Lisbon Local

Live transit, all Lisbon

Privacy Policy

Last updated: 14 August 2026

This Privacy Policy explains how Axon Rook LLC, a limited liability company organised under the laws of New Mexico, United States, with its principal place of business at 1209 Mountain Rd PI NE, STE N, Albuquerque, NM 87110, United States of America (“Lisbon Local”, “we”, “us”), processes personal data in connection with the website at lisbon-local.com and any subdomain (the “Site”).

We are the controller of the personal data described below. Contact: [email protected].

Because the Site is directed at people in and travelling to Portugal, the EU General Data Protection Regulation applies to our processing under Article 3(2) GDPR, even though we are established in the United States.

This Policy covers the Site only. Our mobile application is covered by a separate App Privacy Policy. Your use of the Site is also governed by our Terms and Conditions.

1. Who this Policy is for

The Site is intended for users aged 16 or over. We do not knowingly collect personal data from anyone under 16, and we do not knowingly collect personal information from children under 13 as defined by the U.S. Children’s Online Privacy Protection Act. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.

2. What we collect

2.1 Data you give us

  • Account data — name or display name, email address, password (stored hashed), and any profile details you choose to add.
  • Content you submit — reviews, ratings, comments, photographs, business listing submissions, and any other material you post.
  • Contact and enquiry data — the content of messages you send us through forms, email, or other channels.
  • Newsletter data — email address and subscription preferences, where you subscribe.
  • Transaction data — billing name, email, country, and the record of what you bought. Card details are handled entirely by our payment processor and are never received or stored on our servers.

2.2 Data collected automatically

  • Technical data — IP address, browser type and version, operating system, device type, language, referring URL, and timestamps.
  • Usage data — pages viewed, links clicked, search terms entered on the Site, session duration, and navigation paths.
  • Cookie and similar identifiers — see Section 6.
  • Server logs — our hosting provider records requests to the Site, including IP address and user agent, for security and diagnostic purposes.

2.3 Data from third parties

  • Social or third-party login, where offered — the identifiers and profile fields that provider releases to us.
  • Payment processor — confirmation of payment, partial card details (last four digits, card type), and fraud signals.
  • Publicly available business information used to compile or verify listings.

3. Why we process it, and on what legal basis

Purpose Legal basis (Art. 6 GDPR)
Providing the Site, creating and maintaining your account, publishing content you submit Performance of a contract (Art. 6(1)(b))
Processing payments and maintaining accounting and tax records Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))
Responding to enquiries Legitimate interests (Art. 6(1)(f)) — responding to those who contact us
Security, fraud prevention, abuse detection, enforcing our Terms Legitimate interests (Art. 6(1)(f)) — protecting the Site, our users, and our business
Maintaining and improving the Site using aggregated server log data Legitimate interests (Art. 6(1)(f)) — understanding and improving how the Site performs
Marketing emails and newsletters Consent (Art. 6(1)(a)), or legitimate interests for existing customers regarding similar services, subject to an opt-out in every message
Complying with legal obligations and responding to lawful requests Legal obligation (Art. 6(1)(c))
Establishing, exercising, or defending legal claims, including in a sale or restructuring of our business Legitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may object at any time — see Section 8.

4. Content you post is public

Reviews, ratings, comments, photographs, and listing submissions are published on the Site and are visible to anyone, including search engines. Your display name is shown alongside them. Do not post anything you are not willing to make public, and do not include other people’s personal data without their agreement. Once content is indexed, cached, or copied by third parties we cannot recall it, and removal from the Site does not remove it from those third parties.

5. Who we share it with

We do not sell your personal data, and we do not share it for cross-context behavioural advertising. We disclose it only to:

  • Processors acting on our documented instructions under written data processing agreements — hosting and infrastructure, email delivery, payment processing, customer support tooling, and security services. We use only processors that store and process personal data within the EEA. A current list of processor categories is available on request from [email protected].
  • Professional advisers — lawyers, accountants, insurers, and auditors, bound by confidentiality.
  • Authorities, courts, and regulators, where we are legally required to disclose or where disclosure is necessary to establish, exercise, or defend legal claims.
  • An acquirer or successor, in connection with a merger, acquisition, financing, insolvency, or sale of assets. Personal data may be transferred as part of the assets.
  • Third parties you direct us to, or whose services you choose to connect.

6. Cookies and similar technologies

We do not use analytics, advertising, or tracking cookies, and we do not profile you or track you across other websites. Because we set no non-essential cookies, we do not display a cookie consent banner.

We use only strictly necessary cookies, and only where you take an action that requires them — signing in, submitting a form, or leaving a comment. These support session management, login state, and security. Under Article 5(3) of the ePrivacy Directive, cookies strictly necessary to deliver a service you have expressly requested do not require consent.

Browsing the Site as a visitor sets no cookies at all.

You can block or delete cookies in your browser settings at any time. Blocking strictly necessary cookies will prevent you from signing in and will break parts of the Site.

If we later introduce analytics, advertising, or any other non-essential cookies or tracking technology, we will update this Policy and obtain your consent before setting them.

7. Where we store it, international transfers, and how long we keep it

7.1 Storage and international transfers

The Site is hosted on servers located in Helsinki, Finland, within the European Economic Area (provider: Hetzner Online GmbH).

Your personal data is stored in the EEA and is not transferred outside it. Although Axon Rook LLC is incorporated in the United States, personal data collected through the Site is held on EEA infrastructure and is accessed only from within the EEA. We do not transfer it to the United States or to any other country outside the EEA.

If this changes — for example if we engage a service provider outside the EEA — we will update this Policy before the transfer begins and will rely on an adequacy decision of the European Commission or on the Commission’s Standard Contractual Clauses under Article 46(2)(c) GDPR, with supplementary measures where required. A copy of the relevant safeguards would be available on request from [email protected].

7.2 Retention

  • Account data — for the life of the account, then up to 12 months after closure to handle disputes and prevent re-registration abuse.
  • Published content — indefinitely, unless you delete it or we remove it; we may retain content in anonymised form after account closure.
  • Enquiries and support correspondence24 months from last contact.
  • Payment, accounting, and tax records7 years, to meet United States federal and state tax and accounting requirements.
  • Server and security logs12 months.
  • Marketing consents and opt-outs — for as long as needed to honour your preference.

We may retain data longer where necessary to establish, exercise, or defend legal claims, or where a legal obligation requires it.

8. Your rights

8.1 If the GDPR applies to you

Subject to the conditions in the GDPR, you have the right to:

  • access your personal data and obtain a copy;
  • have inaccurate data corrected;
  • have data erased;
  • restrict processing;
  • receive data you provided in a structured, machine-readable format and have it transmitted to another controller, where processing is based on consent or contract and carried out by automated means;
  • object to processing based on legitimate interests, and to object at any time and without giving reasons to processing for direct marketing;
  • withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

8.2 If you are a United States resident

Depending on your state of residence, you may have the right to know what personal information we collect and how we use and disclose it; to access, correct, or delete it; to obtain a portable copy; to opt out of sale, sharing for targeted advertising, or profiling; and not to be discriminated against for exercising these rights. As stated in Section 5, we do not sell personal information and do not share it for cross-context behavioural advertising.

8.3 Exercising your rights

Contact [email protected]. We respond within one month, extendable by a further two months for complex requests, and will tell you if we extend. We may ask you to verify your identity before we act. Requests that are manifestly unfounded or excessive, in particular because they are repetitive, may attract a reasonable fee or be refused, as permitted by Article 12(5) GDPR. You may use an authorised agent where applicable law permits.

We do not carry out automated decision-making producing legal or similarly significant effects.

9. Complaints

If you are unhappy with how we handle your data, please contact us first at [email protected]. If the GDPR applies to you, you also have the right to lodge a complaint with the supervisory authority in your country of residence or workplace. In Portugal this is the Comissão Nacional de Proteção de Dados (CNPD), Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, www.cnpd.pt.

10. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls, and regular updates. No method of transmission or storage is completely secure, and we cannot and do not guarantee absolute security. You are responsible for keeping your password confidential and for all activity under your account. If we become aware of a personal data breach likely to result in a high risk to your rights, we will notify you and the competent supervisory authority as required by Articles 33 and 34 GDPR, and will comply with applicable United States state breach notification laws.

11. Third-party sites and services

The Site links to and embeds third-party websites, maps, booking tools, social media, and business listings. We do not control those services and are not responsible for their content, practices, or privacy policies. Their processing of your data is governed by their own terms, which you should read.

12. Changes to this Policy

We may update this Policy at any time. The “Last updated” date above shows the current version. Where changes are material, we will give reasonable notice by posting a notice on the Site or emailing registered users. Continued use of the Site after a change takes effect constitutes acceptance of the revised Policy. Where a change requires your consent under applicable law, we will ask for it.

13. Contact

Axon Rook LLC
1209 Mountain Rd PI NE, STE N
Albuquerque, NM 87110
United States of America
Email: [email protected]