Updated . This notice explains how SEMPR handles personal data received through enquiries and client work, and how the browser-based ITSM Health Check handles your answers.

Who is responsible

SEMPR - Serviços Empresariais Lda is the controller responsible for the personal data it receives and uses to handle ITSM.COACH enquiries and requested services. ITSM.COACH is a service brand of SEMPR.

Registered address: Rua de Oliveira e Sá, 198 | 4475-263 MAIA | Portugal

João Costa is your contact for privacy questions and requests: joaocosta@itsm.coach. You can also write to the address above.

Contact details and enquiries

The Contact form asks for your name, business email, organisation, the support you are interested in and a description of your challenge. It prepares a message within your browser. You review it and choose whether to copy the text or open a draft in your email application.

The form does not send an enquiry to a website database or confirm an appointment. SEMPR receives the message only when you send it through your email application. Your email provider also handles the message you send.

Providing enquiry details is voluntary. The form requires those fields to prepare a useful message; without sufficient contact and enquiry information, we may be unable to respond or provide the requested support. Please avoid passwords, unnecessary personal information and confidential client identifiers.

Why we use your information

We use enquiry and subsequent correspondence only to respond, discuss your requirements and manage the services requested. We do not use these details for newsletters, promotional emails or advertising profiles.

For business enquiries and communications with an organisation’s representatives, the legal basis is our legitimate interest in responding to requests and managing professional service relationships (Article 6(1)(f) GDPR). Where processing is necessary to take steps you request before a contract, or to fulfil a contract with you personally, the basis is Article 6(1)(b). Records that legislation requires us to keep are retained to comply with that legal obligation (Article 6(1)(c)).

The ITSM Health Check

Your assessment context, answers, selected challenges and optional desired outcome are processed in the current page memory to calculate an indicative service management profile. They are not submitted to a website database or saved in browser storage. Reloading or leaving the page clears the assessment.

Downloading your results saves a text file on your device. Copying a summary places it on your clipboard. Those copies remain under your control. Answers are not automatically transferred to Contact, email or analytics. SEMPR receives assessment information only if you choose to include it in a message you send.

The Health Check is guidance about reported service management practices. It is not used to make decisions with legal or similarly significant effects about an individual.

Access and storage

Within SEMPR, João Costa alone accesses enquiry and client records. Records are held in Outlook email under Microsoft 365 Business Basic and files on his computer, with manual backup copies on an external drive. OneDrive and SharePoint are not used to store these enquiry or client records.

The Exchange Online data location shown for our account is European Union/EFTA. This describes the configured storage geography and does not mean all processing or support access occurs within that region.

Microsoft provides the email and associated Microsoft 365 services. Its authorised service providers may also process information to operate and support those services. See Microsoft’s data-processing information and its Data Protection Addendum.

How long we keep records

Review and deletion are performed manually. The same deadlines apply to the manual external-drive copies. Records that must be kept longer to comply with legislation are retained for the applicable legal period.

Removal from our working records does not mean every Microsoft 365 recovery copy disappears immediately. Technical recovery copies follow that service’s configured recovery and preservation settings. Our manual deletion policy is separate from those provider processes.

Fonts and external links

Quicksand fonts are served from this website’s own hosting; loading them does not require requests to Google Fonts. External links, including LinkedIn and reference websites, take you to services with their own privacy arrangements.

Processing outside the EEA

Microsoft documents safeguards for personal data transferred outside the European Economic Area, including contractual protections. See its processing and transfer information. Contact us for information about the safeguards applicable to your records.

Your rights

Depending on the circumstances, you can request access to your personal data, correction, erasure or restriction of processing. You can object to processing based on legitimate interests. Data portability applies where its legal conditions are met.

Send a request to joaocosta@itsm.coach or the postal address above. We may ask for information needed to verify your identity. We will normally respond within one month; where an extension is permitted for a complex request, we will explain it within that first month.

You also have the right to complain to a supervisory authority. In Portugal, this is the Comissão Nacional de Proteção de Dados (CNPD). You can complain without first contacting us.

Changes to this notice

We will update this notice if the website or our handling of personal data changes. The date above identifies the latest revision.