Version 1.2 · October 2026
Privacy Policy
This policy explains what personal data Eagle Dream Lda. ("Eagle Dream", "we") collects through eagledream.pt, through its timesheet service at timesheets.eagledream.pt and in the course of its business, why we collect it, who receives it, and what rights you have. We keep it short because we collect very little.
1. Who is responsible
The controller of your personal data is Eagle Dream Lda., Rua da Garça Real 15, 2890-351 São Francisco, Portugal, tax number PT515064971. For anything in this policy, write to the Managing Director at info@eagledream.pt. Eagle Dream is not required to appoint a data protection officer.
2. What we collect, and why
- When you write to us, through the contact form or by email: your name, work email address, what you need, and the content of your message. We use it only to answer you and, if you ask for one, to prepare a proposal. Legal basis: steps taken at your request before a contract, and our legitimate interest in answering business enquiries (GDPR Article 6(1)(b) and (f)).
- When you visit the site: our hosting provider processes your IP address, your browser type and the pages requested in its server logs, to deliver the site and keep it secure. We do not use these logs to identify you. Legal basis: legitimate interest (Article 6(1)(f)).
- When you use our timesheet service as a consultant: your name, email address, phone number, company, country, VAT number and bank account (IBAN), the days or hours you record, your expenses and the receipts you upload, the invoices you upload (number, date, value and the document itself) and when they were paid, and when you last used the service. We use it to record and approve your work, to pay you and to invoice our client. The service may also send you automatic reminder emails about a timesheet or an invoice that is due. Legal basis: performance of our contract with you and our legal obligations (Article 6(1)(b) and (c)).
- When you use our timesheet service for a client, as approver or contact: your name, work email address and phone number, and your decisions on timesheets (approval, rejection, comments and requests), with the date, time and IP address of each decision. The service may send you a reminder email when a timesheet is waiting for your decision. We use it to obtain and keep proof of your approval of the work we invoice. Legal basis: performance of our contract with your employer and our legitimate interest in keeping that proof (Article 6(1)(b) and (f)).
- When we work together: the business contact details of our clients' and partners' staff, and the professional data of consultants and subcontractors, such as CVs, contracts and invoicing details. We use it to perform our contracts and meet our legal obligations (Article 6(1)(b) and (c)).
3. Cookies and tracking
This site sets no cookies and uses no analytics, advertising or social-media trackers. It stores one technical flag in your browser's session storage so that the opening animation plays only once. The flag holds no personal data, never leaves your browser and is deleted when you close the tab. The timesheet service uses no analytics or advertising either. When you sign in, it keeps a sign-in token in your browser (local storage and a session cookie) so that you stay signed in. This is strictly necessary for the service and is removed when you sign out.
4. Fonts
The site and the timesheet service load their typefaces from Google Fonts. To fetch them, your browser contacts Google's servers, which discloses your IP address to Google. No cookies are set in the process.
5. Who receives your data
- Service providers that process data on our behalf: Netlify, Inc. (hosting of the website and of the timesheet service, including its database, uploaded receipts and invoices, sign-in accounts and contact-form messages), Microsoft (email, documents, and the encrypted storage that holds the backup copies of the timesheet service), InvoiceXpress (the certified invoicing software in which we issue our invoices to clients; an invoice names the client, the consultant and the month worked) and Google (delivery of fonts).
- Clients and partners, only where that is needed for an engagement you are part of. In the timesheet service, a client's approvers see the consultant's name, the days or hours worked, the expenses and the receipts for their own contract, and the consultant sees the name of the approver. A client never sees a consultant's rate or invoices, and a consultant never sees what we invoice the client.
- Public authorities, only where the law requires it.
- We do not sell personal data and do not share it for marketing.
6. Transfers outside the European Union
The data of the timesheet service (its database, the uploaded receipts and invoices, and the programs that process them) is held in the European Union, in Frankfurt, Germany. Its backup copies are held in our Microsoft 365 storage. Some providers may nevertheless process data in the United States, for example Netlify for sign-in accounts and for delivering pages, and Google for fonts. Such transfers rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses.
7. How long we keep it
- Enquiries: up to 24 months after our last contact, unless they lead to a contract.
- Contract, invoicing and accounting data: 10 years, as Portuguese tax and commercial law requires. This includes timesheets, expenses, receipts, approval records and consultants' invoices, which support our invoices and payments.
- Backup copies of the timesheet service: made daily and kept for about one month, after which the oldest are deleted.
- Sign-in accounts for the timesheet service: until the engagement ends or access is no longer needed.
- Server logs: kept by our hosting provider for a limited period.
8. Your rights
You have the right to access your data, to have it corrected or erased, to restrict or object to its use, and to receive it in a portable format. Write to info@eagledream.pt and we will reply within one month. You also have the right to lodge a complaint with the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (CNPD), www.cnpd.pt.
9. Security
We protect personal data with multi-factor authentication, encrypted devices and access limited to the people who need it. The timesheet service is available by invitation only, runs over encrypted connections, shows each person only what their role allows, requires a second sign-in step (a code from an authenticator app) from administrators, logs administrator actions, and is backed up daily. If a personal data breach occurs, we act as the GDPR requires, including notifying the CNPD within 72 hours where necessary.
10. Automated decisions and children
We make no decisions by automated means and do no profiling. This site is aimed at businesses and is not directed at children.
11. Changes to this policy
We update this policy when our practices or the law change. The version and date at the top show when it was last revised. This policy follows the General Data Protection Regulation (EU) 2016/679 and Portuguese Law 58/2019.
Prefer a document? Download this policy as a PDF.