Who we are
This site is run by LxCortex, Lda, registered in Portugal at Rua do Alecrim 12, 1200-017 Lisboa. For the purposes of EU data-protection law (the GDPR), we are the data controller for the personal data described here.
This policy explains what we collect, why, and the rights you have over it. It sits alongside our Terms & Conditions. Questions are welcome any time — just write to us.
What we collect
We try to collect as little as possible. Depending on how you use the site, that may include:
- Order details — your name, delivery and billing address, email and phone number.
- Payment data — handled by our payment provider; we receive a confirmation and the last four digits, never your full card number.
- Account & contact — anything you send us by email, or save in an account if you create one.
- Usage data — basic analytics about how the site is used, usually in aggregated or pseudonymous form (see Cookies).
How we use it
We use your data to do the things you’d expect of a small shop:
- to take, make, pack and deliver your order, and handle returns;
- to reply to your messages and provide support;
- to send order updates — and, only if you opt in, the occasional note about new batches;
- to keep the site secure, prevent fraud, and meet our tax and accounting obligations.
We will never sell your personal data, or use it to build intrusive advertising profiles.
Legal bases
Under the GDPR we rely on a handful of legal bases: performance of a contract (to fulfil your order), legal obligation (to keep invoices for tax law), consent (for marketing emails and non-essential cookies, which you can withdraw any time), and our legitimate interests in running and securing a small business — balanced against your rights.
Who we share with
We share data only with service providers who help us run the shop, and only what they need to do that work:
- our payment provider, to take payment securely;
- shipping carriers, to deliver your parcel;
- our email and hosting providers; and
- authorities or advisers where the law requires it.
Where a partner processes data outside the EU/EEA, we make sure appropriate safeguards (such as the EU Standard Contractual Clauses) are in place.
Cookies
We use a small number of cookies. Essential cookies keep your cart and session working and can’t be switched off. Analytics cookies help us understand, in aggregate, what’s useful on the site — these only run with your consent, and you can change your choice whenever you like.
Your choice, your control
You can clear or block cookies in your browser settings at any time. Blocking essential cookies may stop parts of the checkout from working, but the choice is yours.
How long we keep it
We keep personal data only as long as we need it. Order and invoice records are kept for as long as Portuguese tax and accounting law requires (typically up to 10 years). Marketing data is kept until you unsubscribe, and support emails are kept for as long as needed to handle your request and maintain our business records, then deleted or anonymised.
Your rights
Under the GDPR you can, at any time, ask us to:
- access the personal data we hold about you;
- correct anything that’s wrong, or delete it;
- restrict or object to certain processing;
- port your data to another provider; and
- withdraw consent for marketing or analytics.
Just email us and we’ll respond within one month. You also have the right to complain to your local supervisory authority — in Portugal, the CNPD (cnpd.pt).
Security
We use reputable providers and sensible technical measures to keep your data safe, including encryption in transit at checkout. No system is ever perfectly secure, but we take it seriously — and if a breach ever affected your rights, we’d tell you and the authorities as the law requires.
Contact us
For anything about your data — a request, a question, or a worry — reach a real person in Lisbon:
- Email — privacy@lxcortex.com
- Post — LxCortex, Lda, Rua do Alecrim 12, 1200-017 Lisboa, Portugal