Skip to content

Privacy Policy

Last updated: May 14, 2026

This Privacy Policy contains information about how the Albert Sabin website (albertsabin.com), operated and maintained by Skallar Marketing Digital LTDA (CNPJ: 34.179.719/0001-53), as the Data Controller, collects, uses, stores, and protects the personal data of users who access it. Our goal is to be transparent about what data is collected, why, how it is used, and how long we retain it.

This policy was drafted in accordance with:

  • Federal Law No. 12,965/2014 (Brazilian Framework for the Internet)
  • Federal Law No. 13,709/2018 (General Data Protection Law—LGPD)
  • General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679, applicable to users residing in the European Union

This Policy may be updated from time to time. We recommend that you review it regularly.


1. What Data We Collect and How

1.1 Data you provide to us directly

When you interact with our website—by filling out contact forms, subscribing to our newsletter, or leaving comments—we collect:

  • First and last name
  • Email address
  • Content of messages or comments submitted

1.2 Data collected automatically

When you browse our website, we automatically collect technical information about your device and browsing behavior, including:

  • IP address: used to identify the source of the connection, detect fraud, block malicious access, and generate geographic audience statistics.
  • Device identifiers: device type, operating system, browser version, configured language, and screen resolution.
  • Advertising identifiers: Ad IDs (such as IDFA on iOS and AAID on Android) used for ad personalization and campaign measurement.
  • Cookies and similar technologies: text files stored in your browser to remember preferences, maintain active sessions, and track browsing behavior for analytical and advertising purposes.
  • Browsing data: pages visited, time spent on the site, links clicked, referral source (e.g., organic search, social media, email), and interactions with content.
  • Approximate location: Derived from your IP address, this allows us to identify your city, state, and country to personalize content and display ads relevant to your region.
  • Precise location: collected only with your explicit consent, when you authorize access to your device’s GPS location.

1.3 Push Notifications (Web Push Notifications)

If you choose to receive our push notifications, consent is collected directly by your browser (Chrome, Safari, Edge, etc.) the moment you click “Allow.” To enable these notifications, we use third-party services (such as OneSignal or Firebase Cloud Messaging), which generate a unique identification token for your device/browser.

In addition to the token, these platforms automatically record:

  • Browser type and version
  • Device operating system
  • IP address (used for approximate geolocation and message targeting)
  • Engagement metrics: whether the notification was delivered, viewed, or clicked

Purpose: sending content updates, alerts about new posts, and specific health and wellness campaigns.

How to revoke consent (opt-out): Since push notifications are controlled by the browser or operating system itself, you must opt out directly in your browser’s permission settings—there is no unsubscribe link on the website. Here’s how to do it in each browser:

  • Chrome: Settings → Privacy and security → Site settings → Notifications
  • Firefox: Preferences → Privacy & Security → Permissions → Notifications
  • Safari: Preferences → Websites → Notifications
  • Edge: Settings → Cookies and site permissions → Notifications

1.4 Third-Party Data

We may receive information about you through third-party platforms integrated with our website, such as:

  • Google Analytics and Google Ads: audience metrics, browsing behavior, and campaign performance.
  • Meta (Facebook/Instagram) Pixel: conversion tracking and ad personalization on Meta platforms.
  • Social media: when you interact with our share buttons or log in via social media.

2. How We Use Your Data

The data collected is used for the following purposes:

  • Website operation: to ensure the proper functioning of pages, forms, and features. (Legal basis: Legitimate Interest — LGPD Art. 7, IX)
  • Audience analysis: to understand how users navigate the website in order to improve the experience and content. (Legal basis: Legitimate Interest — LGPD Art. 7, IX)
  • Content personalization: to display articles, recommendations, and relevant content based on your interests and location. (Legal basis: Legitimate Interest — LGPD Art. 7, IX)
  • Personalized advertising: Display targeted ads based on your browsing profile, interests, and approximate location, both on our website and on third-party platforms (such as Google and Meta). (Legal basis: Consent — LGPD Art. 7, I)
  • Fraud detection and security: Identify and block suspicious access attempts, attacks, and abusive behavior using data such as IP addresses and browsing patterns. (Legal basis: Legitimate Interest — LGPD Art. 7, IX)
  • Push notifications: Sending content updates and alerts to the device of users who have authorized receipt. (Legal basis: Consent — LGPD Art. 7, I)
  • Email communications: sending newsletters, content updates, or responding to inquiries, when you choose to receive them. (Legal basis: Consent — LGPD Art. 7, I)
  • Compliance with legal obligations: Responding to requests from competent authorities when required by law. (Legal basis: Legal Obligation — LGPD Art. 7, II)

3. Data Retention — How Long We Retain Your Information

We retain your data only for as long as necessary to fulfill the purposes described in this policy or to comply with legal requirements:

  • Browsing data and access logs (IP addresses, analytical cookies): up to 26 months, in accordance with Google Analytics standards and the minimum requirement of the Brazilian Civil Rights Framework for the Internet (Art. 15).
  • Contact form data: up to 24 months after the last contact, unless a longer retention period is required for legal reasons.
  • Newsletter data (email and name): for as long as you maintain an active subscription. After cancellation, the data is deleted within 30 days.
  • IP addresses and advertising data (Google Ad Manager, Meta): anonymized or deleted by partners within 9 to 18 months, in accordance with industry standards and Google’s retention policies.
  • Advertising cookies: generally between 90 days and 13 months, depending on the partner platforms.
  • Comments and user-generated content: for as long as the content remains published on the website; it may be deleted upon request.
  • Data related to legal and tax obligations: for the period specified by applicable law, generally 5 years.

Once the above retention periods have expired, the data is anonymized or securely deleted.


4. Cookies

We use cookies and similar technologies to improve your experience on the website. Our consent management platform (CMP) operates in accordance with the IAB Transparency & Consent Framework (TCF), enabling the following mandatory signals:

  • IAB TCF Special Purpose 2: Security, fraud detection, and debugging — based on Legitimate Interest.
  • IAB TCF Feature 3: Use of precise geolocation data — based on Explicit Consent.

The types of cookies we use include:

  • Essential cookies: necessary for the basic functioning of the website (e.g., keeping your session active).
  • Analytics cookies: collect anonymous data about how you use the website (e.g., Google Analytics).
  • Advertising cookies: track your interests to display relevant ads (e.g., Google Ads, Meta Pixel).
  • Preference cookies: remember your settings and browsing preferences.

You can manage or disable cookies at any time in your browser settings. Please note that disabling certain cookies may affect the website’s functionality.


5. Sharing Data with Third Parties

We do not sell your personal data. We may share information in the following cases:

  • Service providers: companies that assist us in operating the website, such as hosting providers (Hostinger), email services, analytics platforms, and advertising platforms. These providers access the data solely to provide the contracted services and are bound by a contractual confidentiality obligation.
  • Push notification platforms: Companies such as OneSignal or Firebase Cloud Messaging (Google) act as operators of token, device, and notification engagement data, under a confidentiality agreement and in accordance with their own privacy policies.
  • Ad technology providers and DSPs: Google LLC (including Google Ad Manager and bidding partners) and Meta Platforms, for the display of personalized ads. The full IP address may be shared in real time with these partners during the real-time bidding process. These partners are prohibited from using the data for purposes other than those disclosed here. To learn how Google uses information from websites that use its services, visit: policies.google.com/technologies/partner-sites (required by Google Ad Manager).
  • Legal obligation: when required by law, court order, or a competent authority.
  • Protection of rights: when necessary to protect the rights, property, or safety of the website, its users, or third parties.

6. User Rights

Under the LGPD, you have the following rights regarding your personal data:

  • Access: to obtain confirmation of what personal data we are processing and to receive a copy of it.
  • Rectification: to correct inaccurate or incomplete data.
  • Deletion (right to be forgotten): to request the deletion of your data, except where there is a legal obligation to retain it.
  • Portability: to receive your data in a structured, machine-readable format for transfer to another service.
  • Objection: to object to the processing of your data for direct marketing or profiling purposes.
  • Restriction: Request that the processing of your data be restricted under certain circumstances.
  • Withdrawal of consent: Withdraw your consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
  • Opting out of personalized advertising: You can disable the use of your data for personalized ads in your Google settings (adssettings.google.com) and Meta settings (facebook.com/ads/preferences).

To exercise any of these rights, please contact our Data Protection Officer (DPO) at the dedicated email address: privacidade@skallardigital.com.br

We will respond to your request within 15 business days.


7. Data Security

We have implemented appropriate technical and organizational measures to protect your data against unauthorized access, loss, destruction, or alteration, including:

  • Secure connection via HTTPS/SSL throughout the website
  • Restricted access control to internal systems
  • Regular security monitoring
  • Periodic software and system updates

Although we take all reasonable precautions, no security system is foolproof. In the event of a security incident affecting your data, we will notify affected users as required by the LGPD.


8. International Data Transfer (Users in the European Union)

The Albert Sabin website is operated by Skallar Marketing Digital LTDA, a company headquartered in Brazil. If you reside in the European Union (EU) or the European Economic Area (EEA), your personal data may be transferred and processed outside the EU, specifically:

  • Brazil: where Skallar Marketing Digital LTDA is established. Brazil does not yet have a formal adequacy decision from the European Commission. To ensure the protection of your data, we use the EU Standard Contractual Clauses (SCCs) as an appropriate safeguard.
  • United States and other countries: where our service providers (such as Google LLC, Meta Platforms, and Hostinger) are headquartered or operate servers. These providers participate in the EU-U.S. Data Privacy Framework or use equivalent transfer mechanisms approved by the EU.

You may request a copy of the safeguards applicable to the transfer of your data by contacting us at: privacidade@skallardigital.com.br


9. Links to Third-Party Websites

Our website may contain links to external websites. This Privacy Policy applies exclusively to albertsabin.com. We are not responsible for the privacy practices of other websites and recommend that you read their policies before providing any data.


10. Children and Adolescents

Our website is not directed at minors, and we do not intentionally collect personal data from children without the consent of their parents or legal guardians.

  • Brazil (LGPD): We provide special protection for individuals under 18 years of age, requiring specific consent from guardians for any data processing.
  • European Union (GDPR): The minimum age for independent consent ranges from 13 to 16 years, depending on the member country. To ensure full compliance with the GDPR, we apply the age limit of 16 for European users.

If we become aware that we have collected data from a minor without proper consent, we will delete that information immediately.


11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, applicable law, or the services we offer. The date of the last update will always be indicated at the top of this page. We recommend that you review this policy regularly.

Significant changes will be communicated via a prominent notice on the website or by email, where applicable.


12. Contact and Data Protection Officer (DPO)

For questions, requests, or complaints regarding this Privacy Policy or the processing of your personal data, please contact us:

  • Data Protection Officer (DPO) Email: privacidade@skallardigital.com.br
  • Data Controller: Skallar Marketing Digital LTDA
  • CNPJ: 34.179.719/0001-53
  • Address: Av. Cel. Pedro Maia de Carvalho, 399, Praia das Gaivotas, Vila Velha/ES, ZIP Code: 29.102-570

Users in Brazil: You have the right to file a complaint with the National Data Protection Authority (ANPD): www.gov.br/anpd

Users in the European Union: You have the right to file a complaint with the Data Protection Authority (DPA) in your country of residence within the EU. To find the competent authority in your country, visit: edpb.europa.eu — members of the European Data Protection Board