FH-Signature Group (“we”, “us” or “our”) respects your privacy and is committed to protecting your personal data.

This Privacy Policy explains how we process personal data when you visit and use our website: https://fh-signature.com

We process personal data in accordance with applicable data protection legislation, in particular the EU General Data Protection Regulation (GDPR).

1. Controller

The controller responsible for the processing of personal data on this website is:

FH-Signature Group
Rua Luciano Cordeiro, 118 2 Dto.
1050-140 Lisbon
Portugal

Email: fauzia.haun@fh-signature.com

If you have any questions concerning the processing of your personal data or wish to exercise your data protection rights, you can contact us at the above email address.

 

2. Personal Data We Process

Depending on how you use our website, we may process the following categories of personal data:

  • name;
  • email address;
  • telephone number;
  • information contained in messages or enquiries submitted to us;
  • IP address and other technical information generated when accessing our website;
  • date and time of access;
  • requested pages or files;
  • browser and device information;
  • information required to protect the website against misuse, attacks and other security threats.

 

We only process personal data to the extent necessary for the purposes described in this Privacy Policy.

 

3. Visiting Our Website

When you visit our website, technical information may be processed automatically in order to provide, secure and maintain the website.

Depending on the hosting configuration, this may include:

  • the requested website or file;
  • date and time of access;
  • referring website;
  • browser type and version;
  • operating system;
  • device type;
  • IP address and other technical connection data;
  • technical information required to ensure the security and stability of the website.

 

Our website is hosted using services provided by IONOS.

IONOS processes technical access and connection data as necessary to provide, maintain and secure the hosting service. The applicable retention periods depend on the relevant IONOS service and contractual configuration.

The legal basis for this processing is Article 6(1)(f) GDPR, based on our legitimate interest in providing a secure, stable and technically functional website.

 

4. Contact Form

You can contact us using the contact form provided on our website.

When you submit the contact form, we process the information you provide, including:

  • your name;
  • your email address;
  • your telephone number;
  • the content of your message.

 

Technical information associated with the submission may also be processed for security and technical purposes.

The information is used exclusively to:

  • receive and process your enquiry;
  • communicate with you regarding your enquiry;
  • respond to your request; and
  • where applicable, take steps at your request prior to entering into a contractual relationship.

 

Where processing is necessary to respond to your request or to take steps at your request prior to entering into a contract, the legal basis is Article 6(1)(b) GDPR.

Where this legal basis does not apply, processing is based on Article 6(1)(f) GDPR, our legitimate interest in responding to enquiries and maintaining effective business communication.

The provision of the information marked as mandatory in the contact form is necessary to process your enquiry. If you do not provide the required information, we may not be able to respond to your request.

 

5. Storage of Contact Form Submissions

Contact form submissions are not stored as Elementor form submissions in the WordPress database.

The form is configured to transmit the submitted information by email rather than retain the submission as a separate database record within Elementor.

The information contained in the resulting email communication may nevertheless be retained in our email system for as long as necessary to process your enquiry and any subsequent business communication, or for as long as required by applicable legal or contractual obligations.

Once the information is no longer required and no statutory retention obligation applies, it will be deleted.

 

6. Email Communication

When you submit the contact form, the information you provide is transmitted to us by email.

Our website uses WP Mail SMTP to transmit emails through our IONOS mail server.

The SMTP service used by the website is: IONOS SMTP server: smtp.exchange.ionos.eu

The information transmitted by email may include the information entered into the contact form and technical information associated with the submission.

The email communication is used exclusively for processing and responding to enquiries.

IONOS provides information regarding its processing of personal data and its data processing arrangements for its services. For applicable IONOS contracts, the data processing agreement under Article 28 GDPR is incorporated into the IONOS General Terms and Conditions for newer contracts; older contracts may require separate completion of the relevant agreement.

 

7. Spam and Website Security

Our website uses technical and organisational measures to protect against spam, automated abuse, unauthorised access and other malicious activity.

Our forms use various anti-spam mechanisms, including honeypot-based protection, Cloudflare Turnstile, Google reCAPTCHA v3 and ActiveLayer spam detection. Depending on the form used, these mechanisms may process technical information such as IP address, user-agent information, timestamps and browser-related security signals in order to distinguish legitimate submissions from automated or abusive requests.

For additional spam detection, we use ActiveLayer, a service provided by ActiveLayer LLC. When a form is submitted, information contained in the submission, such as name, email address, message or other form fields, as well as technical information including the submitter’s IP address and user-agent information, may be transmitted to ActiveLayer for the purpose of detecting and preventing spam and abusive submissions. Spam detection submissions processed through ActiveLayer are configured to be automatically deleted after 30 days.

Cloudflare Turnstile is used on certain forms to distinguish legitimate visitors from automated traffic. Turnstile processes security-related signals such as IP address, user-agent information and browser-related information. According to Cloudflare, Turnstile does not access, store or transmit the contents entered into the form.

Google reCAPTCHA v3 is used on certain forms to assess whether a form submission originates from a legitimate user or from automated activity. In connection with this service, technical and usage-related information may be transmitted to Google.

In addition, our website uses Wordfence Security for website security, firewall protection, malware scanning, brute-force protection and other security functions. In connection with these functions, technical information associated with web requests may be processed, including IP addresses, timestamps, user-agent information and request information.

Our current Wordfence configuration uses Security Only traffic logging rather than logging all website traffic. Live Traffic data is configured to be retained for a maximum of 7 days.

The legal basis for the processing described in this section is Article 6(1)(f) GDPR, based on our legitimate interest in protecting our website, forms, IT systems and communication infrastructure against attacks, fraud, spam and unauthorised access.

 

8. Cookies and Similar Technologies

Based on the current configuration of our website, we do not use cookies for advertising, behavioural tracking or analytics.

Our technical tests have not identified cookies being set on the fh-signature.com domain during normal page visits or following submission of the contact form.

Technically necessary processing may nevertheless occur as part of the operation, security and administration of the website.

If we introduce additional cookies or similar technologies in the future that require consent under applicable law, we will provide the necessary information and obtain consent where required before such technologies are activated.

 

9. Google Fonts

The website uses several web fonts, including:

  • Arapey;
  • Roboto Slab;
  • Outfit;
  • Cormorant Garamond; and
  • Josefin Slab.

 

These fonts are loaded locally from our own website server.

They are not currently requested directly from Google servers when the website is accessed.

Accordingly, the current website configuration does not require the visitor’s browser to establish a connection to Google’s Google Fonts infrastructure merely to display these fonts.

 

10. Third-Party Content and External Links

Our website may contain links to external websites and social media platforms, including social media profiles.

These links do not by themselves establish a connection to the respective third-party service merely because you visit our website.

If you click an external link, you leave our website and the privacy policy of the respective third-party provider applies from that point onwards.

We are not responsible for the privacy practices or content of external websites.

 

11. Data Recipients

Personal data may be processed by service providers that support the operation, security, hosting and communication functions of our website.

Depending on the processing concerned, these may include:

  • IONOS – hosting and email infrastructure;
  • Wordfence – website security and security services.

 

Where IONOS processes personal data on our behalf, the applicable requirements of Article 28 GDPR are ensured in accordance with the contractual arrangements applicable to the relevant IONOS services.

IONOS states that, since 19 July 2022, its agreement on commissioned processing (AVV) has been part of its General Terms and Conditions. For contracts concluded from that date onwards, a separate AVV is therefore generally not required. For older contracts, the AVV may need to be concluded separately.

 

 

12. International Data Transfers

Where personal data is transferred to recipients outside the European Economic Area (EEA), such transfer will only take place where the requirements of applicable data protection law are fulfilled.

Where required, appropriate safeguards, such as an adequacy decision or standard contractual clauses, will be used.

 

13. Data Security

We use appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.

These measures include:

  • encrypted HTTPS connections;
  • secure email transmission using TLS;
  • firewall protection;
  • brute-force protection;
  • malware scanning;
  • security monitoring;
  • appropriate access controls.

 

However, no transmission or storage system can be guaranteed to be completely secure.

 

14. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected.

Contact enquiries may be retained for as long as necessary to process the enquiry and any subsequent business relationship.

Where statutory retention obligations apply, the relevant data may be retained for the legally prescribed period.

Once the applicable purpose and retention obligations have expired, personal data will be deleted or securely anonymised.

Technical hosting data is subject to the applicable retention periods of our hosting provider. For its web hosting products, IONOS currently states a retention period of eight weeks for the relevant visitor data.

 

15. Your Rights

Under the GDPR, you may have the following rights:

  • Right of access – you may request information about the personal data we process about you.
  • Right to rectification – you may request correction of inaccurate or incomplete personal data.
  • Right to erasure – you may request deletion of your personal data where the legal requirements are met.
  • Right to restriction of processing – you may request restriction of processing in certain circumstances.
  • Right to data portability – where applicable, you may receive personal data in a structured, commonly used and machine-readable format.
  • Right to object – you may object to certain processing based on legitimate interests, including where applicable processing for direct marketing.
  • Right to withdraw consent – where processing is based on consent, you may withdraw that consent at any time.

 

Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.

The European Commission confirms these rights, including access, rectification, erasure, restriction, portability and objection.

To exercise your rights, please contact us at: fauzia.haun@fh-signature.com

 

16. Right to Lodge a Complaint

You have the right to lodge a complaint with a competent data protection supervisory authority if you believe that the processing of your personal data infringes applicable data protection law.

As the controller is based in Portugal, the competent Portuguese data protection authority is: Comissão Nacional de Proteção de Dados (CNPD)

You may also contact the supervisory authority in the EU Member State of your habitual residence, place of work or place of the alleged infringement, where applicable.

 

17. Automated Decision-Making and Profiling

We do not use personal data submitted through this website for automated decision-making that produces legal or similarly significant effects.

We do not use contact form submissions for profiling.

 

18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our website, services, legal requirements or data processing practices.

The current version will always be published on this page.

Last updated: 15 August 2026