ROVENSA, S.A. («ROVENSA») is committed to full compliance with all applicable European Union and national legislation governing data protection, privacy and information security, including, without limitation, the General Data Protection Regulation (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 – «GDPR») and the applicable national Data Protection Law.
ROVENSA has established and maintains a Personal Data Protection System and an Information Security System designed to ensure ongoing regulatory compliance and to demonstrate institutional accountability for data protection and information security, adopting all appropriate technical and organizational measures to that end.
For any enquiries, clarifications, additional information, or to exercise any rights conferred under applicable data protection legislation, data subjects and other interested parties may contact the Data Protection Officer of ROVENSA at the following email address: dataprotection@rovensa.com.
Definitions
«Personal data» means information relating to an identified or identifiable natural person («data subject»); an identifiable person is a natural person who can be identified, directly or indirectly, in particular by reference to an identifier. Personal identifiers may be, for example, a name, an identification number, location data, identifiers by electronic means or one or more specific elements of the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
«Processing» means an operation or a set of operations carried out on personal data or on personal data sets by automated or non-automated means, such as collection, recording, organization, structuring, storage, adaptation or modification, retrieval, consultation, use, disclosure by transmission, dissemination or any other form of disclosure, comparison or interconnection, limitation, deletion or destruction.
«Cookies» are small text files stored on a user’s device (such as a computer or mobile phone) via the web browser when visiting a website. They contain information that enables the website to remember the user’s actions and preferences over time, such as login details, language selection, or other personalized settings. Cookies can also be used for statistical, analytical, or marketing purposes, depending on their type and the user’s consent.
Data Controller
ROVENSA, S.A., with registered office at Ed. Central Office, Av. Dom João II 45 8º, 1990-084 Lisboa – Portugal, registered with the Commercial Registry Office of Lisbon under No. 514194910 and holding the same Corporate Person number, with a share capital of € 232.200.591,00, hereinafter referred to as «ROVENSA», is the entity responsible for the websites www.rovensa.com and for the computerized applications (hereinafter collectively referred to as «channels» or «applications»), through which Users, Service Recipients or Clients may have remote access to the services and products related to the Agrobusiness, which are presented, marketed or provided, at any time, through such channels.
The use of the channels or applications by any User, Service Recipient or Client may entail the performance of personal data processing operations, whose protection, privacy and security by ROVENSA, as the entity responsible for their processing, is in accordance with the terms of this Data Protection and Privacy Policy.
Contact Details of the Data Controller and the Data Protection Officer
For any enquiries relating to the processing of personal data or the exercise of data subject rights, the Data Controller, ROVENSA, may be contacted through the following means:
- Registered office and postal address: Ed. Central Office, Av. Dom João II, 45, 8.º, 1990-084 Lisboa, Portugal
- General telephone number: +351 213 222 750 (Call to the national fixed network, costs may apply).
For matters specifically related to data protection and the exercise of rights under the GDPR, data subjects may also contact the Data Protection Officer of ROVENSA at the following email address: dataprotection@rovensa.com.
When submitting any request or enquiry, data subjects are kindly requested to clearly indicate the subject matter of their communication so as to facilitate its prompt and appropriate handling.
Collection and Processing of Personal Data
ROVENSA processes only the personal data that is strictly necessary for the purposes of providing information and ensuring the operation of its channels, according to the uses made by Users, Service Recipients or Clients, whether those provided by Users or Service Recipients for the purpose of registering requests or obtaining information, or those provided by Clients for the purposes of subscribing to those channels, or those resulting from the use of the services provided by ROVENSA through them, such as access, consultation, instructions, transactions and other records relating to their use.
In particular, the use or activation of certain channel functionalities may involve the processing of a number of direct or indirect personal identifiers, such as name, address, contact details, device addresses or geographical location, provided that the express consent of the User, Service Recipient or User/Client for such use has been given.
In all cases, Users, Service Recipients or Clients will always be informed of the need to access such personal data for the use of the functionalities of the channels in question.
The personal data collected by ROVENSA are processed electronically and, where applicable, through an automated processing operation, including file processing and in the scope of pre-contractual, contractual or post-contractual relationship management with Users, Service Recipients or Clients, in accordance with the applicable national and European Union data protection legislation. In accordance with Articles 13(2)(f) and 22 of the GDPR, ROVENSA hereby informs data subjects that it does not currently carry out any processing operations based solely on automated decision-making, including profiling, which produce legal effects concerning the data subject or similarly significantly affect them. Should ROVENSA implement any such processing in the future, this Policy will be updated accordingly, and data subjects will be informed prior to the commencement of such processing.
Categories of Personal Data Processed
The categories or types of personal data of Users, Service Recipients or Clients processed are name, surname, date of birth, address, postcode, country, landline number, mobile number, e-mail, taxpayer number or identification document number (non-mandatory).
Legal Principles
All personal data processing operations carried out by ROVENSA are conducted in strict compliance with the principles established set in the GDPR, namely the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality.
ROVENSA also adheres to the principle of accountability and is committed to being able to demonstrate compliance with these principles to data subjects and to any competent supervisory authority or other party with a legitimate interest therein.
Legitimate Grounds
ROVENSA only processes personal data where at least one of the lawful bases set out in Article 6(1) of the GDPR is applicable. The lawful bases relied upon for the processing of personal data include, in particular, the following:
- The data subject has given their freely given, specific, informed and unambiguous consent to the processing of their personal data for one or more specific purposes;
- The processing is necessary for compliance with a legal obligation to which ROVENSA, as controller, is subject;
- The processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract;
- The processing is necessary for the purposes of the legitimate interests pursued by ROVENSA or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data. The legitimate interests relied upon by ROVENSA include, namely: (i) the prevention of fraud and ensuring the security of ROVENSA’s networks and information systems; (ii) the improvement and optimization of the services, products and digital channels offered by ROVENSA; (iii) the production of aggregated and anonymized statistical analyses for internal business purposes; and (iv) the establishment, exercise or defense of legal claims. Where ROVENSA relies on legitimate interests as a legal basis, it has carried out a balancing assessment to ensure that such interests are not overridden by the rights and freedoms of the data subjects concerned. Data subjects may request further information about these assessments by contacting the Data Protection Officer.
Purpose of Processing
ROVENSA processes personal data for specific, explicit and legitimate purposes, in accordance with the principle of purpose limitation set out in Article 5(1)(b) of the GDPR and the information obligations established in Article 13(1)(c) of the GDPR. The main purposes for which personal data is collected and processed by ROVENSA include, without limitation, the following:
- Responding to information requests submitted by Users and Service Recipients in the context of the use of ROVENSA’s digital channels and services;
- Managing communications and relationships with Users, Service Recipients and Clients, including the conduct of pre-contractual, contractual and post-contractual interactions arising from the provision of services;
- Performing and delivering the services subscribed to by Clients, including all operations necessary for the fulfilment of the contractual obligations assumed by ROVENSA;
- Ensuring the technical and operational functioning, security and integrity of ROVENSA’s digital channels and information systems;
- Complying with legal and regulatory obligations to which ROVENSA, as controller, is subject;
- Generating aggregated and anonymized statistics for internal analysis and service improvement, on the basis of ROVENSA’s legitimate interest in optimizing its products, services and digital channels;
- Sending promotional or marketing communications regarding new features, products or services offered by ROVENSA, through electronic or traditional means (e.g., email, SMS, telephone or postal mail), where the data subject has given their prior consent or, where applicable, in the context of an existing customer relationship;
- Conducting satisfaction surveys or other forms of direct engagement for promotional purposes;
Each of the processing activities described above is grounded on at least one of the lawful bases set out in Article 6(1) of the GDPR, including, as applicable, the necessity for the performance of a contract to which the data subject is party, compliance with a legal obligation, the data subject’s consent, or the legitimate interests pursued by ROVENSA. Where applicable, the specific lawful basis applicable to each processing activity shall be communicated to the data subject at the time of data collection.
Where personal data is to be processed for purposes other than those for which it was originally collected, ROVENSA shall assess the compatibility of such further processing with the original purpose, including the link between the original and intended purposes, the context of collection, the nature of the data, the possible consequences for data subjects, and the existence of appropriate safeguards.
Where such further processing is not compatible with the original purpose shall obtain the data subject’s explicit consent prior to proceeding.
In all cases, the data subject shall be informed in advance of the new purpose and of their rights in relation to such processing, in accordance with the applicable data protection legislation.
Data Storage Periods
ROVENSA retains personal data only for the period strictly necessary to fulfil the purposes for which such data was collected, in accordance with the principle of storage limitation under the GDPR.
The specific retention periods applied by ROVENSA are determined having regard to the nature of the personal data concerned, the purposes of the processing, any applicable legal or regulatory obligations requiring longer retention, and the relevant limitation periods, as follows:
| Purpose | Retention period |
|---|---|
| Providing information requested by users | For the relevant categories of data, 12 months from the date of the last interaction, unless a contractual or pre-contractual relationship is established |
| Pre-contractual and contractual relationship management | For the relevant categories of data, duration of the contractual relationship plus 3 years after its termination |
| Compliance with legal and regulatory obligations | For the relevant categories of data, as required by the applicable legal provision (e.g. accounting and tax records: 10 years under Portuguese law) |
| Marketing communications (consent-based) | For the relevant categories of data, until withdrawal of consent or, in the absence of withdrawal, 12 months from the date of the last active interaction |
| Technical and operational functioning of the digital channels | For the relevant categories of data, 30 days from the date of collection, except where longer retention is required for information security incident investigation |
| Cookies and browsing data | For the relevant categories of data, see the specific retention periods in the Cookie Table below |
Without prejudice to the foregoing, where personal data is reasonably required for the purposes of establishing, exercising or defending legal claims, ROVENSA may retain such data for as long as the applicable limitation period has not expired, on the basis of its legitimate interest pursuant to Article 6(1)(f) of the GDPR.
Upon expiry of the applicable retention period, personal data shall be securely deleted or irreversibly anonymized in such a manner as to preclude the identification of the data subjects concerned, in accordance with the technical and organizational measures adopted by ROVENSA.
Recipients and Categories of Recipients of Personal Data
The provision of services by ROVENSA through its channels may involve the engagement of third-party processors, including entities established outside the European Union, whose activity may entail access to the personal data of Users, Service Recipients or Clients.
In such cases, ROVENSA ensures that all processors provide sufficient guarantees of implementing appropriate technical and organizational measures in such a manner that the processing meets the requirements of the GDPR and ensures the protection of the rights of the data subjects. These obligations are formalized through written data processing agreements, in compliance with Article 28(3) of the GDPR.
Where personal data is transferred to countries outside the European Economic Area (EEA), ROVENSA ensures that such transfers comply with Chapter V of the GDPR, including, where applicable, the use of standard contractual clauses adopted by the European Commission, binding corporate rules, or other appropriate safeguards.
In addition, ROVENSA may disclose personal data to third parties when required to do so by law, for example in response to lawful requests by public authorities, regulators, courts, or law enforcement agencies, in accordance with legal obligations to which ROVENSA is subject (Article 6(1)(c) of the GDPR).
Outside these situations, and except in the scope of compliance with legal obligations, personal data will not be communicated to third parties that are not processors or otherwise legitimately entitled to receive such data, nor will any communication be carried out for purposes other than those described in this Policy.
Security Measures
ROVENSA implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR. These measures are adopted taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, as well as the risk of varying likelihood and severity for the rights and freedoms of data subjects.
Such security measures aim to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, and any other form of unlawful processing.
Where ROVENSA relies on third-party processors that may access personal data, these entities are required, under written agreement, to implement equivalent security measures to ensure the confidentiality, integrity, and availability of the data, in accordance with applicable data protection laws.
Users, Service Recipients, and Clients also have an important role in safeguarding their personal data. They are responsible for maintaining the confidentiality of their access credentials and must not share them with third parties. When using digital channels provided by ROVENSA, they should ensure that their access devices are kept secure and follow recommended security practices, including regularly updating security software.
Exercise of Rights by Data Subjects, Complaints, Suggestions and Incident Reporting
In accordance with the GDPR, data subjects have the right to request from the controller access to their personal data, as well as the rectification or erasure of such data. They also have the right to request the restriction of processing, to object to the processing of their data, and to request the portability of their personal data to another controller, where applicable.
Where the processing is based on consent, data subjects have the right to withdraw their consent at any time. The withdrawal of consent shall not affect the lawfulness of processing carried out on the basis of consent prior to its withdrawal.
Where personal data are processed for direct marketing purposes, data subjects have the right to object at any time, without the need to provide any justification, by using the unsubscribe mechanism included in each marketing communication or by contacting the Data Protection Officer through any of the means indicated below.
Upon receipt of such objection, ROVENSA shall cease processing the data subject’s personal data for direct marketing purposes without undue delay.
Furthermore, data subjects have the right to lodge a complaint with a supervisory authority. In Portugal, the competent supervisory authority is the Comissão Nacional de Proteção de Dados (CNPD), to which complaints may be submitted directly through the website www.cnpd.pt.
These rights may be exercised at any time by submitting a written request to the Data Protection Officer of ROVENSA via email to dataprotection@rovensa.com, or by written correspondence addressed to Ed. Central Office, Av. Dom João II, 45, 8.º, 1990-084 Lisboa, Portugal.
ROVENSA shall respond to any request for the exercise of data subject rights without undue delay and, in any event, within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of requests received. In such cases, ROVENSA shall inform the data subject of the extension and of the reasons for the delay within one month of receipt of the original request, in accordance with Article 12(3) of the GDPR. If ROVENSA does not take action on the request, it shall inform the data subject without delay, and at the latest within one month of receipt, of the reasons for not taking action and of the data subject’s right to lodge a complaint with the supervisory authority and to seek a judicial remedy.
Users, Service Recipients, and Clients may also address any suggestions, enquiries, or concerns related to data protection by contacting ROVENSA through the means indicated in the preceding paragraph.
Incident Reporting
ROVENSA has established and maintains an incident management system designed to ensure a timely, structured and effective response to any personal data breach, in compliance with applicable data protection and information security legislation.
For the purposes of this Policy, a personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed, within the meaning of Article 4(12) of the GDPR.
Users, Service Recipients, and Clients who become aware of, or have reasonable grounds to suspect, the occurrence of a personal data breach affecting data processed by ROVENSA are strongly encouraged to report the incident without undue delay. Such reports shall be submitted to the Data Protection Officer of ROVENSA via email to dataprotection@rovensa.com, providing, to the extent possible, a description of the nature of the suspected breach, the categories and approximate number of data subjects concerned, and any other relevant information that may assist in the assessment and handling of the incident.
Amendment of Privacy Policy
ROVENSA reserves the right to amend this Data Protection and Privacy Policy at any time, in particular to reflect changes in applicable data protection legislation, regulatory guidance, or ROVENSA’s processing activities. Users, Service Recipients and Clients are encouraged to consult this Policy on a regular basis in order to remain informed of any amendments thereto.
Any material amendments shall be communicated to Users, Service Recipients, and Clients through the channels made available by ROVENSA, including by publishing the updated version on its website. Where amendments concern processing activities based on consent, ROVENSA will, where required, seek renewed consent from the data subjects concerned.
The current version of this Policy was approved and published on Jule 6th, 2026.
Legal Basis and Acceptance
This Data Protection and Privacy Policy are complementary to, and shall be read in conjunction with, the terms and provisions concerning the processing of personal data set out in the General Conditions of Use of ROVENSA’s channels.
By accessing or using ROVENSA’s channels, or by providing their personal data, Users, Service Recipients and Clients acknowledge that they have read and understood the terms of this Policy. ROVENSA processes personal data on the basis of one or more lawful grounds under applicable data protection legislation, as described in Section 7 of this Policy. The use of ROVENSA’s digital channels does not, by itself, constitute consent to the processing of personal data. Where consent is required, it is obtained through specific and separate mechanisms, such as consent forms, tick-boxes or other affirmative opt-in procedures, in accordance with the requirements of Article 7 of the GDPR.