Privacy Policy
Last updated: 2026-08-06 · Version: 2026-08-v1
This policy explains what personal data we collect, what we use it for, on what legal basis, how long we keep it and what rights you have. It applies to viva-voice.com and to bookings made through it.
1. Data controller
Viva Voice, a brand of Pedro Rosa, sole trader. Portuguese tax number (NIF) 244834350. Phone: (call to a Portuguese mobile network). Email: pedro.rosa@viva-voice.com.
To exercise your rights or ask anything about this policy, write to pedro.rosa@viva-voice.com.
2. What data we process
- Booking data: name, email, phone, any notes you write, language, chosen experience, session date and time, number and type of tickets.
- Payment data: payment identifier, payment method type and payment status. Card details are entered directly into a Stripe form and never pass through or get stored on our servers.
- Coupon and partner data: the discount code used and, where applicable, the partner the sale is attributed to.
- Contact data: name, email, phone, organisation and message, when you use the contact form.
- Technical and usage data: collected only if you accept analytics cookies, as described in section 6.
3. Why we use it and on what basis
- Managing your booking, processing payment, sending the confirmation and the reminder 24 hours before the session: performance of the contract (Article 6(1)(b) GDPR).
- Meeting legal, accounting and tax obligations: compliance with a legal obligation (Article 6(1)(c)).
- Preventing payment fraud and receiving internal alerts about failed or unfinished payments: legitimate interests (Article 6(1)(f)).
- Replying to contact form messages: consent (Article 6(1)(a)).
- Analysing site usage to improve it: consent, given through the cookie banner (Article 6(1)(a)).
We do not sell personal data and we do not use it for targeted advertising.
4. Who we share it with
We use service providers who process data on our behalf under Article 28 GDPR processing agreements:
- Stripe: payment processing and fraud prevention. Stripe also acts as an independent controller for its own legal and anti-fraud obligations.
- Resend: sending transactional emails (confirmation, reminder, notifications).
- Vercel: website hosting.
- Neon: hosting of the database where bookings are stored.
- Microsoft: Microsoft Clarity analytics, loaded only if you accept cookies.
Some of these providers may process data outside the European Economic Area. Those transfers rely on standard contractual clauses approved by the European Commission or on adequacy decisions. You may ask us for information about these safeguards.
5. How long we keep it
- Booking and payment data: for the legal retention period for accounting and tax records, after which it is deleted or anonymised.
- Contact form messages: up to 2 years after the last contact.
- Record of your cookie choice: kept in your browser until you clear or change it.
- Analytics data: for the retention period of the tool used.
6. Cookies and local storage
On your first visit we show a banner where you can accept or reject analytics cookies. No analytics is loaded before you accept.
- vv_cookie_consent: stored in your browser's local storage, recording only your choice (accept or reject).
- Microsoft Clarity: analytics cookies that help us understand how the site is used, including heatmaps and session recordings. Loaded only after you accept.
- Stripe: cookies required for secure payment processing and fraud detection, active only during checkout.
You can change your mind at any time by clearing this site's data in your browser, which makes the banner appear again.
7. Partner programme
When a booking is made with a partner's coupon, that partner can see, in a private area, the customer's name, the experience, the session date, the amount paid and the commission. Partners cannot see the customer's email, phone or notes.
8. Automated decisions
We do not take automated decisions with legal effects about you and we do not carry out profiling. Stripe performs automated anti-fraud analysis of transactions as part of payment processing.
9. Security
- The whole site is served over an encrypted connection (HTTPS).
- Access to the management area is protected by authentication and restricted.
- Card details are never stored by Viva Voice.
10. Your rights
You have the right to access your data, rectify it, erase it, restrict or object to processing, to data portability, and to withdraw consent at any time without affecting the lawfulness of processing carried out beforehand.
To exercise any of these rights, write to pedro.rosa@viva-voice.com. We reply within a maximum of 30 days.
If you believe the processing does not comply with the law, you may complain to the Portuguese data protection authority (CNPD) at www.cnpd.pt.
11. Changes to this policy
This policy may be updated. The version in force is always the one published on this page, with the date and version shown at the top.