsletters, in which case the rules of this Data Protection Policy will apply.

The personal data collected may be processed electronically, either automatically or manually, ensuring strict compliance with personal data protection laws in all cases. It is stored in specific databases created for this purpose, and under no circumstances will the collected data be used for any purpose other than that for which it was collected or for which the data subject has given consent.

RECIPIENTS OF PERSONAL DATA

Without prejudice to the recipients identified throughout this Privacy Policy, INTERPASS CLUBE may disclose the Member’s/Customer’s personal data to law enforcement, judicial, tax, and regulatory authorities for the purpose of complying with legal obligations.

PURPOSES OF PERSONAL DATA PROCESSING

In general, the personal data collected is based on and intended for the management of the contractual relationship, the provision of the contracted services, and the tailoring of services to the needs and interests of the Member/Client, specifically for the purposes of providing access to commercial offers and service presentations, as well as for informational and marketing activities.

Without prejudice to any additional information provided at the time of data collection, INTERPASS CLUBE may also, provided it is legally permissible, use the personal data provided by the data subject for other purposes, such as for social intervention initiatives, the submission of complaints and suggestions, the dissemination of institutional information about the Group, and/or to publicize campaigns, promotions, advertising, and news regarding the products and/or services of the Interpass Group, as well as to conduct market research or evaluation surveys.

RETENTION OF PERSONAL DATA

The length of time for which personal data is stored and retained varies depending on the purpose for which the information is processed.

In fact, there are legal requirements mandating that data be retained for a minimum period of time. Therefore, in the absence of a specific legal requirement, data will be stored and retained only for the minimum period necessary to fulfill the purposes for which it was collected or subsequently processed, in accordance with the law.

DATA SUBJECT RIGHTS

As data subjects, Members/Customers are guaranteed, at any time, the right to access, rectify, update, restrict, and erase their personal data (except for data that is essential for INTERPASS CLUBE to provide its services—data that has been duly identified as mandatory—or for compliance with legal obligations to which the data controller is subject), the right to object to the use of such data for commercial purposes by INTERPASS CLUBE and to withdraw consent, without this affecting the lawfulness of the processing carried out under that consent, as well as the right to data portability.

RIGHT OF ACCESS AND CONTROL OF DATA

Without prejudice to the provisions of the GDPR, the data subject may do so either directly or by submitting a written request to the relevant data controller using the contact information provided for this purpose in this document, as well as any other contact information provided by INTERPASS CLUBE.

INTERPASS CLUBE may promote new products or services to its Members/Customers, including via telephone, email, SMS, MMS, or any other electronic communications service, provided that the data subject has given their consent.

If the data subject no longer wishes to receive these communications, they may withdraw their consent to the use of their data for marketing purposes at any time.

Without prejudice to the right to file complaints directly with INTERPASS CLUBE using the contact information provided for that purpose, Members/Customers may file a complaint directly with the Supervisory Authority, which is the National Data Protection Commission (CNPD), using the contact information provided by that entity for that purpose.

MEASURES TAKEN TO ENSURE THE SECURITY OF PERSONAL DATA

INTERPASS CLUBE is committed to ensuring the security of the personal data provided to it and has adopted and implemented strict rules in this regard. Compliance with these rules is mandatory for all those who are legally authorized to access such data.

Given INTERPASS CLUBE’s commitment to protecting personal data, we have implemented a range of technical and organizational security measures to safeguard the personal data provided to us against disclosure, loss, misuse, alteration, unauthorized processing or access, as well as against any other form of unlawful processing.

In addition, third parties that, in the course of providing services, process the personal data of Members/Customers on behalf of and for the account of INTERPASS CLUBE are required, in writing, to implement appropriate technical and security measures that, at all times, meet the requirements set forth in applicable law and ensure the protection of the data subject’s rights (namely, the protection of the privacy and personal data of Members/Customers).

In this regard, on all INTERPASS CLUBE websites, forms for collecting personal data require encrypted browser sessions, and all personal data provided is securely stored on INTERPASS CLUBE’s systems, which, in turn, are located in a national operator’s data center, protected by all the physical and logical security measures that INTERPASS CLUBE has deemed essential for the protection of personal data.

Notwithstanding the security measures adopted by INTERPASS CLUBE, INTERPASS CLUBE advises all Internet users to take additional security measures, specifically ensuring that they use a computer and browser that are up to date with properly configured security patches, with an active firewall, antivirus, and anti-spyware software, and that they verify the authenticity of the websites they visit online, avoiding websites whose reputation they do not trust.

DISCLOSURE OF DATA TO OTHER ENTITIES (THIRD PARTIES AND SUBCONTRACTORS)

INTERPASS CLUBE may, in the course of its business, engage third parties to provide certain services. At times, the provision of these services requires such third parties to access the personal data of Members/Customers. When this occurs, INTERPASS CLUBE takes appropriate measures to ensure that the entities with access to the data are reputable and offer the highest level of security, which is duly established and safeguarded in a contract between INTERPASS CLUBE and the third-party entity or entities.

Accordingly, any entity subcontracted by INTERPASS CLUBE will process the personal data of our Members/Customers on behalf of INTERPASS CLUBE, adopting the necessary technical and organizational measures to protect personal data against accidental or unlawful destruction, accidental loss, alteration, disclosure, or unauthorized access, as well as against any other form of unlawful processing.

In any case, INTERPASS CLUBE remains responsible for the personal data provided to it.

TRANSFER OF PERSONAL DATA

The provision of certain services by INTERPASS CLUBE may involve the transfer of your data outside of Portugal, including outside the European Union.

In such cases, INTERPASS CLUBE will strictly comply with applicable legal provisions, particularly regarding the assessment of the adequacy of the destination country or countries with respect to the protection of personal data and the requirements applicable to such transfers, including, where applicable, the execution of appropriate contractual arrangements that ensure compliance with and respect for the legal requirements in force.

CHANGES TO THE PERSONAL DATA PRIVACY POLICY

INTERPASS CLUBE reserves the right to make adjustments or changes to this Privacy Policy at any time; such changes will be duly announced through INTERPASS CLUBE’s various communication channels.

All companies within the Interpass Group that may process your personal data.

COOKIE POLICY

“Cookies” are small pieces of software that are stored on your computer via your browser; they retain only information related to your preferences and do not, therefore, include personal data.

To learn more about how to manage cookies in your browser, please see the information on Cookie Management.

Cookies are used to help determine the usefulness, appeal, and usage of websites, enabling faster and more efficient browsing by eliminating the need to repeatedly enter the same information.

There are two types of cookies that can be used:

• Persistent cookies—these are cookies that are stored at the browser level on your devices (PC, mobile, and tablet) and are used whenever you visit one of the INTERPASS CLUBE websites. They are generally used to tailor your browsing experience to your interests, allowing us to provide a more personalized service.

• Session cookies – these are temporary cookies that remain in your browser’s cookie file until you leave the website. The information collected by these cookies is used to analyze web traffic patterns, helping to identify issues and provide a better browsing experience.

Types of Cookies Used:

• Strictly necessary cookies – These cookies enable you to navigate the website and use its features, as well as access secure areas of the website. Without these cookies, the requested services cannot be provided

• Analytical cookies – These are used anonymously to generate and analyze statistics in order to improve the website’s performance.

• Functionality cookies – These cookies store your preferences regarding the use of the website, so you don’t have to reconfigure the site every time you visit it.

• Third-party cookies – These measure the success of applications and the effectiveness of third-party advertising. They may also be used to personalize a widget with user data.

• Advertising cookies – These cookies tailor advertising to each user’s interests, allowing advertising campaigns to be targeted based on users’ preferences. They also limit the number of times you see an ad, helping to measure the effectiveness of the advertising and the success of the website’s organization. All browsers allow users to accept, reject, or delete cookies, and to be notified whenever a cookie is received, specifically by selecting the appropriate settings in their browser. Users can configure cookies in the “Options” or “Preferences” menu of their browser.

However, disabling cookies may prevent some web services from functioning properly, which could partially or completely affect your browsing experience on the website.

Terms and Conditions