Privacy Policy

Introduction

WAY BEYOND is committed to respecting user privacy and ensuring the protection and security of personal data. Users should carefully read this privacy policy and freely decide whether to provide their personal data to WAY BEYOND before using its services.

Users warrant that they are of legal age and that the data provided is true, accurate, complete, and up-to-date, bearing responsibility for any discrepancies. If the data provided belongs to a third party, the user warrants that they have informed that third party of the terms set out in this document and obtained their authorisation to provide their data to WAY BEYOND for the stated purposes.

About the Company

WAY BEYOND is a Portuguese company, headquartered at Rua Julieta Ferrão 10, 8.º Esq., 1600-131 Lisbon, Portugal. We are a facilitation, consulting and applied research studio working with people, teams and organisations.

In the course of its operations, WAY BEYOND acts as the entity responsible for the processing of personal data and ensures the protection of its users' personal data, in accordance with this Privacy Policy and the principles and standards established by the General Data Protection Regulation (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016) and the Data Protection Law (Law No. 58/2019 of 8 August).

About this Privacy Policy

This Privacy Policy governs the processing of personal data collected by WAY BEYOND, specifying the grounds for such collection as well as the terms and manner in which the data will be used and, where applicable, transmitted to third parties.

WAY BEYOND is committed to protecting the personal data of its users and ensuring its confidentiality. The company has adopted measures it deems appropriate to safeguard the accuracy, integrity, and confidentiality of personal data, as well as to uphold all other rights of the data subjects, in accordance with applicable legislation—specifically Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR).

We are committed to adhering to best practices regarding the security and protection of our customers' personal data, ensuring that all those who entrust us with the collection and processing of their personal data are informed of the purpose of such collection and of the procedures implemented to uphold the rights of the data subjects.

Subject matter of the processing of personal data

WAY BEYOND assumes responsibility for the collection and processing of personal data necessary for the performance of the contract entered into – personal data is understood to mean any information, of any nature and regardless of its medium, including sound and image, relating to an identified or identifiable natural person.

To carry out the different purposes, WAY BEYOND may process the following types of personal data:

  • identification data (such as name, nationality, citizen card/ID card, tax identification number, date of birth);
  • contact details (such as mobile phone, telephone, address, or email);
  • professional activity data (such as profession and workplace);
  • remuneration data;
  • candidate evaluation data within the scope of recruitment and selection processes for WAY BEYOND employees;
  • bank details (necessary for operations involving the issuance of inherent financial documents).

Within the scope of our activity, personal data may be collected by WAY BEYOND in person, by telephone, via email, by subscribing to our newsletter, by filling out registration/evaluation forms, or when submitting a job application. The processing of this data complies with appropriate technical and organisational security measures in accordance with personal data protection legislation.

In some cases, WAY BEYOND may collect personal data indirectly. When WAY BEYOND processes personal data collected indirectly, it will provide all information regarding the processing of such data to the respective data subjects at the earliest opportunity.

Under no circumstances will personal data be requested regarding racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, or data concerning health, sex life, or sexual orientation.

Under no circumstances will WAY BEYOND carry out any of the following activities with the personal data provided through its website, in person, or by telephone, without the prior express consent of the data subject:

  • Sending commercial and promotional communications;
  • Sharing with third parties;
  • Transferring personal data outside the European Economic Area (EEA).

The personal data collected is processed electronically and in strict compliance with the aforementioned personal data protection legislation. It is stored in specific databases created for this purpose, and under no circumstances will the collected data be used for any purpose other than that for which consent was given by the data subject.

Grounds and purposes for the collection of personal data

All data collected and processed by WAY BEYOND is based on one of the following grounds for lawfulness:

Consent of the data subject to process their personal data for specific, explicit, and legitimate purposes—namely, purposes related to sending newsletters, conducting marketing activities, and sending promotional information regarding WAY BEYOND’s business and services.
Performance of a contract or pre-contractual measures. This ground applies whenever WAY BEYOND processes personal data for the purpose of providing its services.
Compliance with legal obligations. This ground applies when processing is necessary to comply with a legal obligation, such as the disclosure of data to public administrative, tax, or judicial bodies.
Legitimate interest. This ground for the lawfulness of personal data processing applies in cases where processing is necessary to pursue the legitimate interests of the data controller or third parties, without infringing upon the rights and freedoms of its clients and/or users.

Website and Newsletter

Our website, located at waybeyond.pt, is owned by Way Beyond Lda. (hereinafter referred to as WAY BEYOND). Its purpose is to showcase our services and portfolio and to facilitate contact with current and potential clients; the site uses cookies.

Cookies are small pieces of information necessary to identify the visitor during their online visit. This allows us to identify and remember your preferences.

Cookies do not store any personal or confidential information regarding the user; only information concerning the pages visited is stored.

You may subscribe to our newsletter via the website by providing your email address, and you may unsubscribe at any time.

Personal data retention period

The period during which data is stored and retained varies according to the purpose for which the information is collected and processed; WAY BEYOND will retain collected personal data only for the time necessary to fulfill the purposes for which it is processed.

Accordingly, and unless a specific legal requirement applies, data will be stored and retained only for the minimum period necessary for the purposes that prompted its collection.

After this period, your personal data will be deleted. However, an exception applies where personal data is required by the data controller (WAY BEYOND) or by subcontractors to demonstrate compliance with contractual or other obligations; in such cases, personal data may be retained until the statute of limitations for the corresponding rights has expired (for example, for billing purposes, where the general personal data retention period is 10 years).

Data Security

WAY BEYOND declares that it has implemented, and will continue to implement, the necessary technical and organisational security measures to ensure the safety of the personal data provided to it. These measures aim to prevent unauthorised alteration, loss, processing and/or access, taking into account the current state of technology, the nature of the stored data, and the risks to which they are exposed.

Whenever WAY BEYOND accesses personal data, it commits to:

Storing the data using legally required technical and organisational security measures that guarantee its safety — thereby preventing unauthorised alteration, loss, processing, or access — in accordance with the state of technology at any given time, the nature of the data, and the potential risks involved;
Using the data exclusively for the purposes previously defined;
Ensuring that the data is processed only by employees whose involvement is necessary to fulfil the data subject's request, with such employees being bound by a duty of secrecy and confidentiality. Should there be a possibility of information being disclosed to third parties for the aforementioned purposes, those parties must be required to maintain appropriate confidentiality in accordance with the provisions of this document.

Notwithstanding the security mechanisms adopted and compliance with all personal data protection rules, the user should be aware that if they do not have the necessary protective barriers in place (e.g., antivirus, firewall, anti-spyware) when accessing the Internet, their personal data could be viewed and used by unauthorised third parties.

In this context, all users are advised to take appropriate security measures while using the Internet, specifically by ensuring they use a web browser that supports secure communication.

Rights of the personal data subject

Personal data subjects have the following rights at any time:

Right to transparency;
Right to information;
Right of access;
Right to rectification;
Right to be forgotten;
Right to restriction of processing;
Right to data portability;
Right to object;
Right not to be subject to automated decision-making;
Right regarding the non-processing of sensitive data;
Right to lodge a complaint with the competent supervisory authority (in this case, the National Data Protection Commission).

All rights referred to herein, expressly provided for in the GDPR, must be exercised by identifying the data subjects (via a copy of their Citizen Card or other identification document) and contacting WAY BEYOND at its physical address or via the email address rgpd@waybeyond.pt.

Regarding the submission of a copy of the Citizen Card or other document, please note that it will be used solely—subject to the data subject's consent—for the stated purpose (i.e., verifying the identity of the holder of the aforementioned rights) and will be deleted once it is no longer necessary for fulfilling the described purpose.

Provision of data to third parties

WAY BEYOND does not disclose users' personal data to third parties without the data subjects' consent, except when necessary to execute contracts (sharing data with service providers or suppliers) or when required by law—specifically to comply with legal obligations to report information to official bodies, such as judicial, tax, and regulatory authorities.

WAY BEYOND may share collected personal data with the following entities:

Parties relevant to the services provided by WAY BEYOND;
Public authorities, in compliance with legal obligations;
Subcontractors engaged by WAY BEYOND to process personal data on its behalf.

In the course of our business, we may engage third parties to provide certain services, as mentioned above. Sometimes, the provision of these services requires these entities to access personal data. In such cases, we take appropriate measures to ensure that the entities with access to the data are reputable and offer the highest level of safeguards; these requirements will be formally established and secured in the contract signed with the service provider.

We may be required to disclose your personal data in compliance with a court order or in accordance with other legal or regulatory requirements. Should this occur, we will take all steps to notify you before disclosing the data, unless we are legally prohibited from doing so.

We reserve the right to update this Privacy Policy whenever appropriate.