Legal
LGPD — data protection.
Last updated: June 7, 2026
Translation provided for convenience; in case of any discrepancy, the Portuguese version prevails.
Theravus processes personal data — including sensitive health data — in accordance with the Brazilian General Data Protection Law (LGPD — Law 13.709/2018) and with the resolutions of the Federal Council of Psychology (Conselho Federal de Psicologia — CFP) and of the Federal Council of Medicine (Conselho Federal de Medicina — CFM). This page is the reference center on the subject; it complements the Privacy Policy and the Terms of Use.
1. Roles: controller and processor
The LGPD distinguishes between whoever decides on the processing (controller) and whoever carries it out on behalf of another (processor — Art. 5, VI and VII):
- Patient data: the clinic or the healthcare professional is the controller — it defines which data is collected and for what purpose. Theravus acts as processor, processing this data strictly in accordance with the controller's instructions and our Data Processing Agreement (DPA) (in Portuguese).
- Data of the professional/clinic itself (account, billing, platform usage): here Theravus is the controller.
2. Legal bases for processing
All processing relies on at least one legal basis of the LGPD. Ordinary data follows Art. 7; sensitive health data follows Art. 11, predominantly the protection of health by a healthcare professional. Main purposes:
| Purpose | Data | Legal basis |
|---|---|---|
| Provision of the service (account, clinical record, schedule, billing) | Professional's identification and contact details, subscription data | Performance of a contract (Art. 7, V) |
| Patient clinical record (clinical record, progress notes, attachments) | Patient's sensitive health data | Protection of health, by a healthcare professional (Art. 11, II, "f") |
| AI features (summaries, transcriptions, analyses) with prior anonymization | Clinical content without direct identifiers | Protection of health + legitimate interest, with safeguards (Art. 11, II + Art. 7, IX) |
| Reminders and messaging with the patient (email, WhatsApp, SMS) | Name, contact details, appointment data | Performance of a contract + consent of the data subject (Art. 7, I and V) |
| Billing and issuance of tax documents | Billing and payment data | Compliance with a legal/regulatory obligation (Art. 7, II) |
| Security, fraud prevention and audit trail | Access logs, IP, device | Legitimate interest + legal obligation (Art. 7, IX and II) |
| Marketing and communication (newsletter, leads) | Name and email of leads/subscribers | Consent, revocable at any time (Art. 7, I) |
3. Sensitive health data
Clinical records, diagnoses, prescriptions, session recordings, transcriptions and questionnaire responses are sensitive personal data (Art. 5, II). Their processing is restricted to the purposes of protecting health and supporting clinical practice, with reinforced professional confidentiality. This data is never used for advertising, sold, or exposed to other tenants. Access is segregated by clinic and recorded in an audit trail.
4. Artificial intelligence features
The AI features (summaries, behavioral analyses, transcriptions, suggestions) operate, by default, on content with prior anonymization of direct identifiers (name, CPF, contact details). The outputs are auxiliary and must be reviewed by the professional before any clinical use — they do not replace human judgment. The professional can disable the AI features per patient or for the entire clinic in Settings → AI.
5. Your rights (Art. 18)
As a data subject, you may exercise at any time:
| Right | What it means |
|---|---|
| Confirmation and access | Know whether we process your data and obtain a copy of it. |
| Correction | Update incomplete, inaccurate or outdated data. |
| Anonymization, blocking or deletion | Of unnecessary or excessive data, or data processed in breach of the LGPD. |
| Portability | Receive your data in a structured and interoperable format (export). |
| Deletion of data processed with consent | Except in cases of mandatory retention (e.g., clinical record for the period set by the CFP). |
| Information about sharing | Know with which processors and third parties your data is shared. |
| Information about refusing consent | Know the consequences of refusing consent to a processing activity. |
| Revocation of consent | Withdraw, at any time, consent previously given. |
| Review of automated decisions | Request human review of decisions made solely by automated processing. |
How to exercise them: professionals use Settings → Privacy to export or request deletion of their data. Patients have their own channel in the patient portal. In both cases, you may also contact our Data Protection Officer via WhatsApp. We respond within 15 days. When Theravus acts as processor, we forward the request to the responsible controller (clinic/professional).
6. Data Protection Officer (DPO)
In accordance with Art. 41 of the LGPD, Theravus maintains a Data Protection Officer (DPO) responsible for receiving communications from data subjects and from the ANPD and for guiding the team on data protection practices. Contact: WhatsApp or through the contact channel on this website.
7. Sharing and processors
We share data only with processors strictly necessary for providing the service (hosting, database, payment gateway, email delivery, WhatsApp and AI providers), all under a processor agreement (Art. 39). The up-to-date list is available in the Privacy Policy. We do not sell personal data.
8. International data transfer
Some processors (for example, AI and infrastructure providers) may process data outside Brazil. In such cases, the transfer complies with the cases set out in Art. 33 of the LGPD — contractual protection clauses, safeguards equivalent to those of Brazilian law and minimization/anonymization whenever possible.
9. Information security
We adopt technical and administrative measures (Arts. 46 to 49): encryption in transit (TLS 1.3), password hashing (bcrypt), data segregation by tenant, optional two-factor authentication, principle of least privilege, audit trail of sensitive actions and backups with automatic purging.
10. Security incidents
In the event of an incident that may result in relevant risk or harm to data subjects, we will notify the Brazilian National Data Protection Authority (ANPD) and the affected data subjects within a reasonable time (Art. 48), informing the nature of the data, the persons involved, the measures adopted and the mitigation recommendations. When we act as processor, we notify the controller immediately.
11. Data of children and adolescents
When the patient is a child or adolescent, the processing complies with Art. 14 of the LGPD and the best interests of the minor: the data is provided and managed by the responsible professional, with specific consent from at least one of the parents or the legal guardian, obtained by the controller.
12. Retention and disposal
Each data category has its own retention period — clinical records, for example, follow the CFP legal minimum. The complete periods and the disposal procedure are set out in the Data Retention Policy (in Portuguese).
13. Complaint to the ANPD
If you believe your rights have not been upheld, you may file a petition with the Brazilian National Data Protection Authority (ANPD) through the official channels at gov.br/anpd. Before doing so, we recommend contacting our Data Protection Officer — we usually resolve matters faster.
14. Related documents
- Privacy Policy — collection, use and processors.
- Terms of Use — platform conditions.
- Data Processing Agreement (DPA) (in Portuguese) — processor ↔ controller relationship.
- Data Retention Policy (in Portuguese) — periods and disposal.
- Cancellation Policy (in Portuguese) — termination and return of data.