Privacy
Paradoxo Coroado, LDA (ParCor) keeps as little personal data as it can. This page says what it keeps, why, where, and for how long.
Who keeps the data
Paradoxo Coroado, LDA, trading as ParCor, NIPC 519363590, registered office in Lisbon, Portugal. Contact: hello@parcor.io.
Contact details
When a person leaves details on the contact page, or hands a business card to one of ParCor's two founders, ParCor keeps the name, company, title, mobile number, WeChat ID, e-mail address, interest, any note, a photo of the card if one is added, and the record of consent (for the form, the time, the language, and the version of this notice; for a card, the two answers, the founder who recorded them, when, and the version of this notice). A WeChat QR code shown instead of a business card counts here as a card, and a photo of it as a photo of the card. The founders also note the person's role, whether the company sells or buys, what it wants, the role of the person they named as a contact (never that person's name), the place and date of the meeting, the next step and its date, how the follow-up stands, their notes on each follow-up, and the date of the last contact. They are used only to follow up about ParCor, which does not sell them or pass them to other companies. Giving them is voluntary; without them ParCor cannot follow up. A form filled in through a link ParCor showed or sent for one record is linked to that record: for example, a contact who fills in the form through the link shown at a meeting is linked to the record of the person who named them. Some details come from someone other than the person: a phone's contact list, or a card-scanning app's export, that a founder imports; unless the person has already agreed aloud, ParCor's first message to that person says where the details came from. The contact page is for business contacts and is not meant for anyone under 18.
Legal basis
Consent (GDPR, Art. 6(1)(a)). For a person met in mainland China, or living there, consent under China's Personal Information Protection Law (Art. 14 and Art. 39), including separate consent to sending the details to Switzerland. A business card handed to a founder is kept if the person, once told who ParCor is, where and for how long it keeps the card and the notes, and how to see, correct, or delete them or withdraw, agrees aloud both that ParCor keeps the details to follow up and that they are sent to Switzerland and kept there; the founder records that answer, and after a no to either question the card is not kept at all. A person met in mainland China, or living there, is added to ParCor's list of contacts only with that answer or the contact page's two ticks. For anyone else, a card a founder adds, or a contact a founder imports, without an answer either way is kept for one follow-up message, which asks for consent and says how to decline; if consent does not follow within 30 days of the card or contact being added, it is deleted (GDPR, Art. 6(1)(f): ParCor's interest in following up a business contact it already has).
Where the data is kept
On a server ParCor rents in Switzerland; a card a founder adds waits on that founder's phone only until it reaches the server. The European Commission recognises Switzerland as protecting personal data adequately. A hosting provider runs the server. Messages between ParCor and the person pass through ParCor's e-mail server, or through WeChat when the person uses it. No one else receives the data.
How long
Two years after the last contact, then deleted; sooner on request or when consent is withdrawn. Backup copies roll off within 14 days.
Rights
The person the data is about can ask at any time to see it, correct it, delete it, limit its use, receive a copy in a common electronic format, object to its use, or withdraw consent, by writing to hello@parcor.io. ParCor answers within one month. Withdrawing consent does not affect what was done before. The person can also complain to Portugal's data protection authority, the CNPD (www.cnpd.pt).
Visiting the site
The web server records each request (the IP address it came from, the time, the page, and the browser's name) to keep the site secure, and deletes these records after 30 days. The application server behind the console and the verifier also records each request made to it: the IP address, the time, the full address asked for, and the headers the browser sent, the browser's name among them but never a cookie's value; from its next update it deletes these records after 30 days. The legal basis for both kinds of record is ParCor's interest in keeping the site secure and working (GDPR, Art. 6(1)(f)). The site uses no analytics and no advertising. For visitors it sets one cookie, and only when the light or dark switch is pressed: the cookie holds that choice and lasts six months.
Automated decisions
None.
Version
Version 1, October 2026. A new version is dated here.