Johanna Farrimond

Privacy Notice

Effective date: [to be set at publication]
Service: johannafarrimond.com/second-opinion
This notice: johannafarrimond.com/privacy

This Privacy Notice explains how Johanna Farrimond, operating as a sole trader (Empresário em Nome Individual) in Portugal ("Practitioner", "we", "us"), collects, processes and protects personal data through the written advisory service The Second Opinion.

1. Data controller

Data Controller: Johanna Farrimond (Empresário em Nome Individual)
Establishment: Portugal
Contact: info@johannafarrimond.com
Privacy queries: privacy@johannafarrimond.com
Supervisory Authority: Comissão Nacional de Proteção de Dados (CNPD), Portugal

2. Service scope, minimisation rules and AI commitments

The Second Opinion provides a written advisory brief analysing workplace relationship dynamics based solely on client-observed accounts.

Mandatory third-party pseudonymisation. Clients must use generic aliases (for example "Person A", "Peer X") and role titles in all intake forms and communications. Clients must never submit real names, personal contact details, or private background information regarding third parties.

Special category data prohibition. Clients must not submit special category data under Art. 9 GDPR (health or medical information, trade union membership, political opinions, religious beliefs). Any unsolicited special category data embedded in an intake submission is purged immediately upon initial review.

Unrecorded sessions guarantee. Live ninety-minute consultation sessions are not recorded by the Practitioner or the video platform, and recording by any party is strictly prohibited under the Terms of Service.

No AI analysis. Client submissions, intake accounts and written briefs are read and analysed manually by the Practitioner. No large language model or AI analysis service is used at any stage of producing the brief.

3. Personal data categories and legal bases

Processing activityData categories processedLawful basis
Intake and case evaluationClient name, email, alias-based interaction accountsArt. 6(1)(b) GDPR, performance of a contract and pre-contractual steps
Live consultation sessionParticipant name, email, unrecorded live video stream, connection metadataArt. 6(1)(b) GDPR, performance of a contract
Billing and invoicingClient name, tax identification number (NIF), billing address, payment confirmation ID. Credit and debit card details are processed directly by Stripe and never enter our systemsArt. 6(1)(c) GDPR, legal obligation under Portuguese tax law (Código do IVA)
Third-party analysisAlias-based workplace accounts provided by the clientArt. 6(1)(f) GDPR, legitimate interests of Practitioner and Client in conducting confidential workplace analysis
Second reads and legal archiveFinal written briefs, graded appendices, decision notesArt. 6(1)(f) GDPR, legitimate interests in managing second reads, dispute resolution and defence against claims

4. Third-party counterparts and exemption from notification

We do not contact, interview or notify third-party counterparts referenced in client accounts. Pursuant to Article 14(5)(b) and Article 14(5)(d) GDPR, individual notification is exempt because:

  • Providing notice would require disproportionate effort and investigation to obtain contact details.
  • Notification would breach client confidentiality, cause workplace disruption, and impair the objective of the confidential advisory service.
  • The processing is subject to professional confidentiality obligations under Portuguese law.

5. Processors and international data transfers

We share necessary personal data with third-party service providers acting as data processors under Article 28 GDPR.

Hostinger International Ltd (Lithuania, EU), website hosting and intake form submission infrastructure. All intake data remains within the European Economic Area.

MICCI (Denmark, EU), trading as PostStack, transactional email delivery of intake form submissions. Case file content is processed and stored within the European Economic Area.

Hetzner Online GmbH (Germany, EU), infrastructure sub-processor engaged by MICCI, hosting application servers, databases, storage, mail relay, backups and logging in Helsinki, Finland. No intake data leaves the European Economic Area.

Google Ireland Limited (Ireland, EU), email communications, with Google LLC (USA) acting as sub-processor. International transfers to Google LLC in the US are safeguarded under Article 45 GDPR via Google's active certification under the EU-U.S. Data Privacy Framework.

Zoom Video Communications, Inc. (USA), facilitation of live, unrecorded consultation sessions. Connection metadata transfers to the US are safeguarded under Article 45 GDPR via Zoom's active certification under the EU-U.S. Data Privacy Framework.

TidyCal / Sumo Group Inc. (USA), consultation appointment scheduling. International transfers of scheduling metadata (name, email, appointment time) to the US are safeguarded under Article 46(2)(c) GDPR via standard contractual clauses.

Stripe Payments Europe, Ltd. (Ireland, EEA), payment processing and invoicing. Credit and debit card details are collected directly by Stripe. Transfers to parent entity Stripe, Inc. (USA) are safeguarded under Article 45 GDPR via Stripe's active certification under the EU-U.S. Data Privacy Framework.

6. Storage and retention

Declined pre-payment case files. Non-sensitive administrative decline records are retained for 30 days post-decision, then deleted. Any unsolicited Art. 9 special category data within intake files is purged immediately upon review.

Intake forms and interaction accounts. Retained in encrypted local storage for 90 days post-session, or 30 days following delivery of the graded appendix, to facilitate accuracy evaluations and free second reads. Then securely deleted.

Session video and audio stream. 0 days. Live stream only, with no recording or cloud storage.

Written advisory briefs and graded appendices. Retained in encrypted local storage for 3 years post-delivery under Art. 6(1)(f) GDPR for dispute resolution and legal defence, then permanently destroyed.

Tax and billing records. Retained for 10 years as required by Portuguese tax law (Art. 123.º CIVA).

7. Your rights

You have the right under Arts. 15–22 GDPR to request access to, rectification of, or erasure of your personal data, and to restrict or object to processing.

Exercising rights: privacy@johannafarrimond.com

Third-party access requests. Access requests submitted by third parties will be restricted or redacted where granting access would adversely affect the rights, freedoms and confidential communications of the Client, pursuant to Art. 15(4) GDPR.

Supervisory authority
Comissão Nacional de Proteção de Dados (CNPD)
Av. D. Carlos I, 134 – 1.º, 1200-651 Lisboa, Portugal
www.cnpd.pt

info@johannafarrimond.com The Second Opinion Terms