Privacy & Data Protection

Privacy Policy

This Policy explains how personal data is processed during navigation and through inquiry contacts made via Dr. Raphael Machado's website.

Last updated: August 2, 2026.

1. Data Controller and Site Management

The party responsible for this website and for decisions concerning the processing of personal data is:

Data Controller: Dr. Raphael Machado

Activity: Consultant Neurosurgeon responsible for the website's content, general customer service, and data collection purposes.

Contact Channel: machado.neurosurgery@gmail.com

2. Personal Data That May Be Collected

Depending on how you interact with the website, the following data may be processed:

  • Name, phone number, email address, and message content voluntarily submitted via the contact form;
  • IP address, timestamp, access logs, and technical information related to security, abuse prevention, and server management;
  • Basic browser, device, and page navigation information automatically logged by web hosting infrastructure;
  • Administrative login credentials for restricted access to the blog management panel, limited to authorized personnel.

3. Health Data and Sensitive Information

The contact form provided on this website is strictly intended for general information requests and administrative inquiries.

Do not submit medical imaging, diagnostic reports, medical histories, prescription details, or third-party health data through this form.

If a visitor spontaneously submits health-related information, it will only be processed to the extent strictly necessary to address or forward the request, and may be deleted when no longer required, subject to applicable legal retention obligations.

This form does not replace a direct medical consultation, emergency medical care, clinical evaluation, or secure channels provided by health institutions.

4. Purposes of Data Processing

Personal data may be used for the following purposes:

  • Responding to visitor inquiries and messages;
  • Managing administrative communication;
  • Taking preliminary steps requested by the data subject prior to a formal appointment or agreement;
  • Protecting the website against spam, fraud, cyberattacks, unauthorized access, and abuse;
  • Complying with legal, regulatory, or administrative requirements;
  • Exercising rights in administrative, judicial, or extrajudicial proceedings.

6. Data Sharing and Service Providers

Personal data is never sold or commercialized. It may be processed by service providers necessary to operate the website and deliver messages, in accordance with their respective security standards and privacy policies.

Hostinger

Provides web hosting infrastructure, server databases, technical logs, and underlying website availability services.

Google / Gmail

Used to receive and securely store messages submitted through the website's contact form.

WhatsApp & Instagram

When accessing external links to these platforms, visitors become subject to the respective providers' privacy policies.

Donne Software

Acted as the website developer without an ongoing maintenance contract. Donne Software does not use data submitted through the contact form for its own purposes.

Any occasional technical access will only occur upon explicit request from the Data Controller and for the strictly required period.

7. International Data Transfers

Certain infrastructure providers, email servers, and third-party tools may operate servers located outside Brazil. In such cases, international data transfers will comply with statutory safeguards and legal requirements.

8. Data Retention Period

Personal data will be retained only for as long as necessary to fulfill the purposes set out in this Policy.

Inquiries that do not lead to clinical appointments, contractual engagements, or legal obligations may be discarded after resolution or within a reasonable administrative timeframe.

Certain records may be retained for longer periods to meet statutory obligations, prevent fraud, ensure security, or support legal defense requirements.

9. Information Security

We employ technical and organizational measures appropriate to the nature of the website and associated risks, including:

  • Enforced HTTPS encryption across all web traffic;
  • Secure storage of admin credentials outside public web directories;
  • Access controls and brute-force protection on administrative panels;
  • Form validation, rate-limiting, and anti-spam protection mechanisms;
  • File upload restrictions regarding format and size limits;
  • Protection of server directories and technical security logs;
  • Regular maintenance and security updates of core components.

While robust protection measures are in place, no digital system is completely immune to security threats. In the event of a significant incident, appropriate steps will be taken in accordance with statutory guidelines.

10. Cookies and Tracking Technologies

This website may use essential cookies strictly necessary for core functionality, security, and administrative session management.

External resources such as web fonts, icons, social media links, and third-party scripts may establish technical connections with their respective external servers.

Should non-essential analytics or marketing cookies be introduced in the future, this Policy will be updated, and a cookie management consent banner will be provided.

11. Data Subject Rights

Under applicable data protection laws, data subjects have the right to request:

  • Confirmation of the existence of data processing;
  • Access to their personal data;
  • Correction of incomplete, inaccurate, or outdated data;
  • Anonymization, blocking, or deletion of unnecessary or non-compliant data;
  • Information regarding public or private entities with whom data has been shared;
  • Data portability where applicable and regulated;
  • Revocation of consent and deletion of consent-based data processing, subject to statutory retention exceptions;
  • Objection to processing carried out in non-compliance with the law;
  • Review of decisions made solely on automated processing, where applicable.

To protect your identity and security, proof of identity may be required before processing specific requests.

12. How to Exercise Your Rights

Inquiries regarding privacy, personal data, and rights requests can be directed to:

Email: machado.neurosurgery@gmail.com

Please use the subject line: “Privacy and Data Protection Request”.

14. Changes to This Privacy Policy

This Policy may be updated periodically to reflect operational changes, technology updates, provider modifications, or evolving legal obligations.

The latest active version will always be displayed on this page along with its revision date.

15. Applicable Law and Jurisdiction

This Policy is governed by and construed in accordance with Brazilian law, notably Law No. 13,709/2018 (General Data Protection Law - LGPD).