Compliance

Privacy Policy

Version 1.0 Effective 11 September 2026 Reviewed annually

This policy explains how Fontana Trading Europe, Sociedade Unipessoal Lda. (the "Company", "we") and our group subsidiaries process personal data. It is written to satisfy the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Portuguese Lei da Proteção de Dados Pessoais (Lei nº 58/2019), the Brazilian Lei Geral de Proteção de Dados (Lei nº 13.709/2018, "LGPD") and the UK Data Protection Act 2018.

1. Who we are

The data controller is Fontana Trading Europe, Sociedade Unipessoal Lda., NIPC 519 541 227, with registered office at Rua Filipe Folque 2, 2º, 1050-113 Lisboa, Portugal. Our Brazilian and UK subsidiaries — Fontana Agronegócios Ltda. (CNPJ 54.793.783/0001-37) and Fontana Trading UK Ltd. — act as joint controllers or processors depending on the activity.

Data protection contact

Written requests should be addressed to privacy@fontana.trade or by post to the Lisbon address above, marked for the attention of the Head of Compliance.

2. Personal data we process

We only process personal data that is necessary for us to trade, comply with law, and manage the relationship with counterparties and their representatives. Specifically:

3. Legal bases for processing

Under Article 6 GDPR (and equivalent Article 7 LGPD), we rely on the following legal bases:

ProcessingLegal basis
Negotiating and performing contracts with counterparties and their representativesContract (Art. 6(1)(b) GDPR)
KYC, sanctions screening, anti-money-laundering checksLegal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f))
Retaining records for tax, customs and regulatory reportingLegal obligation (Art. 6(1)(c))
Managing the counterparty relationship, business development, market intelligence distributionLegitimate interest (Art. 6(1)(f))
Marketing to prospective counterpartiesConsent (Art. 6(1)(a)) or legitimate interest with opt-out
Site security cookies and essential analyticsLegitimate interest (Art. 6(1)(f))

4. Who we share data with

We share personal data only with recipients who need it to help us perform a contract or comply with law. Categories include:

We do not sell personal data. We do not transfer personal data to unrelated third parties for their own marketing.

5. International transfers

As a business active on three continents, we transfer personal data between the European Union, the United Kingdom, Brazil and the countries where our counterparties are located (including China, EU member states, the UK, Egypt, Nigeria and other markets). Transfers outside the European Economic Area are made under one of the following safeguards:

6. How long we keep data

CategoryRetention period
Contracts, invoices and shipping documents10 years from the end of the accounting period (Portuguese Commercial Code, Art. 40)
KYC records7 years after the relationship ends (AML Directive 5)
Sanctions screening results7 years after the last screening
Commercial correspondence (email, chat)7 years after the trade closes
Unsuccessful KYC / declined counterparties5 years, for audit trail
Marketing listsUntil opt-out, reviewed annually
Job applications (unsuccessful)12 months, with candidate consent

7. Cookies and website

fontana.trade uses only strictly necessary cookies for form submission (Netlify Forms) and security headers. We do not use advertising, retargeting or third-party analytics cookies. If we introduce analytics in future we will update this policy and, where required, request your consent through a cookie banner.

8. Your rights

Under GDPR and LGPD you may exercise the following rights in respect of personal data we hold about you:

To exercise any of these rights, email privacy@fontana.trade. We will respond within one month (GDPR) or fifteen days (LGPD), extendable if the request is complex.

9. Security

We apply technical and organisational measures appropriate to the risk: encrypted transport (TLS 1.2+ for all web traffic), encryption at rest for backups, multi-factor authentication on business systems, least-privilege access controls, quarterly access reviews, and a documented incident response plan. Personal data breaches affecting the rights of data subjects will be notified to the competent supervisory authority within 72 hours and to affected individuals without undue delay, as required by GDPR Art. 33–34 and LGPD Art. 48.

10. Changes to this policy

We review this policy at least annually and update it if our processing activities, legal obligations or safeguards change. The date at the top of the page reflects the latest revision. Material changes are notified through the site header, and to counterparties by email where the change affects a live relationship.

Not legal advice. This policy states how Fontana Trading Europe processes personal data. It does not constitute legal advice for readers. Counterparties should consult their own counsel where necessary.