LMH

Legal

Privacy Policy

Last updated: 17 September 2026

Article 1 — Data controller

The controller of the personal data collected through this website (lmh.pt) is LMH – Consultoria Estratégica, Projectos Integrados e Governança Corporativa, Lda, with registered office at Rua do Oriente, 1C, 2830-500 Palhais, Barreiro, and an office at Avenida do Brasil 1 (Centro de Escritórios Campo Grande), 1700-062 Lisbon. Data protection contacts: luismiguelhenrique@lmh.pt · +351 910 892 838. No Data Protection Officer (DPO) has been appointed, as the conditions of Article 37 GDPR are not met.

Article 2 — Applicable law

The processing of personal data is governed by Regulation (EU) 2016/679 (GDPR), Portuguese Law no. 58/2019, Law no. 41/2004 and other applicable legislation.

Article 3 — Personal data collected

This website is a static institutional page: it has no contact form, no restricted area and no mechanism for collecting data directly. Contact is made through the email address and telephone number shown on the site. The data you send us that way — name, email address and the content of the message, plus whatever else you choose to include — is processed under this policy.

For technical and security reasons, the site's hosting generates access logs that may include the IP address, the date and time of the request and the browser type. This website does not create user accounts or collect passwords, does not collect payment data, does not process special categories of data (Article 9 GDPR) and uses no analytics or audience measurement tools.

Article 4 — Purposes and legal bases

The data you send us by email or telephone is processed to respond to the enquiry and assess a possible request, including a prior check for conflicts of interest, on the following legal bases:

  • Responding to enquiries and requests — legitimate interest in responding to enquiries of a professional nature (Article 6(1)(f) GDPR) and, where the enquiry concerns engaging our services, steps taken at the data subject's request prior to entering into a contract (Article 6(1)(b)).
  • Access logs generated by the hosting provider — legitimate interest in security, stability and the prevention of abuse (Article 6(1)(f)).

Article 5 — Retention period

Messages you send us are retained for as long as necessary to respond and, at most, for 24 months, after which they are deleted, unless a professional relationship or legal obligation justifies longer retention. Access logs generated by the hosting provider are retained for the period set by that provider for security and technical diagnostic purposes.

Article 6 — Processors and international transfers

As no data is collected directly through the site, we use no processors for data submitted by users. The following third parties are nonetheless involved in delivering the site:

  • Hosting provider — delivery of the pages and generation of the technical access logs referred to in Article 3.
  • Google (Google Ireland Limited) — supply of the typefaces used on the site, loaded from the domains fonts.googleapis.com and fonts.gstatic.com. When any page opens, the browser connects to those servers, which involves transmitting the visitor's IP address to Google (see Cookie Policy).

These providers may process data outside the European Economic Area; in such cases, transfers rely on appropriate safeguards under Chapter V GDPR (namely standard contractual clauses or adequacy decisions, such as the EU-US Data Privacy Framework). The adequacy of these mechanisms should be confirmed as at the date of publication.

Article 7 — Rights of the data subject

Under the GDPR, the data subject has the right to: access (Article 15); rectification (16); erasure (17); restriction of processing (18); portability (20); objection (21); and to withdraw consent at any time (7(3)), without affecting the lawfulness of processing carried out beforehand.

Exercising these rights is free of charge and may be requested at luismiguelhenrique@lmh.pt. The data subject is also entitled to lodge a complaint with the Portuguese Data Protection Authority (CNPD — Av. D. Carlos I, 134, 1.º, 1200-651 Lisbon; geral@cnpd.pt), without prejudice to judicial remedies.

Article 8 — Security

We adopt technical and organisational measures appropriate to the protection of personal data (Article 32 GDPR), including encryption of communications in transit (HTTPS/TLS) and restricted access to the messages received.

Article 9 — Cookies

The use of cookies and local storage technologies is described in the Cookie Policy, which forms an integral part of this policy.

Article 10 — Changes

This policy may be updated. The version in force is the one published on this page, with the date of the last update.