1. Data controller
The controller of your personal data is [Razão social da empresa Ltda.], CNPJ [CNPJ], registered at [Endereço completo], Rio de Janeiro - RJ, Brasil, operating under the OPO Rio brand.
Data protection officer and privacy contact: geral@opotransfer.eu · +351 920 226 818.
2. Data we collect
- Booking form: name, phone number (with country code), pickup location, destination, date and time, number of passengers and luggage.
- Contact form: name, email, phone, subject and message.
- WhatsApp, email or phone: any data you send us directly (for example, flight number).
- Browsing data: technical and statistical information collected through cookies, as described in our Cookie policy.
We do not ask for sensitive personal data. Please do not include it in your messages.
3. Purposes and legal bases
- Handling your request and booking (quote, confirmation, contact with the driver) — performance of a contract and preliminary steps (Art. 7, V, LGPD).
- Answering messages — preliminary steps and legitimate interest (Art. 7, V and IX).
- Complying with legal and tax obligations (Art. 7, II).
- Statistics and website improvement through non-essential cookies — consent (Art. 7, I), which you may revoke at any time.
We do not sell your data.
5. How long we keep it
- Booking and contact requests: for as long as needed to handle the request and provide the service, and up to 2 years afterwards to deal with any complaints.
- Tax documents: for the period required by law.
On the confirmation page, your booking details are temporarily stored in your browser (sessionStorage) to prepare the WhatsApp message, and deleted when you close the tab.
6. Your rights
Under Art. 18 of the LGPD, you may request: confirmation of processing, access, correction, anonymisation, blocking or deletion, portability, information about sharing and revocation of consent.
To exercise your rights, write to geral@opotransfer.eu. You may also petition Brazil's National Data Protection Authority (ANPD) — www.gov.br/anpd.
7. Security
We use technical and administrative measures to protect your data against unauthorised access, loss or misuse.
8. Changes
We may update this policy. The date of the last update is shown at the top of this page.