Privacy Policy

Dr Padel Racket values your privacy. This Policy explains how we collect, use, store, and protect your personal data when you use the website www.drpadelracket.com.

1. Data Controller Company name: MACHADO SPORTS, LDA. Tax identification number: 518 123 189 Headquarters: Rua Gomes de Amorim, 139, 2.º Dto., 4490-641 Póvoa de Varzim, Portugal Contact for privacy issues: info@drpadelracket.com

2. Personal Data Collected We collect the following data: Identification data: name, surname, date of birth (when applicable). Contact data: address, email address, phone number. Order data: order history, purchased products, rackets submitted for repair/customization. Payment data: payments are processed by our partners (EasyPay, Eupago, PayPal, Shop Pay), so we do not store bank card data. Browsing data: IP address, browser type, pages visited, duration of visit, collected through cookies and similar technologies. Communications: messages you send us via email, WhatsApp, social media, or website forms.

3. Purposes and Legal Bases We process your data for the following purposes, with the indicated legal bases: Contract performance (Art. 6(1)(b) GDPR): processing orders, deliveries, repairs, customizations, invoicing, and customer support. Compliance with legal obligations (Art. 6(1)(c) GDPR): issuing invoices, retaining tax and accounting documentation. Legitimate interest (Art. 6(1)(f) GDPR): fraud prevention, website security, improvement of our services. Consent (Art. 6(1)(a) GDPR): sending newsletters and commercial communications, non-essential cookies, publishing content you share on social media. You can withdraw consent at any time, without retroactive effect.

4. Data Recipients (Sub-processors) Your data may be communicated, only to the extent necessary, to the following sub-processors, who act on behalf of Dr Padel Racket and are bound by confidentiality and security obligations: Shopify Inc. - e-commerce platform that hosts the website. EasyPay - Payment Institution, S.A. - payment processing. Eupago - Payment Institution, Lda. - payment processing. PayPal (Europe) S.à r.l. et Cie, S.C.A. - payment processing. Carriers and logistics partners - order delivery, racket collection and return. Email and marketing service providers - sending transactional notifications and, with consent, newsletters. Meta Platforms, Inc. and Google LLC - analytics and advertising (with cookie consent). MiniExtensions - platform used in the Customer Portal. Public authorities - when required by law (Tax Authority, courts, etc.).

5. International Data Transfers Some sub-processors (Shopify, Meta, Google) may process data on servers outside the European Economic Area, specifically in the United States. In these cases, we ensure that transfers are carried out under appropriate safeguards, such as Standard Contractual Clauses approved by the European Commission or certifications under the EU-US Data Privacy Framework.

6. Retention Periods Order and billing data: 10 years, due to tax requirements (Art. 123(4) of the Corporate Income Tax Code). Customer account data: until the account is closed or 3 years of inactivity. Direct marketing data: until consent is withdrawn or 3 years after the last interaction. Browsing data (cookies): as indicated in the cookie policy, with a maximum of 24 months. Email communications: 3 years after the last contact, unless associated with an order.

7. Minors Our services are not intended for minors under 16 years of age. The use of the website or the purchase of products by minors is only permitted with the express authorization of parents, guardians, or legal representatives. Dr Padel Racket may, at any time, request proof of such authorization.

8. Your Rights Under the GDPR, you have the following rights: Access: to know what data we process about you. Rectification: to request correction of incorrect or outdated data. Erasure: to request the deletion of your data, except for legal retention obligations. Restriction: to request temporary suspension of processing. Objection: to object to processing based on legitimate interest or direct marketing. Portability: to receive your data in a structured format and transmit it to another controller. Withdrawal of consent: at any time, without retroactive effect. To exercise these rights, send an email to info@drpadelracket.com, identifying yourself and indicating the right you wish to exercise. We will respond within a maximum of 30 days.

9. Complaints If you believe that the processing of your data violates the law, you have the right to complain to the supervisory authority: Comissão Nacional de Proteção de Dados (CNPD) Av. D. Carlos I, 134, 1.º, 1200-651 Lisbon Telephone: +351 213 928 400 Email: geral@cnpd.pt Website: www.cnpd.pt

10. Security Dr Padel Racket applies appropriate technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction: HTTPS protocol, encryption, access control, and team training. However, no internet transmission is completely secure. We recommend that you keep your credentials confidential and immediately notify us of any suspected unauthorized access.

11. Cookies The website uses cookies to ensure proper functioning, personalize the experience, analyze traffic, and support marketing actions. You can manage cookie preferences at any time through the banner provided on the website.

12. Changes Dr Padel Racket may update this Policy. Changes will be published on this page, with an indication of the date of the last update.