1. Introduction
This Privacy Policy describes how DIAF – Venda de Produtos e Serviços Online, Lda ("DIAF", "we", "our") collects, uses, stores, and protects personal and operational data processed through the Orditio.com platform ("Platform"). DIAF complies with the General Data Protection Regulation (GDPR) and other applicable legislation in Portugal and the European Union.
2. Data Controller
DIAF – Venda de Produtos e Serviços Online, Lda
Portuguese company registered and operating in accordance with Portuguese law.
support@orditio.com
3. Types of Data Collected
The Platform collects only the data necessary for its operation.
3.1. Account and Identification Data
- Company name
- User name and email
- Password (encrypted)
- Billing information
- Account preferences and settings
3.2. Operational Data from Integrations
The Platform integrates with suppliers and e-commerce platforms to collect operational data, including:
- Order data (ID, date, products, quantities, values, discounts)
- Logistics costs, fees, commissions, and processing costs
- Billing data associated with orders
- Operational and logistics performance information
- Inventory data, when applicable
3.3. Technical Data
- IP address
- Device type and browser
- Usage logs
- Performance data and internal metrics
3.4. Derived Data
- Profitability indicators
- Dashboards and reports
- Aggregated metrics and statistical analyses
4. Purpose of Processing
- Platform operation
- Profitability calculation per order and period
- Generation of reports and dashboards
- Automatic integration with external platforms
- Account management and customer support
- Continuous service improvement
- Compliance with legal obligations
5. Legal Basis
- Contract execution
- Legitimate interest
- Compliance with legal obligations
- Consent, when applicable
6. Data Sharing
Data may be shared with:
- Technology service providers (hosting, databases, security)
- Integrated e-commerce platforms, as authorized by the customer
- Legal authorities, when required
We never sell personal data.
7. International Transfers
If data transfer outside the EU occurs, Standard Contractual Clauses or equivalent mechanisms will be applied.
8. Security
- Data encryption in transit and at rest
- Firewalls and continuous monitoring
- Access control and enhanced authentication
- Regular backups
- Internal security audits
9. Data Retention
Data is retained while the account is active and up to 12 months after contract termination, unless otherwise required by law.
10. Your Rights
- Access
- Rectification
- Erasure
- Data portability
- Restriction or objection
11. Cookies
The Platform uses technical and analytical cookies. A detailed policy will be made available separately.
12. Changes
DIAF may update this policy. The most recent version will always be available at Orditio.com.
Last Updated: April 2026