Last updated: 9 September 2026
Dantesco is a commentary and critique magazine with an international readership and a community of contributors. This policy explains what personal data we collect, why we collect it, who we share it with, and the rights you have over it.
It is written to satisfy both the Brazilian Lei Geral de Proteção de Dados (LGPD, Law 13.709/2018) and the European General Data Protection Regulation (GDPR, Regulation 2016/679), because our operations are based in Brazil and a substantial part of our readership is in the European Union.
1. Who is responsible for your data
Data controller
Felipe Dizioli — publisher of Dantesco, acting as a natural person
São Paulo, Brazil
Contact for privacy matters: publisher@dantes.co
Dantesco is currently published by an individual and not by an incorporated entity. When a company is formed, this section will be updated with its legal name, registration number and registered address, and the change will be announced on this page.
2. What we collect
2.1 Data you give us deliberately
- Account data — when you register: username, display name, e-mail address, and the password (stored only as a cryptographic hash, never in readable form).
- Profile data — anything you choose to add to your public profile: biography, avatar, cover image, links.
- Content you publish — essays, comments, forum posts, activity updates and messages inside the community area. This content is published under your name and is visible according to the rules described in section 6.
- Newsletter subscription — your e-mail address and the language you chose.
- Messages sent through the contact form — your name, e-mail address and the content of your message.
2.2 Data collected automatically
- Technical log data — IP address, browser and operating system, referring page, and the date and time of each request. Our host records this for security and abuse prevention.
- Audience measurement — pages visited, time on page, approximate geographic region and device type, collected through Google Analytics.
- Cookies and equivalent technologies — described in detail in our Cookie Policy.
3. Why we process it, and on what legal basis
| Purpose | Legal basis (LGPD) | Legal basis (GDPR) |
|---|---|---|
| Creating and maintaining your account; letting you publish and interact | Art. 7, V — performance of a contract | Art. 6(1)(b) — contract |
| Sending service e-mails (activation, password reset, replies and mentions) | Art. 7, V — performance of a contract | Art. 6(1)(b) — contract |
| Sending the newsletter and editorial announcements | Art. 7, I — consent | Art. 6(1)(a) — consent |
| Audience measurement and improving the publication | Art. 7, IX — legitimate interest | Art. 6(1)(f) — legitimate interest |
| Security, abuse prevention and moderation | Art. 7, IX — legitimate interest | Art. 6(1)(f) — legitimate interest |
| Complying with legal obligations | Art. 7, II — legal obligation | Art. 6(1)(c) — legal obligation |
Where we rely on consent, you may withdraw it at any time — this does not affect the lawfulness of processing carried out before the withdrawal. Where we rely on legitimate interest, you have the right to object; see section 7.
4. Who else touches your data
We do not sell personal data and we do not share it for third-party advertising. We do rely on service providers who process data on our behalf:
- GoDaddy — hosting and content delivery. Servers in the United States.
- Resend — delivery of transactional and newsletter e-mail. Servers in the United States.
- Google — Google Analytics for audience measurement, Google Fonts for typography, and Google AdSense for advertising. Google operates globally.
- Akismet (Automattic) — spam filtering for comments and registrations. Servers in the United States.
We may also disclose data when required by a court order, by a competent authority, or to defend our rights in legal proceedings.
5. International transfers
Because our host and our service providers are based in the United States, your personal data is transferred outside Brazil and outside the European Economic Area.
For transfers out of the EEA, these providers rely on the European Commission’s Standard Contractual Clauses and, where applicable, on the EU–US Data Privacy Framework. For transfers out of Brazil, we rely on LGPD Art. 33, II (contractual clauses offering an adequate level of protection) and, for account-related transfers, on Art. 33, VI (necessary for the performance of a contract).
6. What is public and what is not
Dantesco is a publication, so part of what you do here is deliberately public:
- Public to anyone, including search engines: essays and articles you publish, your author name, your public profile page if you are a contributor, and comments on published articles.
- Visible only to logged-in members: the Society Hall activity feed, member directory beyond contributors, Circles, forum discussions, and profile details other than name and biography.
- Never public: your e-mail address, your IP address, your password, and any message you send us privately.
7. Your rights
Under LGPD Art. 18 and GDPR Arts. 15–22, you may:
- Confirm and access — know whether we process your data and obtain a copy of it.
- Correct — have incomplete, inaccurate or outdated data fixed.
- Delete — request the deletion of your data and your account.
- Port — receive your data in a structured, machine-readable format.
- Object and restrict — object to processing based on legitimate interest, or ask us to restrict it.
- Withdraw consent — unsubscribe from the newsletter at any time, through the link in every e-mail.
- Be informed — know with whom we have shared your data.
- Complain — to the Brazilian Autoridade Nacional de Proteção de Dados (ANPD) or, in the EU, to your national supervisory authority.
Write to publisher@dantes.co. We answer within 15 days as required by the LGPD, and within 30 days as required by the GDPR — in practice, whichever is sooner. We may ask you to confirm your identity before acting on a request.
A note on deletion: if you delete your account, we remove your personal data. Essays and articles already published remain online, because they are part of the editorial record of the magazine — but on request we will remove your name from them and attribute them to a former contributor.
8. How long we keep it
- Account and profile data — while your account exists, and for 30 days after deletion to allow recovery from mistakes.
- Published content — indefinitely, as part of the editorial archive.
- Newsletter address — until you unsubscribe.
- Server logs — up to 12 months.
- Analytics data — up to 14 months.
- Contact form messages — up to 24 months.
9. Security
The site is served exclusively over HTTPS. Passwords are stored as salted hashes. Administrative access requires individual accounts, and application-level credentials are rotated. No system is perfectly secure, and we will notify you and the competent authority of any breach likely to result in significant risk to your rights, as required by LGPD Art. 48 and GDPR Art. 33.
10. Children
Dantesco is not directed at children. We do not knowingly create accounts for anyone under 16. If you believe a child has registered, write to publisher@dantes.co and we will delete the account.
11. Changes to this policy
When we change this policy we update the date at the top. If the change is material — a new purpose, a new category of data, a new processor — we announce it on the site and, for registered members, by e-mail before it takes effect.
