1. Data Controller and Site Management
The party responsible for this website and for decisions concerning the processing of personal data is:
Data Controller: Dr. Raphael Machado
Activity: Consultant Neurosurgeon responsible for the website's content, general customer service, and data collection purposes.
Contact Channel: machado.neurosurgery@gmail.com
2. Personal Data That May Be Collected
Depending on how you interact with the website, the following data may be processed:
- Name, phone number, email address, and message content voluntarily submitted via the contact form;
- IP address, timestamp, access logs, and technical information related to security, abuse prevention, and server management;
- Basic browser, device, and page navigation information automatically logged by web hosting infrastructure;
- Administrative login credentials for restricted access to the blog management panel, limited to authorized personnel.
3. Health Data and Sensitive Information
The contact form provided on this website is strictly intended for general information requests and administrative inquiries.
Do not submit medical imaging, diagnostic reports, medical histories, prescription details, or third-party health data through this form.
If a visitor spontaneously submits health-related information, it will only be processed to the extent strictly necessary to address or forward the request, and may be deleted when no longer required, subject to applicable legal retention obligations.
This form does not replace a direct medical consultation, emergency medical care, clinical evaluation, or secure channels provided by health institutions.
4. Purposes of Data Processing
Personal data may be used for the following purposes:
- Responding to visitor inquiries and messages;
- Managing administrative communication;
- Taking preliminary steps requested by the data subject prior to a formal appointment or agreement;
- Protecting the website against spam, fraud, cyberattacks, unauthorized access, and abuse;
- Complying with legal, regulatory, or administrative requirements;
- Exercising rights in administrative, judicial, or extrajudicial proceedings.
5. Legal Bases for Processing
Data processing is conducted in compliance with applicable law, specifically Brazil's General Data Protection Law (LGPD - Law No. 13,709/2018), based on:
- Pre-contractual procedures initiated upon the data subject's request;
- Compliance with legal or regulatory obligations;
- Regular exercise of rights in legal proceedings;
- Legitimate interest, particularly regarding website security, fraud prevention, and operational integrity, while respecting user rights;
- Consent, when explicitly requested and legally appropriate for a specific purpose.
6. Data Sharing and Service Providers
Personal data is never sold or commercialized. It may be processed by service providers necessary to operate the website and deliver messages, in accordance with their respective security standards and privacy policies.
Hostinger
Provides web hosting infrastructure, server databases, technical logs, and underlying website availability services.
Google / Gmail
Used to receive and securely store messages submitted through the website's contact form.
WhatsApp & Instagram
When accessing external links to these platforms, visitors become subject to the respective providers' privacy policies.
Donne Software
Acted as the website developer without an ongoing maintenance contract. Donne Software does not use data submitted through the contact form for its own purposes.
Any occasional technical access will only occur upon explicit request from the Data Controller and for the strictly required period.
7. International Data Transfers
Certain infrastructure providers, email servers, and third-party tools may operate servers located outside Brazil. In such cases, international data transfers will comply with statutory safeguards and legal requirements.
8. Data Retention Period
Personal data will be retained only for as long as necessary to fulfill the purposes set out in this Policy.
Inquiries that do not lead to clinical appointments, contractual engagements, or legal obligations may be discarded after resolution or within a reasonable administrative timeframe.
Certain records may be retained for longer periods to meet statutory obligations, prevent fraud, ensure security, or support legal defense requirements.
9. Information Security
We employ technical and organizational measures appropriate to the nature of the website and associated risks, including:
- Enforced HTTPS encryption across all web traffic;
- Secure storage of admin credentials outside public web directories;
- Access controls and brute-force protection on administrative panels;
- Form validation, rate-limiting, and anti-spam protection mechanisms;
- File upload restrictions regarding format and size limits;
- Protection of server directories and technical security logs;
- Regular maintenance and security updates of core components.
While robust protection measures are in place, no digital system is completely immune to security threats. In the event of a significant incident, appropriate steps will be taken in accordance with statutory guidelines.
11. Data Subject Rights
Under applicable data protection laws, data subjects have the right to request:
- Confirmation of the existence of data processing;
- Access to their personal data;
- Correction of incomplete, inaccurate, or outdated data;
- Anonymization, blocking, or deletion of unnecessary or non-compliant data;
- Information regarding public or private entities with whom data has been shared;
- Data portability where applicable and regulated;
- Revocation of consent and deletion of consent-based data processing, subject to statutory retention exceptions;
- Objection to processing carried out in non-compliance with the law;
- Review of decisions made solely on automated processing, where applicable.
To protect your identity and security, proof of identity may be required before processing specific requests.
12. How to Exercise Your Rights
Inquiries regarding privacy, personal data, and rights requests can be directed to:
Email: machado.neurosurgery@gmail.com
Please use the subject line: “Privacy and Data Protection Request”.
13. External Links and Platforms
This website may contain links to external third-party platforms. This Privacy Policy does not apply to data practices conducted by those third parties. We encourage visitors to review the privacy notices of external websites prior to providing personal data.
14. Changes to This Privacy Policy
This Policy may be updated periodically to reflect operational changes, technology updates, provider modifications, or evolving legal obligations.
The latest active version will always be displayed on this page along with its revision date.
15. Applicable Law and Jurisdiction
This Policy is governed by and construed in accordance with Brazilian law, notably Law No. 13,709/2018 (General Data Protection Law - LGPD).