Legal notice & privacy
This website is built to collect as little personal data as possible. This page names who is responsible for it and explains exactly what happens with the data that does reach us. Last updated: September 2026.
Privacy policy
Controller
The controller within the meaning of the GDPR is Angelo Daniel da Silva Joao, trading as tanomedia, Rua Vale de Cubas 7, 3100-373 Pombal, Portugal, hello@tanomedia.com. We have not appointed a data protection officer because we are not legally required to.
Hosting and server logs
This website is hosted by Hostinger International Ltd. (Larnaca, Cyprus, EU) in a data centre in the EU; we have concluded a data processing agreement with Hostinger (Art. 28 GDPR). When you visit, the web server automatically processes connection data — IP address, date and time of the request, requested resource, browser and operating system, referring URL — in server logs. This is technically necessary to deliver the site securely and reliably and to detect misuse (legitimate interest, Art. 6(1)(f) GDPR). Log data is kept for a short period for security purposes and then deleted; it is not merged with other data.
Contact form and direct enquiries
If you use the contact form, we process the details you enter. First name, email address, the service you are interested in and your message are required (marked with *) — without them we cannot answer your enquiry. Last name, phone number and company are optional. The form also transmits the language and path of the page you send it from, the time of submission, the version of the privacy notice shown next to the form and, if available, the campaign attribution described below.
We use this data to answer your enquiry and, where relevant, to prepare an offer (Art. 6(1)(b) GDPR — steps taken at your request prior to entering into a contract). If you contact us on behalf of a company, we process your details as its contact person on the basis of Art. 6(1)(f) GDPR; our legitimate interest is answering business enquiries and the pre-contractual communication that follows.
How your enquiry travels: it is sent over an encrypted connection (TLS) to a script on our web host (Hostinger) and stored there only in encrypted form. Our CRM — software we operate ourselves on a virtual server rented from Contabo GmbH (Munich, Germany) in a data centre in Germany — retrieves these encrypted enquiries, usually within a few minutes, decrypts them and then deletes them from the web host. The server is not publicly reachable from the internet, only through our own private, encrypted network. Contabo processes the data only on our behalf, under a data processing agreement (Art. 28 GDPR). Enquiries that have not been retrieved are deleted from the web host after 30 days at the latest. The host's backup copies of these encrypted files are kept for up to 6 weeks; until they expire, they may still contain an encrypted copy of your enquiry and the short-lived hashes of IP addresses and newsletter email addresses described below.
To protect the forms against spam and abuse, the web host counts attempts using a keyed, short-lived hash of your IP address (for IPv6, of its network prefix) — never the address itself — and deletes it after 48 hours at the latest (Art. 6(1)(f) GDPR; our legitimate interest is keeping the forms secure and usable).
The data of your enquiry stays in our CRM for as long as we need it to handle your enquiry and a possible business relationship arising from it. We review older enquiries regularly, at least once a year, and archive those that are no longer relevant. Archived contacts are deleted automatically 12 months after the last activity on them, unless a business relationship has developed — that is, a contract or a project exists or an offer has been accepted — or statutory retention obligations apply. Offers that are still open, were declined or have expired, and past appointment bookings do not prevent this deletion. If a contract follows, the data becomes part of the contract file and is kept for the statutory retention periods. If we record an enquiry you make by phone, email or WhatsApp in our CRM, that entry is treated the same way. The messages themselves in our mailbox (Proton) and in WhatsApp are not deleted automatically: we review them at least once a year and delete those we no longer need to handle the enquiry or a business relationship, unless statutory retention obligations apply. You can ask us to delete your data at any time (Art. 17 GDPR); we will then erase it unless a statutory obligation requires us to keep it.
We use Proton (Proton AG, Switzerland) for our email. If you write to us by email, or we answer your enquiry by email, the messages are stored there. The European Commission has recognised that Switzerland provides an adequate level of data protection (adequacy decision, Art. 45 GDPR). Purpose and legal basis are the same as for enquiries sent through the contact form; how long we keep your messages is explained in the contact form section.
Newsletter
If you subscribe to our monthly newsletter, we process your email address, the language of the page and the time of your sign-up. The legal basis is your consent (Art. 6(1)(a) GDPR), which you give by ticking the separate checkbox in the form. We use the double opt-in procedure: you first receive an email asking you to confirm, and your address is only added to the mailing list once you click the confirmation link. Your sign-up reaches our CRM the same encrypted way as a contact enquiry (see above); to prevent repeated sign-ups, the web host keeps a keyed hash of the email address for up to 48 hours (backup copies at the host: up to 6 weeks).
We send the newsletter via Brevo, a service of Sendinblue SAS, Paris, France. Brevo processes your data on our behalf under a data processing agreement (Art. 28 GDPR) and hosts it in the EU. Some of Brevo's sub-processors are located outside the EU; for these transfers Brevo relies on the EU Standard Contractual Clauses or the EU-US Data Privacy Framework.
Our newsletters contain no per-recipient open or click tracking: we do not record whether you open an email or which links you click.
At Brevo we store your email address together with the language, the time of your sign-up and of your confirmation, the version of the consent text you agreed to and the source of the sign-up (the form on our website). This lets us send you the newsletter in your language and prove your consent (Art. 7(1) GDPR).
Your address stays on the mailing list until you unsubscribe. You can withdraw your consent at any time with effect for the future, using the unsubscribe link in every newsletter or by emailing hello@tanomedia.com. After that, your address remains only on Brevo's block list, so that no further newsletters are sent to it (Art. 6(1)(c) and (f) GDPR; our legitimate interest is making sure your unsubscription is respected for good).
If you do not confirm your sign-up, Brevo does not add your address to the mailing list and you will not receive any newsletter. We cannot promise how long Brevo keeps an unconfirmed sign-up; if you would like it deleted straight away, just write to us.
The WhatsApp button opens a chat with us in the WhatsApp app or web client, which is operated by Meta Platforms Ireland Limited. No data is transmitted to Meta by merely displaying the button — only when you click it and start a chat. From that moment, WhatsApp's privacy policy applies. We use the content of the conversation to answer your enquiry and, where relevant, to prepare an offer; purpose and legal basis are the same as for enquiries sent through the contact form, and how long we keep your messages is explained in the contact form section.
Cookies and local storage
This website sets no cookies and embeds no third-party tracking. Your browser stores your light/dark theme preference (localStorage), and only once you switch it, plus your decision about the reach measurement described below — and, if you agree to it, its identifier. Nothing of this leaves your device except that identifier. When you start filling in a form, your browser also fetches a short-lived form token from our server that protects the forms against spam; it contains no information about you, is kept only in the open page and can be used only once. Basic reach measurement stores nothing in your browser; we only ask you beforehand for recognition through an identifier. If you turn measurement off for your device entirely, your browser remembers that too (key _tano_ignore). Everything else on this site works regardless of your decision.
Reach measurement
We measure how this website is used, to understand which content is read and through which channels visitors arrive, and to improve the site. The measurement has two levels: basic measurement, which stores nothing on your device and runs without consent, and recognition across visits, which only happens with your consent. Both run on our own software on our own server — no analytics provider, no third party.
Basic measurement records: the page view with its path and page title, the address of the page including campaign parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term), the referring website (its address and host name, if you came from outside), the visible time on page and the scroll depth per page, clicks on outbound links, file downloads and clicks on email and phone links, goals reached (conversions), device type, browser and operating system, screen size, your browser language and the country — plus region and city where they can be determined.
Basic measurement stores nothing on your device and reads nothing from it; the measurement script works without any identifier. Your IP address is only processed in memory while the request is handled: to limit the number of requests, to determine the country and to build a daily rotating hash value that tells you apart from other visitors within one day — the next day that value is a different one, so it cannot recognise you across days. The IP address is not stored. The country is determined from a local GeoLite2 database on our own server — no external service is asked.
The legal basis for basic measurement is our legitimate interest (Art. 6(1)(f) GDPR) in measuring the reach of our own website — with a data-minimising tool that we run ourselves, that belongs to us alone (first party), builds no profiles across websites and stores no IP address. You can object to this processing at any time (Art. 21 GDPR): with the button “Turn measurement off for this device entirely” below this section, or by informal email to hello@tanomedia.com. We do not need your consent for basic measurement under Art. 5(3) of the ePrivacy Directive (Art. 5 of Law no. 41/2004 in Portugal, § 25 TTDSG in Germany), because nothing is stored on your device and nothing is read from it.
Recognition across visits: only if you choose “Accept” in the banner does the script store a random identifier in your browser (localStorage, key _tano_vid) and send it with every event, so that we recognise you as a returning visitor on a later day. The legal basis is your consent (Art. 6(1)(a) GDPR; for storing and reading the identifier also Art. 5(3) of the ePrivacy Directive as implemented in Portugal, and § 25(1) TTDSG for visitors in Germany). The identifier holds no information about you, applies to this website only and stays until you withdraw your consent or clear your browser storage. If you choose “Decline”, only basic measurement runs. Your decision itself is stored together with its version and the time in the key tano-consent; we ask again when the text changes, and after twelve months at the latest.
We use no analytics provider. The measurement runs on our own software on a virtual server we rent from Contabo GmbH (Munich, Germany) in a data centre in Germany. Contabo processes the data solely on our behalf under a data processing agreement (Art. 28 GDPR). There is no transfer to a country outside the EU, the data is not passed on to third parties and it is not combined with data from other websites.
The measurement data is held in our CRM on the server named above. There is no fixed deletion period for it so far: it stays for as long as we evaluate the reach of this website, and if we delete the website in our CRM, all measurement data belonging to it is deleted with it. A link to a person beyond a single day only exists through the identifier described above — your name, email address or other details from the contact form are not connected to the measurement data of this website.
Withdrawing, objecting, switching off: you can withdraw your consent to recognition at any time with effect for the future — through “Analytics” in the footer of every page or with “Turn recognition off” below this section. The identifier _tano_vid is then removed from your browser immediately; basic measurement keeps running, and the lawfulness of the processing carried out until then is unaffected. If you do not want basic measurement either, choose “Turn measurement off for this device entirely”: the key _tano_ignore is then set in your browser, the measurement script is no longer loaded on this device and nothing is counted any more — until you turn it back on there or clear your browser storage. If your browser sends a Global Privacy Control signal or “Do Not Track”, recognition stays off from the outset and we do not show you the banner at all; basic measurement, which stores nothing on your device, runs even then.
Campaign attribution
When you send the contact form, it also transmits how you reached the page you send it from — and only this: the campaign parameters utm_source, utm_medium and utm_campaign in that page's address (if present), the page's path (without any further address parameters) and, if you came to that page from another website, that website's host name (for example “example.com”, never the full address). None of this is stored in your browser, and other parameters such as ad click IDs are neither read nor sent. The information is transmitted only together with a contact enquiry you choose to send, so that we know how it came about (Art. 6(1)(f) GDPR; our legitimate interest is understanding which channels lead to enquiries). There is no profiling, no recognition across websites and no sharing with third parties. If the page has no campaign parameters and you did not come to it from another website, no attribution is sent.
Fonts, links and embedded content
All fonts (Inter, Space Grotesk, Instrument Serif, JetBrains Mono) are hosted on our own server — your browser does not contact Google or any other font provider. Links to Instagram, LinkedIn, Facebook, Hostinger and to client websites are plain links: nothing is loaded from these providers until you click, and their own privacy policies apply once you do.
Data security
All data is transmitted over an encrypted HTTPS connection (TLS). Form submissions are stored on the web host only in encrypted form (AES-256-GCM with a separate key for each submission, which is itself encrypted with RSA); the private key needed to decrypt them exists only in our CRM, not on the web host. Access to the systems that receive your data is restricted to us and protected by strong authentication.
Your rights
Under the GDPR you have the right to access the personal data we hold about you (Art. 15), to have it corrected (Art. 16) or erased (Art. 17), to restrict its processing (Art. 18), to data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). Where processing is based on consent, you can withdraw it at any time with effect for the future. Just write to hello@tanomedia.com.
You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the Comissão Nacional de Proteção de Dados (CNPD), Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, Portugal, cnpd.pt. You may also contact the supervisory authority of your own EU member state.
Right to object (Art. 21 GDPR)
Where we process your data on the basis of legitimate interests (Art. 6(1)(f) GDPR) — for enquiries on behalf of a company, abuse protection for the forms, server logs, basic reach measurement and campaign attribution — you have the right to object to this processing at any time on grounds relating to your particular situation. We will then no longer process the data for these purposes unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. Where data is processed for direct marketing, you can object at any time without giving reasons. An informal email to hello@tanomedia.com is enough.
Changes
We update this policy whenever the website or our processes change. The current version always applies; the date of the last revision is shown at the top of this page.
Legal notice
Provider: tanomedia — Angelo Daniel da Silva Joao (sole trader), Rua Vale de Cubas 7, 3100-373 Pombal, Portugal.
Contact: hello@tanomedia.com · +351 916 491 371
Tax identification number (NIF): 277687411 · VAT ID: PT277687411
Responsible for editorial content (including the Insights articles): Angelo Daniel da Silva Joao, address as above.
Consumer disputes: we are neither obliged nor willing to take part in dispute resolution proceedings before a consumer arbitration board. Consumers in Portugal can find the competent alternative dispute resolution entities at consumidor.gov.pt. Electronic complaints book: livroreclamacoes.pt.
All content, design and code on this website are © tanomedia unless stated otherwise. Client work shown in case studies remains the property of the respective clients. External links are provided in good faith; we are not responsible for the content of linked third-party websites.