λ

1. Identity and Contact Information of the Data Controller

The data controller for your personal information is:

  • Full Legal Name: Elysium λ Development & Research
  • Legal Representative: Daniel Alonso Morales Ávila
  • NIF / VAT: 321979257PT
  • Registered Address: Bragança, Portugal, European Union
  • Email for Privacy Enquiries: info@elysiumdr.eu

2. Information We Collect and Purpose

We only collect personal information that you provide voluntarily through our digital channels:

  • Contact & Onboarding Forms: Full name, professional email address, company name, website, and project-specific details.
  • Purpose: To manage your inquiries, provide requested technical information, and execute pre-contractual or contractual measures necessary to initiate our professional services.

3. Sensitive Data — Health Information (Art. 9 GDPR / Art. 9 Law 8968)

Where our services involve health-related or clinically sensitive data (e.g., physical assessments, medical history), this constitutes special category data under Art. 9 of the GDPR (EU 2016/679) and sensitive personal data under Art. 9 of Costa Rica's Law No. 8968.

Such data will only be processed upon your explicit, documented consent (recorded as consentHealthData: true in our system). You may withdraw this consent at any time. Processing without consent is strictly prohibited.

4. Legal Basis for Processing

We process your data based on the following legal foundations:

  • Explicit Consent: When you voluntarily complete our forms and check the explicit acceptance box, or specifically authorise health data processing.
  • Pre-contractual measures: When your request involves the preparation of a budget, quote, or technical assessment.
  • Legitimate Interest: To maintain the security, integrity, and optimal functioning of our internal systems and digital delivery infrastructure.
  • Legal Obligation: To comply with applicable fiscal, regulatory, and security obligations in Portugal (EU) and Costa Rica.

5. Data Retention & Automated Purging

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or to comply with applicable legal, tax, or regulatory obligations. Our automated retention policy operates as follows:

  • Health & clinical data: Anonymised after 5 years of inactivity.
  • Fiscal & user profile data: Fully anonymised and purged from authentication systems after 10 years of inactivity, in line with European fiscal obligations and Costa Rica's Law 8968.

Automated purging is executed via scheduled backend tasks to ensure compliance without manual intervention.

6. Your Comprehensive Rights

Consistent with the GDPR (EU), Law No. 58/2019 (Portugal), and Law No. 8968 (Costa Rica / PRODHAB), you possess the following rights which may be exercised free of charge:

  • Access: To obtain confirmation on whether your data is being processed and access it.
  • Rectification: To correct inaccurate or incomplete data.
  • Erasure (Right to be Forgotten): To request the deletion of data when it is no longer necessary.
  • Restriction of Processing: To limit how your data is used under specific circumstances.
  • Data Portability: To receive your data in a structured, electronic format.
  • Objection: To oppose processing for specific reasons or marketing purposes.
  • Withdrawal of Consent: You may withdraw your consent at any time without affecting the lawfulness of prior processing.

To exercise these rights, please send an explicit request to info@elysiumdr.eu.

7. Recipients and Third Parties

We do not sell or trade your data. We share information only with essential service providers who act as processors under our strict instructions:

  • Hosting & Backend: Firebase (Google Cloud), with servers primarily in the EU.
  • Communication: Corporate email and secure CRM systems used strictly for project management.

8. International Data Transfers

When using global infrastructure like Google Cloud, data may occasionally be transferred to regions outside the European Economic Area (EEA). We ensure these transfers are covered by Standard Contractual Clauses (SCCs) approved by the European Commission (Art. 46 GDPR), guaranteeing a level of protection equivalent to the GDPR.

For Costa Rica users, cross-border transfers comply with Law No. 8968, which requires that recipient systems guarantee adequate levels of security and confidentiality — a condition met by Google Cloud's internationally certified infrastructure.

9. Technical Security Measures

We implement robust technical and organisational security measures, including:

  • HSTS (Strict-Transport-Security): Forces exclusive HTTPS connections for one year, protecting against man-in-the-middle (MitM) attacks.
  • Content Security Policy (CSP) Level 3: Strict directives blocking unauthorised script and style injection (XSS).
  • X-Frame-Options / frame-ancestors: Mitigates Clickjacking attacks.
  • Permissions-Policy: Restricts browser access to camera, microphone, and geolocation.
  • HMAC-SHA256 Cryptographic Signing: Used for token integrity verification, preventing tampering.
  • Role-Based Access Control (RBAC): Enforced at database level via Firestore security rules — only authenticated data owners can access their own records.
  • User Enumeration Protection: Sensitive endpoints return generic responses to prevent user account discovery.
  • Constant-Time Comparison: Token verification uses timing-safe equality to prevent timing-based information leakage.
  • Secret Manager: All credentials and cryptographic secrets are stored in Google Cloud Secret Manager — never in source code.

10. Infrastructure Certifications

Our platform is hosted on Google Cloud / Firebase infrastructure. Although Elysium λ Development & Research does not hold private audit certifications (standard for independent professional businesses), our platform inherits the following Google Cloud certifications:

  • ISO/IEC 27001, 27017, 27018 — Information Security Management and Cloud Security.
  • SOC 1, SOC 2, SOC 3 — System and Organisation Controls.
  • PCI-DSS compatibility and HIPAA-eligible services (de facto reference standard for private clinics in Costa Rica selecting cloud providers).

11. Cookies and Tracking

Our website utilises only essential and technical cookies required for navigation and basic security. We do not employ third-party tracking, profiling, or behavioral advertising cookies without your explicit, opt-in consent, in compliance with the ePrivacy Directive (2002/58/EC) and the principles of Law No. 8968 (Costa Rica).

12. Mandatory Nature of Information

Fields marked with an asterisk (*) in our forms are strictly mandatory to process your request. Failure to provide this minimum information will prevent us from establishing contact or delivering the requested services.

13. Right to Lodge a Complaint

If you believe your data has been handled improperly, you have the right to claim before the competent supervisory authorities:

  • Portugal (EU): Comissão Nacional de Proteção de Dados (CNPD) — www.cnpd.pt
  • Costa Rica: Agencia de Protección de Datos de los Habitantes (PRODHAB) — www.prodhab.go.cr