Last updated: May 2026
1. Who We Are
AchiraWare Electronics is an online store specialising in the design and sale of electronic circuit boards (PCBs) made in Portugal. We operate at achiraware.com and are based in Porto, Vila Nova de Gaia, Portugal (European Union).
For any privacy-related queries, you can contact us at: customerservice@achiraware.com
We act as the Data Controller of your personal data, in accordance with Regulation (EU) 2016/679 (GDPR) and the Portuguese Personal Data Protection Law (Lei n.º 58/2019, LPDP).
2. What Personal Data We Collect
We collect only the data that is strictly necessary to process your orders and operate our store. This includes:
- Identity data: first name, last name
- Contact data: email address, phone number (if provided)
- Delivery data: billing and shipping address
- Order data: products purchased, order value, order history, payment status
- Technical data: IP address, browser type, device type (collected automatically by WordPress/WooCommerce during your visit)
- Cookie data: functional cookies necessary for the shopping cart and session to work (see Section 8)
We do not collect sensitive personal data (such as health data, political opinions, or biometric data). We do not use tracking technologies for advertising or marketing analytics (no Google Analytics, no Facebook Pixel, no similar tools).
3. Why We Collect Your Data and the Legal Basis
We process your personal data for the following purposes, each with a specific legal basis under the GDPR:
- Processing and fulfilling your order — Legal basis: Performance of a contract (Article 6(1)(b) GDPR). We need your name, address, email, and payment information to complete your purchase, dispatch your order, and send you order confirmations and shipping updates.
- Fraud prevention and payment processing — Legal basis: Legitimate interest (Article 6(1)(f) GDPR) and performance of a contract. Payment data is processed directly by Stripe or PayPal; we do not store your full card details.
- Compliance with legal and tax obligations — Legal basis: Legal obligation (Article 6(1)(c) GDPR). Portuguese tax law requires us to retain invoicing and order records for a minimum of 10 years (Código do IVA and Código Comercial). As a minimum, fiscal records are kept for 5 years.
- Customer account management (if you create an account) — Legal basis: Performance of a contract. We retain your account data for as long as your account is active.
- Responding to your enquiries — Legal basis: Legitimate interest. When you contact us by email, we use your data solely to respond to your query.
- Security and prevention of abuse — Legal basis: Legitimate interest. We log IP addresses and technical session data to detect and prevent fraudulent activity or server attacks.
4. How Long We Keep Your Data
- Order records (invoices, billing data): retained for a minimum of 10 years, as required by Portuguese tax and commercial law (Art. 52 CIVA; Art. 40 Código Comercial).
- Customer account data: retained for as long as your account remains active. If you delete your account, your personal data is erased within 30 days, except where retention is required by law (e.g. completed orders).
- Email enquiries: retained for up to 2 years after the last interaction, then deleted.
- Technical/server logs (IP, session): retained for a maximum of 12 months.
- Cookie data: session cookies expire when you close your browser; persistent functional cookies expire within 2 years at most (see Section 8 for details).
5. Who We Share Your Data With
We only share your personal data with the third-party service providers that are strictly necessary to operate our store and fulfil your orders. All processors are contractually bound to protect your data and comply with the GDPR.
Payment Processors
-
Stripe, Inc. — Used to process card payments. Stripe may process your payment data in the United States under Standard Contractual Clauses. We never see or store your full card number.
Privacy Policy: https://stripe.com/en-pt/privacy -
PayPal (Europe) S.à r.l. et Cie, S.C.A. — Used as an alternative payment method. PayPal processes your payment details under their own terms.
Privacy Policy: https://www.paypal.com/pt/webapps/mpp/ua/privacy-full
Shipping Provider
-
CTT — Correios de Portugal, S.A. — Your name and delivery address are shared with CTT in order to ship your order via Correio Azul.
Privacy Policy: https://www.ctt.pt/ctt/politica-de-privacidade
Hosting Provider
-
OVHcloud (OVH SAS) — Our website is hosted on OVHcloud servers located in the European Union. OVHcloud may have access to server-level data (logs, backups) as part of their infrastructure services.
Privacy Policy: https://www.ovhcloud.com/en/personal-data-protection/
We do not sell, rent, or trade your personal data to any third party for marketing or advertising purposes.
6. Your Rights Under the GDPR
As a data subject, you have the following rights regarding your personal data:
- Right of access (Art. 15): You may request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): You may ask us to correct any inaccurate or incomplete data.
- Right to erasure / “right to be forgotten” (Art. 17): You may request that we delete your personal data, subject to legal retention obligations (e.g. tax records).
- Right to data portability (Art. 20): You may request a structured, machine-readable copy of the data you have provided to us, where technically feasible.
- Right to object (Art. 21): You may object to processing based on legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds.
- Right to restriction of processing (Art. 18): You may request that we restrict how we use your data in certain circumstances.
- Right to withdraw consent: Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please send an email to: customerservice@achiraware.com. We will respond within 30 days. We may ask you to verify your identity before processing your request.
7. Right to Lodge a Complaint
If you believe that your data is being processed unlawfully, or that your rights have not been respected, you have the right to lodge a complaint with the Portuguese supervisory authority:
CNPD — Comissão Nacional de Proteção de Dados
Rua de São Bento, 148-3º, 1200-821 Lisboa, Portugal
Website: https://www.cnpd.pt
Email: geral@cnpd.pt
You also retain the right to seek judicial remedy before the competent courts.
8. Cookies
Our website uses only strictly necessary and functional cookies. We do not use analytical, advertising, or tracking cookies of any kind. Because we only use essential cookies, no prior consent is required under EU ePrivacy rules; however, we inform you here for full transparency.
WooCommerce functional cookies
- woocommerce_cart_hash — Stores a hash of your shopping cart contents so WooCommerce can detect changes. Duration: session.
- woocommerce_items_in_cart — Records whether your cart contains items to avoid unnecessary requests to the server. Duration: session.
- wp_woocommerce_session_[ID] — Stores your session data (cart, user preferences) so your cart is preserved during your visit. Duration: 2 days.
- wordpress_logged_in_[hash] — Indicates whether you are currently logged in to your account. Duration: session / 14 days (if “Remember me” is selected).
Payment provider cookies
When you proceed to checkout, Stripe and/or PayPal may set their own cookies to detect fraud and ensure secure payment processing. These are governed by their respective privacy policies (see Section 5).
How to manage cookies
You can manage or delete cookies through your browser settings. Please note that disabling functional cookies may prevent the shopping cart and checkout from working correctly. For instructions specific to your browser, visit: www.aboutcookies.org
9. Data Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure. Our website uses HTTPS encryption. Payment data is processed via Stripe and PayPal, which are PCI-DSS compliant; we never store your full card details on our servers.
10. International Data Transfers
Your data is primarily stored on OVHcloud servers within the European Economic Area (EEA). Some data may be transferred outside the EEA when processed by Stripe (USA) and PayPal (Luxembourg, with potential global operations). Both providers use Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection for any such transfers.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we do, we will revise the “Last updated” date at the top of this page. We encourage you to review this page periodically. For significant changes, we may notify you by email or by a prominent notice on our website.
Continued use of our website after any changes constitutes acceptance of the updated policy.
12. Contact Us
For any questions about this Privacy Policy or how we handle your personal data, please contact us:
AchiraWare Electronics
Vila Nova de Gaia, Porto, Portugal
Email: customerservice@achiraware.com
Website: https://achiraware.com
