Privacy and Personal Data Protection Policy
International Newborn Brain Conference – INBBC
Last updated: August 2026
1. Purpose of this Policy
The International Newborn Brain Conference – INBBC recognizes the importance of privacy and of protecting the personal data of its participants, speakers, authors, website visitors, sponsors, suppliers, and other people related to the event.
This Policy explains:
- which personal data may be collected;
- the purposes for which it will be used;
- with whom it may be shared;
- how long it may be retained;
- what rights data subjects have;
- how to get in touch to exercise those rights.
2. Controllers
The INBBC is organized by the Newborn Brain Society – NBS and the Protegendo Cérebros Salvando Futuros Institute.
Depending on the activity, one of these entities may act as controller of the personal data, or both may make decisions regarding its processing.
The entity responsible for operating the registration and the financial transaction will be identified on the registration form, on the payment receipt, or on the corresponding fiscal document.
Contact details
- Newborn Brain Society — Email: info@inbbc.org — Address: PO Box 200783, Roxbury Crossing, Massachusetts 02120, United States.
- Protegendo Cérebros Salvando Futuros Institute — Email: contato@institutosalvandofuturos.org — Address: Avenida Paulista, 1079, 16th floor, São Paulo – SP, Brazil. CNPJ: 38.660.811/0001-91.
Privacy channel and data protection officer
Email: contato@institutosalvandofuturos.org
The specific responsibilities of each entity will follow the applicable contracts, the event's operational workflows, and applicable law.
3. Who this Policy applies to
This Policy applies to people who:
- visit or use the INBBC website;
- create an account;
- complete a registration or receive one as a courtesy;
- attend the event in person or virtually;
- submit scientific papers;
- act as speakers, moderators, or committee members;
- request information;
- receive communications;
- take part in surveys or evaluations;
- interact with sponsors and exhibitors through the event's official tools.
4. Personal data that may be collected
4.1. Identification and contact data
The following may be collected:
- full name;
- email address;
- phone number;
- country, state, and city;
- language;
- billing address for duly authorized charges;
- identification document, when necessary;
- profile photograph, when voluntarily provided.
4.2. Professional and academic data
The following may be collected:
- profession;
- specialty;
- position or role;
- institution;
- department;
- country of practice;
- academic background;
- professional category;
- membership number;
- information required to substantiate discounts;
- curriculum vitae, biography, and conflicts of interest, when applicable.
4.3. Registration and participation data
The following may be collected:
- registration category and modality;
- selected workshops and activities;
- session attendance;
- entry and check-in records;
- certificate issuance;
- continuing education credits;
- responses to surveys and evaluations;
- interactions with the virtual platform;
- communications with the support team.
4.4. Financial and payment data
The following may be processed:
- payer's name;
- billing address;
- CPF, CNPJ, tax identification, or equivalent information;
- transaction amount;
- currency;
- payment status;
- order number;
- receipts and information required for refunds.
Full credit card data will normally be processed directly by specialized payment companies and should not be stored by the Organizers, except when expressly disclosed and duly authorized under applicable law.
4.5. Accessibility, dietary, and specific needs data
Participants may voluntarily provide:
- accessibility needs;
- dietary restrictions;
- relevant allergies applicable to food;
- requests and/or needs related to mobility or participation;
- other needs required for their safety and inclusion.
This information may reveal sensitive personal data. For that reason, it will be requested only when necessary and processed on a restricted basis, with consent or another applicable legal basis.
Participants should not send medical information beyond what is strictly necessary to organize their participation. Likewise, information submitted by participants that is not applicable to the purposes set out in this Policy will be discarded.
4.6. Data of authors, scientific papers, and speakers
When abstracts are submitted or there is scientific participation, the following may be processed:
- authors' names;
- affiliations;
- email addresses;
- curriculum vitae and biography;
- academic identifiers;
- conflicts of interest;
- abstract or paper content;
- reviews and decisions of the scientific committee;
- presentations, photographs, audio, and video;
- information required for publication in the proceedings or event materials.
4.7. Technical and browsing data
While using the website or the virtual platform, the following may be collected:
- IP address and/or other information related to the means of access;
- date and time of access;
- browser and device type;
- operating system used;
- session identifiers;
- pages visited;
- clicks and interactions;
- error logs;
- security data;
- cookies and similar technologies.
4.8. Photographs, audio, and video
The following may be produced during the event:
- general photographs;
- capture of images and/or sound from speech and/or other sources;
- recordings of lectures;
- live broadcasts;
- interviews;
- testimonials;
- records of social and scientific activities.
Whenever required, individualized or promotional use of image and voice will be carried out under specific authorization, which may be obtained through prior consent.
5. How data may be obtained
Data may be obtained:
- directly from the data subject, through prior and/or incidental disclosure;
- from the person or institution registering on the participant's behalf;
- from partner organizations offering discounts or registrations;
- from registration, payment, or broadcasting platforms;
- from sponsors or exhibitors, when the data subject requests an interaction;
- through cookies and technical logs;
- from public professional or academic sources, when necessary for scientific organization and permitted by law.
6. Purposes of processing
Data may be used to:
- create and manage accounts;
- process registrations and payments;
- validate categories and discounts;
- issue receipts, invoices, certificates, and educational credits;
- organize workshops and sessions, and direct them according to matching profiles;
- provide in-person or virtual access;
- send confirmations, instructions, and operational updates;
- answer questions and provide support;
- ensure security, prevent fraud, and control access;
- accommodate accessibility and dietary needs;
- organize scientific reviews and paper submissions;
- publish programs, proceedings, and scientific materials;
- document and promote the event;
- comply with tax, accounting, regulatory, and legal obligations;
- defend rights in administrative, judicial, or arbitration proceedings;
- conduct satisfaction surveys aimed at matching participant profiles;
- produce statistics and analyses, preferably in aggregate form;
- improve the website, the services, and future editions of the event;
- send institutional and promotional communications, where permitted;
- respond to requests from competent authorities.
7. Legal bases used
Depending on the activity and applicable law, processing may be based on:
- performance of a contract or procedures related to the registration;
- compliance with a legal or regulatory obligation;
- regular exercise of rights;
- legitimate interest of the Organizers or third parties, following assessment and permissions granted by the data subjects;
- fraud prevention and security;
- consent;
- protection of life or physical integrity, in exceptional situations;
- other grounds provided for in applicable law.
Consent will not be used when another legal basis is better suited to the data subjects' expression of will.
When processing depends on consent, the data subject may withdraw it, without affecting the lawfulness of processing carried out previously.
8. Operational and promotional communications
8.1. Operational communications
Participants may receive messages necessary to carry out the registration, including:
- payment confirmation;
- access information;
- program changes;
- check-in guidance;
- security communications;
- certificates;
- information about cancellations or refunds.
These messages are essential to providing the service and do not depend on marketing consent.
8.2. Promotional communications
News about future conferences, activities, programs, or partners will only be sent where there is an adequate legal basis.
Whenever such communications depend on consent, the option will be presented separately and unchecked by default.
Data subjects may unsubscribe at any time through the link available in the message itself or through the privacy channel.
9. Data sharing
Data may be shared, to the extent necessary, with:
- companies responsible for the registration platform;
- payment processors;
- technology, hosting, and storage providers;
- broadcasting and audiovisual companies;
- event organization agencies and companies;
- the event venue and check-in and security companies;
- catering suppliers, when necessary to accommodate restrictions declared by participants;
- companies responsible for certificates or accreditation;
- consultants, auditors, accountants, and legal advisors;
- partner scientific organizations;
- public authorities, when legally required;
- sponsors or exhibitors, only when authorized or requested by the data subject.
Providers must receive only the data that is necessary and use it in accordance with the applicable instructions and contracts.
The Organizers do not sell participants' personal data.
10. Sponsors, exhibitors, and badge scanning
Providing data to sponsors for their own marketing will not be a condition for attending the event.
When a participant voluntarily allows their badge to be scanned, fills in a form, or provides their data directly to an exhibitor, they are authorizing the sharing of the information indicated at that moment.
From that point on, the sponsor or exhibitor may act as an independent controller and must make its own privacy policy available.
11. International data transfers
Because the INBBC is international in nature and involves entities, participants, and providers located in different countries, personal data may be stored or processed outside the data subject's country of residence.
Such transfers may occur, for example, between Brazil, the United States, countries of the European Economic Area, and locations where technology providers are established.
Where required, adequate protection mechanisms will be adopted, including:
- contractual clauses;
- standard clauses approved by the competent authorities;
- verification of an adequate level of protection;
- technical and organizational measures;
- specific consent, when applicable;
- other legally authorized grounds.
12. Cookies and similar technologies
The website may use cookies and similar technologies.
12.1. Necessary cookies
These are used for essential functions, such as:
- keeping the session active;
- completing the registration;
- ensuring security;
- processing payments;
- remembering essential choices.
These cookies cannot be disabled through the website's preference panel when they are indispensable to its operation.
12.2. Analytics and performance cookies
These may be used to understand how visitors use the website and to improve its performance.
Where required, they will only be activated after the user's consent.
12.3. Advertising or social media cookies
These may be used for campaigns, personalized content, or social media integration.
These cookies must depend on consent where required.
Users may manage non-necessary cookies through the banner or preference panel available on the website.
13. Retention period
Data will be retained only for the period necessary to fulfill the purposes described in this Policy.
As general criteria:
- registration and payment data and related documents may be retained for the period necessary to comply with legal, tax, and accounting obligations and to defend rights, generally for up to five years after the event, unless a different period is required by law;
- technical logs will be retained for the period necessary for security and compliance with legal obligations;
- data used for marketing will be retained until consent is withdrawn, an objection is raised, or the purpose ends;
- abstracts, programs, proceedings, and scientific records may be preserved as part of the event's historical and academic archive;
- institutional photographs and recordings may be retained for as long as they remain relevant to the disclosed purposes, respecting the data subject's rights.
After the applicable period ends, data will be deleted, anonymized, or securely retained where such retention is permitted or required.
14. Information security
The Organizers will seek to adopt technical, administrative, and organizational measures proportionate to the risks, including:
- access control;
- use of specialized providers;
- authentication and credential management;
- backups;
- security monitoring;
- restricted access to sensitive data;
- confidentiality agreements;
- incident response procedures.
No system is completely immune to risk. In the event of a relevant incident, the measures provided for by law will be taken, including notifying data subjects and authorities when necessary.
15. Data subject rights
Under applicable law, data subjects may request:
- confirmation that processing exists;
- access to their data;
- correction of incomplete, inaccurate, or outdated data;
- information about sharing;
- anonymization, blocking, or deletion of unnecessary or unlawfully processed data;
- portability, where applicable;
- deletion of data processed on the basis of consent, except in cases where retention is legally required;
- information about the possibility of withholding consent and its consequences;
- withdrawal of consent;
- objection to processing;
- review of decisions made solely by automated means, where applicable;
- the filing of a complaint with the Brazilian National Data Protection Authority or the competent authority in their country.
Requests may require identity confirmation to protect the data subject against fraud.
Some requests may be limited when retention or processing is necessary to comply with a legal obligation, perform the contract, protect third parties, exercise rights, or in other cases provided for by law.
16. Participants in the European Economic Area and other jurisdictions
Where applicable, participants located in the European Economic Area, the United Kingdom, or other jurisdictions may exercise additional rights provided for under their local laws.
These rights may include:
- restriction of processing;
- portability;
- objection to legitimate interest;
- filing a complaint with the local supervisory authority.
17. Data of children and adolescents
The website and registrations are primarily intended for adults and professionals.
Individuals under 18 may only register through their legal guardians or with appropriate authorization.
The Organizers do not intend to knowingly collect children's data without the involvement or authorization of their guardians.
18. Automated decisions
The Organizers do not intend to make decisions producing relevant legal effects solely by automated means.
Automated tools may be used for fraud prevention, security, registration management, and statistical analysis. Where applicable, data subjects may request information and review under the terms of the law.
19. Third-party websites and platforms
This Policy does not apply to third-party websites, systems, or services accessed through external links.
Data subjects should review each third party's privacy policy before providing their data.
20. Changes to this Policy
This Policy may be updated to reflect legal, technological, or operational changes.
The most recent version will be published on the website with the update date.
Relevant changes may be communicated by email or through a prominent notice on the website.
21. How to exercise your rights
Privacy-related requests, questions, or complaints may be sent to:
INBBC Privacy Channel — Email: contato@institutosalvandofuturos.org
The request must contain enough information to identify the data subject and understand the request.
Data subjects may also file a complaint with the Brazilian National Data Protection Authority – ANPD or with the competent data protection authority in their country.