Privacy Policy
Last updated: March 24, 2026
1. Who we are
Clinicerto is an electronic health records (EHR) platform developed and operated by Clinicerto Tecnologia em Saúde Ltda., headquartered in Brazil. For purposes of this Policy, we are the controller of the personal data of health professionals and clinics registered on the platform.
Patient data entered by a professional is processed by us as a processor, under the instructions of the responsible professional, who remains the controller of that information with respect to their patients.
2. Data we collect
2.1 Professional / clinic data
- Full name, email, phone number, and optionally CPF/CNPJ (Brazilian tax IDs).
- Professional registration number (CRM, CFM, CRP, CRO, etc.).
- Access credentials (email + hashed password or Google OAuth token).
- Account configuration preferences.
2.2 Patient data (entered by the professional)
This data is considered sensitive health data under Brazilian law (LGPD, Art. 5, II). It includes, as entered by the professional:
- Patient name, date of birth, sex, phone, and email.
- Clinical history, anamneses, visit records, and procedure notes.
- Documents and images attached to the medical record.
Clinicerto does not access patient clinical content for commercial or marketing purposes. Technical access is restricted to system support and maintenance operations, with the professional's express authorization.
2.3 Usage data and technical logs
- IP address, browser, operating system, and access timestamps.
- Aggregated usage events for performance analysis and product improvement.
3. How we use your data
| Purpose | Legal basis (LGPD) |
|---|---|
| Creating and managing your account | Contract performance (Art. 7, V) |
| Processing and storing patient records | Health protection (Art. 11, II, f) |
| Sending essential service communications | Contract performance (Art. 7, V) |
| Sending marketing communications (newsletters) | Consent (Art. 7, I) — revocable at any time |
| Security and fraud prevention | Legitimate interest (Art. 7, IX) |
| Compliance with legal obligations | Legal obligation (Art. 7, II) |
4. Data sharing
We do not sell or rent your data. We share only with:
- Infrastructure providers (Amazon Web Services) — data stored on servers in the sa-east-1 region (São Paulo, Brazil).
- OAuth authentication (Google) — only if you choose to sign in with Google.
- Public authorities — when required by law, court order, or to protect rights.
All subprocessors are subject to contractual confidentiality obligations.
5. International transfers
Data is stored primarily in Brazil (AWS sa-east-1). Some technical support activities may involve access from outside Brazil. In those cases, we apply the safeguards required by LGPD Art. 33 (standard contractual clauses or adequacy of the receiving country).
6. Data retention
- Account data: retained during the contract term and for up to 5 years after closure, per applicable health regulations.
- Patient records: retained for the minimum period required by Brazilian Federal Council of Medicine (CFM) rules (20 years for electronic records) or longer as required by the specialty.
- Technical logs: 90 days.
7. Your rights as a data subject
Under LGPD Art. 18, you may at any time request:
- Confirmation and access to your data.
- Correction of incomplete, inaccurate, or outdated data.
- Anonymization, blocking, or deletion of unnecessary or excessive data.
- Portability of your data to another provider.
- Deletion of data processed based on consent.
- Information about sharing performed.
- Revocation of consent, without affecting prior processing.
To exercise these rights, contact us at privacidade@clinicerto.com.br. We will respond within 15 business days.
8. Security
We adopt appropriate technical and organizational measures to protect your data, including: encrypted communications (TLS), securely hashed passwords (Argon2), role-based access control, and suspicious activity monitoring. In the event of an incident that may generate significant risk, we will notify the ANPD (Brazil's national data protection authority) and affected data subjects as required by law.
9. Cookies and similar technologies
We use strictly necessary cookies for authentication and session management. On the marketing site, we use analytical cookies to measure page performance. You can disable cookies in your browser, though this may affect functionality.
10. Data Protection Officer (DPO)
Our DPO can be reached at privacidade@clinicerto.com.br.
11. Changes to this Policy
We may update this Policy periodically. Material changes will be communicated by email or in-app notification at least 30 days in advance. The date at the top of the page always reflects the most recent version.
12. Contact us
Clinicerto Tecnologia em Saúde Ltda.
General: contato@clinicerto.com.br
Privacy: privacidade@clinicerto.com.br
Brazil