Legal
Privacy Policy
Last updated: 3 October 2026
This policy explains what personal data we collect when you use this website or get in touch, why we collect it, who sees it and what rights you have. We try to collect as little as possible.
1. Who is responsible
The data controller is Maria Pignatelli, an independent consultant based between Lisbon and Barcelona who trades as Proof of Change. Proof of Change is not a registered company. Contact: [email protected]. A postal address is available on request.
2. What we collect and why
- Messages and booking details. Your name, email, organization, role and what you write to us, or what you enter when you book a call. We use them to reply and prepare the conversation. Legal basis: steps taken at your request before a contract, and our legitimate interest in answering enquiries.
- Client and engagement information. Contact and invoicing details and the material you share so we can do the work. Legal basis: performing our contract and meeting legal duties such as accounting and tax.
- Newsletter signups. Your email address, if you subscribe. The newsletter is delivered through Substack. Legal basis: your consent, which you can withdraw at any time with the unsubscribe link in every email.
- Website usage data. If you allow analytics cookies, aggregated information such as pages visited, approximate country, device type and where you came from. Legal basis: your consent.
- Cookie choices. A small record of the cookie preferences you set, stored on your device. Legal basis: our legitimate interest in respecting your choices.
- Technical data. Your IP address and browser details are processed by our hosting provider to deliver the site and keep it secure. Legal basis: legitimate interest in running a secure website.
3. What we do not do
We do not sell your personal data, we do not use it for automated decisions that affect you, and we do not knowingly collect data from children.
4. Who we share it with
We share data only with providers that help us run the work, under terms that protect it:
- Cloudflare: website hosting, delivery, security and DNS.
- Microsoft 365: email and calendar for communicating with you.
- Cal.com: booking calls with us. When you book, Cal.com handles the details you enter under its own privacy policy.
- Substack: sending the newsletter and managing subscribers. Substack is a separate controller for the data you give when subscribing and has its own privacy policy.
- Our accountant and invoicing tools, for bookkeeping and tax.
- Collaborators who work with us on a project, bound by confidentiality.
- Authorities, when the law requires it.
5. International transfers
Some of these providers are based in, or process data in, countries outside the European Economic Area, including the United States. When that happens we rely on safeguards such as the European Commission's standard contractual clauses or an adequacy decision such as the EU-US Data Privacy Framework.
6. How long we keep it
- Enquiries that do not lead to work: up to 12 months.
- Client records and engagement files: for the engagement plus the period the law requires us to keep accounting records (often up to 10 years for invoices). File content is deleted or returned up to 3 years after the engagement ends, unless you ask earlier.
- Newsletter subscriptions: until you unsubscribe.
- Analytics data: in aggregated form, up to 14 months.
- Cookie preferences: until you clear them or change them.
7. Confidential client material
Documents and data you share for an engagement are treated as confidential, used only for that work, kept in access-controlled storage and deleted or returned when the engagement ends, as agreed with you.
8. Your rights
Under the GDPR you can ask us to access, correct, delete or restrict the use of your data, object to processing based on legitimate interest, receive your data in a portable format, and withdraw consent at any time without affecting earlier processing. Write to [email protected] and we will reply within one month. You can also complain to your data protection authority, such as the Comissão Nacional de Proteção de Dados in Portugal (cnpd.pt) or the Agencia Española de Protección de Datos in Spain (aepd.es).
9. Cookies
We explain what we use in our Cookie Policy. You can change your choices at any time using "Cookie preferences" in the footer of every page.
10. Security
We use reasonable technical and organizational measures, including encrypted connections (HTTPS), access controls and password managers. No system is perfectly secure. If there is a breach that puts your rights at risk, we will tell you and the authorities as the law requires.
11. Changes
We may update this policy. The date at the top shows the latest version, and material changes will be highlighted on this page.
