Privacy Policy
Last updated: September 22, 2026
This Privacy Policy is intended for the travelers, users and potential customers of WAVES & LOVE's products, services and platforms, as well as for the people depicted in photographs taken or used by WAVES & LOVE, including NGO beneficiaries. It explains, in a transparent manner, how their personal data is processed.
1. Data Controller
This Privacy Policy covers the website www.wavesnlove.com and the processing activities relating to trips, activities and photographs described in this Policy, including those carried out outside the website, by WAVES & LOVE, Unipessoal, Lda., with registered office at Rua Cidade de São Paulo, n.º 25, 4.º A, 2735-656 Agualva-Cacém, Sintra, Portugal, NIPC 519518225, hereinafter "WAVES & LOVE".
WAVES & LOVE is the data controller for personal data within the meaning of Regulation (EU) 2016/679 (GDPR) and Law No. 58/2019 of August 8.
Contact for privacy matters:
- Address: Rua Cidade de São Paulo, n.º 25, 4.º A, 2735-656 Agualva-Cacém, Sintra
- Phone: +33 7 59 70 81 91
- Email: contact@wavesnlove.com
The entity responsible for collecting and processing personal data is WAVES & LOVE, which, within the scope of the contractual or pre-contractual relationship and according to the service requested, will collect and process the personal data essential for that purpose.
WAVES & LOVE has not appointed a Data Protection Officer. The need for such an appointment is reassessed in light of Articles 37 to 39 of the GDPR; until then, requests should be directed to the privacy contact above.
2. Categories of Personal Data Processed
WAVES & LOVE may collect and process the following categories of data:
- Identification and travel data: to create an account, first name, surname, date of birth, country of birth and country of residence are requested, in addition to email and phone number. For the trip, only the strictly necessary fields from an identification document, passport or visa are processed; a full copy is not routinely collected when partial information or verification without retention is sufficient. A copy of the national ID card is only made in the cases and under the conditions legally permitted.
- Contact data: email and phone number. In the optional "Emergency & Travel Info" section of the profile, the traveler may provide the name, phone number and relationship of the person to contact in case of emergency. These fields are not required to create an account or make a Booking.
- Communication, support, complaints and public review data: messages, requests and responses; rating, text, destination or mission, date, display name or pseudonym, and authenticity and moderation records.
- Browsing data: cookies, IP address, online identifiers.
- Data necessary for organizing trips: Booking, stay, activities, logistical and administrative requirements, necessary fields from travel documents, and minimal proof of the existence and essential coverage of insurance. Notes are limited to the facts and instructions necessary for organizing, assisting with or closing out a service; health information follows Section 3.6 and is not included in generally accessible notes. Attendance may be recorded on a paper sheet, with minimal identification, activity, date and confirmation, without geolocation.
- Marketing data: email for sending newsletters.
- Billing and booking data: where applicable, data necessary for issuing accounting documents.
- Health data and dietary restrictions: the traveler may optionally provide dietary restrictions or allergies in the "Emergency & Travel Info" profile, without this being a condition for creating an account or making a Booking. Allergies and elements that reveal health information are health data; a dietary preference is not automatically sensitive, but if it reveals health, religion or another category under Article 9 of the GDPR, it follows the corresponding regime. Where necessary for the activity, a functional confirmation of fitness or instructions limited to necessary adaptations or precautions may also be processed, without routinely collecting medical history or copies of certificates.
- Activity preparation and conduct-commitment data: identification of the participant, the NGO and the mission, a record of the reading steps and comprehension questions actually completed, the versions and language of WAVES & LOVE's general rules and the NGO's specific rules presented, completion and, where applicable, the date and proof of the electronic signature of the commitment, and the supporting statement made available to the NGO, including the additions required by a change to the mission or the rules. For other activities, where a legal representative is involved, only their identification, capacity and a record of the necessary involvement are processed. The specific child-protection path currently applies only to adult participants assigned to missions involving contact with beneficiary minors. No declarations about convictions, investigations or judicial bans are requested.
- Public review data: rating, comment, experience reviewed, date, optional display name or pseudonym, internal link to the Booking, and complaint and moderation records; these are not used, manually or automatically, for profiling, pricing, Bookings, participation or restriction of access.
- Image data: photographs; minimal identification of the person depicted and of the representative where necessary, context, authorized purposes and media, duration, proof of consent and any withdrawal.
- Post-stay donations: where the feature is available and used, the necessary identification and contact details, the chosen recipient entity or project, the amount, date and reference of the transaction, in accordance with the information presented before the donation.
3. Purposes and Legal Bases of Processing
Personal data is processed lawfully, fairly and transparently. The purposes and their respective legal bases are:
3.1 Managing Contacts and Responding to Requests
Purpose: managing requests sent through the "Contact us" section.
Data processed: first name, surname, email, phone, message.
Legal basis: steps taken prior to entering into a contract (Art. 6(1)(b) GDPR).
3.2 Marketing and Newsletter
Purpose: sending information about products, services, destinations and news.
Data processed: email.
Legal basis: consent (Art. 6(1)(a) GDPR).
3.3 Cookies and Browsing Data
Purpose: improving the browsing experience, personalizing content and analyzing statistics.
Data processed: online identifiers, cookies.
Legal basis: consent for non-essential cookies; strictly necessary cookies benefit only from the exception under Article 5 of Law No. 41/2004, and any subsequent personal data processing must have its own basis under Article 6 of the GDPR.
3.4 Organizing Trips and Activities
Purpose: creating and managing the traveler's account and organizing the booking, coordination and performance of trips, stays and activities. The optional profile fields are intended to facilitate preparation and assistance for current or future trips; they are not duplicated in a per-mission file.
Data processed: account data and Booking, traveler, document, insurance, accommodation, activity, attendance and logistics data necessary for managing the account, pre-contractual steps, contract performance, assistance and legal obligations. The optional profile fields follow the purposes and legal bases specifically described in this Section and in Section 3.6. The data is provided by the traveler or, for companions and minors, by whoever makes the Booking or by the legal representative; partners communicate only the coordination elements that are necessary. Paper attendance sheets are not published and are not intended for tracking movements. Where data is not obtained directly from the data subject, the information required under Article 14 of the GDPR is provided.
Legal basis: pre-contractual steps or performance of the contract where the data subject is a party, including when validly represented, only for the data objectively necessary for the account or the requested service (Art. 6(1)(b) GDPR). For companions who are not parties, organizing and performing the trip, assistance and coordination rest on the legitimate interest of WAVES & LOVE and those travelers, following a balancing of the rights involved and limited to what is necessary (point (f)). Specifically applicable legal obligations are based on point (c). Optional, non-sensitive dietary preferences rest on consent (point (a)); sensitive information follows Section 3.6. The emergency contact's data rests on the legitimate interest in preparing assistance for the traveler, following a balancing of the rights of the person named. The traveler must inform that person of being named and of this Policy; WAVES & LOVE provides the information required under Article 14 within the applicable terms and time limits, without substituting it with the traveler's consent.
3.5 Compliance with Legal Obligations
Purpose: compliance with tax, accounting, administrative or security obligations.
Legal basis: legal obligation (Art. 6(1)(c) GDPR).
3.6 Health Data (Art. 9 GDPR)
Purpose: allowing the traveler to optionally save in their profile the health information useful for the safe preparation of current or future trips, and making available only what is necessary for the specific activity or assistance. This also covers verifying fitness or health requirements and the adaptations or precautions necessary for the activity.
Data processed: allergies, dietary restrictions that reveal sensitive information, and functional instructions necessary for adaptations or precautions. No clinical file is created, and medical history or full copies of certificates are not routinely requested. Access, which may be limited within the existing tools, is reserved to the preparation, safety or assistance functions that need it. Sensitive information in notes or emergency fields keeps this regime; it is not made available indiscriminately to partners.
Legal basis: the optional storage in the profile and the sharing necessary with identified partners for preparation and assistance rest on explicit, specific, informed, demonstrable and freely given consent, under Articles 6(1)(a) and 9(2)(a) of the GDPR. Consent is separate from general acceptance of the account or the Booking, may be withdrawn at any time without affecting services that do not depend on the information, and is not presumed merely from optionally filling in a field. Any other processing requires its own basis under Article 6 and an applicable condition under Article 9(2). In an emergency, vital interests presuppose the physical or legal impossibility of the data subject giving consent. Without an applicable basis, the data is neither collected nor made available.
Retention: the optional fields may remain in the profile for future trips for as long as the traveler wishes to keep them and they remain necessary and up to date, under Section 10. Their continued presence does not extend the NGO's access after the mission. Accounting needs do not justify retaining health data.
3.7 Preparation for Activities and Conduct Commitment
Purpose: preparing the participant for the mission's safety and conduct rules, including child protection where applicable, verifying the steps actually completed, and evidencing the commitment where formalized. The preparation brings together WAVES & LOVE's general rules with the rules of the NGO and the chosen mission. The path may be made available in the personal area from the moment the mission is selected in the Booking request, with appropriate notifications and reminders, without its completion bringing forward the definitive confirmation of the Booking or the mission. The time limits and the consequences of failing to complete it are those set out in the Terms and Conditions for missions involving contact with minors; they are not automatically extended to other activities. If the mission actually confirmed, or the applicable rules, differ, steps that remain appropriate are carried over and only the necessary additions are recorded.
Data processed: identification of the participant, the NGO and the mission, the steps actually completed, the answers necessary to verify comprehension, the versions and language of the rules presented, additions and, where they exist, the date and proof of the electronic signature. The questions concern rules and conduct scenarios and may be repeated after an explanation; they are not intended to assess personality or background. Where issued and necessary for coordinating the mission, the statement made available to the NGO identifies the participant, the mission and the applicable versions, and evidences only the steps completed and the commitment actually formalized. It does not include the history of answers, nor does it certify background or suitability to work with minors. For other activities, any necessary involvement of a legal representative is recorded only to the extent applicable.
Legal basis: pre-contractual steps requested by the participant themselves, or performance of the contract, only to the extent the processing is objectively necessary for preparing and carrying out the chosen mission, with regard to the participant who requests those steps or is a party to the contract, including when validly represented (Art. 6(1)(b) GDPR). The preparation and coordination of other participants, and any processing not covered by that contractual necessity that is strictly necessary for the safety of the activities, participants and beneficiaries, rest on legitimate interest, following a balancing of the rights and interests involved (point (f)). Retaining the evidence necessary to defend rights, and processing the representative's strictly necessary data, likewise rest on legitimate interest, following a balancing exercise, with particular attention to minors. Including a step in the path does not, by itself, make the processing necessary for the contract. Legal obligations are invoked only where specifically applicable. The signature formalizes the conduct commitment; it does not constitute consent to process criminal data.
Legally required checks: documents or information about background that the NGO must obtain for admission are handled directly between the NGO and the participant, under the applicable law, outside the path and outside WAVES & LOVE's document handling. Coordination between WAVES & LOVE and the NGO is manual and limited to the overall operational decision and the elements necessary for admission or assignment, without any indicator of the result of a criminal check or any explanation revealing that data. If WAVES & LOVE has its own legal obligation, or an incident report is received, the processing follows a specific pathway, with restricted access, appropriate information and the applicable legal basis, including the requirements of Article 10 of the GDPR where criminal data is involved.
Automation: making the path available, the explanatory answers and the reminders may be automated. Updating the coordination status with the NGO, and any reassignment, are carried out manually by the teams, with no automated admission decision. Failure to complete the path does not result in an automated suitability assessment or the automatic cancellation of the entire Booking. Any termination is assessed by WAVES & LOVE in the cases and under the conditions set out in the Terms and Conditions, allowing the participant to report an error, a difficulty accessing the path, or another relevant circumstance.
3.8 Public Reviews
Purpose: enabling optional reviews of destinations and missions, verifying correspondence with the actual experience, preventing fake reviews, moderating content and providing information to other users.
Data processed: rating, comment, destination or mission, date, optional display name or pseudonym, internal link to the Booking, and complaint, response and moderation records. By default, the review does not reveal the account holder's identity.
Legal basis: specific and demonstrable consent for public posting; documented legitimate interests for authentication, fraud prevention and moderation, following a balancing test; legal obligation only where specifically applicable.
Transparency: the interface identifies public fields, recipients, possible indexing, verification method, ranking, moderation and incentives. No contact details, health or criminal data, or data of minors or third parties should be included. There is no manual or automatic use for behavioral scoring, profiling, pricing, Bookings, participation or future access.
Rights: the author may edit or withdraw the review, request removal or anonymization, exercise their GDPR rights and challenge moderation decisions. Positive and negative reviews are subject to the same criteria. Reuse in advertising or on social media requires its own information and legal basis.
3.9 Photographs and WAVES & LOVE Communications
Purpose: taking and using images of travelers or NGO beneficiaries for WAVES & LOVE's communications, only for the specifically authorized purposes and media. The authorization distinguishes between publication on the website, on social media and in advertising, according to the uses actually intended.
Data processed: image and minimal identification of the person, the context in which it was taken, authorized uses, duration, and proof of authorization. For NGO beneficiaries, authorization is given by the person with capacity to do so or by the competent legal representative, with understandable information and respect for the minor's wishes and maturity. The NGO may facilitate and evidence the collection, but its agreement does not replace the authorization of whoever has the power to give it. No identifiable image of a child is published without valid specific authorization, nor content that exposes them to risk or violates their dignity.
Legal basis: prior, free, specific, informed and demonstrable consent, separate from acceptance of the Booking or the conduct commitment (Art. 6(1)(a) GDPR), without prejudice to the legal requirements on the right to one's own image and representation. Refusal or withdrawal does not affect the trip, participation, or the support provided by the NGO. If the image reveals data subject to Article 9, the specific applicable basis is also required; a generic authorization is not sufficient.
Use and withdrawal: the form identifies WAVES & LOVE, the uses, the recipients, the media, and the chosen period for use and retention. The data subject may withdraw consent via contact@wavesnlove.com or through the same simple channel used to collect it, without affecting the lawfulness of prior processing. WAVES & LOVE stops new uses and removes the images from the media it controls, taking reasonable measures with respect to disclosures already made; it informs beforehand that public posts may be copied or shared by third parties. Content is not reused for a different purpose or medium without a new, appropriate basis and information.
3.10 Post-Stay Donations
Purpose: enabling, where the feature is available, optional donations at the traveler's request. The entity receiving the donation, the intended use of the amount, and WAVES & LOVE's involvement are identified before any collection or payment. Choosing not to donate does not affect the trip or the relationship with WAVES & LOVE.
Data processed and basis: only the data necessary to carry out the donor's request, confirm the transaction and comply with specifically applicable legal obligations, based on Article 6(1)(b) and (c) of the GDPR, to the extent corresponding to each entity's actual involvement. Recipients, any transfers, retention and contact details are provided at the time of collection. Public disclosure of the donor's identity or of the amount donated, and its use for marketing, depend on separate information and consent where required; they do not follow automatically from the donation.
4. Recipients of the Data
Personal data may be shared with:
- Duly authorized WAVES & LOVE staff; for reviews and for photographs whose publication has been authorized, the public, social media users and search engines may access only the content and fields whose publication was specifically consented to, on the media indicated to the data subject.
- Partner hotel establishments in Peru, Senegal and the Philippines: Booking data, traveler identification, coordination contacts and information necessary for safety, the activity or a legal obligation. Partner NGOs in those countries: identification, mission assignment, necessary contacts and operational notes and, where applicable, the supporting statement from the path. Emergency contacts and health or dietary information are only made available to the extent necessary for the mission and to the functions that need them, with Section 3.6 applying to sensitive data. The presence of these fields in the profile does not grant partners general access. After the mission, the NGO retains only the name, necessary contact details and a minimal record of participation, within the limits of Section 10, which also apply to authorized exports, subject to the specific cases provided for there. Identification data is consulted in a restricted area, in read-only mode with no download function. Certificates, statements or criminal-record results are not made available through this path.
- Technical service providers, including newsletter delivery, under a contract in accordance with Art. 28 GDPR.
- Aon France, through the Chapka Assurances brand, and the insurer or distributor identified for the product purchased, only when the traveler directly initiates the subscription offered through the platform. Chapka generally acts as an independent controller for the processing linked to its services, in accordance with its privacy information available at https://www.chapkadirect.fr/index.php?action=rgpd. WAVES & LOVE does not send them data without a prior basis and prior information; a mere Booking does not amount to an insurance subscription.
- Dispute-resolution bodies, courts, authorities, insurers and advisors, only when necessary for a claim, defense of rights or a legal obligation.
- Payment service providers, including Stripe as indicated at checkout, with respect to the data necessary for authorization, capture, fraud prevention and refunds; and public authorities, when required by law. Depending on the transaction, Stripe acts on behalf of WAVES & LOVE or as an independent controller, in particular for its own purposes of fraud prevention and compliance with legal obligations. Its privacy information and data processing agreement are available at https://stripe.com/privacy and https://stripe.com/legal/dpa.
Transfers to third parties are strictly limited to the intended purposes and applicable legal bases, including contract performance, compliance with legal obligations, legitimate interest or consent, where required.
Irreversibly anonymized data may be used for statistical or marketing purposes.
5. International Transfers
Organizing trips may involve communicating or making data available to partners outside the European Economic Area, depending on the destination booked, including in Peru, Senegal and the Philippines. Remote access by the NGO to its restricted area, including to identification data and the path's statement where made available, also constitutes an international transfer where the recipient NGO is located outside that Area, even if the data remains hosted on servers in Europe and there is no download function. These transfers are subject to the following conditions:
- where an adequacy decision applicable to the recipient and the processing exists, the transfer may rely on that decision; in other cases, partners' routine access depends on an appropriate safeguard under Article 46 of the GDPR, including Standard Contractual Clauses where applicable, following an assessment of the destination and the necessary supplementary measures. The choice and formalization of the safeguard take into account the entities' roles and the processing actually carried out;
- the data subject receives, before the transfer, information about the country, the recipient and the basis used, as well as how to obtain a copy of the safeguard, where applicable, through the Booking information or the privacy contact. Only the necessary data is made available. The derogations under Article 49 are used only in the specific situations and conditions that article allows and do not form the general basis for partners' routine access to the platform.
Stripe's services may involve transfers to the United States and other countries identified in its documentation. The transfer agreement available at https://stripe.com/legal/dta sets out the applicable mechanisms, including the EU-US Data Privacy Framework where valid for the recipient and the processing and, in other covered cases, the Standard Contractual Clauses. Directly subscribing to insurance may also involve the recipients and transfers described in Chapka's and the insurer's privacy information. Processing within these services may therefore take place outside the European Economic Area.
6. Cookies
The Website uses cookies to improve browsing and personalize the user experience.
Non-essential cookies are used only with prior consent, collected through the cookie banner.
Users may review their choices and withdraw consent for non-essential cookies at any time, as easily as it was given, through the preference management mechanism made available on the Website. Browser settings also allow cookies to be blocked or deleted, but do not replace consent management on the Website.
The detailed Cookie Policy is available at https://www.wavesnlove.com/en/cookies.
7. Data Subject Rights
Under applicable law, users have the following rights:
- Access to their personal data.
- Rectification of inaccurate data.
- Erasure of data, under legal terms.
- Restriction of processing.
- Objection to processing.
- Data portability.
- Withdrawal of consent, without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise these rights, please contact:
- Address: Rua Cidade de São Paulo, n.º 25, 4.º A, 2735-656 Agualva-Cacém, Sintra
- Email: contact@wavesnlove.com | Phone: +33 7 59 70 81 91
For security purposes, additional information is only requested, proportionately, where there is reasonable doubt as to identity. If, exceptionally, a copy is required, unnecessary fields are hidden, access is restricted, and the copy is destroyed immediately after verification.
8. Personal Data of Minors
Data of minors is processed only when necessary for the trip, safety or a legal obligation, under the involvement of whoever holds parental responsibility or is legally authorized, or for photographs specifically authorized under Section 3.9. Currently, minor travelers are not assigned to missions involving contact with beneficiary minors and do not complete the specific commitment intended for those missions. For other activities, the preparation is suited to the minor's age and maturity, and the representative's involvement is limited to the acts required by law or by the activity, making use of the data already identified in the Booking, without requiring the minor to have their own account. At launch, minors do not post public reviews.
Information is presented in age-appropriate language; there is no behavioral scoring, profiling, decision based solely on automated processing that produces legal effects or similarly significant effects, nor marketing directed at minors. Access and sharing are limited, and the representative may exercise rights, without prejudice to the minor's own personal rights according to their age and maturity.
9. Data Security
WAVES & LOVE implements appropriate technical and organizational measures, including:
- encryption in transit and, where appropriate to the risk, at rest;
- access control based on functional need, authentication and periodic review;
- logging, backups, vulnerability management and incident response proportionate to the risk;
- internal policies, training, contracts with providers and regular effectiveness testing.
These measures aim to ensure the integrity, confidentiality and availability of the data.
10. Data Retention Period
Personal data is retained only for the period necessary for the purposes of processing:
- Requests and prospective customers: for the time necessary to respond and, where justified, for a limited evidentiary or limitation period, with review and deletion of inactive contacts.
- Account, contractual and complaint data: account data is retained for as long as necessary to manage it, with review of inactive accounts; deleting the account does not erase elements that have their own basis for retention. Contractual and complaint data is retained during performance and for the applicable legal periods of liability, evidence and limitation; the records necessary for price-reduction or compensation claims are retained for at least two years. This period does not determine the retention of identification copies, the optional profile fields, or the complete history of answers to the path. Proof of the Booking conditions is linked to the version and language actually presented at acceptance.
- Identification and travel insurance: only the elements necessary for verification are retained. The NGO's access to the identification copy ends at the end of the mission, or earlier if no longer necessary, and any copies legitimately held by the NGO are also deleted. The copy is deleted from WAVES & LOVE's current records within seven calendar days after the end of the stay, or earlier when it is no longer necessary, in particular due to cancellation or early termination of participation. The NGO is not authorized to make copies. Insurance copies are deleted after verification, retaining only the minimal record necessary to perform and evidence the contract. Any additional retention of a document requires a legal obligation, an incident, or a specific need to defend rights, with separate and restricted access limited to the necessary elements and period.
- Preparation and conduct commitments: the identification of the participant, NGO and mission, the steps, the accepted text and language, dates and additions, and, where applicable, the signature, the statement and proof of the representative's involvement are retained under the contractual evidence criteria set out above. Answers and attempts are deleted once they are no longer necessary to complete or evidence the path. The NGO's access to the supporting documents ends at the end of the mission, or earlier if no longer necessary. After that, the NGO retains only the name, necessary contact details and a minimal record of participation, including the mission and dates, until it confirms the service and reconciles payments, expenses or receipts. Operational notes are not part of that record. Once those operations are complete, the data is deleted or irreversibly anonymized, even without a formal closing record. Only accounting documents legally required, and elements necessary for another legal obligation, ongoing assistance, an incident, or the defense of rights, remain in a separate or restricted file, for the applicable period. A review, at least annual, checks these limits. Subsequent statistics use anonymized data; the history is not used for marketing.
- Marketing: ceases immediately upon withdrawal of consent or objection. Only a minimal suppression list is kept, for a justified period, to prevent further unwanted contact.
- Identity verification for exercising rights: the exceptional copy is destroyed immediately after verification; only a minimal record of the request and validation is kept for the period necessary to prove compliance.
- WAVES & LOVE billing data: 10 years, unless a special legal time limit applies, and only for accounting documents and elements required by law. This rule does not cover the participant's operational file, nor does it determine the retention period for a foreign NGO's own obligations.
- Optional "Emergency & Travel Info" fields: the emergency contact and the dietary restrictions or allergies remain in the profile, with no per-mission copy, for as long as the traveler wishes to keep them for future trips and they remain necessary and up to date. They may be corrected or withdrawn without deleting the account; they are erased on request, on withdrawal of consent where applicable, on deletion of the account, or when they are no longer useful. The review of inactive accounts checks this necessity, without presuming unlimited retention merely because the account exists. The NGO loses access at the end of the mission, or earlier if no longer necessary, and deletes the operational records, including any notes containing this data. Only the elements necessary for ongoing assistance, an incident, a legal obligation, or the defense of rights may remain separately, with their own basis and restricted access, for as long as the reason persists. These limits cover authorized copies and exports; an outstanding financial matter does not extend access to health or emergency data.
- Reviews: positive and negative reviews remain published for twenty-four months or until withdrawn, if earlier; minimal proof of consent, authenticity and moderation is kept for twelve months after removal, except in the case of documented litigation or legal obligation.
- Photographs and authorizations: images are used and retained for the period stated in the authorization, with use stopping earlier if consent is withdrawn. Only the minimal proof necessary of the authorization, the uses and any withdrawal is kept separately, for the justified period needed for compliance and the defense of rights, without extending the disclosure of the image.
- Paper attendance records: only for as long as necessary for coordinating and evidencing the activity and, where applicable, under the retention criteria for contractual records, without creating a record of movements or location. Donations: the periods stated before collection apply to the specific transaction, with additional retention only to the extent required by a legal obligation or the defense of rights.
11. Complaints
Users may file a complaint with the Comissão Nacional de Proteção de Dados (CNPD), Portugal's national data protection authority, at: https://www.cnpd.pt
12. Changes to this Privacy Policy
WAVES & LOVE may update this Privacy Policy at any time as necessary. The updated version will be published on the Website.
Last updated: September 22, 2026
