Privacy Policy
Last update: 21-04-2025
INSYGMA Nutrition, operated by PRIMARSEC TRANSFORMADORES LDA (“INSYGMA”, “we”, “our”), is committed to protecting your privacy. This Policy explains how we collect, use, share and protect your personal data when you interact with our website. https://insygma.com, services, campaigns and communications.
1. Data controller
- Company: PRIMARSEC TRANSFORMERS LDA
- VAT Number: 508601436
- Address: 4700-793 Braga, Portugal
- E-mail: [email protected]
- Phone: +351 935 217 494
2. What data do we collect?
We collect data in three categories:
a) Data provided directly by you:
- Name, email, address, phone number
- Payment information (processed via Stripe, Klarna, etc.)
- Order details, purchase history, returns
- Marketing preferences
- Submitted content (reviews, messages, forms)
b) Data collected automatically and technically:
- IP address, browser type, operating system, device type
- Interactions with the website (pages visited, clicks, browsing time)
- Source reference (e.g. advertising campaigns)
- Pseudonymized technical identifiers
- Data collected by indirect measurement operational technologies
c) Sensitive data:
We do not collect, store or infer any data considered sensitive under the GDPR (e.g. health, diagnoses, clinical conditions).
3. How do we use your data?
- Process orders, payments and deliveries
- Manage your account and purchase history
- Send transactional and support communications
- Communicate campaigns and offers based on your consent
- Analyze campaign performance and browsing behavior
- Maintaining platform security and preventing fraud
- Fulfil legal and tax obligations
4. Legal basis for processing
- Contract execution: orders, billing and deliveries
- Consent: marketing communications, cookies
- Legal obligation: tax data, GDPR compliance
- Legitimate interest: security, fraud prevention, performance measurement, essential technical operation
5. Sharing data with third parties
We only share data with entities essential to our services:
- Payment platforms (e.g. Stripe, Klarna)
- Carriers and logistics operators
- Email and automation tools (e.g. Omnisend)
- Analytics and advertising platforms (e.g. Meta, Google Ads)
- Legal and regulatory authorities, when required
We do not sell your data. All sharing is protected by data processing agreements and appropriate contractual clauses.
6. International transfers
Some of our providers operate outside the European Union. In these cases, we ensure appropriate protection mechanisms, such as Standard Contractual Clauses approved by the European Commission.
7. Cookies and Technical Measurement Technologies
We use cookies and additional measurement technologies to:
- Ensure essential website functionality
- Analyze navigation patterns in an aggregated way
- Present relevant promotions
- Maintaining the technical security of the platform
You can manage your cookie preferences through the banner displayed on the website or on the Cookie Policy. Some operational technologies may continue to collect minimal technical data, even after you refuse cookies, exclusively for statistical purposes and to protect the infrastructure.
8. Data retention
- For as long as necessary for the purposes described in this policy
- During mandatory legal deadlines (e.g. 10 years for tax data)
- Until you request the deletion of your data, where applicable
9. Your rights
You may, at any time and under the terms of the GDPR:
- Request access to your data
- Correct or update data
- Request deletion ("right to be forgotten")
- Request data portability
- Object to processing based on legitimate interest
- Withdraw consent (e.g. email marketing)
To exercise your rights, send an email to [email protected].
If you consider that the processing of your data violates the GDPR, you can file a complaint with National Data Protection Commission (CNPD).
10. Security of your data
We apply technical and organizational measures to protect personal data against loss, unauthorized access, misuse or alteration. INSYGMA operates with principles of minimization, pseudonymization and segregation of access whenever possible. Use of the website is at your own risk.
11. Privacy of minors
We do not knowingly collect data from anyone under the age of 16. If you detect any violation, please contact us to delete the data immediately.
12. External links
Our website may contain links to third-party websites. We are not responsible for the policies or practices of these websites. We recommend that you always read their privacy policies.
13. Updates to this Policy
We may update this policy at any time. Relevant changes will be communicated on the website or by email. The most recent version is always available at /privacy-policy.
14. Contacts
For any question or exercise of rights: