Privacy Policy
VTXRM respects your privacy. This Privacy Policy describes who we are, with which purpose we can use your data, how we handle the data, with whom we share it, for how long we keep it, and also how to contact us and to practice your rights.
Who are we?
Your data will be handled by VTXRM – SOFTWARE FACTORY LDA., legal person n. 510480209, headquarters in Avenida Prof. Dr. Cavaco Silva, Edifícios Qualidade, Bloco B3, 1º andar, 2740 – 296 Porto Salvo, telephone number +(351) 210 497 779, henceforth “VTXRM”.
VTXRM is responsible for the handling of personal data in accordance to the Data Protection Regulation.
Overview
VTXRM is committed to protecting the privacy and security of personal data as a service provider in the financial services sector operating globally.
This Data Privacy Policy outlines how we collect, process, store, and protect personal data of individuals ("data subjects") in compliance with applicable data protection laws, such as the ones listed below but not limited to:
- The General Data Protection Regulation (GDPR) in the EU
- The California Consumer Privacy Act (CCPA) in the USA
- The Personal Information Protection Law (PIPL) in China
- Relevant regulations in the Middle East
Scope
This policy applies to:
- Personal data processed by us in our role as a data controller and data processor;
- Data collected from users of VTXRM´s technology solutions;
- Data of clients, employees, partners, and end-users where VTXRM operates;
Legal Basis for Processing Data
We process personal data under the following legal bases:
- Contractual necessity (Article 6(1)(b) GDPR): To deliver services to clients
- Legitimate interests (Article 6(1)(f)): To improve services and ensure security
- Legal obligation (Article 6(1)(c)): Compliance with financial and regulatory laws
- Consent (Article 6(1)(a)): Where required, particularly for marketing communications
- Meet legal, regulatory, or contractual obligations
Note: Either “on Premises” solutions and SaaS Services, VTXRM´s client act as Data Controller role being primary responsible for managing personal data compliance. Only in SaaS Services VTXRM act as Data Processor.
Data Retention
We retain personal data only for as long as necessary for the purposes described in this policy, including satisfying legal, accounting, or reporting requirements.
Rights of Data Subjects:
Depending on the jurisdiction, data subjects may have the following rights as listed below but not limited:
EU (GDPR)
- Right to access
- Right to rectification
- Right to erasure (“right to be forgotten”)
- Right to restriction of processing
- Right to data portability
- Right to object
- Right not to be subject to automated decision-making
USA (CCPA/CPRA)
- Right to know what personal data is collected and shared
- Right to delete personal information
- Right to opt out of sale or sharing of personal information
- Right to non-discrimination for exercising rights
China (PIPL)
- Right to be informed
- Right to access and copy personal information
- Right to correction and deletion
- Right to restrict or refuse processing
- Right to portability (where applicable)
Data subjects may exercise their rights by contacting us at: dpo@vtxrm.com
Data Transfer
We only transfer personal data to countries outside the data subject’s jurisdiction, if fully authorized and ensuring appropriate safeguards such as:
- Legal Requirements;
- Standard Contractual Clauses;
- Data Processing Agreements;
- Transfer Impact Assessments;
Data Security
We implement appropriate technical and organizational measures to protect personal data, including:
- Encryption in transit and at rest;
- Role-based access controls;
- Multi-factor authentication;
- Regular penetration testing and vulnerability assessments;
- Data anonymization/pseudonymization where applicable.
VTXRM implements appropriate technical and organizational security measures to protect your personal data against loss, unauthorized access, alteration, and disclosure.
VTXRM´s website – personal data
When you fill in the available forms on our website, your personal data (name, email, telephone number, or address) are collected by VTXRM and handled in a way to answer your questions and requests, or to provide information. If you register for one of our events, some of your personal data can be shared with organizations related to the actual event and/or with other participants.
By providing your contacts, VTXRM may contact you for marketing reasons related to its services, as long as you have consented to handle your personal data for this effect. If you consent, you will receive marketing communication via email. You may, at any moment, object to this data handling.
Your consent is essential for VTXRM to handle your personal data for specific purposes; in the meantime, if you choose not to consent, your visit to our webpage will not be affected.
VTXRM´s recruitment data
Within Recruitment activity, VTXRM´s gathered the candidate´s information for 3 years.
VTXRM´s CCTV images
Footage retention doesn´t not exceed 30 days, unless a specific incident requires longer retention for legal purposes.
Regulatory Authorities
Data subjects in the EU have the right to lodge a complaint with their local Data Protection Authority (DPA). In other jurisdictions, similar rights apply under local laws.
Do you have any questions?
If you still have any questions related to data handling, or intend to exercise your rights, please contact us:
E-mail: dpo@vtxrm.com
Address: Avenida Prof. Dr. Cavaco Silva, Edifícios Qualidade, Bloco B3, 1º andar, 2740 – 296 Porto Salvo.
Breaches of Policy
Breaches of this policy and/or security incidents are incidents which could have, or have resulted in, loss or damage to VTXRM assets, including IT equipment and information, or conduct which is in breach of VTXRM’s security procedures and policies.
All parties identified within the scope of this policy have a responsibility to report security incidents and breaches of this policy as quickly as possible through VTXRM’s Incident Reporting Procedure. This obligation also extends to any external organization contracted to support or access the Information Systems of VTXRM. In the case of suppliers, service providers, consultants or contractors, noncompliance could result in the immediate removal of access to the system.
Please consider that VTXRM will occasionally update this Privacy Policy. To maintain updated, please review this document periodically.