Privacy Policy and Personal Data Protection

  • 1. Introduction and Identity of the Controller

    PluriBrands (MultiGoods Unipessoal, Lda.) attaches the utmost importance to the protection of the privacy and personal data of its Customers, partners, and Platform users. This Privacy Policy describes in a comprehensive, transparent, and accessible manner how PluriBrands collects, uses, stores, shares, and protects personal data, in strict compliance with the General Data Protection Regulation (GDPR – Regulation EU 2016/679) and national data protection legislation.


    The Data Controller is MultiGoods Unipessoal, Lda., with registered office at Rua Santa Marta n.º 118 - Pav. 1, 4750-189 Barcelos, Portugal, registered under VAT number PT513567097. For any questions related to the processing of your personal data, you may contact us via the dedicated email address: privacidade@pluribrands.com.


    PluriBrands has appointed a Data Protection Officer (DPO), whose duties include supervising GDPR compliance across all company operations. The DPO's contact information can be obtained upon request to privacidade@pluribrands.com.

  • 2. Categories of Personal Data Processed

    PluriBrands collects and processes the following categories of personal data, strictly necessary for the provision of its services:

    2.1. Identification and Contact Data
    • Full name;
    • Email address;
    • Telephone or mobile number;
    • Date of birth (mandatory upon registration, for verifying majority and the minimum legal age required for the acquisition of certain products);
    • Tax Identification Number (NIF/VAT), exclusively for the issuance of invoices.

    2.2. Address and Delivery Data
    • Full billing address;
    • Delivery address(es) registered in the account;
    • Country of residence and postal code.

    2.3. Transaction and Commercial History Data
    • Record of orders placed, including products, quantities, and values;
    • History of returns and complaints;
    • Product preferences and interest categories inferred from purchasing behavior;
    • Vouchers, credits, and benefits accumulated in the loyalty program.

    2.4. Financial Data
    • Last 4 digits of the payment card (to identify the method used);
    • Preferred payment method;
    • Note: full payment data is not stored by PluriBrands – it is processed by PCI DSS certified payment platforms.

    2.5. Browsing and Technical Data
    • IP address and approximate geolocation;
    • Device type, operating system, and browser used;
    • Pages visited, session duration, and interactions on the Platform;
    • Cookie data as described in the Cookie Policy;
    • Error logs and technical performance reports.

    2.6. Communication Data
    • Content of communications exchanged with Customer Support;
    • Reviews, comments, and product ratings voluntarily submitted;
    • Marketing communication preferences (newsletter consent, promotion alerts).
  • 3. Purposes and Legal Bases for Processing

    The processing of personal data by PluriBrands is based on legitimate legal grounds, identified for each specific purpose as required by Article 13 of the GDPR:


    3.1. Performance of a Contract (Article 6(1)(b) GDPR)
    Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract. This basis legitimizes:

    • Processing of orders, payments, and deliveries;
    • Management of returns, exchanges, and refunds;
    • Creation and management of user accounts;
    • Sending order confirmations, invoices, and delivery updates.


    3.2. Compliance with Legal Obligations (Article 6(1)(c) GDPR)

    • Compliance with tax and accounting obligations (retention of invoices and financial documents for 10 years, in accordance with the Portuguese Tax Code);
    • Responding to regulatory obligations and requests from competent authorities;
    • Prevention and detection of fraud in compliance with anti-money laundering standards.
    • Customer age verification, via the date of birth collected upon registration, to comply with legal obligations regarding the sale of age-restricted products, namely alcoholic beverages, the acquisition of which PluriBrands restricts to individuals over 18 years of age in all markets where it operates.


    3.3. Legitimate Interests of PluriBrands (Article 6(1)(f) GDPR)

    • Continuous improvement of the Platform and services through browsing data analysis (with minimal impact on the data subject's privacy);
    • Personalization of the shopping experience based on Customer history (limited to what is essential for the service);
    • Detection and prevention of fraud, abuse, and security breaches;
    • Statistical and performance analysis for logistical optimization.


    3.4. Explicit Consent (Article 6(1)(a) GDPR)

    • Sending commercial communications (newsletters, promotions, new product alerts);
    • Use of non-essential personalization and advertising cookies (as per the Cookie Policy);
    • Participation in satisfaction surveys and customer experience analysis programs.
  • 4. Data Retention Period

    Personal data is kept for the period strictly necessary to fulfill the purposes for which it was collected, in compliance with the following criteria:

    • Active account data: while the account remains active, plus a period of 2 years after the last recorded activity;
    • Transaction data (invoices and accounting records): 10 years, in compliance with Portuguese tax obligations;
    • Customer Support communication data: 3 years after the matter is closed;
    • Browsing data and cookies: as indicated in the Cookie Policy (usually between 30 days and 2 years);
    • Data for marketing purposes (consent): until consent is withdrawn or for a maximum of 3 years without commercial activity;
    • Fraud prevention data: up to 5 years after the last suspicious occurrence.
    • Date of birth: retained while the account remains active, as it is necessary for age verification on every purchase of age-restricted products. This data is used exclusively for this purpose. 
  • 5. Recipients and Processors

    PluriBrands may share personal data with third parties under the conditions and for the purposes described below, always ensuring that recipients provide sufficient guarantees of GDPR compliance:

    • Carriers and Logistics Operators: recipient's name, address, and contact details, strictly necessary for order delivery;
    • Payment Platforms: data necessary for the secure processing of the financial transaction (never including full card details);
    • Technology Service Providers: cloud infrastructure providers, transactional email services, CRM, and data analysis platforms, bound by GDPR-compliant data processing agreements (Article 28);
    • Public Authorities: whenever required by law, court order, or a competent regulatory authority;
    • Marketing Partners: only with the Customer's explicit consent and limited to the data necessary for the consented purpose.


    PluriBrands does not sell, rent, or make personal data available to third parties for their own commercial purposes without the data subject's explicit consent.

  • 6. International Data Transfers

    Some of PluriBrands' processors and technological partners may be located outside the European Economic Area (EEA). In such cases, PluriBrands ensures that transfers are carried out based on legally recognized transfer mechanisms, namely:

    • Adequacy Decisions by the European Commission for countries with a level of protection equivalent to the EEA;
    • Standard Contractual Clauses (SCC) adopted by the European Commission;
    • Binding Corporate Rules (BCR) for multinational business groups.


    The data subject may request information about specific transfers and the mechanisms used via privacidade@pluribrands.com.

  • 7. Data Subject Rights

    Under the GDPR, the personal data subject benefits from the following rights, exercisable at any time with PluriBrands:

    • Right of Access (Article 15 GDPR): the right to obtain confirmation as to whether or not their data is being processed and, if so, to access it and information about the processing;
    • Right to Rectification (Article 16 GDPR): the right to obtain the correction of inaccurate or incomplete data;
    • Right to Erasure / Right to be Forgotten (Article 17 GDPR): the right to request the deletion of their data when it is no longer necessary for the purpose for which it was collected, or when the subject withdraws consent (without prejudice to legal retention obligations);
    • Right to Restriction of Processing (Article 18 GDPR): the right to request the suspension of processing in specific circumstances, namely during the verification of data accuracy or the assessment of an objection;
    • Right to Data Portability (Article 20 GDPR): the right to receive their data in a structured, machine-readable format and to transmit it to another controller;
    • Right to Object (Article 21 GDPR): the right to object to processing based on legitimate interests or for direct marketing purposes;
    • Right not to be subject to Automated Decision-Making (Article 22 GDPR): the right not to be subject to decisions based solely on automated processing, except in the cases provided for by law.


    To exercise any of the rights described above, the subject must send a written request to privacidade@pluribrands.com, accompanied by an identification document. PluriBrands will respond within a maximum of 30 days (extendable by a further 60 days in cases of special complexity, with notification to the subject).


    If the subject considers that the processing of their data violates the GDPR, they have the right to lodge a complaint with the National Data Protection Commission (CNPD – www.cnpd.pt) or the competent supervisory authority of their Member State of residence.

  • 8. Data Security

    PluriBrands implements appropriate technical and organizational measures to ensure a level of personal data security appropriate to the risk, in compliance with Article 32 of the GDPR. These measures include:

    • Data encryption in transit (TLS 1.3 protocol) and at rest (AES-256);
    • Access control based on the principle of least privilege;
    • Two-factor authentication (2FA) for access to internal systems;
    • Security audits and penetration testing conducted by independent external entities;
    • Security Incident Response Plan (SIRP), including notification to the CNPD within 72 hours in the event of a data breach posing a risk to data subjects;
    • Regular training for employees on data protection and cybersecurity.
  • 9. Changes to the Privacy Policy

    This Privacy Policy may be updated periodically to reflect legislative changes, shifts in internal processes, or the introduction of new services. The last revision date is indicated in the document header. Substantial changes will be communicated to the Customer via email with 30 days' notice.