Legal
Privacy Policy
This policy explains what personal data Braga AI Builders processes, why we process it, who may receive it, how long we keep it, and the rights available to you under the GDPR.
Last updated: 14 July 2026
1. Who controls your data
Braga AI Builders, operated by its community organizers in Braga, Portugal, determines how this community site processes personal data and acts as the data controller for that processing.
To contact the organizers about privacy or exercise a data-protection right, use Report a Bug on the second line of the site footer, begin the description with “Privacy request”, and provide an email address so we can respond privately. We may ask for information needed to verify your identity before acting on a request.
2. Scope
This policy covers this Braga AI Builders website, member accounts, invitations, community posts and comments, votes, bookmarks, profiles, and support reports. External services reached through links—including WhatsApp, event registration pages, GitHub, and Buy Me a Coffee—operate under their own privacy notices.
3. Data we process
When you browse or participate without an account
- Technical request information processed by our hosting and backend providers, such as IP address, request time, browser information, and requested page.
- A random browser identifier stored locally for anonymous posts, votes, and bug-report rate limiting.
- A one-way hash or keyed hash of an IP address used to prevent abuse and enforce reasonable rate limits. We do not publish that value.
- Public content you submit, including post titles, post bodies, selected categories and tags, and votes.
When you have a member account
- Your email address, account identifier, authentication records, and invitation or sign-in delivery records.
- Invitation security data, which may include request IP address, browser user-agent information, timestamps, and redemption status.
- Profile information you choose to provide, such as handle, display name, biography, avatar, website, and social links. Profiles are private by default and become public only when you enable directory visibility.
- Your posts, comments, votes, bookmarks, invitations, moderation status, and other community activity.
When you send a support report
- The description, current page URL, random visitor identifier, and a keyed hash of the request IP address.
- Your name and email address only when you choose to provide them for follow-up.
4. Why we process data and our legal bases
- Provide the community service and member features: performance of our agreement with you, or steps you request before joining.
- Publish and organize community contributions: performance of the service and our legitimate interest in operating a useful local community archive.
- Protect the site, prevent abuse, enforce rate limits, and moderate content: our legitimate interests in security, integrity, and community safety.
- Send requested magic-link and invitation emails: steps requested by you and your explicit confirmation that we may send that transactional email.
- Display an optional public profile: your choice to enable public directory visibility; you may turn it off again.
- Respond to support and privacy requests: our legitimate interest in resolving problems and our legal obligations under data-protection law.
- Comply with law and establish or defend legal claims: legal obligation or legitimate interests, as applicable.
We do not sell personal data, use it for third-party advertising, or make decisions about you based solely on automated processing that produce legal or similarly significant effects.
5. What you have to provide
You can browse public pages without creating an account. When you choose a feature, some information is necessary to provide it:
- An email address is required to create or access a member account and receive a requested magic link. Without it, we cannot provide member-only features.
- Post or comment content and the related anti-abuse identifier are required when you choose to publish. Without them, we cannot accept that contribution.
- Profile biography, avatar, social links, public-directory visibility, bug-report name, and bug-report email are optional.
- A useful description is required for a support report; without it, organizers cannot investigate the problem.
6. Public, private, and anonymous participation
Public posts, comments, vote totals, and opted-in public profile fields can be read by anyone. When you choose identified participation, your public profile may appear beside your contribution. When you choose an anonymous option, the public interface does not reveal your member profile or browser identifier, although limited technical records remain available to trusted providers and organizers where needed for security and moderation.
If a member account is deleted, a non-anonymous comment may remain as a contribution from a “Former member” so an existing discussion is not destroyed. The deleted profile is not exposed. Content may also be retained where necessary for legal claims, safety, or the rights of other community members.
7. Browser storage and cookies
The site uses browser storage for essential functions such as authentication sessions, restoring an unfinished post, and remembering pseudonymous visitor or vote state. Our infrastructure providers may also use strictly necessary security or session identifiers.
We do not currently use advertising cookies or behavioral analytics. If we introduce non-essential tracking, we will update this policy and request consent where the law requires it. Clearing browser storage may sign you out or reset anonymous participation state.
8. Who receives data
- Supabase provides authentication, database, storage, and Edge Function infrastructure.
- Vercel hosts and delivers the website and may process technical request logs.
- Transactional email providers deliver requested sign-in, invitation, and operational messages.
- Community organizers may access account, moderation, invitation, and support information only as needed to operate the community.
- The public receives content and profile fields you choose to publish.
- Authorities or professional advisers may receive information where required by law or necessary to protect legal rights.
These service providers act under their own contractual and legal obligations. We do not give them permission to use community data for their own advertising.
9. International transfers
Some infrastructure or email providers may process data outside Portugal or the European Economic Area. Where GDPR transfer rules apply, we rely on an adequacy decision or appropriate safeguards offered by the provider, such as the European Commission’s Standard Contractual Clauses. Contact the organizers through the footer support form if you want more information about the safeguards relevant to your data.
10. How long we keep data
We keep personal data only for as long as needed for the purposes above. The exact period depends on the type of record:
- Account and profile data are generally kept while the account remains active and are removed or de-identified after a valid deletion request, subject to necessary exceptions.
- Community content remains until it is deleted, moderated, or no longer needed for the community archive. Some comments may remain de-identified to preserve discussion continuity.
- Invitation, abuse-prevention, security, and support records are retained only for the period reasonably needed to prevent misuse, resolve the matter, meet legal duties, or establish legal claims.
- Provider logs and backups follow limited operational retention cycles and are overwritten or deleted in the ordinary course.
11. Your GDPR rights
Depending on the circumstances, you may have the right to be informed, access your data, correct inaccurate data, erase data, restrict processing, receive portable data, object to processing based on legitimate interests, and withdraw consent without affecting earlier lawful processing. These rights are not absolute; the GDPR permits exceptions, including protection of other people’s rights and freedom of expression.
Send a request through Report a Bug in the footer as described above. We aim to respond without undue delay and ordinarily within one month. You may also complain to Portugal’s supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD).
12. Security
We use access controls, private-by-default profiles, restricted database functions, rate limits, encrypted transport, and least-privilege infrastructure practices. No online service can guarantee absolute security. Please do not post secrets, confidential documents, or personal data that you do not have the right to share.
13. Children
This community site is not designed for children who cannot lawfully agree to these services on their own. If you are a minor, use the site only with the involvement of a parent or legal guardian where required. A guardian who believes a child’s data was submitted improperly should contact the organizers.
14. Changes to this policy
We may update this policy when the service, providers, or legal requirements change. The current version and update date will remain available on this page. We will provide additional notice where a change materially affects how personal data is used.
15. Official GDPR information
For the authoritative rules, see the General Data Protection Regulation, the European Commission’s information for individuals, and the CNPD’s guide to data-protection rights.