Introduction
Zybro Tecnologia Ltda ("Zybro", "we", "our", or "us") operates the website zybrousa.com and provides laboratory management software and related professional services. We are incorporated in Brazil under CNPJ 67.850.285/0001-20, headquartered at Rua Cristiano Viana, 62, Apt 225, Cerqueira César, São Paulo – SP, Brazil.
This Privacy Policy describes how we collect, process, use, store, and disclose personal data when you visit our website, communicate with our team, or otherwise interact with us as a prospective or existing client. It applies to all individuals whose personal data we handle, regardless of their country of residence.
Our practices are designed to comply with Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD – Law 13.709/2018) and, where applicable, the General Data Protection Regulation of the European Union (GDPR – Regulation EU 2016/679), as well as other relevant data-protection laws. By accessing our website or otherwise providing us with personal information, you acknowledge that you have read and understood this policy.
If you have any questions or concerns before continuing, you are welcome to reach us directly at [email protected] at any time.
Information We Collect
We collect only the personal data that is necessary for the specific purpose for which it is gathered. The categories below describe the data we may hold about you and the circumstances under which it arises.
Data You Provide Directly
- Enquiry & Contact Data When you reach out to us by email, phone, or through any other direct communication channel, you may share your name, professional title, laboratory or institution name, email address, phone number, and the content of your message. We use this information exclusively to respond to your enquiry and, with your consent, to follow up with relevant information about our services.
- Commercial Relationship Data If you become a Zybro client or partner, we collect billing information, contract details, and account contact information as required to perform our contractual obligations, issue invoices, and provide technical support. This may include names of authorised users within your organisation.
Data Collected Automatically
- Log & Technical Data Our web servers automatically record certain technical details whenever a browser loads a page from our site. This includes your IP address (in truncated form where feasible), browser type and version, operating system, the pages you visit, time-stamps, and the URL of the page that referred you to us. This data is used for security monitoring, diagnosing server errors, and understanding aggregate traffic patterns.
- Analytics Data We use third-party analytics tools (see Section 4) to collect aggregated, pseudonymous information about how visitors navigate the site — which pages attract the most interest, how long sessions last, and where visitors drop off. This helps us improve the usefulness and clarity of our content.
- Cookie & Tracking Data We use cookies and similar technologies to maintain session state, remember your preferences, and, where you have consented, to deliver relevant advertising. A full description appears in Section 4.
We do not collect special-category (sensitive) personal data — such as health records, racial or ethnic origin, political opinions, or biometric identifiers — through this website.
How We Use Your Information
Every use of your personal data is grounded in at least one lawful basis as defined by the LGPD and the GDPR. The table below maps our purposes to the corresponding legal grounds.
- Responding to enquiries and communications When you contact us, we use your contact details to reply to your message promptly and accurately. Legal basis: performance of pre-contractual measures or our legitimate interest in providing responsive customer communication.
- Delivering our contracted services For active clients, we use personal data to onboard your team, provide software access, issue invoices, and fulfil all obligations under our service agreement. Legal basis: performance of a contract.
- Improving our website and services Anonymised and aggregated analytics data helps us understand how our website performs and where we can make it more helpful. Legal basis: legitimate interest, balanced against your rights and expectations as a visitor.
- Marketing communications We may send you information about new features, product updates, or industry insights by email — but only where you have expressly consented or where we have an existing business relationship that makes such communications reasonably expected. You may opt out at any time. Legal basis: consent or legitimate interest.
- Legal and regulatory compliance We may process personal data to comply with applicable laws, respond to lawful government requests, enforce our Terms of Service, or protect the rights, property, and safety of Zybro, our clients, and the public. Legal basis: compliance with legal obligation or legitimate interest.
Cookies & Tracking Technologies
Cookies are small text files placed on your device by your browser when you visit a website. They enable the site to remember certain information between page loads and sessions. We use four categories of cookies, as described below.
Strictly Necessary Cookies
These cookies are essential for the website to function correctly. They enable core features such as page navigation and access to secure areas. You cannot opt out of these cookies without impairing the basic operation of the site. No personal data collected by these cookies is used for any purpose other than enabling the service you requested.
Performance & Analytics Cookies
We use Google Analytics 4 to collect anonymised data about visitor behaviour, including pages visited, session duration, geographic region (country level), device type, and acquisition channel. Google Analytics is configured with IP anonymisation enabled, meaning no full IP address is stored. Data collected through GA4 is subject to Google's Privacy Policy. Analytics cookies are only placed if you have given consent through our cookie-preference mechanism.
Advertising & Targeting Cookies
Where you have consented, we may use Google Ads conversion tracking and remarketing tags to measure the effectiveness of our advertising campaigns and to show relevant Zybro advertisements to users who have previously visited our site. These cookies are managed through the Google Ads platform and operate under Google's advertising policies. You can manage your advertising preferences at adssettings.google.com or through the Digital Advertising Alliance opt-out tool.
Functional Cookies
Functional cookies allow the site to remember choices you have made — such as language or display preferences — to provide a more personalised experience. These cookies do not track your activity across other websites.
Managing Your Cookie Preferences
When you first visit our website, a consent banner invites you to accept or decline non-essential cookies. You can revisit and change your preference at any time by clearing your browser cookies and revisiting the site, or by adjusting your browser settings to block cookies. Note that blocking all cookies may affect the functionality of certain features.
Sharing With Third Parties
We share personal data with third parties only when there is a clear, lawful reason to do so. We never share information for the benefit of third parties' own commercial interests without your explicit consent. The categories of recipients who may access your data, and the reason for sharing, are described below.
- Service Providers & Processors We work with carefully selected companies that help us operate our website and deliver our services — including cloud hosting providers, email delivery platforms, analytics services, and customer-support tools. Each provider is bound by a Data Processing Agreement (DPA) that restricts them from using your data for any purpose other than performing the services contracted by Zybro.
- Google LLC As noted in Section 4, we use Google Analytics 4 and Google Ads for analytics and marketing measurement. Data shared with Google is governed by Google's terms and policies. Where transfers to the United States occur, they are subject to Google's compliance with Standard Contractual Clauses or equivalent safeguards.
- Professional Advisors Our lawyers, accountants, and auditors may access personal data when strictly necessary to perform their professional duties. All such parties are bound by confidentiality obligations.
- Legal & Regulatory Authorities We may disclose personal data to courts, law-enforcement bodies, regulatory agencies, or other public authorities when we are required to do so by applicable law, or when disclosure is necessary to protect the vital interests of individuals or to establish, exercise, or defend legal claims.
- Business Transfers In the event of a merger, acquisition, restructuring, or sale of all or part of Zybro's business, personal data held by us may be transferred to the successor entity. We will notify affected individuals and, where required by law, seek consent before any such transfer occurs.
When personal data is transferred outside Brazil or the European Economic Area (EEA), we ensure that appropriate safeguards are in place — such as Standard Contractual Clauses, the recipient country's adequacy decision, or another mechanism recognised under the LGPD and/or GDPR.
Data Retention
We retain personal data only for as long as is necessary to fulfil the purpose for which it was collected, or as required by law. When data is no longer needed, we delete it securely or anonymise it so that it can no longer be associated with any individual.
- Contact & Enquiry Data Data submitted through direct communications channels (email, phone) is retained for up to 24 months from the date of last contact. If no commercial relationship develops, data is deleted or anonymised at the end of that period. If a commercial relationship does develop, data migrates to the client file and is retained for the duration of the contract plus five years thereafter.
- Client Contract Data Personal data tied to an active client relationship is retained for the duration of the contract and for a minimum of five years after termination, to satisfy tax, accounting, and legal obligations under Brazilian law (in particular, the Brazilian Civil Code and Federal Revenue regulations).
- Analytics & Log Data Web server logs are retained for a maximum of 90 days, after which they are automatically purged. Google Analytics data is retained for 14 months within the GA4 platform, after which it is automatically deleted per our account configuration.
- Cookie Consent Records Records of your cookie preferences are retained for 12 months so that we do not re-prompt you unnecessarily and to demonstrate our compliance with consent requirements.
These retention periods may be extended where we are subject to a legal obligation to keep the data for longer, or where the data is needed to defend or pursue legal proceedings.
Data Security
Protecting your personal data is a core operational priority at Zybro. We implement a layered set of technical and organisational security measures designed to prevent unauthorised access, accidental loss, destruction, or disclosure of personal data.
Technical Measures
All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher (HTTPS). Access to systems that store personal data is restricted by role-based access controls, multi-factor authentication, and the principle of least privilege — meaning that only individuals who genuinely need access to perform their responsibilities are granted it. Our infrastructure is hosted on reputable cloud platforms that maintain their own extensive security certifications (including ISO 27001 and SOC 2).
Organisational Measures
Our team members who handle personal data are trained in data-protection principles and bound by confidentiality obligations. We conduct periodic internal reviews of our data-processing activities and update our practices in response to emerging threats, changes in regulation, and the evolving nature of our operations.
Incident Response
In the unlikely event of a data breach that poses a risk to the rights and freedoms of affected individuals, we will notify the relevant supervisory authority (Brazil's Autoridade Nacional de Proteção de Dados – ANPD) within the timeframe required by law, and we will communicate directly with affected individuals without undue delay when the breach is likely to result in a high risk to their rights.
Your Rights
Depending on your jurisdiction, you hold a number of rights over the personal data we hold about you. Brazilian residents enjoy rights under the LGPD (Art. 18 and related provisions), while residents of the European Union or EEA enjoy equivalent or analogous rights under the GDPR. In practice, we extend these rights to all individuals whose data we process, regardless of where they are located.
Right of Access
You may request a copy of the personal data we hold about you, along with information about how it is being used, the legal basis for processing, and who it has been shared with.
Right of Correction
If the personal data we hold is inaccurate, incomplete, or out of date, you have the right to request that we correct or update it without undue delay.
Right of Deletion
You may request that we delete your personal data where it is no longer necessary for the purpose it was collected, where consent has been withdrawn, or where processing is unlawful — subject to legal retention obligations.
Right to Object
You may object to processing carried out on the basis of legitimate interest, including direct marketing. Where you object, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
Right to Restrict Processing
In certain circumstances, you may request that we limit the ways in which we use your data — for example, while we verify the accuracy of data you have disputed.
Right to Data Portability
Where processing is based on consent or contract, and carried out by automated means, you may request that we provide your data in a structured, commonly used, and machine-readable format.
Right to Withdraw Consent
Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.
Right Not to Be Discriminated Against
Under the LGPD, you have the right not to suffer any discrimination — including denial of services — as a consequence of exercising your data-protection rights.
How to Exercise Your Rights
To make a request, please contact our Data Protection Officer by email at [email protected], clearly stating your name, the nature of your request, and — where relevant — the specific data or activity your request concerns. We will acknowledge your request within five business days and respond substantively within the timeframe required by applicable law (generally 30 days, with a possible extension of a further 30 days for complex requests).
We will need to verify your identity before fulfilling any request. This is to protect your data from being disclosed to, amended by, or deleted at the request of an unauthorised third party. Verification may require you to provide information that only you, as the data subject, would be expected to know.
If you are dissatisfied with how we have handled your request or believe we are processing your data unlawfully, you have the right to lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) in Brazil, or — if you are located in the EU/EEA — with the supervisory authority of your member state.
Children's Privacy
Our website and services are intended exclusively for business professionals and institutional clients operating within the life-sciences, clinical laboratory, and healthcare sectors. We do not knowingly direct our services toward individuals under the age of 18, and we do not knowingly collect personal data from children or adolescents.
If you are a parent or guardian and believe that your child has provided us with personal data without your knowledge or consent, please contact us immediately at [email protected]. We will take prompt steps to identify and delete any such data from our systems.
Where we become aware that we have inadvertently collected personal data from a person under the age of 18, we will delete it as quickly as technically feasible and, where required by the LGPD or applicable laws, we will notify the relevant supervisory authority.
Changes to This Policy
The digital landscape, the regulatory environment, and our own business practices evolve over time. We may therefore update this Privacy Policy periodically to reflect changes in applicable law, new technologies we adopt, new services we launch, or changes in our organisational structure.
When we make changes, we will update the "Last updated" date at the top of this page. Where changes are material — meaning they significantly affect the way we process your data or the rights available to you — we will take additional steps to bring them to your attention. This may include displaying a prominent notice on our website or, where we hold your email address and you have opted into communications from us, sending you a direct notification.
We encourage you to review this page periodically so that you remain informed about our current practices. Your continued use of the Zybro website following the publication of any updated version of this policy constitutes your acknowledgement of the revised terms, to the extent permitted by applicable law.
Previous versions of this Privacy Policy are available on request. To request a prior version, email us at [email protected] with the subject line "Privacy Policy – Historical Version Request".
Contact & Data Protection Officer
We have designated a Data Protection Officer (DPO) responsible for overseeing our compliance with data-protection obligations and acting as the primary point of contact for data-subject requests, complaints, and enquiries about this Privacy Policy or our broader data-handling practices.
If you have any questions, concerns, or requests relating to your personal data or this policy, please reach out to us using any of the contact details below. We are committed to providing a substantive, helpful response within the timeframes required by applicable law.
CNPJ: 67.850.285/0001-20
Registered Address: Rua Cristiano Viana, 62, Apt 225, Cerqueira César, São Paulo – SP, Brazil
Data Protection Email: [email protected]
Subject Line: Please include "Privacy / Data Protection" so your message reaches the DPO directly
Response Commitment: We acknowledge all privacy-related correspondence within 5 business days and aim to resolve straightforward requests within 30 days.
If you are based in the European Union and have concerns that we have not addressed satisfactorily, you also have the right to contact your local supervisory authority. A full list of EU data-protection authorities is available at the European Data Protection Board's website. For matters concerning Brazilian data subjects, the competent authority is the Autoridade Nacional de Proteção de Dados (ANPD), reachable at www.gov.br/anpd.