Privacy Policy
Version 2.1 · in force since 4 August 2026
This policy explains what personal data we collect on this website, what we use it for, on what basis, who we share it with and how long we keep it. It applies to esad.pt, esadidea.pt and the services offered there.
The Portuguese version is the binding one; this English version is a courtesy translation.
1. Who the controller is
The controller of your data is C.I.F.A.D. — Centro de Investigação e Formação em Artes e Design, Lda., the founding entity of ESAD — Escola Superior de Artes e Design, with registered office at Avenida Calouste Gulbenkian, 907, 4460-268 Senhora da Hora, Matosinhos, Portugal, company number 502147350. In this document, "ESAD" means that entity.
Contact: info@esad.pt · +351 229 578 750.
For questions about this policy or your data, including exercising your rights, write to info@esad.pt, putting "Data protection" in the subject line.
2. What we process, why, and on what basis
When you visit the site. We record technical information about each request — the page address, the referring page, the language, the screen resolution, the browser type and the IP address — to keep the service running, diagnose faults and protect the site against abuse. Usage statistics are produced by Umami, installed on ESAD's own servers. For each page view, Umami receives the page address, the referring page, the language, the screen resolution and the page title; for clicks on links leaving the site, it also receives the destination and the link's title. The IP address and browser identification travel with each submission. The IP address and browser identification are used only at the moment of the request — to derive an approximate location and to compute a pseudonymous session identifier, whose salt changes every month — and are not retained. Umami uses no cookies and does not track you across different sites; it reads only the umami.disabled local-storage key, to respect anyone who has turned collection off — see the Cookie Policy.
Basis: legitimate interest in ensuring the security, operation and improvement of the site (Article 6(1)(f) GDPR). You may object to this processing through the contact given above.
When you accept statistics or marketing cookies. If you allow it in the cookie notice, we use Google Analytics and the Meta Pixel to measure use of the site and the effectiveness of our campaigns. Without that permission, neither tool is loaded and no data is sent to them. The full cookie-by-cookie description is in the Cookie Policy.
Basis: your consent (Article 6(1)(a) GDPR and Article 5 of Lei no. 41/2004). You may withdraw it at any time, with the same effort it took to give it.
When you request a brochure or information material. We collect your email address, the language of the page, the address of the page where you made the request — including any campaign parameters it contains — and the programme or degree the request relates to. You receive the material whether or not you agree to receive communications.
Basis: legitimate interest in student recruitment — knowing who expressed interest in which programme, and from which page (Article 6(1)(f) GDPR). Delivery is by link, on the same screen; we send you no message.
If you agree to receive communications. We additionally record the date and time you consented, the version of this policy in force at that moment, and the IP address from which you did so, so we can demonstrate when and how consent was given.
Basis: your consent. You may withdraw it at any time, free of charge and without giving reasons, by writing to the address above. Withdrawal does not affect the lawfulness of processing carried out beforehand.
When you create an account and use the restricted area. Students and staff sign in with their institutional Google account; we store the account identifier, the email address, the name and the access profile. Companies sign in with a code sent to their registered address; we store the IP address and browser of every sign-in and sign-out, in an audit log, and send the company a notice containing that information so it can detect access it does not recognise.
Basis: performance of the contract for use of the service, and legitimate interest in account security.
When you use the careers portal. If you are a student and create a profile, we store what you enter — personal email address, telephone, biography, links and the CV you upload. When you apply for a vacancy, we store the application, the cover letter and its status.
If your application is sent to a company, that company can then see your name, email addresses, telephone, biography, links, CV and cover letter. We also record who inside ESAD viewed or downloaded your CV.
Basis: performance of the contract for use of the portal. Sending your data to the company is the very thing you request by submitting the application (Article 6(1)(b) GDPR).
When you write to us or report a problem. We keep your message, to reply and to correct the service. The restricted area has a form for reporting problems: when you send a bug report, a record of your most recent actions in the application — the pages and buttons you passed through — travels with it, so we can reproduce the fault; for general feedback, that record is only sent if you tick the box.
Basis: legitimate interest in responding and correcting the service.
Staff pages. Pages for teaching staff and researchers publish each person's name, institutional email address and professional links. These are also indexed in the site's search engine.
Basis: legitimate interest in publicising the institution's academic and scientific activity.
Internal tools supporting our work. In the restricted area, and only for authenticated users with an authorised role, ESAD staff have a conversational assistant and a document-search tool. The assistant transmits the text of conversations, and the institutional content they refer to, to OpenAI, which processes it to produce the answer. Document search transmits uploaded documents, and the questions asked about them, to Google (the Gemini service), which indexes them so they can be queried. Neither tool is reachable from the public pages, and neither processes data about site visitors. Where an uploaded document contains personal data, that data is then also processed by the provider concerned, on the terms described in sections 5 and 6.
Basis: legitimate interest in the management and internal operation of the institution (Article 6(1)(f) GDPR).
3. Minors
The services on this site are intended for people aged 13 and over. Under Article 16 of Lei no. 58/2019, consent by children under 13 to information society services must be given or authorised by the holder of parental responsibility. If we learn that we have collected data from a child under 13 without that authorisation, we delete it.
4. Cookies
We use cookies necessary for the site to function and, only with your permission, statistics and marketing cookies. The details — name, purpose, duration and recipient of each cookie — are in the Cookie Policy, which carries its own version and can change without this policy changing.
5. Who we share with
- Providers processing data on our behalf and on our instructions: application hosting, database, file storage, search engine, email delivery, and logging and diagnostics tools.
- Meta Platforms Ireland Limited, when you allow marketing cookies. To that extent, ESAD and Meta are joint controllers under Article 26 GDPR as regards the collection of data through the Meta Pixel and its transmission to Meta. Meta assumes the Article 13 and 14 information duties for the processing it carries out after that transmission, and makes the essence of the arrangement available at
www.facebook.com/legal/controller_addendum. You may exercise your rights against either party. - Google Ireland Limited, when you allow statistics cookies, and also as our authentication and email provider and as the Gemini service behind internal document search.
- OpenAI, as regards content submitted to the restricted area's conversational assistant.
- Employer companies, solely in the context of applications sent to them and only with the data described above.
- Public authorities, where the law requires it.
We do not sell personal data and we do not make it available for third-party advertising.
Some pages include YouTube and Vimeo videos; the Erasmus partner-schools page shows a map with tiles from CARTO. When you open those pages, your IP address is disclosed to the content provider — Google, Vimeo or CARTO — which applies its own policies. We request this content in cookie-free mode, so nothing is stored on or read from your device.
Basis: legitimate interest in presenting the content the page exists to show (Article 6(1)(f) GDPR).
6. Transfers outside the European Economic Area
The database behind the site is hosted in the European Union.
EmailOctopus is operated by Three Hearts Digital Ltd, a United Kingdom company, with data hosted in Ireland; transfers to the United Kingdom are covered by the European Commission's adequacy decision for the United Kingdom.
Google, Meta and OpenAI, as well as the providers of the embedded videos, are established in the United States of America or rely on infrastructure located there. Google and Meta are certified under the EU-US Data Privacy Framework, the subject of a European Commission adequacy decision. Where neither mechanism is available, the transfer relies on the standard contractual clauses approved by the European Commission or on another appropriate safeguard under Chapter V GDPR. You may request further information through the contact given above.
7. How long we keep it
We keep data for as long as it is needed for the purpose that justifies it. Except where an automatic period is given below, erasure happens on request: write to info@esad.pt and we will delete your data, under Article 17 of the GDPR and subject to the limits set out there.
| Data | Period |
|---|---|
| Technical server logs | 30 days, after which they are deleted automatically |
| CV access records | 30 days, because they are held within the technical logs above |
| Brochure requests and the consent record | Three years from the last contact |
| Cookie consent record | For as long as it may be needed as evidence of your consent |
| Account and profile in the restricted area | For as long as the account exists, or until you ask us to delete it |
| Student profiles, applications and CVs | For as long as the profile exists, or until you ask us to delete it |
| Company accounts | For as long as the account exists, or until the company asks us to delete it |
| Database audit records | Kept indefinitely, including after the account is deleted, for security and as evidence of use |
8. Your rights
You may ask us, at any time, for: access to your data; rectification of anything incorrect; erasure; restriction of processing; objection to processing carried out on the basis of legitimate interest; and portability of the data you provided. You may also withdraw consent you have given, without affecting the lawfulness of earlier processing.
To exercise any of these rights, write to info@esad.pt. We reply within one month of receiving the request, extendable by two months where complexity justifies it, in which case we will tell you within the first month.
If you believe your data is not being handled properly, you may lodge a complaint with the Comissão Nacional de Proteção de Dados — www.cnpd.pt.
9. Changes
We publish any change to this policy here, with a new version and a new date. Where the change is significant and affects data collected with your consent, we will tell you directly.