Privacy Policy
WeNou respects the privacy of everyone who visits this website, writes to us or asks us for an analysis. This page explains what personal data we handle, why we handle it, on what legal basis, and what you can ask us to do about it. It is written to meet Regulation (EU) 2016/679 (the General Data Protection Regulation) and Portuguese Law no. 58/2019.
1. Who is responsible for your data
The controller is WeNou, an independent laboratory based in Lisbon, created in May 2019, which provides DNA-based analytical services to the food, feed, environmental and veterinary sectors.
WeNou Office — Ed. Incubadora da Universidade de Lisboa, Avenida Professor Gama Pinto, 2, 1649-003 Lisboa, Portugal. Phone: +351 217 904 700, extension 34335.
WeNou Lab — Estrada do Paço do Lumiar, Campus do Lumiar, Ed. F, 1649-038 Lisboa, Portugal. Phone: +351 215 999 538.
For anything to do with this policy or with your personal data, write to [email protected], telephone either number above, or send a letter to the office address. Your message reaches the people who can actually deal with it.
2. What we handle, and how it reaches us
This website has no contact form, no registration area, no shop and no comment section. It does not ask you for personal data and it does not build a profile of you as you read it.
We handle personal data when you choose to send it to us — by e-mail, by telephone, or in the course of work we do for you. In practice that means:
- your name, and the organisation you are writing on behalf of;
- your e-mail address and telephone number;
- whatever you put in your message, including what you tell us about the analysis you need;
- for work we carry out, the information that comes with a quotation request or a sample — typically the contact person for the job and the references used to identify the samples;
- the correspondence, quotations, reports and invoices that the work generates.
Please do not send us health information or any other special category of data (Article 9 of the GDPR) that we have not asked for. Our analyses are performed on food, feed, environmental and veterinary samples, not on people, so there is normally no reason for us to receive data of that kind. If a project ever does require it, we will agree in writing with you beforehand what may be sent and how it will be protected.
3. Why we handle it, and on what legal basis
We use personal data only for the purposes below, and each purpose has a legal basis under Article 6 of the GDPR:
- To answer your enquiry and prepare a quotation. Article 6(1)(b) — steps taken at your request before entering into a contract.
- To carry out the analytical service agreed and to issue the corresponding reports and invoices. Article 6(1)(b) — performance of the contract.
- To meet obligations the law places on us, including accounting and tax duties and the records our accredited activity has to keep. Article 6(1)(c) — compliance with a legal obligation.
- To send you information about our services, where you have asked us to. Article 6(1)(a) — your consent, which you can withdraw whenever you like.
- To keep our own record of the enquiries and projects we have handled, and to establish or defend a legal claim if one arises. Article 6(1)(f) — our legitimate interest, which we weigh against your rights and freedoms.
We do not use personal data to make automated decisions about you and we do not profile you.
4. Who else sees it
We do not sell personal data, rent it or exchange it.
It is shared only where sharing is necessary, and then only to the extent necessary: with the providers who keep our operation running, such as our e-mail and IT services and our administrative and accounting support, who act on our instructions and for no other purpose; with public authorities, accreditation bodies or supervisory bodies, where the law or the terms of our accreditation require it; and with our legal advisers, where we need to establish or defend a claim.
5. Transfers outside the European Economic Area
Our work is carried out in Portugal. Where a provider we depend on processes data outside the European Economic Area, we require the safeguards the GDPR demands for such transfers before the data goes anywhere. If you want to know whether any transfer affects data of yours, ask us at [email protected] and we will tell you.
6. How long we keep it
We keep personal data only for as long as the purpose it was collected for needs it.
Correspondence that does not lead to a contract is kept while the enquiry is live and for a reasonable period afterwards, so that we can pick the conversation up again if you come back to us. Records connected to a service we actually performed are kept for as long as our legal, accounting and accreditation obligations require — those periods are fixed by law and by the terms of our accreditation, not chosen by us. Once a record is no longer needed for any of those reasons it is deleted, or kept only in a form that no longer identifies anyone.
If you would like to know the period that applies to a particular record of yours, ask us and we will tell you what it is.
7. Your rights
Under the GDPR you may ask us to:
- confirm and give you access — tell you whether we hold personal data about you and, if we do, let you see it;
- rectify — correct anything inaccurate, and complete anything that is incomplete;
- erase — delete data where there is no longer a lawful reason for us to hold it;
- restrict — pause our use of it while a question about its accuracy or lawfulness is being settled;
- port — give you, or another controller you name, a copy in a structured, commonly used, machine-readable format, where the processing rests on your consent or on a contract and is carried out by automated means;
- object — stop processing that we base on our legitimate interest.
Where we rely on your consent you may withdraw it at any time, and withdrawing it is as easy as giving it — one e-mail is enough. Withdrawal does not make anything we did lawfully beforehand unlawful.
To exercise any of these rights, write to [email protected] or to the office address in section 1. We may first need to satisfy ourselves that you are who you say you are, so that we do not hand someone else's data to the wrong person. We answer within the time limit the GDPR sets, and we tell you if a request is going to take longer and why.
8. Complaints
If you think we have handled your personal data badly, please tell us first — we would far rather put it right. You also have the right, at any time and without asking us first, to complain to the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD).
9. Keeping it safe
We apply technical and organisational measures appropriate to the risk: access to systems and to the places where records are held is controlled and limited to the people who need it, and everyone who works with the data is bound to keep it confidential. If a breach ever occurs that is likely to put your rights at risk, we notify the CNPD and, where the law requires it, you.
10. Cookies
How this website uses cookies is set out separately, on our Cookies Policy page.
11. Changes to this policy
We update this page whenever our practice or the law changes. The version published here is the one that applies. Last updated: August 2026.
