ACES PORTUGAL · EUROPEAN CITIES OF SPORTKnowledge that transforms communities ↗
ACADEMYpowered by GADES SPORTS
PT/EN
Create account →
PRIVACY & TRANSPARENCY

Privacy policy

How your data is used, protected and managed throughout your training journey.

1. Who is responsible for your data

This policy applies to ACES Academy at acesportugal-academy.pt. The data controller is ACES Portugal — Associação Portuguesa das Cidades Europeias do Desporto, at Rua do Zambujal n.º 7, 2.º Direito, 2725-472 Mem Martins, Portugal. For privacy enquiries and the exercise of your rights, contact geral@acesportugal.pt. The expression “powered by GADES Sports” identifies project collaboration and does not by itself change the controller identified in this policy.

2. What data we process

  • Account: name, email, municipality or organisation and a password stored as a hash.
  • Training: courses and editions, enrollment status, attendance and participation certificates.
  • Payment: validation status, administrative reference or note and confirmation date. The platform does not collect card numbers or bank credentials.
  • Communication: support and privacy requests and emails about your account, enrollment, sessions and certificates.
  • Security: access and administration events, download requests and technical information related to attempted use, including IP addresses in server logs or abuse prevention identifiers.

3. Purposes and legal grounds

Account management, enrollment, session communication and access to materials and certificates provide the service you request and perform the training relationship or pre-contractual steps (GDPR Article 6(1)(b)).

Administrative payment validation supports enrollment management. Records required for tax, accounting or other legal duties are processed on the basis of those duties where applicable (Article 6(1)(c)).

Account protection, abuse prevention, access control and incident handling rely on the legitimate interest in maintaining a secure platform and protecting data (Article 6(1)(f)), using proportionate safeguards and subject to your rights.

Confirmation, recovery, session and certificate emails are service communications. This Academy version does not include marketing or newsletter subscriptions. A future optional purpose requiring consent will have its own information and choice; creating an account does not authorise it.

4. Sources and required information

Data comes from you or, for institutional enrollment, an authorised administrator or the organisation requesting training. Attendance and payment validation are recorded by the management team.

Name, email and credentials are required for your account; enrollment and attendance information are necessary for training management and certificates. Essential functions cannot be provided without the necessary information. The municipality/organisation field is optional in normal registration. Do not enter health or other sensitive data in free-text fields.

5. Who can access data

Participants access their own records. Authorised administrators access what is necessary to manage training, support, payment, attendance and certificates. Materials and certificates are controlled by enrollment and recipient.

Technical providers may process data within their contracted services, according to their role and applicable obligations. Service categories: Platform hosting and technical maintenance; transactional email delivery; online session services identified in each course communication. You may request the identity of the providers used through the privacy contact. Public authorities may receive information where required by law. The platform does not publish participant lists or sell data for advertising.

6. Online sessions and international transfers

Session links are provided in your reserved area. When you open an external service, its privacy and cookie information also applies. Depending on the functions used, that service may process your name, email, image, voice and technical data. Any recording must be communicated in advance by the session organiser; this policy does not authorise recording.

Provider locations and safeguards depend on contracted services. Where transfers outside the European Economic Area occur, the controller must ensure the applicable mechanism, such as an adequacy decision or standard contractual clauses with any required supplementary measures. You may request recipient details and information about safeguards from the privacy contact.

7. Retention

Account data is kept while the account is active and required for the participant relationship. After closure, records are reviewed for deletion or anonymisation, retaining only those needed for legal obligations, complaints or evidence and reissue of certificates. Enrollment, payment and attendance records are retained for as long as required for those purposes. Technical log and backup retention depends on hosting configuration. You may request information on retention applicable to your case.

Password reset tokens expire after 30 minutes and email confirmation tokens after 24 hours. Expiry prevents use; it does not itself mean that all technical records are immediately deleted.

8. Your rights

Within the GDPR’s conditions and limits, you may request access, correction, erasure, restriction, portability and object to processing. Where processing relies on consent, you may withdraw it without affecting the lawfulness of prior processing.

You can export the records available in your participant area and submit a privacy request there, or contact geral@acesportugal.pt. You do not need an active account to exercise your rights. Proportionate identity checks may be needed. A response is normally provided within one month; any legally permitted extension will be communicated with reasons.

Erasure may be limited by legal obligations or the need to retain information for the establishment, exercise or defence of claims. In that case, the reason and scope of retention will be explained. You can complain to Portugal’s supervisory authority, Comissão Nacional de Proteção de Dados, at www.cnpd.pt, without prejudice to other remedies.

9. Security and access rules

The application uses password hashes, parameterised queries, protected sessions, authorisation checks and private document storage. Service security also depends on HTTPS, permissions, updates and hosting backups.

Enrollment, payment and attendance are confirmed by the team. The system applies those records to make sessions, materials and certificates available. If a record is incorrect, you may request human review. This version does not create commercial profiles or analyse behaviour for advertising.

10. Cookies and policy updates

Application cookies are described in the Cookie Policy. The current version and update date appear on this page. Material changes to purposes or services must be accompanied by updated information before the new processing takes place.

See exactly what this application stores on your device.

Cookie policy · Privacy policy