Privacy policy
Last updated August 19, 2026
This policy explains what MARIA CRISTINA ROSSI LTDA collects when you visit sagefire.online, why, who we share it with, and what you can require us to do about it.
1. Who we are
The controller (controlador) of personal data collected through this website is:
MARIA CRISTINA ROSSI LTDA (CNPJ 54.457.372/0001-70)
Av. Paulista 1636, Conj 04, Bela Vista, Sao Paulo - SP, 01310-100, Brazil
Email: [email protected]
Website: https://sagefire.online/
MARIA CRISTINA ROSSI LTDA is a company established in Brazil. Because our processing activity is carried out in Brazil, Brazil’s Lei Geral de Proteção de Dados (LGPD, Law No. 13,709/2018) applies to it. Because this site is read in the United States, Europe and elsewhere, the GDPR and U.S. state privacy laws including the CCPA/CPRA may apply as well. Where these give you overlapping rights, we apply whichever is more protective of you.
2. What we collect
Information you give us
- Contact form submissions — your name, email address, and the content of your message. We use this only to reply.
Information collected automatically
Very little, because this site runs no analytics and no advertising tags.
- Server logs — our hosting provider records your IP address, the page requested, a timestamp, and your browser’s user-agent string, in order to serve the site and protect it from abuse. We do not use these to profile you.
- Advertising click parameters — if you arrive from an advertisement, identifiers such as
gclidmay be present in the URL. When you click through to a merchant these are appended to the outbound link so the merchant can attribute the visit. They travel in the URL only: we do not store them and we do not set a cookie to remember them.
We set no cookies and write nothing to your browser’s local storage. See our cookie policy.
What we do not collect
We do not collect payment card details, and we never see them — purchases happen entirely on the merchant’s site. We do not knowingly collect data from anyone under 18. We do not ask for, and do not want, health information about you; please do not send it through our contact form.
3. Why we process it, and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Serving the website securely | Server logs | Legitimate interests — GDPR Art. 6(1)(f), LGPD Art. 7, IX |
| Replying to enquiries | Contact form data | Your request / legitimate interests — GDPR Art. 6(1)(b) or (f), LGPD Art. 7, V or IX |
| Affiliate attribution | Click parameters passed in the outbound URL | Legitimate interests — no storage, no cookie |
| Meeting legal and tax obligations | Correspondence records | Legal obligation — GDPR Art. 6(1)(c), LGPD Art. 7, II |
We do not currently rely on consent for anything, because we operate no analytics or advertising technology. If that changes we will introduce a consent mechanism and update this policy before setting anything that requires consent.
4. Third parties we share data with
We do not sell or share your personal information, and we do not disclose it to advertising partners. There is no analytics vendor and no advertising vendor in the chain. Two service providers necessarily process data as part of delivering the site:
- Our hosting provider, which processes server logs including IP addresses in order to serve the site.
- Our email provider, where you write to us.
The merchant you click through to is a separate matter. When you follow an affiliate link you leave this site, and what the merchant collects is governed by their privacy policy, not ours. We receive only aggregate commission reporting — never your name, address, or payment details.
Note for California residents: because we disclose nothing to advertising partners for cross-context behavioural advertising, no “sale” or “share” under the CCPA/CPRA takes place on this site. Your other rights are unaffected — see section 7.
5. International transfers
We are established in Brazil and most of our readers are not, so data crosses borders by the nature of the arrangement.
- Into Brazil: correspondence you send us is read and stored where we operate.
- Out of Brazil: our hosting and email providers may process data in the United States or the European Union.
For transfers subject to the LGPD, we rely on the grounds permitted by Art. 33 — principally the necessity of the transfer for performance of a contract or a procedure to which you are a party, your specific consent where applicable, and contractual clauses with our providers.
For transfers of data originating in the European Economic Area or the United Kingdom, we rely on appropriate safeguards, principally the European Commission’s Standard Contractual Clauses. Note that Brazil has not received an EU adequacy decision, so transfers to us from the EEA rest on those clauses rather than adequacy.
6. How long we keep it
- Contact form messages: up to 24 months from the last correspondence.
- Server logs: typically 30–90 days, per our hosting provider.
- Analytics data: none is collected.
7. Your rights
Under the LGPD (any data subject, since we process in Brazil): Article 18 gives you the right to obtain confirmation that processing exists; to access your data; to correct incomplete, inaccurate or outdated data; to request anonymisation, blocking or deletion of unnecessary or excessive data or data processed unlawfully; to data portability; to deletion of data processed on the basis of consent; to information about the public and private entities with which we have shared your data; to information about the possibility of refusing consent and the consequences of doing so; and to revoke consent. You may also petition the ANPD (Autoridade Nacional de Proteção de Dados) directly.
If you are in the EEA or UK (GDPR): you have the right to access your data, correct it, have it erased, restrict or object to processing, receive it in a portable format, and withdraw consent. You may also complain to your national data protection authority.
If you are in California (CCPA/CPRA): you have the right to know what is collected and to whom it is disclosed, to delete it, to correct it, to opt out of sale or sharing for cross-context behavioural advertising, and not to be discriminated against for exercising these rights.
Other U.S. states including Virginia, Colorado, Connecticut, Utah and Texas provide broadly comparable rights.
To exercise any of these, email [email protected] with the subject line “Privacy request”. We will respond within the period the applicable law requires — immediately in simplified form or within 15 days under LGPD Art. 19, 30 days under GDPR, 45 days under CCPA — and may need to verify your identity first. Exercising these rights is free of charge.
There are no advertising or analytics cookies on this site to opt out of. Requests concerning data held by a merchant you purchased from must be made to that merchant, since we do not hold it.
8. Data protection contact
Privacy questions and requests go to [email protected]. That address is our channel for communication with data subjects and with supervisory authorities, as contemplated by LGPD Art. 41.
We operate as a small-scale processing agent (agente de tratamento de pequeno porte) within the meaning of ANPD Resolution CD/ANPD No. 2/2022, and process a very limited amount of personal data: server logs and any message you choose to send us. Under that resolution small processing agents are not required to formally appoint an encarregado, but must maintain a communication channel — which is the address above. If our processing grows beyond that threshold we will appoint an encarregado and publish their details here.
9. Do Not Track and Global Privacy Control
We honour the Global Privacy Control (GPC) signal where your browser sends it. In practice it changes nothing on this site, because we already do not sell or share personal information and set no tracking cookies. There is no consistent industry standard for the older Do Not Track header, and we do not respond to it separately.
10. Security
The site is served over HTTPS and we apply reasonable technical and organisational measures to protect the limited data we hold. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Children
This site is intended for adults. We do not knowingly collect personal information from anyone under 18, and we do not direct any content at children. The LGPD (Art. 14) affords specific protection to the processing of children’s and adolescents’ data, and the U.S. COPPA rule protects children under 13. If you believe a minor has provided us with data, contact us and we will delete it.
12. Changes to this policy
We may update this policy. The revision date at the top always reflects the current version. Material changes will be flagged on the site.
13. Contact
Questions or requests: [email protected], or write to MARIA CRISTINA ROSSI LTDA (CNPJ 54.457.372/0001-70), Av. Paulista 1636, Conj 04, Bela Vista, Sao Paulo - SP, 01310-100, Brazil.
If you are not satisfied with our response, you may complain to the ANPD in Brazil, to your national data protection authority in the EEA or UK, or to your state attorney general in the United States.