Skip to content

LEGAL INFORMATION

Privacy Policy

FINOVA respects the privacy of the users of the finova.pt website and of its clients, and processes personal data lawfully, transparently and only to the extent necessary. This Policy explains which data is processed, for what purposes and on what grounds, with whom it is shared, for how long it is kept, and how the data subject can exercise their rights.

Last updated:

1. Data controller

1.1. The controller of the personal data collected through the website and in connection with the provision of credit intermediation services is:

Trading name
FINOVA
Holder
Susana Cardoso Montenegro Santos de Vasconcelos
Address
Rua de Pedrouços 37B, 1400-285 Lisboa
Banco de Portugal registration
no. 0008496 (Tied Credit Intermediary)

1.2. For any question concerning the processing of your personal data or the exercise of your rights, the data subject may contact FINOVA at apoio@finova.pt.

2. Categories of data processed

2.1. In connection with the use of the website and the provision of the services, FINOVA may process the following categories of personal data:

  • a) Identification and contact data: name, email address and telephone number, provided in the contact forms and in the simulation-request and application flows.
  • b) Financial and asset data: income, liabilities, property value, deposit, requested amount and term and, in the case of a remortgage, the current institution and outstanding balance. This data is entered voluntarily by the User when using the calculators or when opening a case.
  • c) Data relating to the credit case and supporting documentation: when the case advances, and only to the extent necessary, identification documents and supporting evidence (namely of income) may be collected for processing with the lending institutions.
  • d) Browsing and technical data: IP address, device and browsing identifiers, and website usage data, collected through cookies and similar technologies, under the Cookie Policy.

2.2. FINOVA does not intentionally collect special categories of data (namely health data), within the meaning of article 9 of the GDPR. The User should not provide data of this nature through the website.

3. Purposes and legal bases

3.1. Personal data is processed for the following purposes and on the following lawful grounds:

PurposeLegal basis (GDPR)
Respond to contact requests and provide informationPre-contractual steps and legitimate interest (art. 6(1)(b) and (f))
Provide the credit intermediation service: analyse the profile, present and process the case with the institutions, and support the ClientPerformance of a contract and pre-contractual steps (art. 6(1)(b))
Make available and run the calculators and other website toolsPre-contractual steps and legitimate interest (art. 6(1)(b) and (f))
Send marketing communications and information about servicesConsent (art. 6(1)(a))
Comply with legal obligations applicable to the credit intermediary, including anti-money-laundering and tax and record-keeping obligationsLegal obligation (art. 6(1)(c))
Ensure the security of the website and prevent fraud and abusive useLegitimate interest (art. 6(1)(f))
Measure website usage through statisticsConsent, where required, under the Cookie Policy (art. 6(1)(a))

3.2. Where processing is based on consent, such consent is freely given, specific, informed and revocable at any time, without affecting the lawfulness of processing carried out before its withdrawal. Consent for marketing communications is independent of the provision of the services, and refusing it does not prevent the User from engaging FINOVA.

4. Sharing with third parties

4.1. FINOVA does not sell personal data. Data may be shared, to the extent necessary, with the following categories of recipients:

  • a) Partner lending institutions: to present and process the Client’s credit case, with their knowledge. Upon receiving the data, these institutions process it as independent controllers, in accordance with their own privacy policies.
  • b) Service providers acting on behalf of FINOVA (processors, within the meaning of article 28 of the GDPR), under instructions and with appropriate contractual safeguards, namely:
    • website hosting and infrastructure (Amazon Web Services);
    • transactional email and contact management (Mailjet);
    • customer relationship management / CRM (Simplify);
    • protection against fraud and abusive automated use (Cloudflare);
    • website usage statistics (Google), triggered only with consent.
  • c) Public authorities and supervisory bodies, where there is a legal obligation to report, namely to Banco de Portugal and to judicial or tax authorities.

4.2. International transfers. Some providers may process data outside the European Economic Area. In such cases, FINOVA ensures appropriate safeguards are in place, namely European Commission adequacy decisions, standard contractual clauses or recognised data-transfer frameworks, ensuring a level of protection equivalent to that of the GDPR.

5. Retention periods

5.1. Data is retained only for the period necessary for the purposes that justified its collection:

  • a) Contacts and requests without engagement: retained for the period necessary to follow up on the request and, where no engagement follows, deleted or anonymised within 24 months of the last contact.
  • b) Clients with services provided: throughout the relationship and, after it ends, for the periods required by law, namely those arising from the duties applicable to credit intermediaries, from anti-money-laundering rules, and from tax and accounting obligations.
  • c) Data processed on the basis of consent (marketing): until consent is withdrawn.
  • d) Browsing data and cookies: for the periods indicated in the Cookie Policy.

5.2. Once the applicable periods have elapsed, the data is deleted or irreversibly anonymised.

6. Data subject rights

6.1. Under the GDPR, the data subject has the right to:

  • a) access their data and obtain information about its processing;
  • b) request the rectification of inaccurate or incomplete data;
  • c) request the erasure of the data, where applicable;
  • d) request the restriction of processing;
  • e) exercise the right to data portability, receiving the data in a structured, commonly used format;
  • f) object to processing based on legitimate interest and, at any time, to processing for marketing purposes;
  • g) withdraw consent at any time, for processing that relies on it.

6.2. FINOVA does not make decisions based solely on automated processing that produce legal effects concerning the data subject. The decision to grant credit lies exclusively with the lending institution.

6.3. The data subject may exercise their rights at apoio@finova.pt. FINOVA may request additional information to confirm the requester’s identity and responds within the legally prescribed period, as a rule one month from receipt of the request.

7. Security and technical measures

7.1. FINOVA adopts appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or improper disclosure, within the meaning of article 32 of the GDPR, namely:

  • a) encrypted communications between the User’s browser and the website (secure protocol / TLS);
  • b) access control and processing limited to what is strictly necessary;
  • c) identity verification mechanisms in the flows and downloads, by means of a code sent by email (OTP);
  • d) protection against abusive automated use of the website;
  • e) selection of service providers that offer appropriate security safeguards.

7.2. In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, FINOVA complies with the duties to notify the supervisory authority and, where applicable, to communicate to the data subjects, under articles 33 and 34 of the GDPR.

8. Contact and complaints

8.1. For questions relating to this Policy or to the processing of your data, the data subject may contact FINOVA at apoio@finova.pt.

8.2. The data subject has the right to lodge a complaint with the supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD) — www.cnpd.pt.

8.3. Complaints relating to the credit intermediation service follow the channels indicated on the Complaint Channels page, which include Banco de Portugal as the supervisory authority.

8.4. Last updated: 23 June 2026.

This English version is a courtesy translation. In the event of any discrepancy between the English and Portuguese versions, the Portuguese version prevails.

WhatsApp