Privacy
Updated 2026-09-19
- Legal name
- Babete
- Registered address
- Travessa da Boa Hora, Lisboa, Portugal
- Contact
- privacy@babete.pt
- Governing law
- Portugal — Lisboa
- Supervisory authority
- CNPD — Comissão Nacional de Proteção de Dados
Controller
Sinal is operated by Babete, whose registration and contact details are set out above. Babete is the controller for the personal data described in this policy.
Scope
This policy covers the public website, the Sinal application, the read API, and the emails Babete sends in connection with the service — everywhere personal data is processed under the Sinal product.
Data we process
Everything a signed-in account holds lives in that account's own database, isolated per person; the tables below never appear in the shared procurement corpus.
| Category | Where | Retention | Purpose |
|---|---|---|---|
| Account email, name and website | Account database | Until you delete your account | Operate the account |
| Profile: CPV prefixes, keywords, competitors | Account database | Until you delete your account | Generate your brief |
| Saved searches and their cursors | Account database | Until you delete your account or the search | Run your alerts |
| Notices already shown to you | Account database | 90 days | Avoid repeating the same notice in a digest |
| Alert state, including the last error text | Account database | Until you delete your account | Schedule digests and show you what went wrong |
| API key hash, prefix, and daily request counters | Account database | Key hash and prefix: until revoked or deleted. Counters: 31 rolling days | Meter API use |
| Session token hashes | Account database | 30 days from sign-in, or until you sign out | Keep you signed in |
| Unsubscribe token | Account database | Until you delete your account | Let a digest email pause itself |
| Digest run counters | Shared database, no personal data | Kept indefinitely | Monitor whether digests are running |
| Request logs: route pattern, status, duration | Cloudflare's request logs | Short-lived, Cloudflare's standard retention | Diagnose and secure the service |
| Rate-limit keys: your IP address, for a window of seconds | Cloudflare's rate limiter | Seconds | Stop abuse of the free tiers |
Purposes and legal bases
Babete relies on three legal bases, depending on what the processing is for.
- Contract — running your account, your saved searches and your digest emails, because you asked us to.
- Legitimate interest — securing the service, enforcing rate limits, and keeping operational logs, which is necessary to keep Sinal working and safe.
- Consent — analytics (Google Analytics, Microsoft Clarity), which only runs after you accept it in the cookie banner.
Cookies and storage
The table below lists every cookie and stored value the site sets.
When analytics is running, Google Analytics operates without Google Signals or ads personalisation, and Microsoft Clarity honours the same consent signal — neither loads before you accept.
| Name | Type | Duration |
|---|---|---|
| sinal_session | Strictly necessary (keeps you signed in) | 30 days |
| sinal-locale | Preference (remembers your language) | 1 year |
| sinal-consent | Consent record (remembers your choice) | 182 days |
| theme, sinal-theme, sinal-locale, rail (localStorage) | Preference, kept on your device only | Until you clear it |
| _ga, _ga_* (Google Analytics) | Analytics — only after you accept | Set by Google, only after consent |
| _clck, _clsk (Microsoft Clarity) | Analytics — only after you accept | Set by Microsoft, only after consent |
Analytics and consent
Sinal uses Consent Mode v2: every analytics and advertising signal defaults to denied, and nothing beyond strictly necessary cookies loads until you accept. Advertising signals stay denied regardless of your choice — Sinal does not run ads. You can change your mind at any time from "Cookie settings" in the footer.
Processors
Babete uses the following processors to run Sinal.
- Cloudflare, Inc. — hosting, the account database, and outbound email, on Cloudflare's global network; data may leave the EU, covered by the EU–US Data Privacy Framework and Standard Contractual Clauses.
- Google Ireland Limited — Google Tag Manager and Google Analytics, only after you accept analytics.
- Microsoft Ireland Operations Limited — Microsoft Clarity, only after you accept analytics.
Third-party personal data in the corpus
The procurement notices Sinal indexes sometimes name a contact person and email address, published by the contracting authority itself as part of the public tender record.
Babete processes that contact information under Article 6(1)(f) GDPR — a legitimate interest in making public spending transparent and searchable. It lives only in the database; Sinal never displays it on a page. If you are named in a notice and object to this processing, write to us and we will act on it.
Retention
Most account data is kept until you delete your account. The exceptions are in the table above: notices already shown to you age out after 90 days, API usage counters roll off after 31 days, and a session expires 30 days after it was created or as soon as you sign out.
Your rights
Under the GDPR you can exercise the following rights at any time. Because your email address is how your account is found, it cannot be changed in place — delete your account and sign up again with the new address. We respond to a request within 30 days.
- Access — ask what we hold about you.
- Rectification — your profile is editable in the app at any time.
- Erasure — delete your account, which removes everything listed above immediately.
- Portability — download your data as a JSON file from the Me page.
- Objection — object to a processing activity, including the third-party contact data described above.
- Restriction — ask us to limit how your data is used while a request is resolved.
Complaints
You can lodge a complaint with the Comissão Nacional de Proteção de Dados (CNPD), Portugal's data protection authority, at cnpd.pt — or with the supervisory authority of your own EU member state.
Security
Sinal is built to keep a compromise small even when something goes wrong.
Report a vulnerability through security.txt, described on the /security page.
- Every connection is HTTPS.
- The session cookie is HttpOnly and cannot be read by a script.
- Login links, session tokens and API keys are stored as hashes — never as the raw secret.
- There are no passwords to steal: sign-in is a one-time link and code, sent to your address.
Children
Sinal is a business tool. It is not directed at, and Babete does not knowingly collect data from, anyone under 16.
Changes
This policy is dated at the top of the page. Babete will update that date whenever the text changes and will not narrow your rights without telling you.
Contact
Questions about this policy or your data: write to the address above.