Privacy Policy

This policy explains what personal data the website locusmariologicus.org collects, what it uses it for, who it shares it with, how long it keeps it and how you can exercise your rights. It applies to all visitors to and readers of the website, whether they are in Brazil, in Portugal, elsewhere in the European Union or anywhere else in the world.

It has been written to comply with Brazil’s General Personal Data Protection Law (Lei Geral de Proteção de Dados Pessoais, LGPD, Law No. 13,709/2018) and with the European Union’s General Data Protection Regulation (GDPR, Regulation (EU) 2016/679). In this policy, to ‘process’ data means to carry out any operation on it, such as collecting, storing, using, sharing or erasing it.

1. Who the controller is and how to contact us

The controller of your personal data (the ‘controlador’, in the terminology of the LGPD) is:

  • LOCUS MARIOLOGICUS BR LTDA, trading as Locus Mariologicus
  • Brazilian limited liability company (sociedade empresária limitada), CNPJ (company registration number) 37.255.183/0001-04
  • Registered office: Rua Desembargador Paulo Mota, 1338, casa 2, bairro Ouro Preto, Belo Horizonte, MG, CEP 31320-022, Brazil

On the website, the controller presents itself as an institute of Mariology, under the name Locus Mariologicus. In this policy, ‘we’, ‘us’ and ‘the institute’ refer to this controller.

  • General enquiries: info@locusmariologicus.org
  • Requests concerning privacy and personal data: danielafonso@locusmariologicus.org
  • Officer in charge of the processing of personal data (the ‘encarregado’ under the LGPD) and contact point for data protection (GDPR): Daniel Afonso, at the same address
  • Representative in the European Union (GDPR, Article 27): Daniel Afonso, Rua da Mó, 3087, Fregim, 4600-595 Amarante, Portugal, at the same email address

2. What data we collect and where

Free reader registration. In articles, a card may interrupt your reading and invite you to register for free. There is also a dedicated registration page. When you register, we collect:

  • your name
  • your email address
  • your WhatsApp number, with the country code (optional)
  • your country
  • the language of the page on which you registered
  • the article on which you registered
  • your IP address
  • the date of registration

To register, we ask for your name and email address. WhatsApp is optional and, if you do not provide your number, you will not receive messages that way. The other items in the list are recorded automatically at the moment you register.

You are not obliged to register. Without registering, you can browse the website and read the beginning of articles, but the full text of articles only becomes available once you have registered.

Free registration includes the weekly email newsletter. When you register, you will start receiving the newsletter with our new studies and, if you gave us your number, WhatsApp messages. You can unsubscribe from the newsletter at any time, with one click, using the link included in every newsletter email.

Your registration details are kept in a dedicated table in the website’s database, which runs on WordPress. They are also copied to a database on the Supabase service, which we use to organise the sequence of messages sent to readers. A cookie, valid for 365 days, is placed in your browser to remember your registration and let you read all articles without filling in the form again.

Browsing, analytics and cookies. When you visit the website, the company that hosts it, Hostinger, and the Cloudflare network receive your IP address and technical data about your visit, such as your browser type. They need this information to deliver the pages and protect the website.

We also use analytics and advertising tools, which collect information about your visit, such as the pages viewed and where the visit came from. These are Google Analytics 4, the Meta Pixel and Cloudflare Web Analytics. Google Analytics and the Meta Pixel are only activated if you give your consent in the cookie banner (CookieYes). Cloudflare Web Analytics does not use cookies and only produces aggregated figures. The list of cookies and their retention periods is available in the cookie banner, which you can open at any time through the Cookie settings link in the footer of every page.

Browser notifications. If you agree to receive notifications from the website in your browser, the OneSignal service stores a technical identifier for your browser in order to send you those notifications. If you do not agree, none of this happens.

Comments. If you comment on an article, the website’s comment system (WordPress and BuddyBoss) stores your name, your email address, the text of your comment and your IP address.

Messages by email or WhatsApp. If you write to us, we receive the data you send us, such as your name, email address or phone number and the content of your message.

Content from other services. Some pages load elements from other services, namely typefaces from Google Fonts and videos from Panda Video and YouTube. To display them, your browser requests this content directly from the servers of those services, which therefore receive your IP address and technical data about your visit.

External platforms. The website contains links to the student area (MemberKit) and to external shops (Nuvemshop and Shopify). When you open one of these links, you leave our website and the privacy policy of that platform applies.

Students and enrolments. Data relating to students and to course enrolments is not covered by this policy. It is processed on the course platforms and is subject to its own rules.

Minors. The website is not aimed at children or at anyone under the age of 16. Reader registration is intended for people aged 18 or over. People aged 16 or 17 should only register with the permission of a parent or legal guardian. If you become aware that a minor has given us data without that permission, please write to us and we will erase that data.

3. What we use it for and on what legal basis

We only use your data for specified purposes and always on a legal basis provided for in the LGPD (Article 7) and in the GDPR (Article 6).

Consent (LGPD, Article 7, item I, and GDPR, Article 6(1)(a)). With your consent, we use your data to:

  • unlock all articles in your browser after you register
  • send you the welcome email
  • send you the weekly email newsletter with our new studies
  • send you WhatsApp messages, if you gave us your number
  • if you accept the relevant cookies, measure how many people visit the website and where they come from (Google Analytics)
  • if you accept the relevant cookies, measure the results of our advertisements on Facebook and Instagram and choose who sees them, which may include people who have already visited the website (Meta Pixel)
  • send you browser notifications, if you have accepted them
  • publish the comment you send us

You can easily withdraw your consent at any time, as explained in section 7. Withdrawing consent does not affect processing carried out before the withdrawal.

Data that may reveal religious beliefs. This is a Marian theology website. For that reason, your registration, the article on which you registered and the pages you read may reveal your religious beliefs, which the law protects as sensitive data (LGPD, Article 5, item II, and Article 11, and GDPR, Article 9). We only process this data with your consent (LGPD, Article 11, item I, and GDPR, Article 9(2)(a)). You give this consent when you register and in the cookie banner, and you can withdraw it at any time.

Legitimate interests (LGPD, Article 7, item IX, and GDPR, Article 6(1)(f)). We use your data, in particular your IP address, to:

  • ensure the security of the website
  • prevent abuse, such as fake registrations or spam comments
  • count visits in aggregate form, without cookies (Cloudflare Web Analytics)
  • display the videos embedded in the pages (Panda Video)
  • reply to the messages you send us

In these cases, we always check that our interests do not override your rights. You can object to this processing, as explained in section 7.

Compliance with a legal obligation (LGPD, Article 7, item II, and GDPR, Article 6(1)(c)). Where applicable, we process data to comply with obligations laid down by law. For example, Brazilian law requires us to keep website access records (IP address, date and time) for six months and to hand them over to the authorities under a court order (Marco Civil da Internet, Brazil’s Civil Rights Framework for the Internet, Law No. 12,965/2014, Article 15). We also respond to requests from competent authorities where the law requires it.

4. Who we share it with

For the website to work, we use suppliers that process data on our behalf (processors, known as ‘operadores’ under the LGPD):

  • Website hosting: Hostinger
  • Security, caching, page delivery and aggregated statistics: Cloudflare
  • Sending emails: Google Workspace (Gmail) and, for bulk sending, Resend
  • Database for the sequence of messages to readers: Supabase
  • Browser notifications, only if you accept them: OneSignal
  • Cookie consent management: CookieYes
  • Videos embedded in the pages: Panda Video

Other services receive data when they are loaded on the pages or when you use them, and they also decide for themselves what to do with that data, in accordance with their own privacy policies:

  • Google: Google Analytics, Google Tag Manager, Google Fonts and YouTube
  • Meta: Meta Pixel and WhatsApp (messages to readers who have given us their number)

In the case of the Meta Pixel, we are joint controllers with Meta for collecting data about your visit and transmitting it to Meta. From that point on, Meta alone is responsible for what it does with that data. You can read Meta’s privacy policy at facebook.com/privacy/policy and Google’s at policies.google.com/privacy.

We may also disclose data to public authorities where the law requires it.

5. Transfers outside the EU and Brazil

The institute is based in Brazil. Several of our suppliers are located outside Brazil and the European Union, mainly in the United States: Google, Meta, Cloudflare, OneSignal, Resend and Supabase. As a result, your data may be processed outside the country in which you are located.

These transfers rely on safeguards provided for by law. For the data of people in the European Union, they rely on the European Commission’s adequacy decision for the United States (EU-US Data Privacy Framework), where the supplier is certified, and on the standard contractual clauses approved by the European Commission in all other cases (GDPR, Articles 45 and 46). Under Brazilian law, they rely on the standard contractual clauses approved by the ANPD (Brazil’s National Data Protection Authority), in accordance with the LGPD, Article 33, item II, point (b), and Resolution CD/ANPD No. 19/2024.

These clauses are model contracts approved by the authorities, which require the supplier to protect your data. You can request a copy of these safeguards by writing to danielafonso@locusmariologicus.org.

6. How long we keep it

  • Reader registration. We keep your data for as long as your registration remains active, with no fixed time limit. Your registration ends when you ask us to remove you or to erase your data. From that moment, we stop sending you messages and we erase your registration data from the website’s database and from the copies on Supabase. The email sending services do not keep your record, only the technical log of each message sent, which the supplier itself deletes at the end of its own retention period. The institute’s mailbox keeps a copy of the welcome email we sent you, and we also erase it when you request erasure. After that, we keep only what is necessary to prove that we have complied with your request or to comply with a legal obligation. The cookie that remembers your registration stays in your browser for up to 365 days, and you can delete it whenever you wish.
  • Website access records. The IP address, date and time of each visit are kept for six months, the period required by Brazilian law, or for longer if there is a court order.
  • Analytics and cookies. Retention periods depend on each supplier and each cookie. They are set out in the cookie banner (the Cookie settings link, in the footer of every page).
  • Browser notifications. The identifier is stored by OneSignal, for the periods set by that supplier. We stop using it when you turn off notifications, which you can do at any time in your browser settings.
  • Comments. These are kept for as long as the comment remains published, or until you ask for it to be deleted.
  • Messages you send us. These are kept for as long as necessary to deal with the matter. You can ask for them to be erased.
  • Students and enrolments. These are subject to their own rules, on the course platforms.

7. Your rights and how to exercise them

As a data subject, you have the right to:

  • know whether we process your data and have access to it
  • have incomplete, inaccurate or out-of-date data corrected (rectification)
  • request the erasure (deletion) of your data
  • request the anonymisation, blocking or deletion of data that is unnecessary, excessive or processed in breach of the law
  • ask us to suspend the use of your data in certain cases, for example while a correction or a complaint is being verified (restriction of processing)
  • receive your data in a commonly used format that you can take to another service, and ask us to send it directly to that service (portability)
  • object to processing based on legitimate interests
  • withdraw your consent at any time, without affecting processing carried out beforehand
  • be informed that you may refuse to give consent and of the consequences of doing so
  • know which entities we share your data with
  • request a review of decisions taken solely on the basis of automated processing

The website does not take automated decisions that produce legal effects concerning people.

To exercise any of these rights, write to danielafonso@locusmariologicus.org. Your request is free of charge. To protect your data, we may ask you to confirm your identity. We reply within 15 days if you are in Brazil (LGPD) and within one month if you are in the European Union (GDPR). If your request is complex, the GDPR time limit may be extended by a further two months. In that case, we will let you know within the first month and explain why.

To stop receiving the newsletter, use the unsubscribe link included in every newsletter email. One click is all it takes. To stop receiving WhatsApp messages, to cancel your registration or to have your data erased, write to danielafonso@locusmariologicus.org. To change your cookie choices, use the Cookie settings link in the footer of every page. To stop receiving notifications, turn them off in your browser settings.

If you believe that your data has not been processed in accordance with the law, you can lodge a complaint with the competent authority:

  • in Brazil, the National Data Protection Authority (Autoridade Nacional de Proteção de Dados, ANPD) or consumer protection bodies
  • in Portugal, the Comissão Nacional de Proteção de Dados (CNPD, Portugal’s National Data Protection Commission)
  • in other European Union countries, and also in Iceland, Liechtenstein and Norway, the local data protection authority
  • in all other countries, the competent authority, if there is one

If you prefer, you can write to us first, so that we can try to resolve the matter directly.

8. Cookies

Cookies are small pieces of information that the website stores in your browser. Some are necessary for the website to work securely. There is also the cookie that remembers your reader registration, valid for 365 days. Analytics and advertising cookies, from Google Analytics and the Meta Pixel, are only activated if you give your consent.

We manage cookies through the cookie banner (CookieYes), which you can open at any time through the Cookie settings link in the footer of every page. In that banner you can accept, reject or choose by category, change your choices and see the list of cookies, their purposes and their retention periods. If you reject analytics and advertising cookies, the website works in the same way.

9. Changes and version date

We may update this policy when the services we use or the law change. The version in force is always the one published on this page, with its version date.

When a change is significant, we will notify registered readers by email. If a change alters the purpose of data processed with your consent, we will notify you before applying it and, where the law requires it, ask for your consent again.

Version dated 15 September 2026.